Rule 4

Consent Manager registration opens — 13 Nov 2026

myconsent+
The Act · Provision map

Every data fiduciary obligation, mapped to the provision

6

duties, each mapped to a named control

Across 8 sections and 5 rules, read against the bare text

The provisions that govern consent, and the thing in the platform that discharges each one. Mapping is not certification — the evidence is yours to check, and this page exists so you can.

The matrix

Left: what the provision requires, in its own terms. Right: what the platform does about it.

Sec. 5 · Rule 3

Notice to the Data Principal

What it requires

An itemised notice, in English or any of the 22 Eighth Schedule languages, given before or at the point consent is requested.

The control

Versioned notice templates per purpose, with the exact text and language snapshotted into the consent record.

Sec. 6(1)

Consent Standard and Data Minimisation

What it requires

Free, specific, informed, unconditional and unambiguous, by clear affirmative action, and limited to the data necessary for the stated purpose.

The control

Purpose-scoped toggles with nothing pre-ticked, one record per purpose, and a diff trail whenever a purpose changes.

Sec. 6(4)–6(6)

Withdrawal of Consent

What it requires

Withdrawal at any time, as easy as granting was, after which the fiduciary and its processors must cease processing within a reasonable time.

The control

One-action withdrawal, downstream propagation over webhooks, and a cessation timestamp per system that acknowledged it.

Sec. 8(5)–(6) · Rules 6–7

Security Safeguards and Breach Reporting

What it requires

Reasonable safeguards to prevent a breach; affected principals intimated without delay and a detailed report to the Board within 72 hours.

The control

Encryption at rest and in transit, role-based access, logs retained for a year, and a breach workflow that runs the 72-hour clock.

Sec. 11–14 · Rule 14

Rights of the Data Principal

What it requires

Access to information about processing, correction and erasure, grievance redressal, and the right to nominate.

The control

A rights portal with identity verification, an SLA clock per request type, and the nomination held with the consent artefact.

Sec. 16 · Rule 15

Cross-Border Transfer

What it requires

Transfer is permitted except to countries the Central Government restricts, and sectoral conditions still apply.

The control

Geo-fenced storage with a transfer register, enforced at the point of write rather than in a policy document.

Ask yourself

Ten questions a Data Fiduciary has to be able to answer

These are not claims about us. They are what the Act puts to you, with the provision each one comes from. If any answer is “we would have to go and look”, that is the finding.

  1. 01Every purpose is itemised, with nothing bundled
  2. 02Notice carries every required particular, in a language the person reads
  3. 03Consent is a clear affirmative action, with nothing pre-ticked
  4. 04Withdrawal is as easy as granting was, and processing stops
  5. 05Consent records can be reproduced with the notice the person actually saw
  6. 06Rights requests have an owner and a published response window
  7. 07A named grievance officer is reachable, and the route is published
  8. 08A breach can be reported to the Board within 72 hours
  9. 09Retention has a clock per purpose, and erasure actually runs
  10. 10Cross-border destinations are checked against the restricted list

Sec. 13 · Rule 14

The duty most platforms answer with a mailbox

A grievance is a statutory obligation with a named officer, a published route and a response window. Every request in the queue has an owner and a clock, and the clock is visible before it runs out rather than after.

Admin Console — Grievance Console
myconsent+ADMIN
ComplianceDashboardPurpose RegistryEvidence & SearchGrievance Console

Grievance console

Every request has an owner and a clock. Sec. 13 · Rule 14

GRV-2026-0142Correction — employment datesOpened 04 Aug 20263 days left
GRV-2026-0139Erasure after exitOpened 02 Aug 20261 day left
GRV-2026-0131Access — processing summaryOpened 28 Jul 2026Answered
Requests sort by time remaining, not by arrival. A request that will breach its window is the first thing on the screen.

What changes

Seven areas, before and after

AreaTodayWith myconsent+
Consent CaptureManual, error-proneAutomated, contextual, granular
Data MappingSpreadsheet-basedAI-driven, real-time discovery
Audit TrailsDisconnected logsAppend-only, hash-chained and verifiable
DSR ResponseDays/weeksReal-time automated fulfillment
Breach DetectionManual monitoringAutomated, instant notification
Cross-BorderNo controlsGeo-fenced, localized enforcement
ReportingQuarterly manualOn-demand, one-click regulatory

Bring a purpose you actually collect consent for

We will build it live — the notice, the capture, the withdrawal, and the evidence you would hand the Board. Thirty minutes, no slides.

Questions people ask

What is a Data Fiduciary under the DPDP Act?
Any person who, alone or with others, determines the purpose and means of processing personal data. It is the DPDP equivalent of a controller, and the duties on notice, consent, safeguards, rights and breach reporting attach to it rather than to a processor.
What is a Significant Data Fiduciary?
A Data Fiduciary the Central Government notifies as significant, judged on volume and sensitivity of data, risk to Data Principals, and effect on sovereignty, electoral democracy and public order. It carries extra duties: a Data Protection Officer in India, an independent auditor, and periodic impact assessment.
What are the main obligations of a Data Fiduciary?
Give notice under Sec. 5. Take valid consent under Sec. 6(1) and honour withdrawal under Sec. 6(4). Keep reasonable security safeguards under Sec. 8(5) and report breaches under Sec. 8(6). Answer rights requests under Sec. 11 to 14. Observe Sec. 16 on cross-border transfer.
What are the penalties for a Data Fiduciary?
The Schedule sets ceilings imposed by the Board under Sec. 33. The largest, ₹250 crore, attaches to failing to take reasonable security safeguards. Failure to notify a breach reaches ₹200 crore, as does breach of the obligations on children's data.
Is a Data Fiduciary the same as a data controller under the GDPR?
Functionally close, but not identical. Both determine purpose and means. The DPDP Act has no separate category for sensitive data, a narrower set of lawful bases, and its own Significant Data Fiduciary tier with duties the GDPR places on controllers generally.