gavelDPDP COMPLIANCE

DPDP Act 2023 Compliance

The provisions that govern consent, and the control in the platform that answers each one. Mapping is not certification — the evidence is yours to check.

Sec. 5 · Rule 3

Notice to the Data Principal

Control mapped

An itemised notice, in English or any of the 22 Eighth Schedule languages, given before or at the point consent is requested.

buildTechnical Control

Versioned notice templates per purpose, with the exact text and language snapshotted into the consent record.

Sec. 6(1)

Consent Standard and Data Minimisation

Control mapped

Free, specific, informed, unconditional and unambiguous, by clear affirmative action, and limited to the data necessary for the stated purpose.

buildTechnical Control

Purpose-scoped toggles with nothing pre-ticked, one record per purpose, and a diff trail whenever a purpose changes.

Sec. 6(4)–6(6)

Withdrawal of Consent

Control mapped

Withdrawal at any time, as easy as granting was, after which the fiduciary and its processors must cease processing within a reasonable time.

buildTechnical Control

One-action withdrawal, downstream propagation over webhooks, and a cessation timestamp per system that acknowledged it.

Sec. 8(5)–(6) · Rules 6–7

Security Safeguards and Breach Reporting

Control mapped

Reasonable safeguards to prevent a breach; affected principals intimated without delay and a detailed report to the Board within 72 hours.

buildTechnical Control

Encryption at rest and in transit, role-based access, logs retained for a year, and a breach workflow that runs the 72-hour clock.

Sec. 11–14 · Rule 14

Rights of the Data Principal

Control mapped

Access to information about processing, correction and erasure, grievance redressal, and the right to nominate.

buildTechnical Control

A rights portal with identity verification, an SLA clock per request type, and the nomination held with the consent artefact.

Sec. 16 · Rule 15

Cross-Border Transfer

Control mapped

Transfer is permitted except to countries the Central Government restricts, and sectoral conditions still apply.

buildTechnical Control

Geo-fenced storage with a transfer register, enforced at the point of write rather than in a policy document.

checklistWhat a Data Fiduciary must be able to answer

Not a list of claims about us. These are the questions the Act puts to you, with the provision each one comes from.

check_circleEvery purpose is itemised, with nothing bundled — Sec. 6(1)
check_circleNotice carries every required particular, in a language the person reads — Sec. 5, Rule 3
check_circleConsent is a clear affirmative action, with nothing pre-ticked — Sec. 6(1)
check_circleWithdrawal is as easy as granting was, and processing stops — Sec. 6(4), 6(6)
check_circleConsent records can be reproduced with the notice the person actually saw
check_circleRights requests have an owner and a published response window — Sec. 11–14, Rule 14
check_circleA named grievance officer is reachable, and the route is published — Sec. 13
check_circleA breach can be reported to the Board within 72 hours — Sec. 8(6), Rule 7
check_circleRetention has a clock per purpose, and erasure actually runs — Sec. 8(7), Rule 8
check_circleCross-border destinations are checked against the restricted list — Sec. 16, Rule 15

compare_arrowsBefore vs After MyConsent+

AreaBeforeAfter MyConsent+
Consent CaptureManual, error-proneAutomated, contextual, granular
Data MappingSpreadsheet-basedAI-driven, real-time discovery
Audit TrailsDisconnected logsAppend-only, hash-chained and verifiable
DSR ResponseDays/weeksReal-time automated fulfillment
Breach DetectionManual monitoringAutomated, instant notification
Cross-BorderNo controlsGeo-fenced, localized enforcement
ReportingQuarterly manualOn-demand, one-click regulatory