Rule 4

Consent Manager registration opens — 13 Nov 2026

myconsent+

Consent Management Platform

Consent management platform, built for the DPDP Act

From multilingual notice generation to a tamper-evident audit trail. Penalties under the Schedule reach ₹250 crore for failing to take reasonable safeguards — this is the platform that produces the record you would defend with.

Scheduled languages
22
Sec. 5(3)
Record per purpose
1
Sec. 6(1)
Pre-ticked boxes
0
Sec. 6(1)
Withdrawal parity, by design
6(4)
The Act
Admin Console — Evidence & Search
myconsent+ADMIN
ComplianceDashboardPurpose RegistryEvidence & SearchGrievance Console

Consent evidence & search

Every consent event, with the digest that proves it has not moved

Export audit pack
Principal — ID or email
Purpose
Event
TimestampPrincipalPurposeEventDigest
06 Aug 2026, 08:02 pmAnanya SharmaPayroll processingNotice serveda3f8d2e1…
06 Aug 2026, 06:45 pmRahul MehtaBenefits sharingWithdrawnb7c9e4f2…
06 Aug 2026, 05:15 pmPriya PatelBiometric attendanceGrantedc1d2f3a4…
05 Aug 2026, 02:30 pmSneha ReddyWellness analyticsExpiringe6f7b8c9…
05 Aug 2026, 11:08 amVikram NairPayroll processingGrantedd4e5a6b7…
Filter by principal, purpose or event; export the audit pack from whatever the filter leaves. The digest column is the chain, not a row identifier.

Core capabilities

Four things the Act makes non-negotiable

Sec. 5 · Rule 322 languages

Multilingual privacy notices

Auto-generate DPDP-compliant consent notices in all 22 scheduled Indian languages. Templates carry every particular Sec. 5 and Rule 3 require, out of the box.

22 languages supported

Sec. 8(5)Hash-chained

Tamper-evident audit ledger

Every consent event is appended to a hash-chained trail, so a record cannot be altered after the fact without the chain failing verification. Zero-knowledge proofs, which would let the Board verify without seeing the data at all, are on the roadmap.

Append-only and verifiable

Sec. 6(1)One record per purpose

Granular purpose-based consent

Capture consent at the data-element level. Each purpose is individually togglable, auditable, and mapped to specific DPDP Act provisions with full lifecycle tracking.

Element-level granularity

Sec. 6(4)Withdrawal parity

One-action withdrawal

Data Principals can withdraw consent as easily as they granted it — a statutory requirement under DPDP. Automated downstream propagation to all processing systems.

Instant propagation

Quick start

Four steps, in this order

Step four is the one that matters. Capturing consent is easy; making a withdrawal reach every system that holds the data is the obligation the Act actually enforces.

  1. 01

    Install the SDK

    npm install @myconsentplus/sdk
  2. 02

    Initialise the client

    const mc = new MyConsent({ tenantId: "..." });
  3. 03

    Capture consent

    await mc.consent.create({ userId, purposes });
  4. 04

    Wire withdrawal

    mc.events.on("consent.withdrawn", ...)

Both dates are closer than they look

Consent Manager registration opens 13 November 2026 and the full duty set commences 13 May 2027. No grace period is expected, and the work between here and there is notice templates, purpose registries and downstream wiring — none of which compresses well.

Working out where to start? The DPDP compliance checklist orders the twelve things by dependency, and the provision map names the control that answers each duty.

Questions people ask

What is a consent management platform?
Software that collects consent, records what it was for, and lets a person withdraw it. Under the DPDP Act it also has to generate the Sec. 5 notice, hold one record per purpose under Sec. 6(1), and produce that record when the Board asks.
Is a consent management platform mandatory under the DPDP Act?
No. The Act names no software. It requires notice, valid consent, withdrawal at parity, and evidence you can produce — obligations that fall on the Data Fiduciary whether a platform exists or not.
What is the difference between a CMP and a Consent Manager?
A consent management platform collects consent for one organisation's own processing. A Consent Manager is a role registered under Rule 4 that acts for the Data Principal across many Data Fiduciaries. The first is software you buy; the second is a regulated position.
Is consent collected before commencement still valid?
Yes, and it does not lapse on 13 May 2027. Sec. 5(2) requires a notice for pre-commencement consent as soon as is reasonably practicable and lets processing continue until the Data Principal withdraws. The work is noticing that existing base, not rebuilding its consent from nothing.
How does withdrawal reach systems that already hold the data?
A withdrawal fires a webhook to every subscribed system — sending platforms, advertising audiences, the warehouse — and each acknowledgement is timestamped into the ledger. A withdrawal recorded only in the consent store has not been honoured.