Consent Management Platform
Consent management platform, built for the DPDP Act
From multilingual notice generation to a tamper-evident audit trail. Penalties under the Schedule reach ₹250 crore for failing to take reasonable safeguards — this is the platform that produces the record you would defend with.
- Scheduled languages
- 22
- Sec. 5(3)
- Record per purpose
- 1
- Sec. 6(1)
- Pre-ticked boxes
- 0
- Sec. 6(1)
- Withdrawal parity, by design
- 6(4)
- The Act
Consent evidence & search
Every consent event, with the digest that proves it has not moved
| Timestamp | Principal | Purpose | Event | Digest |
|---|---|---|---|---|
| 06 Aug 2026, 08:02 pm | Ananya Sharma | Payroll processing | Notice served | a3f8d2e1… |
| 06 Aug 2026, 06:45 pm | Rahul Mehta | Benefits sharing | Withdrawn | b7c9e4f2… |
| 06 Aug 2026, 05:15 pm | Priya Patel | Biometric attendance | Granted | c1d2f3a4… |
| 05 Aug 2026, 02:30 pm | Sneha Reddy | Wellness analytics | Expiring | e6f7b8c9… |
| 05 Aug 2026, 11:08 am | Vikram Nair | Payroll processing | Granted | d4e5a6b7… |
Core capabilities
Four things the Act makes non-negotiable
Multilingual privacy notices
Auto-generate DPDP-compliant consent notices in all 22 scheduled Indian languages. Templates carry every particular Sec. 5 and Rule 3 require, out of the box.
22 languages supported
Tamper-evident audit ledger
Every consent event is appended to a hash-chained trail, so a record cannot be altered after the fact without the chain failing verification. Zero-knowledge proofs, which would let the Board verify without seeing the data at all, are on the roadmap.
Append-only and verifiable
Granular purpose-based consent
Capture consent at the data-element level. Each purpose is individually togglable, auditable, and mapped to specific DPDP Act provisions with full lifecycle tracking.
Element-level granularity
One-action withdrawal
Data Principals can withdraw consent as easily as they granted it — a statutory requirement under DPDP. Automated downstream propagation to all processing systems.
Instant propagation
Quick start
Four steps, in this order
Step four is the one that matters. Capturing consent is easy; making a withdrawal reach every system that holds the data is the obligation the Act actually enforces.
- 01
Install the SDK
npm install @myconsentplus/sdk - 02
Initialise the client
const mc = new MyConsent({ tenantId: "..." }); - 03
Capture consent
await mc.consent.create({ userId, purposes }); - 04
Wire withdrawal
mc.events.on("consent.withdrawn", ...)
Both dates are closer than they look
Consent Manager registration opens 13 November 2026 and the full duty set commences 13 May 2027. No grace period is expected, and the work between here and there is notice templates, purpose registries and downstream wiring — none of which compresses well.
Working out where to start? The DPDP compliance checklist orders the twelve things by dependency, and the provision map names the control that answers each duty.
Questions people ask
- What is a consent management platform?
- Software that collects consent, records what it was for, and lets a person withdraw it. Under the DPDP Act it also has to generate the Sec. 5 notice, hold one record per purpose under Sec. 6(1), and produce that record when the Board asks.
- Is a consent management platform mandatory under the DPDP Act?
- No. The Act names no software. It requires notice, valid consent, withdrawal at parity, and evidence you can produce — obligations that fall on the Data Fiduciary whether a platform exists or not.
- What is the difference between a CMP and a Consent Manager?
- A consent management platform collects consent for one organisation's own processing. A Consent Manager is a role registered under Rule 4 that acts for the Data Principal across many Data Fiduciaries. The first is software you buy; the second is a regulated position.
- Is consent collected before commencement still valid?
- Yes, and it does not lapse on 13 May 2027. Sec. 5(2) requires a notice for pre-commencement consent as soon as is reasonably practicable and lets processing continue until the Data Principal withdraws. The work is noticing that existing base, not rebuilding its consent from nothing.
- How does withdrawal reach systems that already hold the data?
- A withdrawal fires a webhook to every subscribed system — sending platforms, advertising audiences, the warehouse — and each acknowledgement is timestamped into the ledger. A withdrawal recorded only in the consent store has not been honoured.