— days until 13 May 2027, when the DPDP Rules apply in full
Ask in her language. Prove it to the Board.
DPConsent gives Indian websites and apps a DPDP notice in all 22 scheduled languages, verified parental consent, a 72-hour breach clock, and consent records sealed so that nobody can quietly change them later.
We ask before we track you
Privacy policy Complain to the Data Protection Board of India
What the Act can cost
The Schedule to the DPDP Act sets a ceiling for each kind of failure. These are maximums per breach, and the Data Protection Board decides the actual amount. A single incident can fall under more than one line.
A cookie banner covers only a small part of this. The Act applies to all digital personal data: sign-up forms, apps, support tickets, loyalty programmes.
- ₹250 crore No reasonable security safeguards against a breach Section 8(5)
- ₹200 crore Not telling the Board and each affected person about a breach Section 8(6), Rule 7
- ₹200 crore Children: no verifiable parental consent, or tracking and targeting them Section 9, Rule 10
- ₹150 crore Significant Data Fiduciaries skipping their yearly assessment and audit Section 10, Rule 13
- ₹50 crore Anything else in the Act or the Rules: notice, consent, rights, retention Schedule, item 7
How ready are you for 13 May 2027?
Nine questions, about two minutes. You get a score, the rule each gap falls under, the maximum penalty attached to it, and what closes it.
A notice that meets Rule 3, piece by piece
Rule 3 asks for more than "we use cookies". Point at a requirement to see where it lives in the preference panel.
Children, and people who consent through a guardian
Section 9 needs a parent's verifiable consent and forbids tracking, behavioural monitoring and targeted advertising of children. DPConsent enforces the second part by itself, so a misconfigured tag cannot slip through.
She agrees to everything. Every purpose she accepted is released.
Schools, crèches, clinics and school transport can rely on the Fourth Schedule exemptions in Rule 12. Mark a purpose as exempt and a child's consent to it needs no parent, while tracking purposes stay refused.
Records that give themselves away when edited
Section 6(10) puts the burden of proof on you: if a customer says she never agreed, you have to show she did. Each change to a DPConsent record is sealed to the one before it. Try editing history.
- Signed receipts. Any record exports as an Ed25519-signed receipt that anyone can check against your public key, without access to your systems.
- Daily anchors. Each day's sealed events are folded into a signed Merkle root and sent to your webhooks, so you hold a copy the system cannot rewrite.
- The exact wording she saw. Every record points at a frozen, hashed version of the notice, not at whatever the notice says today.
This demonstration hashes the records in your browser with SHA-256, the way the platform seals them.
The deadlines the Act sets, and who keeps them
Each of these starts a timer. DPConsent runs the timer and warns you before it ends.
- 48 hours Warn a person before their data is erased for inactivity A webhook goes out so you can tell them. Rule 8(2)
- 72 hours Send the Board a full breach report The breach register counts down and drafts the report and the notice to people. Rule 7
- 90 days Answer an access, correction, erasure, grievance or nomination request Requests are due inside your own deadline, capped at 90 days, with a reminder five days before. Rule 14(3)
- 1 year Keep processing logs at the very least Evidence retention cannot be set below 365 days. Rule 6(1)(e)
- 3 years Erase inactive users of large e-commerce, gaming and social platforms Report activity with one call; erasure happens on schedule. Rule 8, Third Schedule
Every duty, mapped to where it lives
Send this table to your lawyer. Filter by the part of the law you care about.
| Duty | Where | How DPConsent meets it |
|---|
What changes for your sector
Live on your site the day you add it
- Add one script. It works out where the visitor is, shows the right notice and holds every tracker until she answers.
- Publish your notice. Pick purposes from the library, each with its data already itemised, then add your wording in every language.
- Gate your own code. Anything that needs consent waits for it:
whenGranted('marketing').
Also for WordPress, Shopify, Google Tag Manager, npm, Node, Python, Android and iOS, plus hosted privacy and request pages you can link to.
Watch a rule change reach a live shop
An Indian storefront, the console, and a new purpose added and re-consented, recorded in one take.
Hosted and run by DPConsent
Nothing to install beyond the script. We run the platform and keep it up to date.
Everything included
- English and all 22 scheduled languages
- Signed receipts and daily anchors
- Children’s consent and guardian verification
- Rights requests on the statutory clock
- A 72-hour breach register
- Hosted privacy and request pages
- Android, iOS, Node and Python SDKs
- Two-person approval before publishing
- A/B tests on your wording
Compared with the usual options
| Capability | Global cookie banner tools | Spreadsheets and legal templates | DPConsent Consent |
|---|---|---|---|
| Notice in all 22 scheduled languages | A few Indian languages at most | If you translate it yourself | Included |
| Itemised data under every purpose | Usually not | In a document, not in the notice | Built into each purpose |
| Verifiable parental consent | No | Manual | DigiLocker token, parent account or ID document |
| No tracking of children, enforced | No | No | Refused automatically |
| Proof a record was never edited | A log of clicks | No | Sealed chain and signed receipts |
| 72-hour breach register | No | Email and a calendar | Countdown, Board report and notice drafts |
| Rights requests on a 90-day clock | Sometimes | Inbox | Included, with reminders |
Questions teams ask before they switch
We already have a cookie banner. Isn't that enough?
No. The DPDP Act covers all digital personal data, not just cookies: sign-up and checkout forms, apps, support and loyalty data. It also asks for things a banner doesn't do: an itemised notice, a language of her choice, proof of what she agreed to, rights requests, breach reporting and erasure.
When do the obligations actually start?
The Rules were notified on 13 November 2025. The Data Protection Board came into being straight away, Consent Managers can register from November 2026, and the notice, consent, security, breach, children and rights obligations apply from 13 May 2027.
Where is our data stored?
On DPConsent’s cloud: we run the platform, so there is nothing for you to host. Identifiers are stored as keyed hashes, so the database never holds the raw email or phone number.
Does it work for mobile apps and our backend?
Yes. There are SDKs for Android, iOS, Node and Python, and your server can record consent directly, including a parent's consent for a child, which a browser is never allowed to record.
How long does it take to go live?
A website is live as soon as the script is added and a notice is published. Most of the time goes into agreeing the wording with your lawyers, and the purpose library gives you a start on that.
Is this legal advice?
No. DPConsent gives you the tools the Act and Rules expect. Your counsel decides how they apply to your business.
Get DPDP-ready before 13 May 2027
Tell us about your business and we'll take you through the notice, the children flow and the evidence with your own sector in mind. If you've taken the readiness check, your answers come with the request.
— days left