Consentrio

DPDP Act consent management platform

Consent you can prove.

Consentrio is a consent management platform for India's DPDP Act. Publish clear consent notices, collect and verify consent, honour withdrawals and rights requests, and keep a tamper-evident record of every decision.

See the product

Built for India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Ready for GDPR.

Consentrio dashboard showing active consents, notices, expiries, grievances and consent trends

The consent lifecycle

  1. 01

    Notice

    Publish a clear, versioned notice for each purpose, in the languages your users read.

  2. 02

    Consent

    Collect consent in your web and mobile apps through our SDKs and APIs.

  3. 03

    Verify

    Check any user's consent for a purpose in real time before you process their data.

  4. 04

    Change

    Let users renew, update or withdraw; processors are notified automatically.

  5. 05

    Prove

    Show auditors and the Data Protection Board a tamper-evident record of every decision.

The product

One platform for your team and your users

A console for your privacy, legal and engineering teams, and a preference centre your users trust. Both run on the same consent record.

Data Fiduciary console: Compliance at a glance

Active consents, published notices, upcoming expiries, open grievances and processor SLA breaches on one dashboard.

Features

Everything the DPDP Act asks of you, in one place

Consent notices

Versioned notices built from your purpose library, with translation workflows and drift alerts when a purpose changes after publishing.

Purposes & data categories

A single catalogue of why you process data and what you process, reused across every notice and report.

Collection SDKs & APIs

Cookie banner, web, Android and iOS SDKs and a Java server SDK, plus a fast consent-validation API your systems call before using data.

Preference centre

A branded portal where your users view, renew, update and withdraw consent and exercise their rights.

Grievances & rights requests

One inbox for access, correction, erasure and complaints, with SLA tracking, internal notes and Jira hand-off.

Processor notifications

HMAC-signed webhooks tell processors about every consent change, with retries, dead-lettering and SLA alerts.

Retention & legal holds

Retention policies per purpose, with legal holds that pause deletion when a dispute or investigation needs it.

Exports & archives

Consent and grievance archives, audit-trail PDFs and analytics CSVs for auditors and the board.

Team roles & MFA

Role-based access for admins, DPOs and operators, with multi-factor sign-in for every staff account.

Why now

The DPDP clock is running

The DPDP Rules were notified in November 2025 with an 18-month transition. Most obligations on Data Fiduciaries apply from May 2027. Consent systems take time to design, integrate and roll out across every product.

₹250 crore
Maximum penalty per instance for failing to protect personal data
May 2027
Most Data Fiduciary obligations under the DPDP Rules take effect
72 hours
To give the Board details of a personal-data breach
Any time
Data principals can withdraw consent, as easily as they gave it

Security & proof

A record auditors can check, not just trust

Consentrio is built so that every consent decision can be proven later, and nobody can quietly change the history.

Hash-chained audit trail

Each audit event carries the SHA-256 hash of the one before it. Any change breaks the chain, and you can verify any date range on demand.

Signed consent artifacts

Every consent is recorded as a cryptographically signed artifact that can be verified later.

Per-record encryption

Sensitive fields are encrypted with AES-256-GCM using a separate data key for each record.

Signed processor webhooks

Outbound notifications are HMAC-SHA256 signed, with zero-downtime secret rotation.

FAQ

DPDP consent, answered

More detail in our DPDP Act guides.

What is the DPDP Act?

The Digital Personal Data Protection Act, 2023 is India's data protection law. It requires organisations (Data Fiduciaries) to process personal data only with valid consent or for specific legitimate uses, give clear notices, let people withdraw consent and exercise their rights, protect the data, and report breaches. The DPDP Rules, 2025 set out the details.

DPDP Act consent requirements →
When do DPDP obligations apply?

The DPDP Rules were notified in November 2025 and apply in phases. Consent Manager provisions start in November 2026, and most obligations on Data Fiduciaries, including notices, security, breach reporting and rights, apply from May 2027.

DPDP Rules 2025 timeline →
Is Consentrio a registered Consent Manager?

No. Under the DPDP Act a Consent Manager is an entity registered with the Data Protection Board that acts for individuals. Consentrio is a consent management platform that Data Fiduciaries use to meet their own obligations: notices, consent capture, withdrawal, rights requests, grievances and proof of consent.

What is a Consent Manager under the DPDP Act? →
What does a DPDP consent notice need to include?

Rule 3 requires a stand-alone notice in clear, plain language with an itemised description of the personal data and the specified purpose, the goods, services or uses it enables, and a link to withdraw consent, exercise rights and complain to the Data Protection Board. It must be available in English or any of the 22 Eighth Schedule languages.

Consent notice checklist →
Does Consentrio work for GDPR as well?

Yes. Purpose-based consent, easy withdrawal, rights requests and an auditable consent record are core to both the DPDP Act and the GDPR, so the same setup supports both.

Pricing

Priced for your size and scope

Pricing depends on how many data principals you serve, the products you connect and the support you need. Tell us about your setup and we'll send a proposal.

  • Annual plans in INR
  • Onboarding and integration support
  • A demo on your own use case

Or email sales@consentrio.com