DPDP Act consent management platform
Consent you can prove.
Consentrio is a consent management platform for India's DPDP Act. Publish clear consent notices, collect and verify consent, honour withdrawals and rights requests, and keep a tamper-evident record of every decision.
Built for India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Ready for GDPR.

The consent lifecycle
- 01
Notice
Publish a clear, versioned notice for each purpose, in the languages your users read.
- 02
Consent
Collect consent in your web and mobile apps through our SDKs and APIs.
- 03
Verify
Check any user's consent for a purpose in real time before you process their data.
- 04
Change
Let users renew, update or withdraw; processors are notified automatically.
- 05
Prove
Show auditors and the Data Protection Board a tamper-evident record of every decision.
The product
One platform for your team and your users
A console for your privacy, legal and engineering teams, and a preference centre your users trust. Both run on the same consent record.

Active consents, published notices, upcoming expiries, open grievances and processor SLA breaches on one dashboard.
Features
Everything the DPDP Act asks of you, in one place
Consent notices
Versioned notices built from your purpose library, with translation workflows and drift alerts when a purpose changes after publishing.
Purposes & data categories
A single catalogue of why you process data and what you process, reused across every notice and report.
Collection SDKs & APIs
Cookie banner, web, Android and iOS SDKs and a Java server SDK, plus a fast consent-validation API your systems call before using data.
Preference centre
A branded portal where your users view, renew, update and withdraw consent and exercise their rights.
Grievances & rights requests
One inbox for access, correction, erasure and complaints, with SLA tracking, internal notes and Jira hand-off.
Processor notifications
HMAC-signed webhooks tell processors about every consent change, with retries, dead-lettering and SLA alerts.
Retention & legal holds
Retention policies per purpose, with legal holds that pause deletion when a dispute or investigation needs it.
Exports & archives
Consent and grievance archives, audit-trail PDFs and analytics CSVs for auditors and the board.
Team roles & MFA
Role-based access for admins, DPOs and operators, with multi-factor sign-in for every staff account.
Why now
The DPDP clock is running
The DPDP Rules were notified in November 2025 with an 18-month transition. Most obligations on Data Fiduciaries apply from May 2027. Consent systems take time to design, integrate and roll out across every product.
- ₹250 crore
- Maximum penalty per instance for failing to protect personal data
- May 2027
- Most Data Fiduciary obligations under the DPDP Rules take effect
- 72 hours
- To give the Board details of a personal-data breach
- Any time
- Data principals can withdraw consent, as easily as they gave it
Security & proof
A record auditors can check, not just trust
Consentrio is built so that every consent decision can be proven later, and nobody can quietly change the history.
Hash-chained audit trail
Each audit event carries the SHA-256 hash of the one before it. Any change breaks the chain, and you can verify any date range on demand.
Signed consent artifacts
Every consent is recorded as a cryptographically signed artifact that can be verified later.
Per-record encryption
Sensitive fields are encrypted with AES-256-GCM using a separate data key for each record.
Signed processor webhooks
Outbound notifications are HMAC-SHA256 signed, with zero-downtime secret rotation.
What is the DPDP Act?
The Digital Personal Data Protection Act, 2023 is India's data protection law. It requires organisations (Data Fiduciaries) to process personal data only with valid consent or for specific legitimate uses, give clear notices, let people withdraw consent and exercise their rights, protect the data, and report breaches. The DPDP Rules, 2025 set out the details.
DPDP Act consent requirements →When do DPDP obligations apply?
The DPDP Rules were notified in November 2025 and apply in phases. Consent Manager provisions start in November 2026, and most obligations on Data Fiduciaries, including notices, security, breach reporting and rights, apply from May 2027.
DPDP Rules 2025 timeline →Is Consentrio a registered Consent Manager?
No. Under the DPDP Act a Consent Manager is an entity registered with the Data Protection Board that acts for individuals. Consentrio is a consent management platform that Data Fiduciaries use to meet their own obligations: notices, consent capture, withdrawal, rights requests, grievances and proof of consent.
What is a Consent Manager under the DPDP Act? →What does a DPDP consent notice need to include?
Rule 3 requires a stand-alone notice in clear, plain language with an itemised description of the personal data and the specified purpose, the goods, services or uses it enables, and a link to withdraw consent, exercise rights and complain to the Data Protection Board. It must be available in English or any of the 22 Eighth Schedule languages.
Consent notice checklist →Does Consentrio work for GDPR as well?
Yes. Purpose-based consent, easy withdrawal, rights requests and an auditable consent record are core to both the DPDP Act and the GDPR, so the same setup supports both.
Pricing
Priced for your size and scope
Pricing depends on how many data principals you serve, the products you connect and the support you need. Tell us about your setup and we'll send a proposal.
- Annual plans in INR
- Onboarding and integration support
- A demo on your own use case
Or email sales@consentrio.com