Consent Management

Prove Every Consent, Forever

Court-admissible cryptographic proof for every consent event. Drop-in SDK, 2 lines of code, works on any framework.

Your penalty exposure
₹250Crinvalid consent (S.5 & S.6)

Without consent records, every personal data record in your database is a potential liability. You have no legal proof any user agreed to anything.

From zero to proof vault in under 30 minutes

1
Build your notice
Use the WYSIWYG builder to create a consent notice with version control and multi-language support.
2
Embed the SDK
Drop 2 lines of JS on any page. The <12KB widget renders your notice and collects consent.
3
User consents
The user reads the notice, selects purposes, and submits consent.
4
Proof generated
SHA-256 cryptographic hash created immediately and stored in WORM-protected proof vault.
5
Audit trail ready
Every event is immutably logged. Download court-admissible proof at any time.

Everything to prove consent at audit time

Core

WYSIWYG Consent Notice Builder

Drag-and-drop editor with purpose blocks, version history, and one-click publish. No developer needed.

Drop-in JS SDK (<12KB)

Two lines of JavaScript. Works on any framework — React, Vue, plain HTML. Lazy-loaded, non-blocking.

SHA-256 Cryptographic Proof

Every consent event hashed with SHA-256 and timestamped. Provably unalterable.

WORM Proof Vault

Consent records stored in write-once, read-many (WORM) storage. Cannot be deleted or modified.

Re-consent Campaign Engine

Policy changed? Auto-detect affected users and send targeted re-consent emails with one click.

22 Scheduled Indian Languages

Full translation support for all 22 languages listed in the DPDP Act. Auto-translate or manage manually.

<12KB
SDK bundle size
22
Indian languages
< 2s
Median integration
₹250Cr
Penalty coverage
Available from Starter plan onwards

All plans include SDK access, WORM proof vault, and consent analytics.

Common questions

What makes a consent notice valid under DPDPA?+

Under DPDPA S.6, consent must be free, specific, informed, unconditional, and unambiguous. It must be given through a clear affirmative action — pre-ticked boxes and bundled consent for multiple purposes are explicitly invalid. Each processing purpose requires its own separate consent item with a timestamped, cryptographic record of the consent event.

How does DPDPA Shield prove consent was given?+

Every consent event captured through DPDPA Shield's SDK widget is stored as an immutable proof record containing the notice version shown, timestamp, user identifier, specific purposes consented to, and the action taken. This record is SHA-256 hashed and can be produced on demand for Board audits or legal proceedings.

What happens when a user withdraws consent?+

DPDPA Shield's withdrawal engine allows users to withdraw any individual consent through the rights portal. Withdrawal triggers automated downstream notifications to linked data processors and updates the user's consent record with a timestamped withdrawal event.

How long does it take to go live with consent management?+

The consent notice builder takes 20–30 minutes to configure. The SDK widget is 2 lines of JavaScript that works on any framework — React, Vue, Angular, or plain HTML. Most customers are capturing compliant, vaulted consent within 2 hours of signing up.

Which DPDPA Shield plan includes consent management?+

Consent management is available on all plans, including the Starter plan. Re-consent campaigns and advanced analytics require the Growth plan. See pricing for details.

Ready to prove every consent?

Set up in under 30 minutes. Free trial, no credit card required.