The only Consent Management Platform built natively for DPDP 2023 — with CERT-In 6-hour breach tracking, Data Discovery across your databases, and global framework coverage from one dashboard.
The DPDP Act 2023 is live, enforceable law. Every digital service processing personal data of Indian residents is in scope — regardless of where the company is headquartered.
From cookie consent to CERT-In breach tracking — see exactly how Consiva keeps your organisation compliant across DPDP, GDPR, and CERT-In simultaneously.
Auto-scans every cookie and tracker on your domain, categorises them by purpose, and presents DPDP-format consent banners in any Eighth Schedule language — deployed via a single script tag.
DPDP 6, 11–14 gives every Indian user clear rights over their personal data. Consiva automates intake, identity verification, routing, fulfilment, and the immutable audit trail — with escalation before SLA breach.
A data breach triggers two separate regulatory clocks simultaneously. Consiva tracks both independently — CERT-In's 6-hour window and DPDP Board's notification window — with auto-drafted reports for each regulator.
Connect your database in one click. Consiva scans every table, flags personal data at rest, and maps it to your DPDP processing purposes — powering your ROPA automatically.
<script> tag and paste it in your site's <head>. For WordPress, install the Consiva Consent Banner plugin and paste your Script Key in Settings — done in under 60 seconds.All plans include DPDP 2023 compliance, CERT-In tracking, and India data residency.
Yes. The DPDP Act received Presidential assent on 11 August 2023. The Government has notified the Data Protection Board and implementation rules. Enforcement through penalties is now active. The ₹250 crore ceiling applies per category of violation — systemic failures can attract cumulative penalties far exceeding that figure.
Yes. DPDP follows the data, not the corporate domicile. Any entity that collects, stores, or processes personal data of individuals in India — regardless of server location or company registration — is subject to DPDP. A US SaaS with Indian users must comply. This mirrors the GDPR extraterritorial model.
CERT-In's April 2022 Directions require reporting cybersecurity incidents within 6 hours of detection — completely independent of DPDP's Board notification obligation. Most consent tools only handle DPDP notification and miss the CERT-In window entirely. Consiva tracks both clocks independently from the moment a breach is logged, with separate auto-drafted reports for each regulator.
The free plan includes 3,000 consent events per month — permanently, no credit card required, no artificial expiry. You get cookie scanning, DPDP and GDPR banner configurations, basic analytics, and email support for one domain. Data Discovery, the CERT-In breach tracker, and Rights Request workflows require a paid plan.
Data Discovery connects to your SQL Server, MySQL, or PostgreSQL databases and scans every table for personal data at rest — email addresses, phone numbers, Aadhaar patterns, and other PII. This is required for an accurate ROPA under DPDP and to identify data that must be erased when a 12 erasure request arrives.
Install the Consiva Consent Banner plugin from the WordPress Plugin Directory. Go to Settings → Consiva Consent Banner and paste your Script Key from the Consiva dashboard. Save — the banner is immediately active on every page, no theme edits needed. The plugin syncs directly with your Consiva dashboard.
The DPDP Act gives every Indian individual: 6(4) withdraw consent at any time; 11 access information about their data being processed; 12 correction and erasure of inaccurate or unnecessary data; 13 grievance redressal through the Data Fiduciary's Grievance Officer; 14 nominate a representative to exercise rights on their behalf after death or incapacity. Consiva manages intake, identity verification, SLA tracking, and fulfilment workflows for all these rights.
Yes — Multi-Framework Mode on Growth and Enterprise plans. Consiva detects the visitor's jurisdiction via IP geolocation and serves the appropriate banner: DPDP format for India, GDPR-compliant for EU/EEA, CCPA opt-out for California, LGPD for Brazil. All from one script tag.
All consent logs, rights request records, breach incident reports, and audit trails are stored exclusively in India on cloud infrastructure meeting DPDP data localisation requirements. Database credentials entered for Data Discovery are encrypted at rest and are write-only — never returned by any API response.
An SDF is a Data Fiduciary designated by the Government under DPDP 10 based on volume, sensitivity, and national security risk. SDFs face additional obligations: appointing an Indian resident as DPO, annual data audits, Data Protection Impact Assessments, and algorithmic accountability measures. Consiva's SDF module — on Enterprise plans — covers all of these.
Set up in under 10 minutes. 3,000 monthly consent events included — forever free. No credit card required.