🇮🇳 DPDP Act 2023 is now enforceable law

India's Privacy Law
Fully Automated.

The only Consent Management Platform built natively for DPDP 2023 — with CERT-In 6-hour breach tracking, Data Discovery across your databases, and global framework coverage from one dashboard.

DPDP 2023
CERT-In Directions
GDPR
CCPA / CPRA
LGPD Brazil
India Data Residency
₹250Cr
Maximum DPDP penalty per category of violation for a Data Fiduciary
DPDP Act 2023 · Section 33
6 hrs
CERT-In mandatory breach reporting window — independent of DPDP Board notification
CERT-In Directions · April 2022
87%
Indian enterprises without a DPDP-compliant consent mechanism as of 2026
Industry Survey 2026
3,000
Consent events included free every month — no credit card, no expiry
Consiva Free Plan · Forever
🇮🇳 DPDP Act 2023NATIVE
🔔 CERT-In 20226-HR SLA
🇪🇺 GDPRCOVERED
🇺🇸 CCPA / CPRA
🇧🇷 LGPD Brazil
☁️ India Data ResidencyIN-REGION
🗄️ SQL Server · MySQL · PostgreSQLDATA DISCOVERY
🌐 WordPress PluginONE-CLICK
🛍️ Shopify AppONE-CLICK
📋 ROPA Auto-Generation
👨‍👩‍👧 DPDP 9 Parental Consent
🏛️ Significant Data Fiduciary ModuleSDF
🇮🇳 DPDP Act 2023NATIVE
🔔 CERT-In 20226-HR SLA
🇪🇺 GDPRCOVERED
🇺🇸 CCPA / CPRA
🇧🇷 LGPD Brazil
☁️ India Data ResidencyIN-REGION
🗄️ SQL Server · MySQL · PostgreSQLDATA DISCOVERY
🌐 WordPress PluginONE-CLICK
🛍️ Shopify AppONE-CLICK
📋 ROPA Auto-Generation
👨‍👩‍👧 DPDP 9 Parental Consent
🏛️ Significant Data Fiduciary ModuleSDF
The Compliance Imperative

DPDP is enforceable.
Most businesses aren't ready.

The DPDP Act 2023 is live, enforceable law. Every digital service processing personal data of Indian residents is in scope — regardless of where the company is headquartered.

Platform Walkthrough

Every compliance workflow
in one connected dashboard.

From cookie consent to CERT-In breach tracking — see exactly how Consiva keeps your organisation compliant across DPDP, GDPR, and CERT-In simultaneously.

consiva.ai/dashboard
⬡ Consiva.ai NAVIGATION 📊 Dashboard 🌐 Domains 🎨 Banner Builder 📈 Analytics 📋 Consent Logs ⚖️ Rights Requests 🔔 Data Breaches 🗄️ Data Discovery Compliance Dashboard Last updated: moments ago · enterprise-corp.com TOTAL CONSENTS 48,291 ↑ 12% this week ACCEPTANCE RATE 73.4% ↑ 4.2% vs prev RIGHTS REQUESTS 142 28 pending review DOMAINS ACTIVE 7 All compliant Consent Trend (30 days) Recent Events ✅ Consent granted ↩ Withdrawal req. 🔍 Rights request 🌐 New domain
01Compliance DashboardReal-time overview
consiva.ai/banner-builder
Banner Builder Visual consent UI designer TEMPLATE DPDP Banner — Dark POSITION Bottom Bar Modal Center ACCENT COLOR PURPOSES Strictly Necessary Analytics & Performance Marketing & Targeting PUBLISH LIVE Live Preview Accept All Manage Preferences Reject
02Visual Banner BuilderNo-code consent UI
consiva.ai/analytics
Consent Analytics enterprise-corp.com · Last 30 days Last 30d ▾ All Domains ▾ Export 73.4% Acceptance Accepted All — 73.4% Partial Accept — 14.1% Rejected — 12.5% Geographic Distribution India Regions · DPDP Coverage Maharashtra 31% Karnataka 18% By Purpose Necessary 100% Analytics 73% Marketing 48% Social 33% Personalisation 20% WITHDRAWALS (30d) 1,847 ↓ 6% vs prev period AVG CONSENT AGE 142 days Renewal recommended COMPLIANCE SCORE 98.2 / 100 2 minor recommendations
03Consent AnalyticsAudit-ready reporting
consiva.ai/consent-logs
Consent Logs Immutable audit trail · All records cryptographically signed 🔍 Search by visitor ID, email, domain… Status ▾ Purpose ▾ Export CSV VISITOR ID TIMESTAMP ACTION PURPOSES CHANNEL REGION v8f3●●●●b2c 2026-07-29 09:41:02 GRANTED Analytics, Marketing Web IN-MH v2a9●●●●f7d 2026-07-29 09:39:17 WITHDRAWN All Purposes Mobile SDK IN-KA v5k1●●●●c9e 2026-07-29 09:38:45 GRANTED Necessary Only Web IN-DL v7m4●●●●a3f 2026-07-29 09:37:01 GRANTED Analytics, Marketing API IN-TN Showing 1–25 of 48,291 records 1 2 3
04Consent Logs & Audit TrailImmutable · Exportable
consiva.ai/rights-requests
Data Principal Rights DPDP 6, 11–14 · Automated workflows · 30-day SLA tracked TOTAL REQUESTS 142 This quarter PENDING 28 Avg 4.2 days wait COMPLETED 108 Within SLA OVERDUE 6 Escalation triggered + New Request REQ ID TYPE DATA PRINCIPAL SUBMITTED STATUS SLA RR-2026-0847 Access Request ad●●●@enterprise.com Jul 29, 2026 IN REVIEW 6 days left RR-2026-0846 Erasure Req. us●●●@corp.com Jul 28, 2026 COMPLETE Done ✓ DPDP RIGHTS COVERED: Consent Withdrawal Right to Access Correction Erasure Grievance · Nomination
05Data Principal RightsDPDP 6, 11–14 compliant
Platform Walkthrough

Every compliance workflow
in one connected dashboard.

🛡️ DPDP-Native Consent

Consent capture designed for India's law — not retrofitted from GDPR.

Auto-scans every cookie and tracker on your domain, categorises them by purpose, and presents DPDP-format consent banners in any Eighth Schedule language — deployed via a single script tag.

  • Purpose-specific consent with DPDP 6 format records and immutable timestamp
  • 22 Eighth Schedule languages — Hindi, Tamil, Bengali, Marathi and more
  • Live banner preview with mobile simulation before publishing
  • Consent logs with version, IP, purpose breakdown — regulator-ready
consiva.ai/dashboard/banner-builder
Consiva.ai 🎨 Banner Builder 📊 Dashboard 🌐 Domains ⚖️ Rights Requests 🔔 Breaches 🗄️ Data Discovery 📈 Analytics Banner Builder — acme.in LANGUAGE Hindi (हिन्दी) ▾ PURPOSES ✓ Necessary (Always Active) ☐ Analytics — Google Analytics 4 ☐ Marketing — Meta Pixel + Add Purpose SCRIPT KEY data-domain-id= "a1b2c3d4-••••-••••" LIVE PREVIEW acme 🍪 हम कुकीज़ का उपयोग करते हैं Analytics और Marketing के लिए। स्वीकार करें प्रबंधित SCRIPT TAG <script src="cookiebot.consiva.ai/...">
⚖️ Data Principal Rights

All DPDP Data Principal rights — with email-verified workflows and live SLA timers.

DPDP 6, 11–14 gives every Indian user clear rights over their personal data. Consiva automates intake, identity verification, routing, fulfilment, and the immutable audit trail — with escalation before SLA breach.

  • Consent Withdrawal · Access to Information · Correction & Erasure · Grievance · Nomination
  • 7-day and 30-day SLA countdown with auto-escalation to DPO
  • Email-verified identity confirmation before any data action
  • Full case audit trail — regulator-exportable PDF
consiva.ai/dashboard/rights
Consiva.ai ⚖️ Rights Requests Data Principal Rights — DPDP 6, 11–14 OPEN REQUESTS 12 DUE TODAY 5 COMPLETED 26 AVG RESOLUTION 4.2 days REFERENCE TYPE DATA PRINCIPAL SLA STATUS DSR-2026-047 ERASURE ••@gmail ✓ ⏱ TODAY IN REVIEW DSR-2026-046 ACCESS ••@yahoo ✓ Aug 3 FULFILLED DSR-2026-045 CORRECTION ••@icloud ✓ Aug 1 FULFILLED DPDP RIGHTS COVERED 6 Consent Withdrawal 11 Access to Info 12 Correction 12 Erasure 13 Grievance 14 Nomination All with SLA + immutable audit
🔔 CERT-In Breach Tracker

The only Indian consent platform with an independent CERT-In 6-hour SLA tracker.

A data breach triggers two separate regulatory clocks simultaneously. Consiva tracks both independently — CERT-In's 6-hour window and DPDP Board's notification window — with auto-drafted reports for each regulator.

  • Separate 6-hr CERT-In countdown, independent of the DPDP Board window
  • 180-day incident log retention per CERT-In Directions 3(iv)
  • Auto-drafted CERT-In report, pre-filled for cert-in.org.in submission
  • Escalation alerts before either regulatory deadline lapses
consiva.ai/dashboard/breaches
Consiva.ai 🔔 Data Breaches ⚠ CERT-In Window Active — Incident #CERT-2026-047 CERT-In closes in 4h 12m · DPDP Board closes in 70h 12m · Breach detected 2026-07-29 09:14 IST CERT-IN 6-HOUR WINDOW 04:12 70% of window elapsed DPDP BOARD WINDOW 70:12 3% of window elapsed Incident #CERT-2026-047 — API Endpoint Exposure Impacted: ~2,400 user records (email, phone) · Vector: Misconfigured endpoint · Contained ✓ CERT-In report: Auto-drafted · Ready to submit at cert-in.org.in DPDP Board notification: Queued · Draft saved Notify CERT-In Queue Board Export PDF
Data Discovery

Find personal data hiding
in your databases — automatically.

Connect your database in one click. Consiva scans every table, flags personal data at rest, and maps it to your DPDP processing purposes — powering your ROPA automatically.

Microsoft SQL Server
ENTERPRISE · EXPRESS · AZURE SQL
BUILT-IN
Connect via host, port, and credentials. Passwords are encrypted at rest and write-only — never exposed in any API response. Scans all tables for PII column patterns.
Auto-detects email, phone, name, Aadhaar patterns
Maps columns to DPDP processing purposes
Generates ROPA entries automatically
PostgreSQL
V12+ · SUPABASE · AWS RDS
BUILT-IN
Full schema introspection across all schemas and tables. Works with managed PostgreSQL on Supabase, AWS RDS, and self-hosted. Encrypted credential storage.
Scans all schemas, tables, and views
Regex + pattern classification of PII columns
Repeat scans with incremental diff report
MySQL / MariaDB
MYSQL 5.7+ · MARIADB · AURORA
BUILT-IN
Connects to any MySQL-compatible database. Scans non-system tables only — safe for production environments. Supports SSL/TLS connections.
Non-system schema scan — zero production risk
Supports SSL/TLS encrypted connections
Compatible with WooCommerce, Magento DBs
One-Click CMS & E-commerce Integrations
🌐
WordPress OFFICIAL PLUGIN
Install the Consiva Consent Banner plugin from WP Plugins. Paste your Script Key from the Consiva dashboard. Done — banner live on every page, zero code required.
Settings → Consiva Consent Banner → Paste Script Key → Save
🛍️
Shopify ONE-CLICK
Install from the Shopify App Store in one click. Auto-injects your consent banner on every storefront page, syncs with Shopify's Customer Privacy API, and captures marketing opt-in at checkout.
App Store → Install Consiva Consent → Enter Script Key → Save
Compliance Scope

If you process Indian users' data,
DPDP applies to you.

🛒
E-Commerce & D2C
Checkout data, order history, returns, loyalty programmes — DPDP regulates every bit of it.
🏥
Healthcare & Wellness
Patient records and health app data are sensitive personal data with stricter DPDP obligations.
🏦
BFSI & Fintech
KYC, transaction histories, and credit data — under both DPDP and RBI data governance frameworks.
📱
SaaS & Mobile Apps
Any SaaS processing Indian user data — regardless of server location — is in scope.
🏫
EdTech & Online Learning
Student data and minors' data invoke DPDP 9 parental consent — one of its strictest provisions.
🌐
Global Enterprises
Overseas companies with Indian customer data must comply. DPDP follows the data, not the domicile.
Platform Capabilities

Everything DPDP requires.
Nothing compliance teams don't.

🔍
Automatic Cookie & Tracker Scanning
Continuous scanner discovers every cookie, pixel, and third-party script on your domains — including those added by CMS plugins or tag managers without your knowledge. Auto-categorised and mapped to consent purposes on every scan cycle.
NecessaryAnalyticsMarketingPreferencesThird-party
📋
ROPA Auto-generation
Records of Processing Activities built automatically from scan results, consent logs, and Data Discovery findings. Updated on every scan cycle — always current for regulator review.
👨‍👩‍👧
Parental Consent (DPDP 9)
DPDP mandates verifiable parental consent before processing children's data. Consiva provides age-gate logic, verification workflow, and a complete audit trail per minor user.
🌏
Multi-Framework Geolocation
Serve GDPR banners in the EU, CCPA opt-outs in California, and DPDP banners in India — auto-switched by visitor location. All from one script tag, one dashboard.
☁️
India Data Residency
All consent logs, rights request records, and breach reports stored exclusively in India — meeting DPDP data localisation provisions on every plan.
📊
Consent Analytics
Opt-in rates by banner variant, category, domain, and traffic source. AB test banner text to optimise consent rates without compromising compliance.
🔒
Immutable Audit Logs
Every consent event, rights action, and breach record written to an append-only log. Tamper-evident, exportable, and ready for regulator review at any time.
🏛️
SDF Module
Significant Data Fiduciary obligations — DPO workflow management, DPIA templates, annual audit readiness, and algorithmic accountability dashboards. Enterprise plan.
Quick Start

Live in 10 minutes.
Compliant for years.

01
Register & Verify Your Domain
Create your free account at cookiebot.consiva.ai — no credit card required. Add your domain and click Verify. Consiva confirms ownership and starts the first cookie scan immediately.
🆓 3,000 consent events free — every month, forever
02
Review Cookies & Set Purposes
The scanner returns every cookie, pixel, and tracker with suggested DPDP purpose categories pre-filled. Review, adjust, and add custom purposes matching your processing activities.
03
Configure Banner & Language
Choose your banner layout, accent colour, and language. Select from 22 Eighth Schedule languages. Preview on mobile and desktop before publishing.
04
Deploy — One Script Tag
Copy a single <script> tag and paste it in your site's <head>. For WordPress, install the Consiva Consent Banner plugin and paste your Script Key in Settings — done in under 60 seconds.
05
Connect Databases (Optional)
Go to Data Discovery → Add Source. Enter your SQL Server, PostgreSQL, or MySQL credentials. Consiva scans your tables, flags personal data columns, and auto-populates your ROPA — no SQL required from your side.
06
Monitor, Respond, Stay Compliant
Your dashboard shows live consent rates, incoming rights requests with SLA timers, and breach incidents. Consiva alerts you before any deadline — CERT-In 6-hour or DPDP Board — and pre-drafts every regulatory notification.
DPDP + CERT-In covered from a single platform
Pricing

Start free. Scale when you're ready.

All plans include DPDP 2023 compliance, CERT-In tracking, and India data residency.

Free
₹0
Forever free · No credit card
Get started with full DPDP compliance for small sites.
Get Started Free
3,000 consent events/month
1 domain
Cookie scanning
DPDP & GDPR banners
Basic analytics
Data Discovery
Rights request workflows
CERT-In breach tracker
Starter
₹5,000
/month · billed monthly
For growing businesses with multiple domains.
Get Access
50,000 consent events/month
5 domains
22 Eighth Schedule languages
Data Principal Rights workflows
CERT-In breach module
WordPress plugin
Data Discovery
ROPA auto-generation
MOST POPULAR
Growth
₹15,000
/month · billed monthly
For data-driven organisations needing full compliance automation.
Get Access
2,50,000 consent events/month
25 domains
All Starter features
Data Discovery — SQL, MySQL, PostgreSQL
ROPA auto-generation
Parental consent workflows (DPDP 9)
Multi-framework geolocation routing
Priority support + onboarding
Enterprise
Custom
Volume pricing · SLA guaranteed
For large enterprises, government bodies, and SDFs.
Contact Sales
Unlimited consent events
Unlimited domains
All Growth features
SDF module — DPO, DPIA, audit
On-premise deployment option
Custom SLA agreements
Dedicated legal team onboarding
Custom integrations & API access
FAQ

Common questions about
DPDP compliance and Consiva.

Yes. The DPDP Act received Presidential assent on 11 August 2023. The Government has notified the Data Protection Board and implementation rules. Enforcement through penalties is now active. The ₹250 crore ceiling applies per category of violation — systemic failures can attract cumulative penalties far exceeding that figure.

Yes. DPDP follows the data, not the corporate domicile. Any entity that collects, stores, or processes personal data of individuals in India — regardless of server location or company registration — is subject to DPDP. A US SaaS with Indian users must comply. This mirrors the GDPR extraterritorial model.

CERT-In's April 2022 Directions require reporting cybersecurity incidents within 6 hours of detection — completely independent of DPDP's Board notification obligation. Most consent tools only handle DPDP notification and miss the CERT-In window entirely. Consiva tracks both clocks independently from the moment a breach is logged, with separate auto-drafted reports for each regulator.

The free plan includes 3,000 consent events per month — permanently, no credit card required, no artificial expiry. You get cookie scanning, DPDP and GDPR banner configurations, basic analytics, and email support for one domain. Data Discovery, the CERT-In breach tracker, and Rights Request workflows require a paid plan.

Data Discovery connects to your SQL Server, MySQL, or PostgreSQL databases and scans every table for personal data at rest — email addresses, phone numbers, Aadhaar patterns, and other PII. This is required for an accurate ROPA under DPDP and to identify data that must be erased when a 12 erasure request arrives.

Install the Consiva Consent Banner plugin from the WordPress Plugin Directory. Go to Settings → Consiva Consent Banner and paste your Script Key from the Consiva dashboard. Save — the banner is immediately active on every page, no theme edits needed. The plugin syncs directly with your Consiva dashboard.

The DPDP Act gives every Indian individual: 6(4) withdraw consent at any time; 11 access information about their data being processed; 12 correction and erasure of inaccurate or unnecessary data; 13 grievance redressal through the Data Fiduciary's Grievance Officer; 14 nominate a representative to exercise rights on their behalf after death or incapacity. Consiva manages intake, identity verification, SLA tracking, and fulfilment workflows for all these rights.

Yes — Multi-Framework Mode on Growth and Enterprise plans. Consiva detects the visitor's jurisdiction via IP geolocation and serves the appropriate banner: DPDP format for India, GDPR-compliant for EU/EEA, CCPA opt-out for California, LGPD for Brazil. All from one script tag.

All consent logs, rights request records, breach incident reports, and audit trails are stored exclusively in India on cloud infrastructure meeting DPDP data localisation requirements. Database credentials entered for Data Discovery are encrypted at rest and are write-only — never returned by any API response.

An SDF is a Data Fiduciary designated by the Government under DPDP 10 based on volume, sensitivity, and national security risk. SDFs face additional obligations: appointing an Indian resident as DPO, annual data audits, Data Protection Impact Assessments, and algorithmic accountability measures. Consiva's SDF module — on Enterprise plans — covers all of these.

Start today — it's free

DPDP is enforceable.
Your compliance window
is closing.

Set up in under 10 minutes. 3,000 monthly consent events included — forever free. No credit card required.

No credit card
Live in 10 minutes
India data residency
DPDP + CERT-In covered
99.9% uptime SLA