Consiva is a privacy operations platform built for India's Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 — not translated from GDPR. Consent, cookies, Data Principal rights, breach response, data discovery and processing records, connected, with a durable record behind every action.
Most DPDP programmes fail in the same place. The policy is written, the banner goes up, the DPO is named — and then a request arrives on a Friday afternoon, or a tag manager adds a tracker nobody categorised, or an incident starts more than one regulatory clock at once. The obligations are continuous. The tooling usually is not.
The substantive DPDP obligations and the penalty regime commence on 13 May 2027 (DPDP Rules 2025, Rule 1(4): Rules 3 and 5 to 16, 22 and 23 come into force eighteen months after publication; publication was 13 November 2025). That is a real deadline and it is worth planning against. It is also not the reason to start now.
The reason to start now is that CERT-In's 2022 Directions are already in force, with a six-hour incident reporting window — so breach readiness is a live obligation today, not a 2027 one. And that a consent record you did not capture in 2026 cannot be reconstructed in 2027. Consent evidence accrues. You cannot backfill it.
Every stage below maps to a module that is shipped and demonstrable. Nothing here is a roadmap item.
Ordered by the obligation that is most urgent today, not by the one that is easiest to sell.
Every control in Consiva resolves to the same five-link chain. It is the difference between a platform that logs activity and one that can prove an obligation was met.
A worked example, end to end:
| Obligation | Rule 3(c)(i): the Data Principal must be able to withdraw consent with ease comparable to that with which she gave it. |
| Control | A withdrawal path in the banner and preference centre, at the same number of steps as acceptance. |
| Signal | A withdrawal event fires, carrying purpose, timestamp, channel and region. |
| Artefact | An append-only consent record, exportable, showing the grant and the withdrawal against the same notice version. |
| Owner | The named administrator responsible for that domain's consent configuration. |
Where Consiva cannot see something — an offline consent taken on paper, a system with no API — the export says so, in writing, on the document. An evidence pack that quietly omits its own blind spots is worse than no evidence pack, because it will be relied on.
This is the Compliance Dashboard, the first screen after login. Across the top: total consent events, acceptance rate, open rights requests and active domains. The panel on the right is a live event feed — a consent grant, a withdrawal, a new rights request, a newly verified domain. Each figure is a link, not a number: clicking open rights requests opens the case list filtered to what is outstanding, with the owner and the elapsed time on each. Everything shown here is derived from the underlying records, so the dashboard and the evidence export can never disagree.
Honest gating, stated up front. Discovering a paywall at the pricing page after reading a feature page is how a signup gets lost.
| Free | Pro | Enterprise | |
|---|---|---|---|
| Cookie and tracker scanning | Basic | Scheduled | Scheduled |
| Consent banner languages | English, Hindi | All 22 | All 22 + regional customisation |
| Consent capture and signed records | ● | ● | ● |
| Data Principal rights intake — unmetered | ● manual | ● automated | ● automated |
| Consent analytics | Basic | Enhanced, CSV export | Enhanced, CSV export |
| CERT-In and DPDP breach tracking | — | ● tracker | ● full module |
| Processor and DPA register | — | ● | ● |
| Webhooks and REST API | — | ● | ● |
| Data Discovery · data mapping · ROPA | — | — | ● |
| Domains | 1 | 5 + add-on packs | Unlimited |
Free is ₹0, permanently, with no card required: 1,000 cookie consents and 50 form consents a month. Pro is ₹5,999/month or ₹60,000/year. Enterprise is scoped.
→ Full pricing at /pricing
Consiva is software first. Some teams also want the work operated for them, and two engagements exist for that. Both are named for what the Rules actually contemplate.
Privacy Point-of-Contact — Rule 9 requires you to publish the business contact information of a person able to answer a Data Principal's questions about processing, and to include it in every response to a rights communication. Consiva can staff that role.
Managed Privacy Officer — Consiva operates the day-to-day privacy function: rights case handling, consent hygiene, processor diligence cadence and evidence upkeep.
Your team keeps decision authority. Consiva does not make legal determinations on your behalf.
Every obligation in this platform traces to a section or rule you can read for yourself. That is deliberate — a compliance tool that cannot show its statutory reasoning is asking you to take its word for it.
At minimum: consent capture with a durable record, cookie and tracker governance, a workflow for Data Principal rights, breach response against the applicable regulatory clocks, a register of processors and their contracts, and Records of Processing Activities. Consiva covers all six, with the discovery, mapping and ROPA modules on the Enterprise plan. What separates platforms is not the module list — it is whether each module leaves behind an artefact that proves the control operated.
Not yet, in the sense that matters. The Data Protection Board is established and Rules 1, 2 and 17 to 21 are in force. The substantive obligations and the entire penalty regime commence on 13 May 2027, eighteen months after the Rules were published on 13 November 2025. Consent Manager registration opens on 13 November 2026. Note separately that CERT-In's 2022 Directions are already in force, with a six-hour incident reporting window — so breach readiness is a present obligation, not a future one.
No, and the distinction matters. A Consent Manager under the DPDP Act is a specific registered entity that acts as a neutral intermediary between Data Principals and multiple Data Fiduciaries, registered with the Board under Rule 4 and subject to the obligations in Part B of the First Schedule. Consiva is a consent management platform — software you deploy to meet your own obligations as a Data Fiduciary. You remain the Data Fiduciary; Consiva acts as your Data Processor.
No. Free covers a single domain with consent, banners and manual rights handling. Pro adds automation, all 22 languages, breach tracking and the processor register. Discovery, mapping and ROPA are Enterprise. Most organisations start with cookie consent because it is the fastest thing to get right, then add rights and breach.
In India. Consent records, rights case files, breach records and audit trails are held in Indian infrastructure. Database credentials supplied for Data Discovery are encrypted at rest and write-only — they are never returned by any API response.
The banner is genuinely fast: register, verify your domain, review the first scan, configure purposes and paste one script tag. Data Discovery is not fast in the same way — it needs database credentials, a conversation with whoever owns those databases, and a review of the classification output. Treat it as a project, not a setup step.
Start with cookie consent — the fastest module to get right — then add rights and breach as you need them.