The Consiva Platform

Every DPDP obligation in one platform — and the evidence that each one operated

Consiva is a privacy operations platform built for India's Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 — not translated from GDPR. Consent, cookies, Data Principal rights, breach response, data discovery and processing records, connected, with a durable record behind every action.

✓ India data residency✓ 22 Eighth Schedule languages✓ Unmetered rights requests on every plan✓ Free plan, no card

Compliance is not a document. It is a set of controls that have to operate.

Most DPDP programmes fail in the same place. The policy is written, the banner goes up, the DPO is named — and then a request arrives on a Friday afternoon, or a tag manager adds a tracker nobody categorised, or an incident starts more than one regulatory clock at once. The obligations are continuous. The tooling usually is not.

The substantive DPDP obligations and the penalty regime commence on 13 May 2027 (DPDP Rules 2025, Rule 1(4): Rules 3 and 5 to 16, 22 and 23 come into force eighteen months after publication; publication was 13 November 2025). That is a real deadline and it is worth planning against. It is also not the reason to start now.

The reason to start now is that CERT-In's 2022 Directions are already in force, with a six-hour incident reporting window — so breach readiness is a live obligation today, not a 2027 one. And that a consent record you did not capture in 2026 cannot be reconstructed in 2027. Consent evidence accrues. You cannot backfill it.

How Consiva works: six stages, one platform

Every stage below maps to a module that is shipped and demonstrable. Nothing here is a roadmap item.

SEE
Find the personal data and the trackers you did not know about
Consiva scans your domains continuously for cookies, pixels and third-party scripts — including the ones added by a CMS plugin or a tag manager container without anyone telling the privacy team. On Enterprise, Data Discovery connects to your databases and classifies personal data column by column.
Produces: A cookie and tracker inventory, and a column-level personal-data inventory. Each scan is timestamped, with a difference report against the previous cycle.
MAP
Connect what you hold to why you hold it
Personal data means nothing to a regulator without a purpose attached. Consiva maps scanned cookies and discovered database columns to your declared processing purposes, and carries that mapping into your Records of Processing Activities. Processors and their data-processing agreements are registered alongside, with risk tiers and sub-processor chains.
Produces: A purpose-mapped inventory, a processor register, and a ROPA built from live sources rather than a spreadsheet someone updated last quarter.
GOVERN
Set the rules once, apply them everywhere
Purposes, notice content, banner behaviour, retention periods, processor terms and who is allowed to change any of it. Role-based access with MFA and SSO means a banner change is attributable to a person.
Produces: A versioned configuration, and an audit log of every administrative change.
EXECUTE
Run the workflow when the obligation actually lands
A visitor accepts or refuses. A Data Principal asks for a copy of her data, or asks you to erase it, or files a grievance. An incident is detected at 07:42 on a Saturday. These are the moments the programme is judged on. Consiva runs each as a workflow with an owner, a state and a clock — not as an email thread.
Produces: Consent events, closed rights cases, and incident records with regulator-ready drafts.
PROVE
Produce the artefact, not the assertion
This is the stage most platforms skip. For every control, Consiva leaves behind something you can put in front of the Data Protection Board: a signed consent record showing purpose, version and timestamp; a rights case file showing what was asked, who was verified, what was done and when the response went out; an incident file showing both clocks and both notifications.
Produces: Exportable evidence, per obligation, on demand.
WATCH
Notice the drift before someone else does
Scheduled re-scans catch a new tracker within a cycle. Consent age and withdrawal rates surface a notice that has gone stale. Processor DPA expiry alerts fire before the contract lapses. Rights cases escalate before your published response period runs out.
Produces: Alerts, trend reporting, and an escalation trail.

Inside the platform

Ordered by the obligation that is most urgent today, not by the one that is easiest to sell.

Breach response
CERT-In and DPDP, tracked separately
One incident, several clocks, two regulators. Consiva tracks CERT-In's six-hour window independently of your DPDP Rule 7 obligations and pre-drafts a submission for each. Available on Pro (tracker) and Enterprise (full module).
Learn more →
Data Principal rights
unmetered on every plan, including Free
Access, correction and erasure, grievance and nomination — with verified identity, an owner, and a case file at the end. Never metered, never charged by volume, on any plan. Manual handling on Free · automated workflows on Pro and Enterprise.
Learn more →
Consent management
records you can produce, not just collect
Purpose-specific consent with a signed record behind every event: purpose, notice version, timestamp, channel and region. Withdrawal made as easy as giving, because the Rules require exactly that. All plans.
Learn more →
Cookie consent and banners
in the language the visitor actually reads
Continuous scanning, purpose classification, and a banner deployed with one script tag in any of the 22 Eighth Schedule languages. English and Hindi on Free · all 22 on Pro and Enterprise.
Learn more →
Discovery, mapping and records
from database columns to a signed ROPA
Connect SQL Server, PostgreSQL or MySQL. Consiva finds personal data at rest, classifies it, maps it to purposes and generates a ROPA where every row names the source that produced it. Enterprise plan.
Learn more →
Processor governance
which of your vendors actually has a valid DPA
A live register of processors with DPA status, risk tier, sub-processor chains and expiry alerts. Section 8(2) requires a valid contract before a processor touches personal data on your behalf. Pro and Enterprise.
Learn more →

The evidence chain

Every control in Consiva resolves to the same five-link chain. It is the difference between a platform that logs activity and one that can prove an obligation was met.

OBLIGATIONCONTROLSIGNALARTEFACTOWNER

A worked example, end to end:

ObligationRule 3(c)(i): the Data Principal must be able to withdraw consent with ease comparable to that with which she gave it.
ControlA withdrawal path in the banner and preference centre, at the same number of steps as acceptance.
SignalA withdrawal event fires, carrying purpose, timestamp, channel and region.
ArtefactAn append-only consent record, exportable, showing the grant and the withdrawal against the same notice version.
OwnerThe named administrator responsible for that domain's consent configuration.

Where Consiva cannot see something — an offline consent taken on paper, a system with no API — the export says so, in writing, on the document. An evidence pack that quietly omits its own blind spots is worse than no evidence pack, because it will be relied on.

What the platform looks like

consiva.ai/dashboard
⬡ Consiva.aiNAVIGATION📊 Dashboard🌐 Domains🎨 Banner Builder📋 Consent Logs⚖️ Rights Requests🔔 Data Breaches🗄️ Data Discovery🏢 VendorsCompliance DashboardLast updated: moments ago · acme.inTOTAL CONSENTS48,291ACCEPTANCE RATE73.4%OPEN RIGHTS REQUESTS28ACTIVE DOMAINS7Consent Trend (30 days)Recent Events✅ Consent granted↩ Withdrawal req.🔍 Rights request🌐 New domain

This is the Compliance Dashboard, the first screen after login. Across the top: total consent events, acceptance rate, open rights requests and active domains. The panel on the right is a live event feed — a consent grant, a withdrawal, a new rights request, a newly verified domain. Each figure is a link, not a number: clicking open rights requests opens the case list filtered to what is outstanding, with the owner and the elapsed time on each. Everything shown here is derived from the underlying records, so the dashboard and the evidence export can never disagree.

What is on which plan

Honest gating, stated up front. Discovering a paywall at the pricing page after reading a feature page is how a signup gets lost.

FreeProEnterprise
Cookie and tracker scanningBasicScheduledScheduled
Consent banner languagesEnglish, HindiAll 22All 22 + regional customisation
Consent capture and signed records
Data Principal rights intake — unmetered● manual● automated● automated
Consent analyticsBasicEnhanced, CSV exportEnhanced, CSV export
CERT-In and DPDP breach tracking● tracker● full module
Processor and DPA register
Webhooks and REST API
Data Discovery · data mapping · ROPA
Domains15 + add-on packsUnlimited

Free is ₹0, permanently, with no card required: 1,000 cookie consents and 50 form consents a month. Pro is ₹5,999/month or ₹60,000/year. Enterprise is scoped.

→ Full pricing at /pricing

Where operations can help

Consiva is software first. Some teams also want the work operated for them, and two engagements exist for that. Both are named for what the Rules actually contemplate.

Privacy Point-of-Contact — Rule 9 requires you to publish the business contact information of a person able to answer a Data Principal's questions about processing, and to include it in every response to a rights communication. Consiva can staff that role.

Managed Privacy Officer — Consiva operates the day-to-day privacy function: rights case handling, consent hygiene, processor diligence cadence and evidence upkeep.

Your team keeps decision authority. Consiva does not make legal determinations on your behalf.

Built on the law as written

Every obligation in this platform traces to a section or rule you can read for yourself. That is deliberate — a compliance tool that cannot show its statutory reasoning is asking you to take its word for it.

Frequently asked questions

At minimum: consent capture with a durable record, cookie and tracker governance, a workflow for Data Principal rights, breach response against the applicable regulatory clocks, a register of processors and their contracts, and Records of Processing Activities. Consiva covers all six, with the discovery, mapping and ROPA modules on the Enterprise plan. What separates platforms is not the module list — it is whether each module leaves behind an artefact that proves the control operated.

Not yet, in the sense that matters. The Data Protection Board is established and Rules 1, 2 and 17 to 21 are in force. The substantive obligations and the entire penalty regime commence on 13 May 2027, eighteen months after the Rules were published on 13 November 2025. Consent Manager registration opens on 13 November 2026. Note separately that CERT-In's 2022 Directions are already in force, with a six-hour incident reporting window — so breach readiness is a present obligation, not a future one.

No, and the distinction matters. A Consent Manager under the DPDP Act is a specific registered entity that acts as a neutral intermediary between Data Principals and multiple Data Fiduciaries, registered with the Board under Rule 4 and subject to the obligations in Part B of the First Schedule. Consiva is a consent management platform — software you deploy to meet your own obligations as a Data Fiduciary. You remain the Data Fiduciary; Consiva acts as your Data Processor.

No. Free covers a single domain with consent, banners and manual rights handling. Pro adds automation, all 22 languages, breach tracking and the processor register. Discovery, mapping and ROPA are Enterprise. Most organisations start with cookie consent because it is the fastest thing to get right, then add rights and breach.

In India. Consent records, rights case files, breach records and audit trails are held in Indian infrastructure. Database credentials supplied for Data Discovery are encrypted at rest and write-only — they are never returned by any API response.

The banner is genuinely fast: register, verify your domain, review the first scan, configure purposes and paste one script tag. Data Discovery is not fast in the same way — it needs database credentials, a conversation with whoever owns those databases, and a review of the classification output. Treat it as a project, not a setup step.

See the whole platform on your own domain

Start with cookie consent — the fastest module to get right — then add rights and breach as you need them.