India · DPDPA

DPDPA-ready consent, built for India

The §9 age-gate, verifiable consent, consent receipts and tamper-evident evidence the DPDPA asks for. Built in, not bolted on by a US or EU tool. Live in about five minutes.

Free forever for one site. No credit card.

yoursite.com
India visitor · DPDPA rules applied

Your consent, your choice

We ask before we use non-essential cookies. We verify age and seek parental consent where required under the DPDPA.

Allow allReject non-essentialManage preferences
DPDPA is in force

Most consent tools were not built for the DPDPA

US and EU platforms retrofit India onto a GDPR model. The DPDPA has its own rules for children, for verifiable consent and for evidence. Generic banners leave those gaps open.

Up to ₹250 crore

the penalty the DPDPA allows for certain breaches, per instance.

§9 children

verifiable parental consent is required, and tracking of children is barred.

Prove consent

the Data Protection Board can ask you to demonstrate it, not just claim it.

DPDPA, handled the way the law is written

Native support for the parts of the DPDPA that generic tools skip.

§9 age-gate and parental flows

DPDPA requires verifiable parental consent for children. ConsentX ships a §9 age-gate and parental flow out of the box, an area underserved by US and EU incumbents.

Verifiable consent and receipts

Capture consent that can be demonstrated, and issue a consent receipt to the data principal. Notice is versioned, so you can show exactly what was agreed and when.

Tamper-evident evidence

Every consent is bound into a per-record SHA-256 hash chain you can verify. When the Data Protection Board asks you to prove a choice, you have provable evidence, not just a stored row.

Region rules for India and beyond

A database-backed Region Rule Engine applies DPDPA behavior to Indian visitors and the right rules everywhere else, all from the dashboard without a redeploy.

DPDPA-native, and ready for every other framework you serve

DPDPA GDPR UK GDPR CCPA / CPRA LGPD PIPEDA PDPA POPIA

Generic consent tool vs DPDPA-native ConsentX

Generic tool

  • India bolted onto a GDPR model
  • No real §9 age-gate or parental flow
  • Stores a row, hard to demonstrate
  • Rules hardcoded, need a deploy

ConsentX

  • DPDPA-native, built for India
  • §9 age-gate and parental consent flow
  • Verifiable consent plus receipts
  • Tamper-evident SHA-256 evidence chain

ConsentX helps you comply with the DPDPA. It does not by itself guarantee compliance. Verify your configuration against your own legal advice.

DPDPA consent questions

What does DPDPA require for children's data?+

India's DPDPA requires verifiable parental consent before processing the personal data of children, and bars tracking or behavioral monitoring of children. ConsentX ships a Section 9 age-gate and parental consent flow to help you meet this, underserved by many US and EU consent tools.

What are the penalties under DPDPA?+

The DPDPA allows penalties of up to ₹250 crore per instance for certain breaches. ConsentX helps you comply with verifiable consent, receipts and tamper-evident evidence, though it cannot by itself guarantee compliance.

Does ConsentX issue consent receipts to data principals?+

Yes. ConsentX can issue a consent receipt to the data principal and versions the notice that was shown, so you can demonstrate exactly what a person agreed to and when.

Can I run DPDPA for India and GDPR or CCPA elsewhere at the same time?+

Yes. The Region Rule Engine applies DPDPA behavior to Indian visitors and the right legal basis and banner behavior for GDPR, UK GDPR, CCPA and other frameworks per visitor, all from one dashboard without shipping code.

Is there a free plan and how fast is setup?+

Yes. The Free plan covers one website forever with no credit card, and setup takes about five minutes with a single script tag or the GTM and WordPress integrations.

Get DPDPA-ready before the Board asks

Launch consent built for India in minutes. Free to start, no credit card.