Know your data
Control your risks
Prove your compliance
One command center for the DPDP Act: auto-discovered data maps, artifact-backed consent, and evidence that beats the 72-hour breach clock. Built for India, not translated for it. One line of code.
Recorded decisions17Last 30 days
Opt-in share37%Non-essential categories
Evidence sealed100%17 of 17 records
Needs attention2See queue below
Consent trend
Decision mix
2 open grievances
Aadhaar found in 3 repositories
High risk
Consent evidence verified
Anchored
- Built for DPDP Act 2023 & Rules 2025
- Cryptographically verifiable consent
- Aadhaar & PII detection built in
- Data residency in India
One platform. Complete privacy lifecycle.
Everything you need for DPDP compliance
Discover & Map
Find and classify personal data across every connected system.
- Personal data discovery
- Data inventory & classification
- RoPA automation
Govern & Protect
Assess risk, manage processors, and handle breaches.
- DPIA & privacy by design
- Vendor & processor risk
- Breach response
Assure & Prove
Audit-ready evidence, always.
- Evidence register
- Audit management
- Board reporting
Active
Data Protection Board operational
Complaints are being accepted now.
Consent Managers come into force
Implementation has to start well before this date, not on it.
Deadline
Full enforcement
The hard deadline for complete DPDP compliance.
₹250 cr
Maximum penalty per instance under the DPDP Act. That is the ceiling; the floor is still in crores.
Rules 2025
Consent, notice and data-principal rights are operational now. The clock on obligations is running.
Every website
DPDP applies by data type, not company size. If you collect personal data, the Act applies to you.
PrivacySuraksha exists so the answer to “show me your consent records” is a link, not a scramble.
One line of code
Add the snippet, verify your domain, publish your configuration. Consent is recorded on the next page load: no build step, no framework integration, no tag manager required.
<script src="https://cdn.privacysuraksha.com/cmp.js" data-key="YOUR_SITE_KEY"></script>- 12KB gzipped
- Shadow DOM isolation
- Google Consent Mode v2
- Global Privacy Control honoured
- Declarative script gating
- Consent renewal policy
Evidence
Proof your consent records haven't been touched
Every consent record is hashed. Each day's hashes are folded into a single Merkle root, and that root is anchored to the Bitcoin blockchain, a public ledger we don't control. Change one record after the fact and the proof stops matching.
A public verify page
Anyone holding a record id can check it without an account. No login, no dashboard, no trust in us required.
A standalone verifier script
Recompute the proof yourself against our published signing key. The script does not call our API to reach its verdict.
Retention enforced in the database
The seven-year consent retention floor is a database constraint, not application logic: it cannot be bypassed by a code path that forgot about it.
consent record
- purpose
- analytics
- decision
- granted
- at
- 2026-08-06T09:14:22Z
sha256 8c4f…a91d
daily root
4f9a…c21b
anchored to the Bitcoin blockchain
Scanning
Find what your site actually sets
A fast markup scan catches what is declared. A real headless browser session catches what only appears once scripts run. Your cookie declaration comes from what the scan found, not a form someone filled in a year ago.
| Tracker | Category | Retention |
|---|---|---|
| Google Analytics | Analytics | 2 years |
| Meta Pixel | Marketing | 3 months |
| Hotjar | Analytics | 1 year |
| LinkedIn Insight | Marketing | 6 months |
AWS
Azure
GCP
PostgreSQL
MongoDB
MySQL
Snowflake
Elasticsearch
Redis
Oracle
Okta
Auth0
Datadog
Splunk
New Relic
Grafana
Integrations
31 systems, one connection each
Cloud storage, databases, and the SaaS tools where personal data quietly accumulates — wired for automated discovery, not a bespoke integration project.
PagerDuty
Slack
GitHub
Jira
Confluence
Notion
Dropbox
Box
Linear
Salesforce
HubSpot
Zendesk
Kubernetes
Docker
Terraform
Built for the teams DPDP actually lands on
Logistics & Supply Chain
Driver KYC, vehicle telematics, CCTV footage, and transporter records.
Manufacturing
Employee biometrics, contractor access logs, and visitor records.
BFSI
KYC documents, transaction history, and high-volume consent.
Healthcare
Patient records, digital health systems, and sensitive processors.
E-commerce
Customer profiles, marketing consent, and payment data.
SaaS & IT
Product analytics, cloud processors, and cross-border data flows.
Education
Student and children's data, parental consent, and digital learning.
More industries
Government, media, hospitality, and more.
The rest of it
A banner is the smallest part of DPDP
The obligations that take real work are the ones behind it: knowing what data you hold and where it goes, what each processor does with it, which controls you actually operate, and what you would send the Board on the worst day.
Data map and ROPA
Discovery connects directly to where personal data actually lives: S3 and Cloudflare R2 buckets, Azure Blob Storage, Google Cloud Storage, Postgres and MySQL databases, and Redis (ACL-scoped, TLS-enabled, key-pattern filtered), plus CSV/XLSX upload for anything else. Derive a record of processing from what it finds, version it, publish it, export it as CSV or PDF.
Vendor assessment
Send a processor questionnaire, score the response, re-assess on a cycle. A vendor nobody has assessed yet reads as unassessed, never as low risk.
Controls and frameworks
Forty-seven DPDP controls, cross-referenced to ninety-three ISO/IEC 27001:2022 Annex A references and to the SOC 2 common criteria. References with no evidence behind them are reported as uncovered, not counted as met.
Risk register and DPIA
Likelihood against impact on a five-by-five matrix taken from NIST SP 800-30, so a risk score means the same thing in every review. A risk can anchor a full Data Protection Impact Assessment (a scored questionnaire linked to that processing activity’s real data-map footprint), so higher-risk work gets the deeper review the DPDP Act expects.
Breach response
Record an incident, generate the board report, generate the notice to affected data principals.
Consent evidence at hand
Consent receipts as PDFs, coverage reporting, and every generated report carrying your own organisation branding. Retention windows and per-purpose consent are configured once in your purpose registry and drive the banner, the notice, and these reports together, not three separate places to keep in sync.
Written for the languages the Act names
Notice text is authored and hosted for all twenty-two Eighth-Schedule languages, in their own scripts. This is not a tool built for one regulation and pointed at another.
हम कुकीज़ और इसी तरह की तकनीकों का उपयोग करते हैं
Hindi
22+ languages: every Eighth-Schedule language, plus the English they are authored from, written and hosted in its own script.
A grievance route, not just a cookie banner
Data principals can raise a request or a grievance from the notice itself, and it lands somewhere you can answer it.
Age self-declaration
Section 9 requires care with children. The banner asks, records the answer against the consent record, and limits collection accordingly.
Consent that can be withdrawn
Withdrawal is as easy as giving consent in the first place, from the same control, with the change recorded as its own event.
The ones every DPDP conversation reaches
Clear answers, including the limits a serious compliance product should state plainly.
Still have questions? Drop an email at info@privacysuraksha.com.
Does the DPDP Act apply to my website?
If you collect personal data digitally (forms, accounts, analytics), yes. Obligations scale with the kind and volume of data you handle, and Significant Data Fiduciaries carry additional duties. The consent banner, the notice, and the consent record are the baseline layer every site needs.
What happens if I don't comply?
The DPDP Act provides for penalties running into hundreds of crores per instance of significant breach, and the harder operational problem is simpler: without consent records, you have nothing to show. The stakes section above has the numbers.
Isn't a cookie banner enough?
The banner is the collection point, not the obligation. DPDP also expects the notice behind it, a record of every consent decision, and working withdrawal and grievance flows. PrivacySuraksha covers all four: banner, notice, hashed records, and DSR and grievance intake.
Do visitors see the notice in their own language?
Notice text is authored and hosted for all 22 Eighth-Schedule languages.
What does PrivacySuraksha not do?
Three things, plainly: script gating is declarative, so it gates scripts declared to it rather than blocking arbitrary runtime behaviour; the age gate is self-declaration, not verified parental consent; and no tool makes you compliant by itself. PrivacySuraksha gives you the consent layer and the proof it happened.
Is this a GDPR tool translated for India, or built for the DPDP Act specifically?
Built DPDP-first. The purpose registry follows the Act's own "specified purpose" language rather than GDPR's legal-basis model, Significant Data Fiduciary duties are handled as their own tier, the grievance officer flow and the Data Protection Board's breach-notification path are India-specific requirements (not GDPR concepts relabelled), and notice text is authored and hosted for all 22 Eighth-Schedule languages, not just English.
Does it cover data discovery, consent management, and audit evidence natively, or do I still need separate tools?
Natively, across all three, with one honest caveat. Data discovery: real connectors scan S3/R2, Azure Blob, Google Cloud Storage, Postgres, MySQL, and Redis, plus CSV/XLSX upload, feeding a ROPA tied to that inventory, not just the cookie/tracker scan the free tool shows. Consent management: banner, hosted notice, and a purpose registry. Audit evidence: every consent record hashed, folded into a daily Merkle root anchored to the Bitcoin blockchain, checkable on a public verify page. The caveat: DPIA is a scored questionnaire linked to your data map, not a fully automated risk engine, and retention periods are configured per purpose but not yet auto-enforced; both are honest gaps, not marketing gaps.
How fast can I get live, and what does the "one line of code" setup actually involve?
Two steps, one sitting. First, verify you own the domain (a DNS TXT record or a hosted verification file, a few minutes). Then add one script tag with your site key, and the consent banner is live. "One line of code" describes that second step accurately; it's not the whole setup, just the only part that touches your site's own code.
See what your own site is leaking
Enter a domain and we name the third-party trackers loading on it. No email, no account, and nothing stored.
DPDP Website Scanner