Skip to content
DPDP deadline in
Learn more →
PrivacySuraksha - Privacy. Trust. Compliance

India's DPDP privacy operations platform

Know your data
Control your risks
Prove your compliance

One command center for the DPDP Act: auto-discovered data maps, artifact-backed consent, and evidence that beats the 72-hour breach clock. Built for India, not translated for it. One line of code.

Prove it before the Board asks.

Ask AI about PrivacySuraksha

OverviewSearch vendors, risks, ROPA…
Recorded decisions17Last 30 days
Opt-in share37%Non-essential categories
Evidence sealed100%17 of 17 records
Needs attention2See queue below
Consent trend
Decision mix
Save preferences
Reject non-essential
Accept all
Withdraw
2 open grievances

Aadhaar found in 3 repositories

High risk

Consent evidence verified

Anchored

One platform. Complete privacy lifecycle.

Everything you need for DPDP compliance

Ready-made, not roll-your-own

8 designs ship with the banner. Pick one, or match your own brand — the consent record it writes is identical either way.

Ready-made designs

Enforcement timeline

DPDP Rules 2025. Three phases, one hard deadline

Learn more
  1. Active

    Data Protection Board operational

    Complaints are being accepted now.

  2. Consent Managers come into force

    Implementation has to start well before this date, not on it.

  3. Deadline

    Full enforcement

    The hard deadline for complete DPDP compliance.

₹250 cr

Maximum penalty per instance under the DPDP Act. That is the ceiling; the floor is still in crores.

Rules 2025

Consent, notice and data-principal rights are operational now. The clock on obligations is running.

Every website

DPDP applies by data type, not company size. If you collect personal data, the Act applies to you.

PrivacySuraksha exists so the answer to “show me your consent records” is a link, not a scramble.

One line of code

Add the snippet, verify your domain, publish your configuration. Consent is recorded on the next page load: no build step, no framework integration, no tag manager required.

<script src="https://cdn.privacysuraksha.com/cmp.js" data-key="YOUR_SITE_KEY"></script>
  • 12KB gzipped
  • Shadow DOM isolation
  • Google Consent Mode v2
  • Global Privacy Control honoured
  • Declarative script gating
  • Consent renewal policy

Evidence

Proof your consent records haven't been touched

Every consent record is hashed. Each day's hashes are folded into a single Merkle root, and that root is anchored to the Bitcoin blockchain, a public ledger we don't control. Change one record after the fact and the proof stops matching.

  • A public verify page

    Anyone holding a record id can check it without an account. No login, no dashboard, no trust in us required.

  • A standalone verifier script

    Recompute the proof yourself against our published signing key. The script does not call our API to reach its verdict.

  • Retention enforced in the database

    The seven-year consent retention floor is a database constraint, not application logic: it cannot be bypassed by a code path that forgot about it.

consent record

purpose
analytics
decision
granted
at
2026-08-06T09:14:22Z

sha256 8c4f…a91d

daily root

4f9a…c21b

anchored to the Bitcoin blockchain

Scanning

Find what your site actually sets

A fast markup scan catches what is declared. A real headless browser session catches what only appears once scripts run. Your cookie declaration comes from what the scan found, not a form someone filled in a year ago.

Generated cookie declaration
TrackerCategoryRetention
Google AnalyticsAnalytics2 years
Meta PixelMarketing3 months
HotjarAnalytics1 year
LinkedIn InsightMarketing6 months
  • AWS
  • Azure
  • GCP
  • PostgreSQL
  • MongoDB
  • MySQL
  • Snowflake
  • Elasticsearch
  • Redis
  • Oracle
  • Okta
  • Auth0
  • Datadog
  • Splunk
  • New Relic
  • Grafana

Integrations

31 systems, one connection each

Cloud storage, databases, and the SaaS tools where personal data quietly accumulates — wired for automated discovery, not a bespoke integration project.

  • PagerDuty
  • Slack
  • GitHub
  • Jira
  • Confluence
  • Notion
  • Dropbox
  • Box
  • Linear
  • Salesforce
  • HubSpot
  • Zendesk
  • Kubernetes
  • Docker
  • Terraform

Built for the teams DPDP actually lands on

The rest of it

A banner is the smallest part of DPDP

The obligations that take real work are the ones behind it: knowing what data you hold and where it goes, what each processor does with it, which controls you actually operate, and what you would send the Board on the worst day.

Written for the languages the Act names

Notice text is authored and hosted for all twenty-two Eighth-Schedule languages, in their own scripts. This is not a tool built for one regulation and pointed at another.

हम कुकीज़ और इसी तरह की तकनीकों का उपयोग करते हैं

Hindi

22+ languages: every Eighth-Schedule language, plus the English they are authored from, written and hosted in its own script.

The ones every DPDP conversation reaches

Clear answers, including the limits a serious compliance product should state plainly.

Still have questions? Drop an email at info@privacysuraksha.com.

Does the DPDP Act apply to my website?

If you collect personal data digitally (forms, accounts, analytics), yes. Obligations scale with the kind and volume of data you handle, and Significant Data Fiduciaries carry additional duties. The consent banner, the notice, and the consent record are the baseline layer every site needs.

What happens if I don't comply?

The DPDP Act provides for penalties running into hundreds of crores per instance of significant breach, and the harder operational problem is simpler: without consent records, you have nothing to show. The stakes section above has the numbers.

Isn't a cookie banner enough?

The banner is the collection point, not the obligation. DPDP also expects the notice behind it, a record of every consent decision, and working withdrawal and grievance flows. PrivacySuraksha covers all four: banner, notice, hashed records, and DSR and grievance intake.

Do visitors see the notice in their own language?

Notice text is authored and hosted for all 22 Eighth-Schedule languages.

What does PrivacySuraksha not do?

Three things, plainly: script gating is declarative, so it gates scripts declared to it rather than blocking arbitrary runtime behaviour; the age gate is self-declaration, not verified parental consent; and no tool makes you compliant by itself. PrivacySuraksha gives you the consent layer and the proof it happened.

Is this a GDPR tool translated for India, or built for the DPDP Act specifically?

Built DPDP-first. The purpose registry follows the Act's own "specified purpose" language rather than GDPR's legal-basis model, Significant Data Fiduciary duties are handled as their own tier, the grievance officer flow and the Data Protection Board's breach-notification path are India-specific requirements (not GDPR concepts relabelled), and notice text is authored and hosted for all 22 Eighth-Schedule languages, not just English.

Does it cover data discovery, consent management, and audit evidence natively, or do I still need separate tools?

Natively, across all three, with one honest caveat. Data discovery: real connectors scan S3/R2, Azure Blob, Google Cloud Storage, Postgres, MySQL, and Redis, plus CSV/XLSX upload, feeding a ROPA tied to that inventory, not just the cookie/tracker scan the free tool shows. Consent management: banner, hosted notice, and a purpose registry. Audit evidence: every consent record hashed, folded into a daily Merkle root anchored to the Bitcoin blockchain, checkable on a public verify page. The caveat: DPIA is a scored questionnaire linked to your data map, not a fully automated risk engine, and retention periods are configured per purpose but not yet auto-enforced; both are honest gaps, not marketing gaps.

How fast can I get live, and what does the "one line of code" setup actually involve?

Two steps, one sitting. First, verify you own the domain (a DNS TXT record or a hosted verification file, a few minutes). Then add one script tag with your site key, and the consent banner is live. "One line of code" describes that second step accurately; it's not the whole setup, just the only part that touches your site's own code.

See what your own site is leaking

Enter a domain and we name the third-party trackers loading on it. No email, no account, and nothing stored.

DPDP Website Scanner