🇮🇳 DPDP Act 2023 is now enforceable law
CERT-In 6 h · DPDP 72 h — both clocks tracked independently
🇮🇳 India Data Residency · 22-Language Banners

India's DPDP Compliance Platform —
Fully Automated.

The only consent management software built natively for DPDP 2023 — and the only DPDP compliance platform that tracks both the CERT-In 6-hour and DPDP 72-hour Board notification breach windows independently. Cookie consent management, Data Principal rights workflows, Data Discovery across your databases, and global frameworks from one dashboard.

DPDP 2023
CERT-In Directions
GDPR
CCPA / CPRA
LGPD Brazil
India Data Residency
ISO 9001 Certified
NASSCOM Member
🏛️ DSCI Member
🔒 DPIIT Recognised
₹250Cr
Maximum DPDP penalty per category of violation for a Data Fiduciary
DPDP Act 2023 · Section 33
6 hrs
CERT-In mandatory breach reporting window — independent of DPDP Board notification
CERT-In Directions · April 2022
22
Eighth Schedule languages — consent banners delivered in every official Indian language
Indian Constitution · Eighth Schedule
1,000
Cookie consents + 50 form consents free every month — no credit card, no expiry
Consiva Free Plan · Forever
ISO 9001 CertifiedNASSCOM Member🏛️ DSCI Member🔒 DPIIT Recognised
🇮🇳 DPDP Act 2023NATIVE
CERT-In 20226-HR SLA
🇪🇺 GDPRCOVERED
🇺🇸 CCPA / CPRA
🇧🇷 LGPD Brazil
☁️ India Data ResidencyIN-REGION
🗄️ SQL Server · MySQL · PostgreSQLDATA DISCOVERY
🌐 WordPress PluginONE-CLICK
🛍️ Shopify AppONE-CLICK
📋 ROPA Auto-Generation
👨‍👩‍👧 DPDP 9 Parental Consent
Significant Data Fiduciary ModuleSDF
🇮🇳 DPDP Act 2023NATIVE
CERT-In 20226-HR SLA
🇪🇺 GDPRCOVERED
🇺🇸 CCPA / CPRA
🇧🇷 LGPD Brazil
☁️ India Data ResidencyIN-REGION
🗄️ SQL Server · MySQL · PostgreSQLDATA DISCOVERY
🌐 WordPress PluginONE-CLICK
🛍️ Shopify AppONE-CLICK
📋 ROPA Auto-Generation
👨‍👩‍👧 DPDP 9 Parental Consent
Significant Data Fiduciary ModuleSDF
The Compliance Imperative

DPDP is enforceable.
Most businesses aren't ready.

The DPDP Act 2023 is live, enforceable law. Every digital service processing personal data of Indian residents is in scope — regardless of where the company is headquartered.

Platform Walkthrough

Every compliance workflow
in one connected dashboard.

From cookie consent to CERT-In breach tracking — see exactly how Consiva keeps your organisation compliant across DPDP, GDPR, and CERT-In simultaneously.

consiva.ai/dashboard
⬡ Consiva.aiNAVIGATION📊 Dashboard🌐 Domains🎨 Banner Builder📈 Analytics📋 Consent Logs⚖️ Rights Requests🔔 Data Breaches🗄️ Data Discovery🔌 Integrations🏢 Vendors🔗 Webhooks👑 SuperadminCompliance DashboardLast updated: moments ago · enterprise-corp.comTOTAL CONSENTS48,291↑ 12% this weekACCEPTANCE RATE73.4%↑ 4.2% vs prevRIGHTS REQUESTS14228 pending reviewDOMAINS ACTIVE7All compliantConsent Trend (30 days)Recent Events✅ Consent granted↩ Withdrawal req.🔍 Rights request🌐 New domain
01Compliance DashboardReal-time overview
consiva.ai/banner-builder
Banner BuilderVisual consent UI designerTEMPLATEDPDP Banner — DarkPOSITIONBottom BarModal CenterACCENT COLORPURPOSESStrictly NecessaryAnalytics & PerformanceMarketing & TargetingPUBLISH LIVELive PreviewAccept AllManage PreferencesReject
02Visual Banner BuilderNo-code consent UI
consiva.ai/analytics
Consent Analyticsenterprise-corp.com · Last 30 daysLast 30d ▾All Domains ▾Export73.4%AcceptanceAccepted All — 73.4%Partial Accept — 14.1%Rejected — 12.5%Geographic DistributionIndia Regions · DPDP CoverageMaharashtra 31%Karnataka 18%By PurposeNecessary 100%Analytics 73%Marketing 48%Social 33%Personalisation 20%WITHDRAWALS (30d)1,847↓ 6% vs prev periodAVG CONSENT AGE142 daysRenewal recommendedCOMPLIANCE SCORE98.2 / 1002 minor recommendations
03Consent AnalyticsAudit-ready reporting
consiva.ai/consent-logs
Consent LogsImmutable audit trail · All records cryptographically signed🔍 Search by visitor ID, email, domain…Status ▾Purpose ▾Export CSVVISITOR IDTIMESTAMPACTIONPURPOSESCHANNELREGIONv8f3●●●●b2c2026-07-29 09:41:02GRANTEDAnalytics, MarketingWebIN-MHv2a9●●●●f7d2026-07-29 09:39:17WITHDRAWNAll PurposesMobile SDKIN-KAv5k1●●●●c9e2026-07-29 09:38:45GRANTEDNecessary OnlyWebIN-DLv7m4●●●●a3f2026-07-29 09:37:01GRANTEDAnalytics, MarketingAPIIN-TNShowing 1–25 of 48,291 records123
04Consent Logs & Audit TrailImmutable · Exportable
consiva.ai/rights-requests
Data Principal RightsDPDP 6, 11–14 · Automated workflows · 30-day SLA trackedTOTAL REQUESTS142This quarterPENDING28Avg 4.2 days waitCOMPLETED108Within SLAOVERDUE6Escalation triggered+ NewRequestREQ IDTYPEDATA PRINCIPALSUBMITTEDSTATUSSLARR-2026-0847Access Requestad●●●@enterprise.comJul 29, 2026IN REVIEW6 days leftRR-2026-0846Erasure Req.us●●●@corp.comJul 28, 2026COMPLETEDone ✓DPDP RIGHTS COVERED:Consent WithdrawalRight to AccessCorrectionErasureGrievance · Nomination
05Data Principal RightsDPDP 6, 11–14 compliant
consiva.ai/data-breaches
⚠ CERT-IN WINDOW ACTIVEIncident #CERT-2026-047 · Detected 2026-07-29 09:14 IST · API Endpoint Exposure · ~2,400 recordsconsiva.aiData Breach TrackerDual-clock compliance · CERT-In 6h + DPDP Board 72h · Tracked independentlyCERT-IN 6-HOUR WINDOW04:12remaining · 70% elapsed⚡ Submit to cert-in.org.in · Report pre-draftedDPDP BOARD WINDOW70:12remaining · 3% elapsed📋 Draft Board notification · Queue for reviewIncident #CERT-2026-047 — API Endpoint ExposureImpacted: ~2,400 user records (email, phone) · Vector: Misconfigured endpoint · Contained ✓CERT-In report auto-drafted · DPDP Board notification queued · India data residency confirmedNotify CERT-InQueue BoardExport PDF🇮🇳 India Data Residency
06Data Breach TrackerCERT-In 6h · DPDP 72h · Dual-clock
consiva.ai/integrations
IntegrationsDeploy your consent banner to any platform — one click, no code requiredWordPressConsiva Consent Banner① Plugins → Add New② Search "Consiva Consent"③ Install → Activate④ Paste Script Key → SaveScript Keycvs-prod-••••••••Save Settings✓ Connected & Live🛍ShopifyOne-click install⚡ ONE-CLICK INSTALL① Shopify App Store② Search "Consiva Consent"③ Authorise — doneAuto-syncs with your dashboard.Consiva Consent4.9 ★ · DPDP VerifiedAdd to ShopifyDPDP 2023 Compliant</> Script TagUniversal · Any platform<!-- paste in <head> --><script src="cdn.consiva.ai/v3.js" data-key="cvs-••••••"></script>Copy CodeWorks with:✓ React / Next.js✓ Angular / Vue✓ Custom HTML / PHP✓ Google Tag Manager
07IntegrationsWordPress · Shopify · Script tag
Platform Walkthrough

Every DPDP obligation,
handled by one platform.

DPDP-Native Consent

Consent capture designed for India's law — not retrofitted from GDPR.

Auto-scans every cookie and tracker on your domain, categorises them by purpose, and presents DPDP-format consent banners in any Eighth Schedule language — deployed via a single script tag.

  • Purpose-specific consent with DPDP 6 format records and immutable timestamp
  • 22 Eighth Schedule languages — Hindi, Tamil, Bengali, Marathi and more
  • Live banner preview with mobile simulation before publishing
  • Consent logs with version, IP, purpose breakdown — regulator-ready
consiva.ai/dashboard/banner-builder
Consiva.ai🎨 Banner Builder📊 Dashboard🌐 Domains⚖️ Rights Requests🔔 Breaches🗄️ Data Discovery📈 AnalyticsBanner Builder — acme.inLANGUAGEHindi (हिन्दी) ▾PURPOSES✓ Necessary (Always Active)☐ Analytics — Google Analytics 4☐ Marketing — Meta Pixel+ Add PurposeSCRIPT KEYdata-domain-id="a1b2c3d4-••••-••••"LIVE PREVIEWacme🍪 हम कुकीज़ का उपयोग करते हैंAnalytics और Marketing के लिए।स्वीकार करेंप्रबंधितSCRIPT TAG<script src="app.consiva.ai/...">
Data Principal Rights

All DPDP Data Principal rights — with email-verified workflows and live SLA timers.

DPDP 6, 11–14 gives every Indian user clear rights over their personal data. Consiva automates intake, identity verification, routing, fulfilment, and the immutable audit trail — with escalation before SLA breach.

  • Consent Withdrawal · Access to Information · Correction & Erasure · Grievance · Nomination
  • 7-day and 30-day SLA countdown with auto-escalation to DPO
  • Email-verified identity confirmation before any data action
  • Full case audit trail — regulator-exportable PDF
consiva.ai/dashboard/rights
Consiva.ai⚖️ Rights RequestsData Principal Rights — DPDP 6, 11–14OPEN REQUESTS12DUE TODAY5COMPLETED26AVG RESOLUTION4.2 daysREFERENCETYPEDATA PRINCIPALSLASTATUSDSR-2026-047ERASURE••@gmail ✓⏱ TODAYIN REVIEWDSR-2026-046ACCESS••@yahoo ✓Aug 3FULFILLEDDSR-2026-045CORRECTION••@icloud ✓Aug 1FULFILLEDDPDP RIGHTS COVERED6 Consent Withdrawal11 Access to Info12 Correction12 Erasure13 Grievance14 NominationAll with SLA + immutable audit
CERT-In Breach Tracker

The only Indian consent platform with an independent CERT-In 6-hour SLA tracker.

A data breach triggers two separate regulatory clocks simultaneously. Consiva tracks both independently — CERT-In's 6-hour window and DPDP Board's notification window — with auto-drafted reports for each regulator.

  • Separate 6-hr CERT-In countdown, independent of the DPDP Board window
  • 180-day incident log retention per CERT-In Directions 3(iv)
  • Auto-drafted CERT-In report, pre-filled for cert-in.org.in submission
  • Escalation alerts before either regulatory deadline lapses
consiva.ai/dashboard/breaches
Consiva.ai🔔 Data Breaches⚠ CERT-In Window Active — Incident #CERT-2026-047CERT-In closes in 4h 12m · DPDP Board closes in 70h 12m · Breach detected 2026-07-29 09:14 ISTCERT-IN 6-HOUR WINDOW04:1270% of window elapsedDPDP BOARD WINDOW70:123% of window elapsedIncident #CERT-2026-047 — API Endpoint ExposureImpacted: ~2,400 user records (email, phone) · Vector: Misconfigured endpoint · Contained ✓CERT-In report: Auto-drafted · Ready to submit at cert-in.org.inDPDP Board notification: Queued · Draft savedNotify CERT-InQueue BoardExport PDF
Data Discovery

Find personal data hiding
in your databases — automatically.

Connect your database in one click. Consiva scans every table, flags personal data at rest, and maps it to your DPDP processing purposes — powering your ROPA automatically.

Microsoft SQL Server
ENTERPRISE · EXPRESS · AZURE SQL
BUILT-IN
Connect via host, port, and credentials. Passwords are encrypted at rest and write-only — never exposed in any API response. Scans all tables for PII column patterns.
Auto-detects email, phone, name, Aadhaar patterns
Maps columns to DPDP processing purposes
Generates ROPA entries automatically
PostgreSQL
V12+ · SUPABASE · AWS RDS
BUILT-IN
Full schema introspection across all schemas and tables. Works with managed PostgreSQL on Supabase, AWS RDS, and self-hosted. Encrypted credential storage.
Scans all schemas, tables, and views
Regex + pattern classification of PII columns
Repeat scans with incremental diff report
MySQL / MariaDB
MYSQL 5.7+ · MARIADB · AURORA
BUILT-IN
Connects to any MySQL-compatible database. Scans non-system tables only — safe for production environments. Supports SSL/TLS connections.
Non-system schema scan — zero production risk
Supports SSL/TLS encrypted connections
Compatible with WooCommerce, Magento DBs
One-Click CMS & E-commerce Integrations
WordPressOFFICIAL PLUGIN
Install the Consiva Consent Banner plugin from WP Plugins. Paste your Script Key from the Consiva dashboard. Done — banner live on every page, zero code required.
Settings → Consiva Consent Banner → Paste Script Key → Save
ShopifyONE-CLICK
Install from the Shopify App Store in one click. Auto-injects your consent banner on every storefront page, syncs with Shopify's Customer Privacy API, and captures marketing opt-in at checkout.
App Store → Install Consiva Consent → Enter Script Key → Save
Compliance Scope

If you process Indian users' data,
DPDP applies to you.

E-Commerce & D2C
Checkout data, order history, returns, loyalty programmes — DPDP regulates every bit of it.
Healthcare & Wellness
Patient records and health app data are sensitive personal data with stricter DPDP obligations.
BFSI & Fintech
KYC, transaction histories, and credit data — under both DPDP and RBI data governance frameworks.
SaaS & Mobile Apps
Any SaaS processing Indian user data — regardless of server location — is in scope.
EdTech & Online Learning
Student data and minors' data invoke DPDP 9 parental consent — one of its strictest provisions.
Global Enterprises
Overseas companies with Indian customer data must comply. DPDP follows the data, not the domicile.
Platform Capabilities

Everything DPDP requires.
Nothing compliance teams don't.

Automatic Cookie & Tracker Scanning
Continuous scanner discovers every cookie, pixel, and third-party script on your domains — including those added by CMS plugins or tag managers without your knowledge. Auto-categorised and mapped to consent purposes on every scan cycle.
NecessaryAnalyticsMarketingPreferencesThird-party
ROPA Auto-generation
Records of Processing Activities built automatically from scan results, consent logs, and Data Discovery findings. Updated on every scan cycle — always current for regulator review.
Parental Consent (DPDP 9)
DPDP mandates verifiable parental consent before processing children's data. Consiva provides age-gate logic, verification workflow, and a complete audit trail per minor user.
Multi-Framework Geolocation
Serve GDPR banners in the EU, CCPA opt-outs in California, and DPDP banners in India — auto-switched by visitor location. All from one script tag, one dashboard.
India Data Residency
All consent logs, rights request records, and breach reports stored exclusively in India — meeting DPDP data localisation provisions on every plan.
Consent Analytics
Opt-in rates by banner variant, category, domain, and traffic source. AB test banner text to optimise consent rates without compromising compliance.
Immutable Audit Logs
Every consent event, rights action, and breach record written to an append-only log. Tamper-evident, exportable, and ready for regulator review at any time.
SDF Module
Significant Data Fiduciary obligations — DPO workflow management, DPIA templates, annual audit readiness, and algorithmic accountability dashboards. Enterprise plan.
Vendor Register & DPA Tracking
Maintain a live register of all data processors, their DPA status, risk tiers, and sub-processor chains. Get alerted when a DPA expires or a vendor's risk profile changes. SCC templates included.
Webhooks & Real-Time Events
Push consent events, rights-request updates, and breach alerts to your own systems in real time via HMAC-SHA256 signed webhooks. REST API available for custom integrations on Pro and Enterprise plans.
Quick Start

Live in 10 minutes.
Compliant for years.

01
Register & Verify Your Domain
Create your free account at app.consiva.ai — no credit card required. Add your domain and click Verify. Consiva confirms ownership and starts the first cookie scan immediately.
🆓 1,000 cookie consents + 50 form consents free — every month, forever
02
Review Cookies & Set Purposes
The scanner returns every cookie, pixel, and tracker with suggested DPDP purpose categories pre-filled. Review, adjust, and add custom purposes matching your processing activities.
03
Configure Banner & Language
Choose your banner layout, accent colour, and language. Select from 22 Eighth Schedule languages. Preview on mobile and desktop before publishing.
04
Deploy — One Script Tag
Copy a single <script> tag and paste it in your site's <head>. For WordPress, install the Consiva Consent Banner plugin and paste your Script Key in Settings — done in under 60 seconds.
05
Connect Databases (Optional)
Go to Data Discovery → Add Source. Enter your SQL Server, PostgreSQL, or MySQL credentials. Consiva scans your tables, flags personal data columns, and auto-populates your ROPA — no SQL required from your side.
06
Monitor, Respond, Stay Compliant
Your dashboard shows live consent rates, incoming rights requests with SLA timers, and breach incidents. Consiva alerts you before any deadline — CERT-In 6-hour or DPDP Board — and pre-drafts every regulatory notification.
DPDP + CERT-In covered from a single platform
Pricing

Start free. Scale when you're ready.

All plans include DPDP 2023 compliance, CERT-In tracking, and India data residency. No hidden fees.

⏳ Limited Time Offer
Free
₹0
Forever free · No credit card required
Full DPDP compliance for individuals and small sites. No time limit.
Get Started Free
Cookie consents 1,000 / mo
Form consents 50 / mo
Domains 1
Basic cookie scanning
DPDP banner (English & Hindi)
Basic analytics
Manual rights request handling
WordPress plugin
1 onboarding session
CERT-In breach tracker
Automated DSR workflows
22 languages
MOST POPULAR
Pro
₹5,999
/month + taxes · billed monthly
Everything a growing business needs — full automation, 22 languages, and CERT-In breach tracking.
Start Pro
Cookie consents 15,000 / mo
Form consents 1,500 / mo
Domains 5 + add-ons
Automated, scheduled cookie scanning
DPDP + GDPR banners
22 Eighth Schedule languages
Enhanced analytics — exportable CSV
Automated DSR workflows — access, correction, erasure, grievance with SLA
CERT-In breach tracker
Parental consent workflows (DPDP §9)
WordPress plugin
5 onboarding sessions + email support
Data Discovery (SQL/MySQL/PostgreSQL)
ROPA auto-generation
Enterprise
Custom
On-prem or cloud · SLA guaranteed
For large enterprises, government bodies, SDFs, and organisations with custom compliance needs.
Get Started
Cookie consents Unlimited
Form consents Unlimited
Domains Unlimited
All Pro features
Multi-framework routing — DPDP, GDPR, CCPA & more
Full CERT-In breach module — playbooks & auto-notifications
Data Discovery — SQL, MySQL, PostgreSQL native connectors
ROPA auto-generation
Regional & dialect language customisation
Custom rights & system-of-record integration
SDF module — DPO workflow, DPIA, annual audit
On-premise deployment option
Dedicated CSM + implementation consultant

Add-On Packs

· Available on annual Pro and Enterprise plans · 20% off pay-as-you-go rates · Prices exclude applicable taxes
Domain Pack
+10 domains
₹80,000/yr
₹8,000 per domain per year
Save ₹20,000 vs pay-as-you-go
Cookie Consent Pack
+10,000 cookie consents/mo
₹14,400/yr
₹1,200/month billed annually
Save ₹3,600 vs pay-as-you-go
Form Consent Pack
+1,000 form consents/mo
₹3,360/yr
₹280/month billed annually
Save ₹840 vs pay-as-you-go
Resources & Blog

DPDP Compliance Guides
for Indian Businesses

Expert guides on DPDP compliance, cookie consent management, data privacy, and CERT-In obligations — written for Indian compliance teams and legal officers.

Is the DPDP Act enforceable yet — commencement dates
DPDP Compliance

Is DPDP Enforceable Yet? What the Gazette Actually Says

The Data Protection Board exists and functions, but the substantive obligations and the entire penalty regime commence on 13 May 2027. The three commencement dates, from the gazette notifications.

Google Consent Mode v2 vs DPDP consent requirements
Consent Management

Google Consent Mode v2 Isn't DPDP Consent. Here's the Gap

Consent Mode v2 tells Google what a visitor chose. It doesn't obtain consent, doesn't produce a record you can show a regulator, and doesn't cover non-Google tags. Here's what's missing.

The Rule 8(2) 48-hour pre-erasure notice
DPDP Compliance

The 48-Hour Notice Nobody Has Built

Rule 8(2) requires you to tell a Data Principal 48 hours before their data is erased. Read as an engineer, that is a scheduled job with a clock, a notification, a reset listener and an audit record.

View All DPDP Compliance Resources
FAQ

Common questions about
DPDP compliance and Consiva.

Yes. The DPDP Act received Presidential assent on 11 August 2023. The Government has notified the Data Protection Board and implementation rules. Enforcement through penalties is now active. The ₹250 crore ceiling applies per category of violation — systemic failures can attract cumulative penalties far exceeding that figure.

Yes. DPDP follows the data, not the corporate domicile. Any entity that collects, stores, or processes personal data of individuals in India — regardless of server location or company registration — is subject to DPDP. A US SaaS with Indian users must comply. This mirrors the GDPR extraterritorial model.

CERT-In's April 2022 Directions require reporting cybersecurity incidents within 6 hours of detection — completely independent of DPDP's Board notification obligation. Most consent tools only handle DPDP notification and miss the CERT-In window entirely. Consiva tracks both clocks independently from the moment a breach is logged, with separate auto-drafted reports for each regulator.

The free plan includes 1,000 cookie consents and 50 form consents per month — permanently free, no credit card required. You get basic cookie scanning, DPDP banners in English and Hindi, basic analytics, manual rights request handling, and WordPress plugin support for one domain. Automated DSR workflows, the CERT-In breach tracker, 22 languages, and multi-domain support require the Pro plan.

Data Discovery connects to your SQL Server, MySQL, or PostgreSQL databases and scans every table for personal data at rest — email addresses, phone numbers, Aadhaar patterns, and other PII. This is required for an accurate ROPA under DPDP and to identify data that must be erased when a §12 erasure request arrives.

Install the Consiva Consent Banner plugin from the WordPress Plugin Directory. Go to Settings → Consiva Consent Banner and paste your Script Key from the Consiva dashboard. Save — the banner is immediately active on every page, no theme edits needed. The plugin syncs directly with your Consiva dashboard.

The DPDP Act gives every Indian individual: §6(4) withdraw consent at any time; §11 access information about their data being processed; §12 correction and erasure of inaccurate or unnecessary data; §13 grievance redressal through the Data Fiduciary's Grievance Officer; §14 nominate a representative to exercise rights on their behalf after death or incapacity. Consiva manages intake, identity verification, SLA tracking, and fulfilment workflows for all these rights.

Yes — Multi-Framework Mode on Pro and Enterprise plans. Consiva detects the visitor's jurisdiction via IP geolocation and serves the appropriate banner: DPDP format for India, GDPR-compliant for EU/EEA, CCPA opt-out for California, LGPD for Brazil. All from one script tag.

All consent logs, rights request records, breach incident reports, and audit trails are stored exclusively in India on cloud infrastructure meeting DPDP data localisation requirements. Database credentials entered for Data Discovery are encrypted at rest and are write-only — never returned by any API response.

An SDF is a Data Fiduciary designated by the Government under DPDP §10 based on volume, sensitivity, and national security risk. SDFs face additional obligations: appointing an Indian resident as DPO, annual data audits, Data Protection Impact Assessments, and algorithmic accountability measures. Consiva's SDF module — on Enterprise plans — covers all of these.

Start today — it's free

DPDP is enforceable.
Your compliance window
is closing.

Set up in under 10 minutes. 1,000 cookie consents + 50 form consents included every month — forever free. No credit card required.

No credit card
Live in 10 minutes
India data residency
DPDP + CERT-In covered
99.9% uptime SLA