Eighth Schedule languages — consent banners delivered in every official Indian language
Indian Constitution · Eighth Schedule
1,000
Cookie consents + 50 form consents free every month — no credit card, no expiry
Consiva Free Plan · Forever
ISO 9001 CertifiedNASSCOM Member🏛️ DSCI Member🔒 DPIIT Recognised
🇮🇳 DPDP Act 2023NATIVE
CERT-In 20226-HR SLA
🇪🇺 GDPRCOVERED
🇺🇸 CCPA / CPRA
🇧🇷 LGPD Brazil
☁️ India Data ResidencyIN-REGION
🗄️ SQL Server · MySQL · PostgreSQLDATA DISCOVERY
🌐 WordPress PluginONE-CLICK
🛍️ Shopify AppONE-CLICK
📋 ROPA Auto-Generation
👨👩👧 DPDP 9 Parental Consent
Significant Data Fiduciary ModuleSDF
🇮🇳 DPDP Act 2023NATIVE
CERT-In 20226-HR SLA
🇪🇺 GDPRCOVERED
🇺🇸 CCPA / CPRA
🇧🇷 LGPD Brazil
☁️ India Data ResidencyIN-REGION
🗄️ SQL Server · MySQL · PostgreSQLDATA DISCOVERY
🌐 WordPress PluginONE-CLICK
🛍️ Shopify AppONE-CLICK
📋 ROPA Auto-Generation
👨👩👧 DPDP 9 Parental Consent
Significant Data Fiduciary ModuleSDF
The Compliance Imperative
The DPDP deadline is real. Most businesses aren't ready.
The DPDP Act 2023 is law, with its substantive obligations and penalty regime commencing 13 May 2027. Every digital service processing personal data of Indian residents will be in scope — regardless of where the company is headquartered.
⚠️
Dual Penalty Exposure — DPDP Board + CERT-In hit simultaneously
DPDP 2023 imposes up to ₹250 Crore per violation category for inadequate consent mechanisms or failure to fulfil Data Principal rights. CERT-In Directions 2022 impose up to ₹1 Crore for failure to report cybersecurity incidents within 6 hours. A single data breach starts both regulatory clocks simultaneously — yet most consent tools only track one. Consiva tracks both, with independent SLA timers and auto-drafted notification reports for each regulator.
Pricing
Start free. Scale when you're ready.
All plans include DPDP 2023 compliance, CERT-In tracking, and India data residency. No hidden fees.
⏳ Limited Time Offer
Basic
₹2,499
₹0
Forever free · No credit card required
Full DPDP compliance for individuals and small sites. No time limit.
· Available on annual Pro and Enterprise plans · 20% off pay-as-you-go rates · Prices exclude applicable taxes
Domain Pack
+10 domains
₹80,000/yr
₹8,000 per domain per year
Save ₹20,000 vs pay-as-you-go
Cookie Consent Pack
+10,000 cookie consents/mo
₹14,400/yr
₹1,200/month billed annually
Save ₹3,600 vs pay-as-you-go
Form Consent Pack
+1,000 form consents/mo
₹3,360/yr
₹280/month billed annually
Save ₹840 vs pay-as-you-go
Platform Walkthrough
Every compliance workflow in one connected dashboard.
From cookie consent to CERT-In breach tracking — see exactly how Consiva keeps your organisation compliant across DPDP, GDPR, and CERT-In simultaneously.
Consent capture designed for India's law — not retrofitted from GDPR.
Auto-scans every cookie and tracker on your domain, categorises them by purpose, and presents DPDP-format consent banners in any Eighth Schedule language — deployed via a single script tag.
Purpose-specific consent with DPDP 6 format records and immutable timestamp
22 Eighth Schedule languages — Hindi, Tamil, Bengali, Marathi and more
Live banner preview with mobile simulation before publishing
Consent logs with version, IP, purpose breakdown — regulator-ready
consiva.ai/dashboard/banner-builder
Data Principal Rights
All DPDP Data Principal rights — with email-verified workflows and live SLA timers.
DPDP 6, 11–14 gives every Indian user clear rights over their personal data. Consiva automates intake, identity verification, routing, fulfilment, and the immutable audit trail — with escalation before SLA breach.
Consent Withdrawal · Access to Information · Correction & Erasure · Grievance · Nomination
7-day and 30-day SLA countdown with auto-escalation to DPO
Email-verified identity confirmation before any data action
Full case audit trail — regulator-exportable PDF
consiva.ai/dashboard/rights
CERT-In Breach Tracker
The only Indian consent platform with an independent CERT-In 6-hour SLA tracker.
A data breach triggers two separate regulatory clocks simultaneously. Consiva tracks both independently — CERT-In's 6-hour window and DPDP Board's notification window — with auto-drafted reports for each regulator.
Separate 6-hr CERT-In countdown, independent of the DPDP Board window
180-day incident log retention per CERT-In Directions 3(iv)
Auto-drafted CERT-In report, pre-filled for cert-in.org.in submission
Escalation alerts before either regulatory deadline lapses
consiva.ai/dashboard/breaches
Data Discovery
Find personal data hiding in your databases — automatically.
Connect your database in one click. Consiva scans every table, flags personal data at rest, and maps it to your DPDP processing purposes — powering your ROPA automatically.
Microsoft SQL Server
ENTERPRISE · EXPRESS · AZURE SQL
BUILT-IN
Connect via host, port, and credentials. Passwords are encrypted at rest and write-only — never exposed in any API response. Scans all tables for PII column patterns.
Auto-detects email, phone, name, Aadhaar patterns
Maps columns to DPDP processing purposes
Generates ROPA entries automatically
PostgreSQL
V12+ · SUPABASE · AWS RDS
BUILT-IN
Full schema introspection across all schemas and tables. Works with managed PostgreSQL on Supabase, AWS RDS, and self-hosted. Encrypted credential storage.
Scans all schemas, tables, and views
Regex + pattern classification of PII columns
Repeat scans with incremental diff report
MySQL / MariaDB
MYSQL 5.7+ · MARIADB · AURORA
BUILT-IN
Connects to any MySQL-compatible database. Scans non-system tables only — safe for production environments. Supports SSL/TLS connections.
Non-system schema scan — zero production risk
Supports SSL/TLS encrypted connections
Compatible with WooCommerce, Magento DBs
One-Click CMS & E-commerce Integrations
WordPressOFFICIAL PLUGIN
Install the Consiva Consent Banner plugin from WP Plugins. Paste your Script Key from the Consiva dashboard. Done — banner live on every page, zero code required.
Install from the Shopify App Store in one click. Auto-injects your consent banner on every storefront page, syncs with Shopify's Customer Privacy API, and captures marketing opt-in at checkout.
App Store → Install Consiva Consent → Enter Script Key → Save
Compliance Scope
If you process Indian users' data, DPDP applies to you.
E-Commerce & D2C
Checkout data, order history, returns, loyalty programmes — DPDP regulates every bit of it.
Healthcare & Wellness
Patient records and health app data are sensitive personal data with stricter DPDP obligations.
BFSI & Fintech
KYC, transaction histories, and credit data — under both DPDP and RBI data governance frameworks.
SaaS & Mobile Apps
Any SaaS processing Indian user data — regardless of server location — is in scope.
EdTech & Online Learning
Student data and minors' data invoke DPDP 9 parental consent — one of its strictest provisions.
Global Enterprises
Overseas companies with Indian customer data must comply. DPDP follows the data, not the domicile.
Platform Capabilities
Everything DPDP requires. Nothing compliance teams don't.
Automatic Cookie & Tracker Scanning
Continuous scanner discovers every cookie, pixel, and third-party script on your domains — including those added by CMS plugins or tag managers without your knowledge. Auto-categorised and mapped to consent purposes on every scan cycle.
NecessaryAnalyticsMarketingPreferencesThird-party
ROPA Auto-generation
Records of Processing Activities built automatically from scan results, consent logs, and Data Discovery findings. Updated on every scan cycle — always current for regulator review.
Parental Consent (DPDP 9)
DPDP mandates verifiable parental consent before processing children's data. Consiva provides age-gate logic, verification workflow, and a complete audit trail per minor user.
Multi-Framework Geolocation
Serve GDPR banners in the EU, CCPA opt-outs in California, and DPDP banners in India — auto-switched by visitor location. All from one script tag, one dashboard.
India Data Residency
All consent logs, rights request records, and breach reports stored exclusively in India — meeting DPDP data localisation provisions on every plan.
Consent Analytics
Opt-in rates by banner variant, category, domain, and traffic source. AB test banner text to optimise consent rates without compromising compliance.
Immutable Audit Logs
Every consent event, rights action, and breach record written to an append-only log. Tamper-evident, exportable, and ready for regulator review at any time.
SDF Module
Significant Data Fiduciary obligations — DPO workflow management, DPIA templates, annual audit readiness, and algorithmic accountability dashboards. Enterprise plan.
Vendor Register & DPA Tracking
Maintain a live register of all data processors, their DPA status, risk tiers, and sub-processor chains. Get alerted when a DPA expires or a vendor's risk profile changes. SCC templates included.
Webhooks & Real-Time Events
Push consent events, rights-request updates, and breach alerts to your own systems in real time via HMAC-SHA256 signed webhooks. REST API available for custom integrations on Pro and Enterprise plans.
Quick Start
Live in 10 minutes. Compliant for years.
01
Register & Verify Your Domain
Create your free account at app.consiva.ai — no credit card required. Add your domain and click Verify. Consiva confirms ownership and starts the first cookie scan immediately.
🆓 1,000 cookie consents + 50 form consents free — every month, forever
02
Review Cookies & Set Purposes
The scanner returns every cookie, pixel, and tracker with suggested DPDP purpose categories pre-filled. Review, adjust, and add custom purposes matching your processing activities.
03
Configure Banner & Language
Choose your banner layout, accent colour, and language. Select from 22 Eighth Schedule languages. Preview on mobile and desktop before publishing.
04
Deploy — One Script Tag
Copy a single <script> tag and paste it in your site's <head>. For WordPress, install the Consiva Consent Banner plugin and paste your Script Key in Settings — done in under 60 seconds.
05
Connect Databases (Optional)
Go to Data Discovery → Add Source. Enter your SQL Server, PostgreSQL, or MySQL credentials. Consiva scans your tables, flags personal data columns, and auto-populates your ROPA — no SQL required from your side.
06
Monitor, Respond, Stay Compliant
Your dashboard shows live consent rates, incoming rights requests with SLA timers, and breach incidents. Consiva alerts you before any deadline — CERT-In 6-hour or DPDP Board — and pre-drafts every regulatory notification.
✅ DPDP + CERT-In covered from a single platform
Resources & Blog
DPDP Compliance Guides for Indian Businesses
Expert guides on DPDP compliance, cookie consent management, data privacy, and CERT-In obligations — written for Indian compliance teams and legal officers.
Legal, IT and marketing each own a slice of privacy compliance, and none of it talks to the others. What a genuine privacy management platform consolidates — consent, rights routing, vendor tracking and breach response — into one shared dashboard.
The DPDP Rules were notified in November 2025 and the full penalty timeline runs to May 2027 — but compliance isn't something you bolt on in a weekend. A ten-step guide to what the Act requires and where India's rollout actually stands.
Spreadsheets, email chains and a bolted-on consent banner quietly fall apart under real DPDP scrutiny. What DPDP compliance software actually does across consent, rights requests, breach clocks, data discovery and ROPA — and why it turns a scramble into a routine.
Not every tool calling itself a DPDP compliance solution actually is one. The ten features that separate the real thing from a rebadged GDPR platform — the checklist to bring to any vendor demo.
Picking a DPDP compliance platform is a decision you live with for years. A practical framework for the call — the non-negotiables, six lenses to judge any shortlist, and the traps that catch buyers.
Rule 8(3) requires a minimum one-year retention of personal data and processing logs — even after account deletion. Section 12 gives a right to erasure. Here is how the two obligations actually interact.
Common questions about DPDP compliance and Consiva.
Not yet, in the sense that matters. The Data Protection Board is established and Rules 1, 2 and 17 to 21 are in force. The substantive obligations and the entire penalty regime commence on 13 May 2027, eighteen months after the Rules were published on 13 November 2025. Consent Manager registration opens on 13 November 2026. Note separately that CERT-In's 2022 Directions are already in force, with a six-hour incident reporting window — so breach readiness is a present obligation, not a future one.
Yes. DPDP follows the data, not the corporate domicile. Any entity that collects, stores, or processes personal data of individuals in India — regardless of server location or company registration — is subject to DPDP. A US SaaS with Indian users must comply. This mirrors the GDPR extraterritorial model.
CERT-In's April 2022 Directions require reporting cybersecurity incidents within 6 hours of detection — completely independent of DPDP's Board notification obligation. Most consent tools only handle DPDP notification and miss the CERT-In window entirely. Consiva tracks both clocks independently from the moment a breach is logged, with separate auto-drafted reports for each regulator.
The free plan includes 1,000 cookie consents and 50 form consents per month — permanently free, no credit card required. You get basic cookie scanning, DPDP banners in English and Hindi, basic analytics, manual rights request handling, and WordPress plugin support for one domain. Automated DSR workflows, the CERT-In breach tracker, 22 languages, and multi-domain support require the Pro plan.
Data Discovery connects to your SQL Server, MySQL, or PostgreSQL databases and scans every table for personal data at rest — email addresses, phone numbers, Aadhaar patterns, and other PII. This is required for an accurate ROPA under DPDP and to identify data that must be erased when a §12 erasure request arrives.
Install the Consiva Consent Banner plugin from the WordPress Plugin Directory. Go to Settings → Consiva Consent Banner and paste your Script Key from the Consiva dashboard. Save — the banner is immediately active on every page, no theme edits needed. The plugin syncs directly with your Consiva dashboard.
The DPDP Act gives every Indian individual: §6(4) withdraw consent at any time; §11 access information about their data being processed; §12 correction and erasure of inaccurate or unnecessary data; §13 grievance redressal through the Data Fiduciary's Grievance Officer; §14 nominate a representative to exercise rights on their behalf after death or incapacity. Consiva manages intake, identity verification, SLA tracking, and fulfilment workflows for all these rights.
Yes — Multi-Framework Mode on Pro and Enterprise plans. Consiva detects the visitor's jurisdiction via IP geolocation and serves the appropriate banner: DPDP format for India, GDPR-compliant for EU/EEA, CCPA opt-out for California, LGPD for Brazil. All from one script tag.
All consent logs, rights request records, breach incident reports, and audit trails are stored exclusively in India on cloud infrastructure meeting DPDP data localisation requirements. Database credentials entered for Data Discovery are encrypted at rest and are write-only — never returned by any API response.
An SDF is a Data Fiduciary designated by the Government under DPDP §10 based on volume, sensitivity, and national security risk. SDFs face additional obligations: appointing an Indian resident as DPO, annual data audits, Data Protection Impact Assessments, and algorithmic accountability measures. Consiva's SDF module — on Enterprise plans — covers all of these.
Start today — it's free
The DPDP deadline is real. Your compliance window is closing.
Set up in under 10 minutes. 1,000 cookie consents + 50 form consents included every month — forever free. No credit card required.