Consent Management
Obtain, record and honour explicit consent for every purpose, channel and law.
Sec. 5, 6, 9
Data inventory
Purpose controls
Evidence log
OVERVIEW
Know where every trace of personal data lives. Capture consent that actually holds. Enforce it across every system and prove it on demand.
8
Products on one shared privacy fabric
18
DPDP obligations owned, with no gap column
5
Regimes on one control library — DPDP, GDPR, CCPA/CPRA, LGPD, PIPEDA
What breaks today
Nothing reconciles the two, so consent is unenforceable the moment it is given. Nobody can answer “where is this person's data?” without a manual hunt — which does not fit inside a statutory clock.
One catalogue of personal data, one consent record of truth, one policy engine, one audit trail.
A rights request, an audit and a breach notification all resolve against the same records rather than three reconstructions.
Each regime is expressed as configuration over a shared control library. DPDP is a mapping, not a rebuild.
The platform
Shared beneath every product: data catalogue, identity resolution, policy engine, AI classification and an immutable evidence trail.
Obtain, record and honour explicit consent for every purpose, channel and law.
Sec. 5, 6, 9
Fulfil access, correction and erasure rights inside statutory clocks.
Sec. 11–14
Identify and classify personal and sensitive data across the whole estate.
Sec. 8(3), 8(7)
Redact and mask sensitive data at scale, by rule and by context.
Sec. 8(4), 8(5)
Assess, evaluate and mitigate privacy risk before a system ships.
Sec. 10(2)
Detect, contain, notify and learn inside the regulatory window.
Sec. 8(6)
Produce evidence on demand for internal, external and regulator review.
Sec. 10(2)(b)
Run the entire privacy programme from a single control plane.
Sec. 4, 7, 10, 16
Worked example · Sec. 6(4)–(6)
A single user action fires four products in sequence, and each hop is written to the trail.
T + 0s
Consent Management records the withdrawal against the specific purpose and stamps it. Click-parity is enforced against the original give-flow.
Consent Management
T + 1s
The policy engine revokes the purpose and fans the event out to every processor that inherited that consent.
Privacy Program Governance
T + 2s
Discovery returns every store holding that Principal's data; erasure executes against the list.
Intelligent Data Mapper
T + 3s
Audit & Evidence Management closes the chain — withdrawal, cessation, erasure and processor acknowledgements, all timestamped.
Audit & Evidence
The withdrawal lands in a banner tool. A ticket is raised. Someone emails four system owners. Two reply. Nobody can evidence cessation, and the erasure obligation quietly lapses.
Four seconds, four products, zero tickets — and an evidence chain that answers the Board’s question before it is asked.
Client value
| Before · point tools and tickets | With one privacy fabric |
|---|---|
| Manual inventories and spreadsheets that go stale between releases | Continuous automated scans with drift detection on every change |
| Static, one-size-fits-all banners that ignore purpose and region | Adaptive consent by region, purpose, channel and age band |
| Siloed preferences with no enforcement past the banner | Real-time orchestration with an acknowledgement from every consumer |
| Evidence assembled after the fact, when the auditor is already waiting | Always-on searchable audit trail and board-ready dashboards |
| Incident response run over email threads and a shared spreadsheet | Structured assess, notify and remediate with the clock tracked |
| Every new law is a new vendor, a new project and a new budget | New regime maps onto controls that already run — configuration |
The question is not whether you can comply with DPDP — it is whether the thing you build for DPDP still works when the next law lands.