Skip to content
Compliance

DPDP, in
plain language.

No clauses, no section numbers, no fear. Here is what the law actually asks of you — and how ConsentEra turns each obligation into something your team can run, day to day.

What the law asks for

Every obligation, in outcomes.

Each card is a duty the DPDP framework places on a Data Fiduciary — rewritten as the result you have to deliver, not the rule you have to memorise.

01

Consent & notice

Ask in plain language, one purpose at a time, in a notice the person can actually read. Every consent is tied to the notice version it was given against.

02

Easy withdrawal

Saying no must be as simple as saying yes. One click withdraws consent and the signal propagates downstream to every system that was relying on it.

03

Data principal rights

People can see what you hold, fix it, erase it, nominate someone to act for them, and raise a grievance — all self-service, all on a tracked deadline.

04

Children's data

Younger users are handled with extra care: age-gating up front and verifiable parental consent before any personal data is processed.

05

Breach response

When something goes wrong, notify the people affected without delay and assemble the report for the regulator — from one structured incident workflow.

06

Cross-border transfers

Know where personal data flows. Map your transfers, record the basis for each, and keep the controls in place if a destination is restricted.

A higher bar

Significant Data Fiduciary duties

A few organisations are designated by the government to carry extra weight — periodic impact assessments, independent audits, and a named Data Protection Officer.

Who this applies to

Applies only to organisations the government designates — not to everyone. For those that are, ConsentEra carries impact assessments, audit-ready records and DPO workflows in one place.

The honest timeline

Phased, not overnight.

DPDP arrives in stages. The Data Protection Board provisions are already in force, the Consent Manager regime commences on 13 November 2026, and the substantive obligations on 13 May 2027. Readiness is a programme, not a switch — and the work has to start well before that.

Aug 2023

Act enacted

Parliament passes the law. The framework exists; the clock to readiness starts.

Nov 2025

Rules notified

The operating detail lands — how notices, consent and rights actually work in practice.

Nov 2026

Consent Manager regime begins

From 13 November 2026 the Consent Manager registration and obligation regime is in force.

May 2027

Obligations enforceable

From 13 May 2027 notice, consent, rights, breach and children's-data duties are enforceable. Readiness programmes have to start well before that.

Be ready now
Beyond DPDP

DPDP first. The rest, supported.

ConsentEra is built India-first around DPDP. If you operate across borders, the same engine carries the major global frameworks — without splitting your programme in two.

Primary

DPDP Act

India

The Digital Personal Data Protection framework is the focus of everything here — notices, consent, rights and records, built India-first.

Where the focus is
Ready

GDPR

European Union

Lawful-basis tracking, subject rights and records of processing carry over for teams operating across the EU.

Ready

CCPA / CPRA

California, US

Opt-out signals, deletion and access requests are supported for global operations alongside your DPDP programme.

Framework support describes the controls ConsentEra provides; it is not a certification or an attestation. DPDP itself is phased — we position the platform as DPDP-ready, with the substantive obligations commencing on 13 May 2027.

Turn the rules into a routine.

A 30-minute walkthrough that maps each obligation to your data, your notices, and your DPDP readiness deadline.