Operate trust. Prove consent.
The consent & data-protection platform built for India's DPDP Act. Capture consent across every surface, automate data-principal rights, and keep a tamper-evident record of all of it — ready well before the obligations bite in May 2027.
- Built for India's DPDP Act
- AES-256 field-level encryption
- Tamper-evident records
- 22 languages + English
Watch a single consent become undeniable.
Requested
The person sees the notice and makes a real, affirmative choice — tied to one purpose.
Granted & sealed
On allow, a standards-based receipt is issued and locked into a tamper-evident hash-chain.
Honoured live
Every use checks the live state first — processed only while consent actually stands.
Withdrawn or renewed
Withdraw and processing halts across every connected system — or renew when it lapses. Appended, never erased.
Provable
Hand over the receipt and the full chain — verifiable end to end.
Consent record
CNS-7F3A·91D4·2E8C
- Purpose
- Checkout & fulfilment
- Notice
- v3 · 22 languages
Audit ledger
Awaiting the person's choice
Every data asset,
accounted for.
ConsentEra finds personal data across your systems, binds each use to a purpose and a consent, and keeps a living record — so you can show, at any moment, what is mapped, what is classified, and what still needs attention.
- Discovery across 50+ source types
- Each asset bound to a purpose and a consent
- A living record — classified, consented, retained
accounted for
0 unmapped
Illustrative — the coverage dial in your dashboard
Six disciplines.
Done properly.
The work that actually matters — without burying your team in features they'll never open.
Consent Management
Capture free, specific, informed consent across web, mobile, cookies and a hosted CMP — bound to a purpose and a notice version, with one-click withdrawal that suppresses every channel and is pushed to the systems you connect.
- Web, mobile, cookie & hosted CMP
- Purpose-bound, notice-versioned
- One-click withdrawal, suppressed everywhere
Purposes
Data Principal Rights
A self-service portal for access, correction, erasure, nomination and grievance — with deadline tracking, routing to the right owner, and a full audit trail of every fulfilment.
- Access · correction · erasure · grievance
- Configurable SLA & deadline tracking
- Cryptographic proof of erasure
Open requests
Records & Audit
Every consent decision is sealed into a tamper-evident record and linked into a cryptographic hash-chain — recomputable end to end from an export, and built to satisfy a regulator inspection. Each receipt carries a signature and the hash of the notice actually shown.
- Tamper-evident consent receipts
- Hash-chained, verifiable audit ledger
- Inspection-ready exports
Hash chain
Data Governance
Discover where personal data lives across your systems, classify it, and keep a living record of processing activities — so notices, retention and accountability stay honest.
- Discovery across 50+ source types
- Records of processing (RoPA)
- Retention & accountability
Discovered sources
Security & privacy engineering
Personal data is encrypted at the field level with keys you control, isolated by the database itself, and protected by masking and re-identification controls — security designed in, not bolted on.
- Field-level AES-256 + per-tenant keys
- Database row-level isolation
- Masking & re-identification controls
Encrypted at the field level
Accountability & obligations
Meet the obligations that decide a real programme — breach response, processor contracts and cross-border records, and the heavier duties that come with being a Significant Data Fiduciary.
- Breach response & regulator-report assembly
- Processor (DPA) & cross-border records
- Impact assessments, audits & DPO workflows
Obligations, handled
Built to survive
the hardest review
in the room.
Personal data is encrypted before it lands, isolated by the database itself, and written into a ledger no one can quietly rewrite.
Visit the Trust CenterAES-256 field-level encryption
Personal data fields — email, phone, Aadhaar, PAN — are encrypted with AES-256-GCM before they ever reach the database.
Per-tenant keys & crypto-shred
Envelope encryption: a per-tenant data key seals every field, and the root key that wraps it lives in your KMS or HashiCorp Vault. Erasing a person destroys their own key material — making what remains cryptographically unrecoverable.
Database row-level security
Tenant isolation is enforced inside the database itself — the database, not application code, decides which rows a request can see.
Tamper-evident audit ledger
Audit events are append-only and hash-chained with periodic anchoring, so any tampering is mathematically detectable.
Search without decrypting
Blind indexing lets you look up encrypted fields by exact match without ever exposing plaintext at rest.
Keys you control
Bring your own keys via AWS KMS, Azure Key Vault or HashiCorp Vault. Rotation and access are yours to govern.
Compliance you can
put your finger on.
Every obligation that touches consent and personal data, mapped to something the platform actually does — described the way your team talks, not the way the statute reads.
Consent & notice
Affirmative, purpose-bound consent against itemised, plain-language notices in 22 scheduled languages plus English.
Easy withdrawal
Withdrawing consent is as easy as giving it — with processing halted and the withdrawal pushed to the systems you connect.
Data principal rights
Access, correction, erasure, grievance and nomination, fulfilled with deadline tracking.
Children's data
Age-gating and verifiable parental-consent workflows, with tracking and targeted ads switched off for minors.
Breach response
A structured incident workflow that notifies affected people without delay and prepares the regulator report.
Cross-border transfers
Transfer records and gating so onward sharing respects restrictions and localisation choices.
The honest timeline
Aug 2023
Act enacted
The Digital Personal Data Protection Act is passed by Parliament.
13 Nov 2025
Rules notified
The DPDP Rules are notified, setting an eighteen-month phased commencement. The Data Protection Board provisions take effect immediately.
13 Nov 2026
Consent Manager regime
The Consent Manager registration and obligation regime commences — twelve months after notification.
13 May 2027
Obligations bite
Notice, consent, rights, breach and children's-data duties become enforceable — eighteen months after notification. Readiness has to start well before that.
Depth a real programme
actually demands.
Processor contracts, cross-border, consent-aware engagement, privacy engineering, workforce — the work that decides a real DPDP programme.
Processors & cross-border
DPA lifecycle, sub-processor approval chains, transfer records with localisation.
ExplorePrivacy engineering
Field-level encryption, masking and re-identification controls — security at the data layer.
ExploreChildren & workforce
Verifiable parental consent, guardian flows, worker rights and surveillance notices.
Explore
See your consent flow,
sealed and verifiable.
A 30-minute walkthrough mapped to your data, your notices, and your DPDP readiness deadline.