Consent management

Consent records that survive the question.

Anyone can capture a tick. A consent management system has to prove what was agreed, when, to what — and that withdrawing was as easy as giving.

See where your consent stands — free Book a demo Five minutes, no login. Or see it running on your own notice.
Append-only — the database refuses edits 5,000+ vetted consent templates Live in an afternoon, one snippet
Sound familiar?

How do you actually collect it?

For most Indian businesses the honest answer is not a web form, which is what most tools assume.

Hospital or clinic

A card at the registration counter, a QR poster, and a receptionist explaining it in Hindi.

SaaS or platform

A sign-up flow, a marketing list someone built two years ago, and analytics nobody has audited.

HR, staffing or payroll

A candidate agreeing to a background check, and an employee opting into a wellness programme.

Why a tick is not a record

“Our CRM already captures consent.”

It captures agreement. The Act asks for six more things, and the difference only shows up when somebody asks.

What a CRM tick gives you

  • A boolean, set at signup
  • Maybe a timestamp
  • One purpose, or none named at all
  • A field your team can edit
  • Nothing about what they were shown

What §6 and Rule 3 ask for

  • The exact notice text they saw, in the language they read it in
  • Each purpose itemised and agreed separately
  • Optional purposes proven to have started switched off
  • Withdrawal as easy as giving, and evidence it was honoured
  • A record no one can alter afterwards — including you
  • All of it produced years later, on request

A consent you cannot evidence is, for enforcement purposes, a consent you never took.

The evidence

A log your own team cannot edit

Not a policy saying nobody will change it. A database constraint that refuses the change.

01

Append-only, enforced

Every consent event — given, updated, withdrawn, erased — is written once. The database blocks UPDATE and DELETE on the log outright. Not your admin, not your developer, not us.

02

Verifiable by a third party

The evidence pack ships with a SHA-256 manifest, and the manifest hash is itself written into the log. Your auditor re-computes it independently — they do not have to take our word, or yours.

03

Read-only, and provably so

The audit screen has no edit control because the API has no edit route. An attempt to delete a record is refused and then itself logged as a security event.

app.ruleexpert.in/consent/audit
The consent audit log: every event listed with its type, channel and time, the data
             principal identified by a hash rather than a name, and a notice stating that records
             cannot be edited or deleted.
Collection

Nine ways in. One record out.

Consent taken at a reception desk and consent taken on your website land in the same log, in the same shape.

Web widgetOne script tag. 3 KB gzipped.
QR codeSigned URL, verified on scan.
REST APIYour own app, your own UI.
WhatsAppThrough your BSP account.
SMSThrough your SMS provider.
Email linkFor campaigns and re-consent.
Call centreOperator-recorded, script enforced.
CSV importBulk request, never bulk consent.
Rights portalSelf-serve, no account needed.

The widget is 3 KB

Vanilla JavaScript, zero dependencies, against a 15 KB budget the build fails if it exceeds. It will not slow your page down, and it does not drag a framework onto it. If the network drops mid-capture it queues the event encrypted in the browser and retries, so a bad connection does not become a missing record.

CSV import never asserts consent

Uploading ten thousand contacts creates ten thousand consent requests, not ten thousand consents. That is §6 — consent has to be given, and no import can give it on someone’s behalf. It is a deliberate limit, and it is the one that keeps the resulting records worth having.

The notice

5,000+ templates your team never has to draft

Vetted by empanelled privacy counsel across industries, so the starting point is a reviewed document rather than a blank page.

§5

Rule 3, itemised

Standalone, plain language, each purpose listed separately with the data it needs, third parties named, and the route to the Data Protection Board included — because Rule 3(c)(iii) requires it and most notices omit it.

8

Eight languages

Hindi, Tamil, Telugu, Kannada, Bengali, Marathi, Gujarati and English. Each version is held against the same notice, so they cannot drift apart when one is edited.

§6

Optional means off

Optional purposes render switched off and cannot be pre-checked from anywhere. Mandatory processing under §7 renders as text with no toggle at all — because offering a choice that is not real is how a consent gets challenged.

A non-compliant notice cannot be published

Before a consent notice goes live it is checked against Rule 3 and §6 line by line — standalone, plain language, itemised purposes, named third parties, withdrawal as easy as giving, the Board complaint route, children’s provisions where §9 applies, and every placeholder resolved. Fail any required check and the publish button stays off. Your DPO does not have to catch it, because the system will not let it out.

app.ruleexpert.in/consent/notices
The consent notices screen, listing published notices with their version numbers,
             languages and status.
Withdrawal

As easy to withdraw as it was to give

§6(4) is one sentence and it is where most consent programmes fail an inspection.

One tap, no account, no form

Every data principal gets a private link to a branded portal. They see the purposes they agreed to, switch off any optional one, or withdraw everything at once. No login, no request form, no email to a shared inbox that nobody owns. The purposes you rely on under §7 are shown as information, and correctly cannot be switched off.

And then it is worked, not filed

A withdrawal lands in a queue with the clock already running and a traffic light against it. Mark it processed and that becomes another entry in the log. If the person disputes how it was handled, it escalates into a grievance with the statutory 90-day clock from Rule 14(3) attached.

app.ruleexpert.in/consent/withdrawals
The withdrawal queue: each request showing how long it has been open against its service
             level, with the data principal identified by a hash.

Find out what your current consent would score.

The free assessment scores consent, notice and rights separately and prices each gap against the Act’s Schedule. Five minutes, no login, yours to keep.

The parts most tools skip

Six obligations that arrive later

Capture is the easy half. These are the ones that surface months in, when the tool you chose has no answer.

§9 · Rule 10

A child’s consent needs a verified parent

Verifiable parental consent, with the Fourth Schedule exemptions applied — clinical care, education, crèche and transport are carved out, and a tool that does not know that will block treatment it should not.

Up to ₹200 Cr
§9

And that child turns 18

Sixty days before the birthday your DPO is alerted; thirty days before, the young adult is asked directly. On the day, the parental consent is archived, not deleted, and a thirty-day grace period runs before the record lapses.

Nobody else does this
§8(7) · Rule 8

Withdrawal does not mean delete tomorrow

Rule 8(3) sets a one-year floor on the log, so erasing on withdrawal can itself be the breach. A 48-hour pre-erasure notice goes out first, legal holds always win, and inactivity erasure runs on its own schedule.

Up to ₹50 Cr
§8(2)

Your processor’s DPA expired

Vendors are linked to the notices whose purposes they serve. When a data processing agreement lapses, sharing under those purposes is flagged as blocked — you stay accountable for them whether or not you noticed.

Up to ₹50 Cr
§16

You added a vendor outside India

Any active notice that does not carry the cross-border clause is surfaced the moment a transfer outside India appears, rather than at the next audit.

Up to ₹50 Cr
CM-20

You changed the notice

A minor edit keeps existing consent valid. A material change to purposes does not, and the system says so — then runs the re-consent campaign to the right audience, excluding everyone who has already withdrawn.

The quiet one
app.ruleexpert.in/consent/retention
The retention and erasure screen showing records retained, notices due, records ready to
             erase, and the one-year statutory retention floor.
Against the alternatives

What you are probably comparing this to

Three honest comparisons for anyone weighing up a consent management platform. Each of these is good at something — just not at this.

A cookie banner

Good at: web tracking consent, quickly.

It governs cookies on one website. DPDP consent covers every purpose you process personal data for, on every channel — a patient form, a call centre, a WhatsApp opt-in. The banner has no view of any of it.

A global consent platform

Good at: GDPR, at scale, across many countries.

Built around GDPR’s structure and priced in dollars. It will not know Rule 3’s itemisation, the Fourth Schedule exemptions, Rule 8’s one-year floor, or that §7 processing must never be shown as a toggle.

Your CRM or HRMS

Good at: being the system your team already lives in.

It stores a field. It does not store the notice text that was shown, keep an unalterable history, or produce evidence years later — and its consent field is editable by anyone with access, which is exactly the problem.

We are not asking you to replace any of them. We are asking where the record lives when someone questions it.

Getting started

Live this afternoon. Evidenced this week.

No implementation project, no professional-services quote, no six-week discovery.

FIRST HOUR

Pick a template, publish

Choose the template for your sector and purposes, fill in your details, and let the compliance check pass it. Copy the snippet.

FIRST DAY

Capture on every channel

Widget on the site, QR at reception, the portal link in your emails. Every one of them writing to the same log from the first record.

FIRST WEEK

Generate the evidence

A pack with a manifest your auditor can verify independently — assembled from what actually happened, not written up afterwards.

Questions

The objections we hear

We already collect consent. Do we have to start again?

No. Existing consent stays as it is; RuleExpert governs it from here on. Where a notice materially changes — new purposes, new recipients — consent for those purposes does need to be taken again, and the re-consent campaign does that to exactly the right audience, automatically excluding anyone who has already withdrawn. Where the change is minor, existing consent stays valid and the system says so rather than making you guess.

How long does it actually take to go live?

A first notice can be published and capturing the same afternoon: choose a vetted template, fill in your company details, let the compliance check pass it, paste one script tag. There is no implementation project and no professional-services quote. The longer work — mapping every purpose across every system — is worth doing, but it is not what stands between you and your first evidenced consent.

Does this need our developers?

For the website, one script tag — a few minutes of someone’s time. QR codes, the rights portal and call-centre capture need no engineering at all. You would involve developers only to capture consent inside your own product through the API, and that is a normal REST integration rather than an SDK to learn.

What about our cookie banner?

Keep it. The two answer different questions: a cookie banner governs tracking on one website, while DPDP consent covers every purpose you process personal data for, on every channel. Worth knowing that the Act has no cookie-specific provision — cookies matter under DPDP only where they process personal data, and then it is ordinary §5 notice and §6 consent, which is exactly what this does.

What happens to our records if we leave?

You take them. The evidence pack is ordinary files — the audit log, the notices and their versions, withdrawal and grievance records, vendor coverage — with a SHA-256 manifest anyone can re-verify. It is built to be readable without our software, because evidence that only works inside one vendor’s product is not much use in front of the Board.

How do we know a record has not been altered?

Because the database will not allow it. UPDATE and DELETE are blocked on the consent log by a constraint, not by a policy or a permission setting — so it holds for your administrators, your developers and for us. An attempt to delete is refused and then logged as a security event. The evidence pack’s manifest hash is written into the log itself, which is what lets a third party check the pack against the record independently.

Where does the data sit, and what do you hold?

On infrastructure in India, data at rest and backups both. We hold the consent record itself, and the person in it is identified by a one-way SHA-256 hash rather than by name, email or phone number — even IP addresses are hashed. We are ISO 27001 certified.

Are you a Consent Manager under the Act?

No, and the distinction matters. “Consent Manager” is a defined role under the Act and Rule 4 — an entity registered with the Data Protection Board that acts on behalf of data principals. RuleExpert is a tool you operate as a Data Fiduciary to meet your own obligations. Anyone selling you software while calling themselves a Board-registered Consent Manager is worth a second question.

What should consent management software actually do for us?

Three things, and most tools do only the first. It has to collect consent wherever your customers are, which for an Indian business is rarely a web form — a counter, a QR poster, WhatsApp, a call centre. It has to prove what was collected months later, which means a record your own team cannot quietly edit. And it has to act on a withdrawal, so that saying no actually stops the processing rather than setting a flag nobody reads. Most consent management tools do the first well and the other two barely at all — and consent management software that captures a tick and stores it in a table has given you a database, not a defence.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

See it against your own notice.

Start with the free assessment, or have someone walk you through it with your purposes and your channels on the screen.