Consent management that holds up when someone asks
Consent asked purpose by purpose on every channel, recorded in a ledger that shows any tampering, relayed to every processor that acts on the data, and produced as signed evidence. Runs inside your infrastructure.
A banner records a click. The Act asks for more.
Bundled and pre-ticked
One checkbox for terms, marketing and sharing is not specific consent (s.6(1)).
No link to the notice
When the notice changes, nobody can say which version a person agreed to.
Withdrawal stops at one database
The CRM, the campaign tool and the vendor keep using the data (s.6(6)).
No proof on the day
A spreadsheet of opt-ins is not evidence anyone outside your company will rely on.
Consent management in five steps, from notice to signed proof
A notice cannot go live incomplete
Each purpose names its lawful basis, data categories and retention. Notices are versioned; publishing stays blocked until the checklist of what a notice must contain is met.
One choice per purpose, in the person's language
A widget beside your form, a no-code consent form, or a hosted consent page for apps and kiosks. The notice version and language are recorded with every choice; legitimate uses are shown as information, not switches.
Every event in a chain that shows tampering
Consents, declines, withdrawals and changes are written to a hash-chained ledger, verifiable end to end on demand. Identifiers are held only as a keyed hash.
Withdrawal that reaches every processor
Each processor holds a scoped key: check consent, read state, record, pull withdrawals. Withdrawals are pushed as signed notifications with every delivery attempt logged.
Ten checks, and a report you can sign
Ten checks run against the record, each tied to its section of the Act. The period report downloads as a signed PDF, verifiable with the public key alone.
Cookies that wait for a yes
Every cookie, with a purpose and a provider
Each site is scanned and every cookie declared against a purpose with its provider and retention. Anything not declared is held from the banner.
Reject as easy as accept
Reject all, Accept all and Customise with equal weight, in the visitor's language, with an accessibility rail on the banner.
Tags held until the category is allowed
Necessary tags run. Functional, analytics and marketing wait for a choice, recorded with the notice version.
Requests on the clock, and the people already on file
Every request on its due date, with evidence
Access, correction and erasure, grievance and nomination in one queue, each acknowledged, tracked to its date and closed with evidence. The s.11 summary exports from the person's record.
Campaigns for the backlog
People on file before the Act asked for consent by email, SMS or WhatsApp from your own senders, with every response and non-response recorded (s.5(2)).
Preference centre
A person sees every consent they have given and changes it per purpose, after a one-time code to their email or mobile.
Consent before you know who it is
The deferred identifier records the choice first and attaches the person when known, for kiosks and anonymous journeys.
Where you collect, and where you use
| Surface | How |
|---|---|
| Websites and forms | Widget snippet per collection point, or a no-code form from the form builder |
| Apps and kiosks | Hosted consent page, mobile SDKs, and the deferred identifier |
| Contact centre | Agent-assisted capture with the channel recorded; IVR through the API |
| CRM, campaign tools, vendors | Scoped processor keys and signed withdrawal notifications, with a delivery log |
| Analytics and data lake | Consent state through the API, signed exports or scheduled sync |
| Your identity provider | Single sign-on, and roles set per screen and per action |
Know what you hold first:Personal data discovery →Where liability arises →
Consent management, answered
Is a cookie banner enough for DPDP consent?
No. A banner covers the website. The Act's consent applies wherever personal data is collected, and asks that withdrawal be as easy as consent and reach the processors acting on the data.
Can we keep using data collected before the Act?
Section 5(2) asks for notice to people whose consent was given before the Act. Campaigns ask them, and record each response or non-response.
Is Wekalp a registered Consent Manager?
No. It is software for a data fiduciary taking consent for its own purposes. It is not a Consent Manager registered with the Board under section 6(9).
Where does it run?
In your infrastructure, on-premises or in your cloud account, with keys from your key store, or hosted.
Twenty questions. Ten minutes. Your exposure, by obligation.
No sign-up. Your answers stay in your browser. You see where liability sits and what would reduce it, including where software is not the answer.
See consent recorded, relayed and signed, on one of your own forms.
Wekalp is software for data fiduciaries and is not a Consent Manager registered with the Data Protection Board under section 6(9) of the Act. Nothing on this site is legal advice.