Home How We Work Security Assurance Resources
Consent management software · DPDP Act

Consent management that holds up when someone asks

Consent asked purpose by purpose on every channel, recorded in a ledger that shows any tampering, relayed to every processor that acts on the data, and produced as signed evidence. Runs inside your infrastructure.

The challenge

A banner records a click. The Act asks for more.

Bundled and pre-ticked

One checkbox for terms, marketing and sharing is not specific consent (s.6(1)).

No link to the notice

When the notice changes, nobody can say which version a person agreed to.

Withdrawal stops at one database

The CRM, the campaign tool and the vendor keep using the data (s.6(6)).

No proof on the day

A spreadsheet of opt-ins is not evidence anyone outside your company will rely on.

Solution highlights

Consent management in five steps, from notice to signed proof

Notice editor for a customer sign-up notice, version 3: a publication checklist with the grievance officer item still open, three purposes each with its basis, and a 24-month retention for marketing; publishing stays blocked until the checklist is met
Step 1 · Define

A notice cannot go live incomplete

Each purpose names its lawful basis, data categories and retention. Notices are versioned; publishing stays blocked until the checklist of what a notice must contain is met.

A sign-up form beside a How we use your data panel in English and Hindi: order delivery shown as information under s.7, separate switches for offers by SMS and personalised recommendations, and the notice version and time shown recorded below
Step 2 · Collect

One choice per purpose, in the person's language

A widget beside your form, a no-code consent form, or a hosted consent page for apps and kiosks. The notice version and language are recorded with every choice; legitimate uses are shown as information, not switches.

Consent ledger of 12,408 events with the hash chain verified: given, declined and withdrawn decisions by purpose, and one event opened to show the previous hash, the notice version and language, and the channel
Step 3 · Record

Every event in a chain that shows tampering

Consents, declines, withdrawals and changes are written to a hash-chained ledger, verifiable end to end on demand. Identifiers are held only as a keyed hash.

A withdrawal of consent for offers by SMS relayed under s.6(6): three of three processors told in four delivery attempts, with the CRM, the SMS campaign tool and a loyalty vendor each marked delivered
Step 4 · Relay

Withdrawal that reaches every processor

Each processor holds a scoped key: check consent, read state, record, pull withdrawals. Withdrawals are pushed as signed notifications with every delivery attempt logged.

Compliance status with ten checks, each tied to a section of the Act and marked compliant, beside a Q3 report ready to download as a signed PDF that includes the public key
Step 5 · Prove

Ten checks, and a report you can sign

Ten checks run against the record, each tied to its section of the Act. The period report downloads as a signed PDF, verifiable with the public key alone.

Built for the DPDP Act
10compliance checks, each tied to a section
4processor scopes: check, read, record, pull
s.5(2)campaigns for people already on file
Ed25519signatures on every export
Website cookies

Cookies that wait for a yes

Website cookie scan across three sites listing each cookie with its purpose, provider and retention, and a newly found cookie flagged as not declared and held from the banner until it is
Scan

Every cookie, with a purpose and a provider

Each site is scanned and every cookie declared against a purpose with its provider and retention. Anything not declared is held from the banner.

Cookie banner on a website with Reject all, Customise and Accept all buttons of equal weight, language options for English, Hindi and Marathi, and a text-size control
Choose

Reject as easy as accept

Reject all, Accept all and Customise with equal weight, in the visitor's language, with an accessibility rail on the banner.

Tags on a page before a choice: necessary tags running while functional, analytics and marketing tags are held; after an analytics-only choice, analytics runs and marketing stays held
Hold

Tags held until the category is allowed

Necessary tags run. Functional, analytics and marketing wait for a choice, recorded with the notice version.

Rights and the backlog

Requests on the clock, and the people already on file

Rights requests queue with access, erasure, grievance and nomination requests under sections 11 to 14, each with a due date and status, and an erasure request open to show evidence from the CRM and a loyalty vendor
Rights · ss.11–14

Every request on its due date, with evidence

Access, correction and erasure, grievance and nomination in one queue, each acknowledged, tracked to its date and closed with evidence. The s.11 summary exports from the person's record.

Campaigns for the backlog

People on file before the Act asked for consent by email, SMS or WhatsApp from your own senders, with every response and non-response recorded (s.5(2)).

Preference centre

A person sees every consent they have given and changes it per purpose, after a one-time code to their email or mobile.

Consent before you know who it is

The deferred identifier records the choice first and attaches the person when known, for kiosks and anonymous journeys.

How it connects

Where you collect, and where you use

SurfaceHow
Websites and formsWidget snippet per collection point, or a no-code form from the form builder
Apps and kiosksHosted consent page, mobile SDKs, and the deferred identifier
Contact centreAgent-assisted capture with the channel recorded; IVR through the API
CRM, campaign tools, vendorsScoped processor keys and signed withdrawal notifications, with a delivery log
Analytics and data lakeConsent state through the API, signed exports or scheduled sync
Your identity providerSingle sign-on, and roles set per screen and per action
FAQ

Consent management, answered

Is a cookie banner enough for DPDP consent?

No. A banner covers the website. The Act's consent applies wherever personal data is collected, and asks that withdrawal be as easy as consent and reach the processors acting on the data.

Can we keep using data collected before the Act?

Section 5(2) asks for notice to people whose consent was given before the Act. Campaigns ask them, and record each response or non-response.

Is Wekalp a registered Consent Manager?

No. It is software for a data fiduciary taking consent for its own purposes. It is not a Consent Manager registered with the Board under section 6(9).

Where does it run?

In your infrastructure, on-premises or in your cloud account, with keys from your key store, or hosted.

Readiness check

Twenty questions. Ten minutes. Your exposure, by obligation.

No sign-up. Your answers stay in your browser. You see where liability sits and what would reduce it, including where software is not the answer.

See consent recorded, relayed and signed, on one of your own forms.

Wekalp is software for data fiduciaries and is not a Consent Manager registered with the Data Protection Board under section 6(9) of the Act. Nothing on this site is legal advice.