DPDP RULES, 2025 Full compliance due 13 May 2027

Consent that holds up when the Board asks.

Promiz is built around one question: can you prove a lawful basis for every record you hold? Map each DPDP obligation to a working control - and export the evidence the day you're asked for it.

22 Indian languagesHosted in IndiaNo per-consent fee
Obligation → control
dpdp_rules_2025
Rule 3 · the obligation
Can a data principal see a clear, itemised notice before you process their data?
Promiz control
Consent notice builder
Stand-alone, plain-language notices with itemised data and specific purposes - served in 22 languages.
Evidence: notice text + version stored against every opt-in
Pick an obligation - see the control behind it● live
00Weeks
00Days
00Hours
00Minutes
00Seconds

Full compliance for Data Fiduciaries is due 13 May 2027. The clock counts down to the deadline.

The gap

Most teams know their DPDP obligations. Proving they've met them is where it falls apart.

Consent lives in form fields, ad tags, CRM flags and email threads - scattered across tools that were never built to produce a defensible record. When the Data Protection Board asks for the basis behind a single data point, you need an answer in minutes, not a forensic project.

Consent is scattered

Opt-ins captured across web, app and offline never reconcile into one record.

No lawful basis on file

Processing runs without a documented purpose tied to each data point.

Withdrawals go nowhere

A revoke on the banner never reaches the analytics, ads and partner tools.

Promiz closes it

One consent record, one lawful basis per purpose, propagated and provable.

The consent lifecycle

Four jobs, one source of truth.

DPDP consent isn't a banner - it's a lifecycle. Promiz owns all of it, so every opt-in stays tied to a purpose from the moment it's captured to the day it's erased.

01 · Collect

Capture consent

Plain-language, purpose-wise notices and banners - in the data principal's own language.

  • Granular, per-purpose opt-in
  • No pre-ticked boxes or cookie walls
  • Verifiable parental consent
02 · Manage

Honour every choice

Withdrawal as easy as consent - propagated to every connected system the moment it changes.

  • One-click withdrawal
  • Real-time propagation via webhooks
  • Preference centre for principals
03 · Prove

Hold the evidence

Every opt-in, change and withdrawal kept immutably - exportable as a defensible trail on demand.

  • Immutable, timestamped records
  • Consent versioning
  • One-click Board-ready export
04 · Connect

Sync your stack

Consent signals flow to the tools that act on data, so nothing processes without a basis.

  • JS snippet & native SDKs
  • CRM, analytics & ad-tag sync
  • Rule 4 Consent Manager interop
Platform modules

Consent doesn't stand alone.

Every opt-in hangs off a purpose you declared, a tracker that fired, and a vendor you shared with. Promiz manages all three as first-class records - so each consent ties back to a reason, a mechanism, and a processor.

Purpose management

Every purpose you process for, defined once and reused everywhere - the spine the whole consent record hangs off.

Purpose registry
Purpose versioning
Per-purpose retention rules
Purpose-wise consent tracking

Tracker management

Not just cookies. Auto-discover everything that collects data on your surfaces and gate each behind purpose-specific consent.

Cookies & pixels
SDKs & scripts
Local & session storage
Auto-categorised inventory

Vendor management

Every processor you share data with, classified by risk and mapped to the exact purposes they're allowed to serve.

Processor registry
Vendor risk classification
Vendor ↔ purpose mapping
Vendor audit trail
DPDP Rules, 2025 · the full map

Every consent obligation, with a control behind it.

The hero interrogates one obligation at a time. Here's the complete reference - each consent obligation under the Rules paired with the Promiz control that satisfies it. Filter by where it sits in the lifecycle.

Rule 3

Consent notice

Stand-alone, plain-language notices with itemised data, specific purposes and a withdrawal link - in 22 languages.

Rule 3-6

Free, specific consent

Granular, purpose-bound opt-in - no pre-ticked boxes, no cookie walls. Each purpose carries its own record.

Rules 10–12

Verifiable parental consent

Guardian verification for under-18s via details on file, an authorised entity, or DigiLocker - Schedule IV exemptions built in.

Rule 14-6

Withdraw consent

Withdrawal as easy as giving consent, propagated to every connected system the moment a principal revokes.

Rule 8

Retention & erasure clock

Track the inactivity period, fire the 48-hour pre-erasure notice, and trigger deletion when the purpose ends.

Rule 14

Data principal requests

A single intake point for access, correction and erasure requests - captured and routed to the systems that fulfil them.

Audit

Consent versioning

Every opt-in, purpose change and withdrawal kept immutably, so the lawful basis behind any record is never in doubt.

Audit

Board-ready evidence

Export a defensible consent trail on demand - every timestamp, purpose and version, ready the day the Board asks.

Rule 4

Consent Manager interop

Built to interoperate with a registered Consent Manager under Rule 4 - so consent stays portable across fiduciaries.

Works with your stack

Promiz feeds your tools - it doesn't replace them.

Some DPDP obligations are security and engineering controls that must live in your own systems. Promiz pushes clean, auditable consent and processing records to the tools you already run - tag managers, analytics, CRMs and your own services.

Plug consent into your whole stack Google Tag Manager HubSpot Google Ads Razorpay Zoho WhatsApp promiz
Rule 6 Security safeguards Encryption, access control and logging live in your infrastructure; Promiz supplies the consent records they protect.
Rule 13 SDF algorithm audits DPIA and algorithmic-fairness checks sit with your governance team; Promiz feeds them purpose and consent evidence.
Rule 6 Identity & access Your IAM owns authentication and RBAC; Promiz consumes verified identity to bind consent to the right principal.
Rule 12 Cross-border monitoring Network and data-flow controls stay in your platform; Promiz records the basis and notice for each sharing event.
How it works

Live in three steps.

From sign-up to a compliant banner on your site - most teams go live in under 48 hours.

app.promiz.in/signup
Copied
<script src="promiz.js" defer>
</script>
<div id="promiz-banner"
  data-lang="ta"
></div>
This site uses cookies

We use cookies for analytics and personalisation under the DPDP Act.

Only necessaryAllow all
Industries

Tuned to your sector's data, not just its name.

Every industry collects different personal data, for different purposes, under different regulators. Pick your sector to see the purpose, vendor and consent templates Promiz ships for it.

Banking

RBI · DPDP

Banks process Aadhaar, PAN, transaction and credit history across dozens of touchpoints. RBI covers security; DPDP adds the privacy-rights layer.

Personal data handled
AadhaarPANTransactionsCredit history
Compliance catch
Customers have a right to erasure, but RBI/SEBI mandate multi-year retention. Promiz tracks purpose-linked retention so you honour both.
The evidence layer

When the Board asks, the answer is one click.

Every consent interaction is recorded with forensic detail - who consented, when, to what, and how it was collected. Not a log you have to interpret. A receipt you can hand over.

WHO

The verified data principal

Identity, language served, and the channel the consent was captured on.

WHEN

Timestamp, immutable

The exact moment of each opt-in, change and withdrawal - versioned, never overwritten.

WHAT

The specific purpose

Each consent bound to a declared purpose, with the notice text the principal actually saw.

HOW

The collection context

Banner version, the affirmative action taken, and the lawful basis recorded against it.

Consent receipt Verified
principaldp_8f21c…
purposeMarketing email
basisConsent · §6
noticeहिन्दी · v3
actionOpt-in (explicit)
captured2026-06-27 14:02 IST
retentionUntil withdrawal
sig: 3a9f…e71d · immutable · exportable as PDF / CSV / API
Made for India

A DPDP law needs a DPDP-native platform.

Global cookie tools were built for GDPR and bolted DPDP on later. Promiz starts from the Rules, the schedules, and the languages your data principals actually read.

தமிழ்हिन्दीEnglishবাংলাमराठीతెలుగుગુజરાતી+ 15 more
0
Indian languages for notices and banners
<0 ms
Consent verification before any data is used
0 yr
Audit-log retention, aligned to the Rules
0 hrs
Breach-notice clock supported with clean records
2026 is the build year

Be ready before the Data Protection Board asks.

Bring one purpose you process for. In 30 minutes we'll show the consent record, the lawful basis, and the evidence export - running on your own data, no slideware.

Go live in ~48 hrsHosted in IndiaNo per-consent fee