DPDP RULES, 2025 Full compliance due 13 May 2027

Consent that holds up when the Board asks.

Promiz is built around one question: can you prove a lawful basis for every record you hold? Map each DPDP obligation to a working control - and export the evidence the day you're asked for it.

22 Indian languagesHosted in India
Obligation → control
dpdp_rules_2025
Rule 3 · the obligation
Can a data principal see a clear, itemised notice before you process their data?
Promiz control
Consent notice builder
Stand-alone, plain-language notices with itemised data and specific purposes - served in 22 languages.
Evidence: notice text + version stored against every opt-in
Pick an obligation - see the control behind it● live
Plug consent into your whole stack

Collect consent anywhere. Keep every system in step.

Consent comes in from each channel. Every change goes out at once as a signed webhook, so your tools act only on what the customer allowed.

Collect
Website script Banner and tag blocking
Forms & KYC Consent with OTP check
Back-end API REST API · Python SDK
Email request Single-use link
Sync
Your CRM Stops outreach on withdrawal
Tags & analytics Fires only allowed tags
Ad & marketing tools Respects each choice
Core & data systems Erasure and cessation tasks

Signed - verify each message with your signing secret.

Retried - failed sends retry, then wait for your review.

Logged - inspect, resend or test any delivery.

Events you can subscribe to

Consent grantedConsent declinedConsent withdrawnConsent re-grantedRequest expiredWithdrawal not acknowledgedPre-erasure warningRetention dueRetention overdueRights request receivedDeadline nearingDeadline missedGrievance raisedErasure requestedCorrection requested

Connect any tool that accepts webhooks or calls an API. Promiz does not ship pre-built app connectors today.

The DPDP gap

Collecting consent is the easy part. The Board will ask what you did next.

Many tools stop at the banner. The legal risk sits in the four steps that follow.

Collect consentEvery tool covers this
Many tools stop here
Prove itNo record of what was shown
Act on withdrawalsSystems keep processing
Erase on timeData kept past its purpose
Answer requestsNo deadline, no trail
Customer withdraws
CRMstill sendingAd toolsstill targetingPartnersnot told

A withdrawal reaches nobody

The customer clicks "withdraw". Your CRM, ad tools and partners keep processing, because nobody told them.

Retention policy.pdfLast opened 14 months ago
Customer data · 3 years old · still stored
No clock running

Data stays past its time

Retention periods live in a policy PDF. Nothing counts down, and nobody can show when data was deleted.

Re: delete my data23 days
Fwd: access request??31 days
Complaint about callsno owner

Requests sit in an inbox

Access, correction and erasure requests arrive by email, with no deadline and no record of the reply.

Penalties under the DPDP Act can reach ₹250 crore. The Board will look for proof, not policies.

See how Promiz closes the gap
One platform

Everything the DPDP consent lifecycle needs, in one place.

Six modules share one record, so every choice ties back to a notice, a purpose and a deadline.

Consent notices

No-code notices for your website, forms and email.

  • Cookie banner, form panel, email request
  • Versioned, per-purpose choices
  • Live preview while you edit

Cookie scanner & trackers

Find what runs on your site and file it under the right purpose.

  • Scan history for every run
  • Auto-filing by cookie category
  • Tags blocked until allowed

Consent records & proof

A permanent, chained record of every grant, change and withdrawal.

  • One-click integrity check
  • Snapshot of the screen shown
  • PDF notice and receipts

Privacy portal & requests

A branded self-service site and a request queue for your team.

  • OTP sign-in, no password
  • Access, correction, erasure, grievance
  • Nominations

Obligations & retention

Deadlines for stopping processing and for erasing data.

  • Separate withdrawal and erasure queues
  • Legal holds at three levels
  • 48-hour pre-erasure notice

Breach management

Log, track and report a breach against the clock.

  • 72-hour countdown
  • Severity and people affected
  • Structured Rule 7 report
Inside Promiz

See how each part works.

Build a notice in five steps. No code.

Write the binding consent text once. Promiz fingerprints it and stores it with every consent, so you can always show what a person agreed to.

  • Three modes - cookie banner, form consent or an emailed request.
  • Rich purposes - legal basis, data categories, retention, child restrictions.
  • 23 languages - translate by hand or with background auto-translation.
  • Version history - per notice, per language and per purpose.

Proof that holds up when the Board asks.

Records are never edited or deleted. Each change is a new entry, linked to the one before it. Any tampering shows at once.

  • Verify integrity - Promiz walks the chain in one click.
  • Screen snapshot - the exact view the customer saw.
  • Downloads - notice PDF and a receipt in PDF or machine-readable form.
  • Assisted withdrawal - staff can withdraw on request, with a reason.

Two duties, two queues, zero guesswork.

"Stop using it" and "delete it" are different duties under the Act. Promiz keeps them apart, so data you must keep by law is never erased by mistake.

  • Withdrawals open a stop-processing task with a confirmation deadline.
  • Erasures start when a purpose ends, with a 48-hour notice first.
  • Legal holds freeze the clock for a dispute or investigation.
  • Machine proof - only your system can close a deletion task.

A privacy portal your customers can use alone.

A branded site with your logo and colours. Customers sign in with a one-time code, manage every consent and raise requests. Your team works one queue with a clock on each request.

  • Six request types - access, correction, erasure, withdrawal, grievance, nomination.
  • Deadlines and reminders - 30 days by default; you set the grievance period.
  • Emails on open and close - customers always know the status.
  • Masked IDs - revealed only when needed, and each reveal is logged.

When a breach happens, the clock is on screen.

Log the breach, its severity and who is affected. Record your investigation and fixes. Promiz builds the structured Rule 7 report from what you recorded.

  • Without delay - tell the Board and each affected person.
  • Within 72 hours - send the Board the detailed report.
  • Every notice tracked - who was told, and when.
Product tour

How Promiz works, in four steps.

Follow one customer from the first notice to a closed task. On the left is what the customer sees. On the right is what your team sees.

Your customer seesYour team sees in Promiz
Sample FinanceENहि
हम आपके डेटा का उपयोग कैसे करेंगे

हर उद्देश्य के लिए अपनी पसंद चुनें। आप कभी भी सहमति वापस ले सकते हैं।

खाता खोलनाआवश्यक · कानूनी दायित्व
मार्केटिंग ईमेलसहमति वापस लेने तक
उपयोग विश्लेषण12 महीने
अस्वीकार करेंपसंद सहेजें

शिकायत अधिकारी: privacy@sample.example

Notice v3 shown in Hindi
Notices › Account opening
Account openingPublished · v3
ModeForm consent · SMS OTP on
LanguagesEnglish + 22 Indian languages
Text fingerprint9c41…a07e
PurposeLegal basisRetention
Account openingLegal obligationAs required by law
Marketing emailConsentUntil withdrawal
Usage analyticsConsent12 months

The customer sees a clear notice, in their language.

One choice per purpose. Required purposes are marked. Nothing is ticked for them. Your team publishes the notice once, with a legal basis and retention for each purpose.

Getting started

From first login to live consent.

  1. 1

    Create an application

    Add your website or product, its domains, branding and keys.

  2. 2

    Build the notice

    Pick the mode, write the text and add purposes.

  3. 3

    Translate

    Publish in the languages your customers read.

  4. 4

    Connect and go live

    Add the script, connect forms or call the API.

Website

One script shows the banner and blocks tags until their purpose is allowed.

Forms

Consent on sign-up, contact and KYC forms, with optional email or SMS OTP.

Back end

Raise requests and check consent before processing, by API or Python SDK.

Offline customers

Branch or call-centre staff send a single-use email link. Unanswered links expire.

Industries

Built for how your industry handles data.

Each sector has its own data, regulators and hard cases. Promiz handles them with the same record, rules and queues.

RBI · DPDP

Banking

Consent across branches, apps and call centres, while RBI rules keep some records for years.

  • Legal-obligation purposes stop use on withdrawal, never erase
  • Legal holds freeze erasure during disputes
  • Branch staff send consent links by email
RBI · DPDP

NBFC & lending

Borrower data flows to partners and collection agents, so every withdrawal must reach them.

  • Signed webhooks tell each partner system at once
  • Overdue alerts when a stop is not confirmed
  • OTP-verified consent on loan forms
IRDAI · DPDP

Insurance

Agents collect health and family details offline, often with no proof of what was shown.

  • Single-use email links for offline customers
  • Snapshot of the exact notice on each record
  • Separate purposes for quotes, claims and marketing
DPDP

Healthcare

Care data must stay available, while research and marketing need their own consent.

  • Per-purpose legal basis and retention
  • Essential care purposes stay on
  • Guardian consent for minors via DigiLocker
DPDP

E-commerce & retail

New pixels and marketing tools appear on the site every week.

  • Cookie scanner keeps your tracker list current
  • Tags blocked until their purpose is allowed
  • Notices in the language each shopper reads
DPDP · Children’s data

Education & ed-tech

Many learners are under 18, so guardian consent and tracking limits apply.

  • Guardian verified as an adult via DigiLocker
  • Child-restriction flags block tracking and targeted ads
  • Fourth Schedule exemptions recorded
DPDP

Travel & hospitality

Guest and booking data moves between hotels, agents and loyalty programmes.

  • One record across web, forms and front desk
  • Retention clocks per booking purpose
  • Self-service portal for guest requests
DPDP

SaaS & technology

Your product and your customers’ users both need clear consent and fast request handling.

  • Multiple applications under one login
  • REST API and Python SDK for your back end
  • Rights requests with tracked deadlines
Don't see your industry?

Promiz works for any Data Fiduciary that collects personal data in digital form.

Book a demo
DPDP guide

Know the dates. Know the duties.

The DPDP Rules, 2025 were notified on 13 November 2025. Here is where things stand, and how Promiz covers each duty.

Full compliance for all Data Fiduciaries
13 May 2027
-days to go
Today
13 Nov 2025Rules notified. Data Protection Board set up.
13 Nov 2026Consent Manager provisions start.Proposed: earlier date for Significant Data Fiduciaries
13 May 2027Notice, consent, rights, security, breach and erasure duties apply in full.

Confirm the dates that apply to you with your legal team. Check whether the proposed Significant Data Fiduciary date has been notified.

The duties, and how Promiz covers them

S. 5 · Rule 3

Clear, itemised notice before processing

In Promiz

Versioned notices in 23 languages, with shown-notice snapshots

S. 6

Free, specific consent for each purpose

In Promiz

A separate choice per purpose; required and optional handled apart

S. 6(4)

Withdrawal as easy as consent

In Promiz

One-click withdrawal in the banner and the privacy portal

S. 6(6)

Stop processing after withdrawal

In Promiz

A stop-processing task per withdrawal, with overdue alerts

S. 8(7) · Rule 8

Erase when the purpose ends

In Promiz

Per-purpose retention, legal holds, 48-hour notice and confirmed deletion

S. 11–14 · Rule 14

Access, correction, erasure, grievance, nomination

In Promiz

Self-service portal and a request queue with deadlines

S. 8(6) · Rule 7

Report a personal data breach

In Promiz

Breach log, 72-hour countdown and a structured report

S. 9 · Rule 10

Verifiable consent for children's data

In Promiz

Guardian verified as an adult through DigiLocker; child-restriction flags

Rule 12 · Fourth Schedule

Exempt classes for children's data

In Promiz

Recorded for the organisation and applied per purpose

Buyer's checklist

Seven questions to ask any consent vendor.

Most DPDP tools now say “22 languages” and “built for India”. These questions show the real difference.

  1. 1

    What happens after a customer withdraws?

    Promiz opens a stop-processing task with a deadline and records who confirmed it.

  2. 2

    Can you prove data was deleted?

    Only your system can close an erasure task. Promiz never marks a deletion it did not receive.

  3. 3

    Can you show the exact screen the customer saw?

    Yes. Each record keeps the notice version, a text fingerprint and a snapshot.

  4. 4

    How do we reach customers who are not online?

    Staff send a single-use email link. Unanswered requests expire.

  5. 5

    How do you handle data RBI makes us keep?

    Mark the purpose with a legal-obligation basis. A withdrawal stops use and never triggers erasure.

  6. 6

    How is a child's guardian verified?

    Through DigiLocker. The verified reference is stored with the consent.

  7. 7

    Can we change the notice text without breaking old proof?

    Yes. Every change saves a new version. Old records always keep the version the customer saw.

Security by design

Secured at every layer.

From the first click to the last webhook.

The record three layers deep
  1. Isolated per business
    Every tenant has its own keys and data boundary.
  2. One-way codes
    Identifiers are hashed; the raw value is never stored.
  3. Encrypted at rest
    Records and secrets are encrypted before they touch disk.
  4. Chained, tamper-evident records
    Each entry links to the one before it. Any change breaks the chain and shows at once.
Customers
Who gives consent
  • OTP verified
  • DigiLocker guardian check
Your apps
Who sends it in
  • Domain-bound keys
  • Hashed · revocable
Your team
Who works the queues
  • Invite-only sign-in
  • Admin · Viewer roles
  • Masked IDs · logged reveal
Your systems
Who acts on it
  • Signed webhooks
  • Encrypted secrets
  • Retry · review
Audit trail
Every admin action · tamper-evident · last-admin safeguard
Certified
SOC 2 Type II · ISO 27001
Question 1 of 12Notice & consent

Before you collect data, do you show a notice that lists the data, the purpose, and how to withdraw or complain?

S. 5 · Rule 3
FAQ

Questions buyers ask.

Not answered here? Ask us in a demo.

Do existing customers need to consent again?

For consent given before the Act started, the Act asks you to send a notice as soon as reasonably practicable. Ask your legal team whether you also need fresh consent. Promiz can send consent requests by email link.

Is Promiz a registered Consent Manager?

No. Promiz is software that you, the Data Fiduciary, use to run your own consent and rights processes. A Consent Manager is a separate role registered with the Data Protection Board.

Do we need consent for cookies?

If a cookie identifies or profiles a person, treat it as personal data. The website script blocks each tag until its purpose is allowed and records the choice.

Which languages are supported?

English and the 22 languages of the Eighth Schedule. Translate by hand or with background auto-translation. Customers can switch language inside the notice.

How do our systems learn about a withdrawal?

By signed webhook, sent at once. Failed deliveries are retried, then held for review. Your system confirms back to Promiz to close the task.

Does Promiz give legal advice?

No. Promiz supports your compliance programme. Your legal team decides purposes, legal bases and retention periods.

Bring one purpose. Leave with the proof.

A 30-minute session on your own use case.

  1. 5 min Find your DPDP gaps for that purpose
  2. 20 min Build the notice, collect consent, withdraw it, and close the task
  3. 5 min Download the receipt and verify the chain

Book your demo

Enter your website. We scan its cookies before the call and show you the results.

Reply within 1 business day