Solutions

The DPDP consent lifecycle, module by module.

Collect consent, prove it, act on withdrawals and erasures, answer rights requests and report breaches. Six modules, one chained record.

Starting point

Where is your DPDP programme today?

Choose your starting point. Each path uses the same platform and the same record.

New to DPDP

Start with one notice and one website

Create one application, write one notice, and add the website script. Consent starts to flow into a record you can prove. Then add the portal so customers can withdraw without a call to you.

  • Consent notices in English and 22 Eighth Schedule languages
  • Cookie scanner to find what runs on your site
  • Privacy portal for withdrawals and requests
We have a cookie banner

A banner collects a choice. DPDP asks for more.

You must also act on a withdrawal, erase data when its purpose ends, answer rights requests on time, and report a breach in 72 hours. Promiz adds these duties to the consent you already collect.

  • Consent records that nobody can edit
  • Withdrawal and erasure queues with deadlines
  • Breach management with a 72-hour clock
Many products, many teams

One login for every product and system

Each website, app or loan system is an application with its own branding, domains, keys and webhooks. Admins and Viewers see only what their role allows. Signed webhooks keep your CRM and data systems in step.

  • Applications and team roles
  • Back-end API and Python SDK
  • 18 webhook events, signed and retried
Consent lifecycle

How does one consent move through Promiz?

Every step writes to the same record. When a customer changes their mind, Promiz opens a task for your team and keeps the proof in the same chain.

  1. 1 Notice shown

    Banner, form or email in 23 languages

  2. 2 Consent given

    Per purpose, with optional OTP check

  3. 3 Record chained

    Fingerprint, version, screen snapshot

  4. 4 Customer acts

    Withdraws or raises a rights request

  5. 5 Task opened

    Deadline starts; webhook sent

  6. 6 Proof closed

    Your system confirms back

The closing proof is a new entry in the same chain. Nothing is edited or deleted.

Module by module

How each part of Promiz works, and which DPDP duty it serves. Your legal team decides purposes, legal bases and retention periods; Promiz runs the process.

Last reviewed 18 Sep 2026

01 · Consent notices

How do consent notices work?

You build a notice in five steps, without code, and choose how it shows: a cookie banner on your site, a consent panel inside a form, or an emailed request with a single-use link. Each purpose gets its own choice, so required and optional processing are handled apart.

The binding text is written once and fingerprinted. Promiz stores that version with every consent it collects, in English and the 22 Eighth Schedule languages, so you can always show exactly what a person agreed to and in which language.

Maps to: S. 5 · Rule 3 - Clear, itemised notice before processing · S. 6 - Free, specific consent for each purpose · S. 9 · Rule 10 - Verifiable consent for children's data

02 · Cookie scanner & trackers

What does the cookie scanner find?

The scanner crawls your site and lists every cookie, script and tracker it finds, then files each one under a cookie category and the purpose it serves. Every run is kept, so you can see what changed between scans.

The website script blocks each tag until its purpose is allowed. When a visitor makes a choice in the banner, only the tags they permitted fire, and the choice is written to the consent record like any other.

Maps to: S. 5 · Rule 3 - Clear, itemised notice before processing · S. 6 - Free, specific consent for each purpose

03 · Consent records & proof

How are consent records kept tamper-evident?

Records are never edited or deleted. Every grant, change and withdrawal is a new entry linked to the one before it, so the history of a consent is a chain rather than a row that gets overwritten.

Promiz walks that chain in one click and flags any break. Each record also keeps a snapshot of the screen the customer saw, the notice version and language, and can be exported as a PDF receipt or in machine-readable form.

Maps to: S. 6 - Free, specific consent for each purpose · S. 6(4) - Withdrawal as easy as consent

04 · Privacy portal & requests

What can customers do in the privacy portal?

Customers sign in with a one-time code, see every consent they have given, withdraw any of them, and raise access, correction, erasure, grievance or nomination requests without calling you. The portal is a branded site with your logo and colours.

On your side, every request lands in one queue with a clock on it: 30 days by default, with the grievance period set by you. Customers get an email when a request is opened and when it is closed, and identifiers stay masked until someone needs to reveal them.

Maps to: S. 11–14 · Rule 14 - Access, correction, erasure, grievance, nomination · S. 6(4) - Withdrawal as easy as consent

05 · Obligations & retention

How do withdrawal and erasure queues differ?

"Stop using it" and "delete it" are different duties under the Act. A withdrawal opens a stop-processing task with a confirmation deadline; an erasure starts when a purpose ends and sends a 48-hour notice before anything is deleted. Promiz keeps the two apart so data you must keep by law is never erased by mistake.

Legal holds freeze the clock at three levels for a dispute or investigation. A deletion task can only be closed by your system confirming back, so the record shows machine proof rather than a manual tick.

Maps to: S. 6(6) - Stop processing after withdrawal · S. 8(7) · Rule 8 - Erase when the purpose ends

06 · Breach management

What happens when a breach is logged?

The 72-hour countdown starts on screen the moment you log a breach, with its severity and who is affected. You then record your investigation and fixes as they happen.

Promiz builds the structured Rule 7 report from what you recorded, and tracks every notice you send to the Board and to affected people, so you can show who was told and when.

Maps to: S. 8(6) · Rule 7 - Report a personal data breach

Foundations

What runs under every module?

Applications

One login for all your products. Each website, app or back-end system has its own branding, domains, API keys and webhooks. Keys are bound to your allowed domains, so a leaked key does not work anywhere else.

Dashboard & analytics

A live view of consent activity, open requests and your DPDP compliance score. Each failing check links to its fix. Trend charts cover 7, 30, 90 or 365 days, with CSV export.

Team & access

Invite staff as Admin (full control) or Viewer (read-only). Promiz stops you from removing your last Admin.

Security

Email addresses are encrypted at rest. IP addresses and phone numbers are stored only as one-way codes. The database keeps each business's data separate. Every admin action goes into a tamper-evident audit trail.

By team

What does each team get from Promiz?

DPDP work crosses teams. Each team works in the same record, with the view it needs.

Legal & privacy

Decide purposes, legal bases and retention once. Prove them for every consent.

  • Section-by-section DPDP mapping
  • Grievance officer details shown to customers
  • Legal holds

Marketing

Run campaigns only on purposes the customer allowed.

  • Tags fire only after consent
  • CRM stops outreach on withdrawal
  • Grant and withdrawal trends, with CSV export

Engineering

One script, one API, one set of events.

  • REST API and Python SDK
  • Signed, retried webhooks
  • Domain-bound API keys

Security & risk

Evidence you can hand to an auditor or the Board.

  • Tamper-evident audit trail
  • Masked IDs, logged reveals
  • 72-hour breach clock
Plug consent into your whole stack

Collect consent anywhere. Keep every system in step.

Consent comes in from each channel. Every change goes out at once as a signed webhook, so your tools act only on what the customer allowed.

Collect
Website script Banner and tag blocking
Forms & KYC Consent with OTP check
Back-end API REST API · Python SDK
Email request Single-use link
Sync
Your CRM Stops outreach on withdrawal
Tags & analytics Fires only allowed tags
Ad & marketing tools Respects each choice
Core & data systems Erasure and cessation tasks

Signed - verify each message with your signing secret.

Retried - failed sends retry, then wait for your review.

Logged - inspect, resend or test any delivery.

Events you can subscribe to

Consent grantedConsent declinedConsent withdrawnConsent re-grantedRequest expiredWithdrawal not acknowledgedPre-erasure warningRetention dueRetention overdueRights request receivedDeadline nearingDeadline missedGrievance raisedErasure requestedCorrection requested

Connect any tool that accepts webhooks or calls an API. Promiz does not ship pre-built app connectors today.

Product FAQ

How does Promiz fit your stack?

Not answered here? Ask us in a demo.

Can we use one module on its own?

Yes. Each module can be switched on separately, but they all write to the same chained record. Most teams start with notices and the cookie scanner, then add the portal and obligation queues as their DPDP programme matures.

How does Promiz collect consent outside the website?

Through a REST API and Python SDK for your own apps and forms, an emailed consent request with a single-use link, and consent captured inside KYC or onboarding flows with an OTP check. Every channel writes the same record.

How do our systems find out about a withdrawal or erasure?

By signed webhook, sent at once. Failed deliveries are retried and then held for your review. Your system confirms back to Promiz, which is what closes the stop-processing or deletion task.

What proof can we show the Data Protection Board?

For any consent: the notice version and language shown, a snapshot of the screen, every later change in a linked chain, and a receipt in PDF or machine-readable form. Promiz verifies the chain in one click, so a break in the record shows immediately.

Does the platform handle children’s data and guardian consent?

Purposes can carry a child restriction, and guardian consent is verified against an adult identity through DigiLocker. Exempt classes under Rule 12 are recorded for the organisation and applied per purpose. Confirm which exemptions apply to you with your legal team.

Scope

What is Promiz built for, and what is next?

Promiz is built for India's DPDP Act 2023. It is not a GDPR tool. Today it does not act as a registered Consent Manager and does not control cross-border transfers.

In development

  • Code scanner for data mapping (Python and Java)
  • Expanded breach workflow with a PDF report
  • Wider reporting, dashboards and exports

Bring one purpose. Leave with the proof.

A 30-minute session on your own use case.

  1. 5 min Find your DPDP gaps for that purpose
  2. 20 min Build the notice, collect consent, withdraw it, and close the task
  3. 5 min Download the receipt and verify the chain

Book your demo

Enter your website. We scan its cookies before the call and show you the results.

Reply within 1 business day