DPDP compliance for websites
Publish a purpose-level banner and preference center on a verified domain, then apply the recorded choice to the scripts you have mapped.
India
DPDP compliance is the work of meeting the Digital Personal Data Protection Act, 2023 for the processing you actually do. Consent Guru helps teams run the consent and rights parts of that work.
DPDP compliance means handling digital personal data in line with India’s Digital Personal Data Protection Act, 2023: a lawful ground, a clear notice where consent is used, a way to withdraw consent, and a way for people to exercise Data Principal rights. Software can help operate those steps. It does not, by itself, make an organization compliant.
The Act applies to digital personal data processed in India and, in defined cases, to processing outside India that is connected with offering goods or services to people in India. A Data Fiduciary decides the purpose and means of that processing. A Data Processor acts on the fiduciary’s behalf.
Consent is one lawful ground. The Act also lists specific legitimate uses where consent is not the basis. Treating every cookie or every form as “DPDP consent” misstates the statute. Counsel still has to decide which ground applies.
Consent Guru is consent management software for the operational layer: the notice you publish, the choice you store, withdrawal, and Data Principal request intake. Registration as a Consent Manager with the Data Protection Board is a separate statutory process. Shipping this product is not that registration.
Step 1
List the personal data and the purpose. Mark what is necessary for the service and what is optional, such as analytics or advertising.
Step 2
For each purpose, decide whether you are asking for consent or relying on a legitimate use the Act lists. Do not relabel one as the other inside the banner.
Step 3
Present the personal data, the purpose, how to withdraw, how to exercise rights, and how to complain to the Board, in language the person can follow.
Step 4
Store the choice with the notice version. Let the person withdraw as easily as they agreed. Route access, correction, erasure, nomination, and grievance requests through a tracked path.
Publish a purpose-level banner and preference center on a verified domain, then apply the recorded choice to the scripts you have mapped.
Use the consent API when the choice is collected in an account settings page instead of, or as well as, a public cookie banner.
Keep an identifier, timestamp, locale, and a snapshot of the notice that was shown, so a later question is not answered from memory.
The public Privacy Centre intakes access, correction, erasure, nomination, grievance, and consent-withdrawal requests, with a tracking reference.
Give privacy, legal, and engineering one published policy to implement for an India-facing service.
Run a DPDP-oriented configuration on the properties that need it without copying that wording onto a GDPR or CPRA site.
Add age assurance and guardian consent before optional processing on a property directed at children.
This page is an operational guide, not legal advice. The Act, the DPDP Rules, sector rules, and any Consent Manager registration requirements should be confirmed with counsel.
Consent Guru helps organizations manage and operationalize consent requirements. It does not guarantee DPDP compliance, and it does not determine Significant Data Fiduciary status.
Public readiness tools on this site are preliminary checks. They are not a finding of the Data Protection Board.
It is software that helps a team present notices, collect and store purpose-level choices, support withdrawal, and intake Data Principal requests. It is an aid to a compliance program, not a certificate that the program is complete.
Publish a specific notice, collect a clear affirmative action for each purpose that relies on consent, store the notice version with the choice, and make withdrawal as easy as the original request. Stop processing that depended on the withdrawn consent unless another ground the Act allows still applies.
No. A Consent Manager under the Act is a person registered with the Data Protection Board, accountable to the Data Principal. Consent Guru is software a Data Fiduciary can use. Those are different roles.
This page describes how Consent Guru supports privacy operations. It is not legal advice, and using the product does not by itself make an organization compliant with GDPR, CCPA, CPRA, the DPDP Act, or any other law.