Designed by data-protection auditors · DPDP consent management for India
DPDP compliance, operationalised.
ConsentLo turns the Act into workflows your team can run: consent that stands up as evidence, rights handled on the clock, breaches reported within 72 hours, and rules that update the moment the Government changes them.
Curated by practising DPDP auditors: every control produces the evidence an audit asks for.
41h 12m
left to notify the Data Protection Board
Containment logged
Done
Board draft
Approved by DPO
Principals notified
12,480 of 12,480
Evidence records
#4,112 sealed
Offers by email: withdrawn
sealed · 2 processors toldEvery obligation, run as a workflow.
Notices that hold up
Versioned notices in English and the 22 Eighth Schedule languages. An Invalidity Engine flags clauses the Act voids before you publish.
Consent as evidence
Every choice is a separate, un-ticked decision tied to the exact notice version, sealed in a hash chain. Withdrawal is one click and cascades to processors.
Rights & grievances
Access, correction, erasure and nomination, each on its own SLA clock, with the Board route opening automatically once redress is exhausted.
72-hour breach desk
Two clocks start on discovery. Board intimation and principal notices are drafted for you, approved by a human, and evidenced.
Children's safeguards
Age signals, verifiable guardian consent, harm reviews, and a hard block on tracking and targeted ads for minors.
Data map & processors
No activity goes live without a defensible basis. Processor contracts, retention, erasure and cross-border checks in one register.
SDF & the Board
DPO, DPIA and audit cycles for Significant Data Fiduciaries; correspondence, appeals and voluntary undertakings with the Board.
Rules Watch
Every deadline is versioned configuration. When a notification changes one, it is published once and every clock follows.
Built by the people who audit DPDP compliance.
ConsentLo is curated by practising data-protection auditors. We have sat across the table from Data Fiduciaries and seen what holds up and what does not, so the product captures proof as your team works, instead of asking for it afterwards.
Get an auditor-led walkthroughStarted as an audit checklist
Every screen began as a question an auditor asks under the DPDP Act and Rules, not as a feature idea.
Evidence by default
Notices, consents, requests and deadlines are sealed in a tamper-evident Evidence Vault the moment they happen.
Controls mapped to the law
Each workflow traces back to the obligation it satisfies, so gaps show up before an inspection, not during one.
An auditor’s seat inside
A read-only, scoped Auditor role reviews the same records your team works from and logs findings in place.
Everyone sees exactly what their role needs.
Workspaces are fully isolated. The platform operator publishes regulatory changes and manages plans, and cannot see a single principal, consent or incident of any tenant.
Tenant Admin
Sets up the Data Fiduciary, users and integrations.
DPO
Owns breaches, DPIAs and the Board; approves rights work.
Grievance desk
Works rights requests and grievances within SLA.
Engineer
Wires in the Consent SDK, APIs and webhooks.
Auditor
Read-only, scoped; records audit findings.
Data Principal
Self-service portal in their own language.
Plans that scale with the principals you serve.
Understand the DPDP Act and DPDP Rules, 2025.
Plain-language explainers on consent management, breach notification, penalties, children's data and a step-by-step compliance checklist.
DPDP Act 2023 explained: a practical guide for Indian businesses
What the Digital Personal Data Protection Act, 2023 means for your business: who it applies to, consent, rights, children, breaches, penalties and how to comply.
Read the guide
DPDP Rules 2025: what they require and when
A clear summary of the Digital Personal Data Protection Rules, 2025: phased commencement, notices, consent managers, breach reporting in 72 hours, retention and children.
Read the guide
Consent management under the DPDP Act
How to collect, record and honour valid consent under India's DPDP Act: notices, purpose-by-purpose choices, withdrawal, proof of consent and a consent management platform.
Read the guide
DPDP compliance checklist: 12 steps to get ready
A practical DPDP Act compliance checklist: data mapping, notices, consent, rights, grievances, processors, breach response, children, retention, security and evidence.
Read the guide
DPDP consent management, answered.
What is ConsentLo?
ConsentLo is a DPDP consent management and compliance platform for India. It runs notices, consent, rights, grievances, breach reporting, children's data and evidence for the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025.
Is ConsentLo a consent management platform?
Yes. It captures purpose-by-purpose consent through a website widget, SDK or privacy portal, keeps a tamper-evident consent ledger, and makes withdrawal one step. It can also receive consent from registered Consent Managers.
Does ConsentLo support Indian languages?
Yes. Notices and the privacy portal work in English and the 22 languages of the Eighth Schedule, including Hindi, Bengali, Tamil, Telugu, Marathi, Gujarati, Kannada and Malayalam.
How does ConsentLo handle the 72-hour breach rule?
Logging a breach starts both clocks, for the Data Protection Board and for affected people. ConsentLo drafts both notices, requires human approval, sends them and keeps the evidence.
Is my data kept separate from other customers?
Yes. Every organisation gets an isolated workspace, and even the platform operator cannot see your principals, consents or incidents.
The clocks are already running.
See it on your own data flows: we will walk you through notices, consent, rights and the breach desk.