Consent management platform for India: what to look for under DPDP
Updated 26 Sep 2026 · 7min read · Reviewed by ConsentLo's DPDP audit team
A consent management platform (CMP) collects, records and enforces people's choices about their personal data. Cookie-banner tools built for Europe cover only a slice of what India's DPDP Act asks. This guide explains what a DPDP-ready CMP must do, and the questions to ask before you buy one.
What a consent management platform does
A CMP shows a notice, captures a clear yes or no for each purpose, stores that decision as evidence, and makes sure your systems honour it, including when someone changes their mind. Under the DPDP Act, consent is the main ground for processing personal data, so the CMP becomes part of your core compliance infrastructure rather than a website add-on.
DPDP requirements a CMP must meet
Look for these capabilities, each of which maps to a requirement in the DPDP Act or the DPDP Rules, 2025:
- Stand-alone notices that itemise the personal data and each purpose, in English and the 22 languages of the Eighth Schedule.
- Separate, un-ticked choices per purpose: no bundled or pre-ticked consent.
- A consent ledger that ties every decision to the exact notice version, time and channel.
- Withdrawal that is as easy as giving consent, and that reaches your processors.
- Verifiable parental consent for anyone under 18, and a block on tracking and targeted ads for children.
- Access, correction, erasure, nomination and grievance handling, with deadlines.
- Breach reporting to the Data Protection Board within 72 hours.
- Tamper-evident evidence you can show an auditor or the Board.
CMP versus a registered Consent Manager
The DPDP Act also creates "Consent Managers": entities registered with the Data Protection Board that let individuals manage consents across many organisations. A CMP is software your organisation uses for its own compliance. You can use a CMP and also accept consents that arrive through a registered Consent Manager.
Questions to ask vendors
Before you shortlist a platform, ask:
- Where is the data hosted, and who can access it?
- Can it version notices and prove which version each person saw?
- Does withdrawal cascade to processors automatically?
- Does it handle rights requests, grievances and breaches, or only cookies?
- Does it support the Indian languages your customers use?
- Can your engineers integrate it by SDK, API and webhooks?
- Was it designed with auditors, and can it export audit-ready evidence?
How ConsentLo fits
ConsentLo is a DPDP-first consent management platform designed by data-protection auditors. It covers notices, the consent ledger, children's safeguards, rights, grievances, breaches, retention and an Evidence Vault in one workspace, with a consent SDK, APIs and webhooks for your engineers.
Frequently asked questions
Do Indian companies need a consent management platform?
The DPDP Act does not name a specific tool, but any organisation relying on consent must capture it validly, prove it, and honour withdrawal. At any real scale, that is very hard to do without a CMP.
Is a cookie banner enough for DPDP compliance?
No. Cookies are a small part of DPDP. You also need notices for every purpose, a consent record, withdrawal, rights and grievance handling, children's safeguards and breach reporting.
What is the difference between a CMP and a Consent Manager?
A CMP is software an organisation uses to manage its own consents. A Consent Manager is an entity registered with the Data Protection Board that individuals use to manage consents across organisations.