DPDPA Compliance Platform

India's most complete DPDPA compliance platform.

15 integrated modules — consent management, data discovery, DSAR, DPIA, breach response & RoPA on your own infrastructure. Zero PII leaves your boundary. On-premise, private cloud, or air-gapped.

Book a Demo →
All 15 Compliance Modules

Built for every DPDP Act obligation.

Each module addresses a specific data protection compliance requirement under the Digital Personal Data Protection Act 2023 — and they all work together on your own infrastructure.

Module 01

Data Discovery

22+ PII categories and PCI-DSS detection using on-device ONNX AI. Scans PostgreSQL, MySQL, Oracle, MongoDB, files, and cloud apps with OCR. SHA-256 hash only — raw PII never transmitted or stored centrally.

✓ 22+ PII Categories ✓ On-Device ONNX AI ✓ OCR Support ✓ SHA-256 Only
Data Discovery — PII scan results across databases and file systems
Module 02

Business Process Register

Map your full data lineage: Product → BPA → Data Elements → Third Parties. Auto-derives ROPA from your process register. Maker-checker workflow enforced on every change — complete governance trail.

✓ Data Lineage Graphs ✓ ROPA Auto-Derivation ✓ Maker-Checker Workflow ✓ Third-Party Mapping
Business Process Activities — data lineage mapping
Module 04

DSAR Portal

Self-service portal at privacy.yourdomain.com. Auto-locates data across all sources and propagates erasure to third parties. Supports OTP, DigiLocker, and Video KYC for parental consent.

✓ Your Domain ✓ Auto Data Location ✓ Erasure Propagation ✓ DigiLocker / Video KYC
Privacy Requests — DSAR tracking with status and deadlines
Module 05

Breach Management

Response timer starts from SIEM detection. Pre-built connectors for Splunk, Sentinel, QRadar, and CEF syslog. Auto-drafts regulatory notices to CERT-In, RBI, DPB, and SEBI — within the mandatory 72-hour window.

✓ Splunk / Sentinel / QRadar ✓ Auto-Draft Notices ✓ CERT-In / RBI / SEBI ✓ 72-Hour Window
Breach Management — incident tracking with 72-hour deadline timer
Module 06

DPIA & ROPA

Pre-filled from your BPA and discovery results. DPDP and native assessment templates. Risk heatmap for high-risk processing. Export to PDF, Excel, or CSV for regulators and auditors.

✓ Pre-Filled from BPA ✓ Risk Heatmap ✓ DPDP Templates ✓ PDF / Excel / CSV Export
DPIA — impact assessments with risk scoring and DPO sign-off

Want to see these modules in action?

Book a Demo →
More Views

Data Elements, Lineage, RoPA & Risk Heatmap

Module 07

Vendor Compliance

8-dimension vendor scoring across 4 questionnaire types — sent via secure link, no vendor login required. Full DPA tracking and sub-processor chain alerts to manage third-party risk end-to-end.

✓ 8-Dimension Scoring ✓ No Vendor Login ✓ DPA Tracking ✓ Sub-Processor Alerts
Vendor Register — third-party compliance scoring and DPA tracking
Module 08

Compliance Monitor

Always-on 6-hourly scans across your environment. Detects 12 violation types and writes to an append-only register. Feeds a real-time organisation maturity score visible to the DPO dashboard.

✓ 6-Hourly Scans ✓ 12 Violation Types ✓ Append-Only Register ✓ Maturity Score
Violations — compliance monitoring with severity and status tracking
Module 09

Governance Portal

12 DPO screens, 10 auto-generated policy types, and an RFC 3161 evidence vault. 40+ widget dashboards. Builds DPDP Annual Reports and RBI Banking compliance reports automatically.

✓ 12 DPO Screens ✓ RFC 3161 Evidence Vault ✓ 40+ Dashboards ✓ RBI Report Builder
Governance Dashboard — DPO overview with quick access to all modules
Module 10

Security & Audit

KMS with Shamir 3-of-5 unseal and 5 BYOK key slots. Hash-chained, ECDSA-signed, RFC 3161 timestamped audit logs retained for 7 years. AES-256 at rest, HMAC-SHA256 integrity throughout.

✓ Shamir 3-of-5 KMS ✓ 5 BYOK Key Slots ✓ ECDSA-Signed Logs ✓ 7-Year Retention
Compliance Score — maturity scoring across 7 compliance dimensions
Module 11

Notifications

Email, SMS, WhatsApp, WebSocket, Slack, Teams, and PagerDuty. 38+ alert rules with escalation chains and digest mode — so the right person is notified at the right time.

✓ 7 Channels ✓ 38+ Alert Rules ✓ Escalation Chains ✓ Digest Mode
Module 12

Access Control & SSO

SAML 2.0 + OIDC with Entra ID, Okta, Google, ADFS, and Keycloak. FIDO2 hardware keys mandatory for DPO and CISO roles. SCIM 2.0, step-up auth, and break-glass access built in.

✓ SAML 2.0 + OIDC ✓ FIDO2 Hardware Keys ✓ SCIM 2.0 ✓ Break-Glass Access
Module 13

Data Principal Portal

White-label portal with magic link authentication. Data principals manage their own consent preferences, rights requests, and nominee designations — fully self-service, fully branded to your organisation.

✓ Magic Link Auth ✓ White-Label ✓ Consent Preferences ✓ Nominee Management
Module 14

Support System

L1/L2/L3 ticketing with integrated knowledge base. PII guard enforced on all support content end-to-end — ensuring personal data is never exposed in support communications.

✓ L1 / L2 / L3 Tiers ✓ Knowledge Base ✓ PII Guard ✓ End-to-End Protection
Module 15

Billing & Licensing

RSA-4096 signed license file with offline capability. Hash-chained activity ledger for complete audit trail. Internal chargeback allocation across business units.

✓ RSA-4096 Signed ✓ Offline Capable ✓ Hash-Chained Ledger ✓ Chargeback Allocation
On-Premise & Private Cloud Deployment

Your infrastructure. Your data boundary.

One codebase — three ways to deploy your DPDPA compliance platform. Zero personal data leaves your network regardless of which model you choose.

On-Premise

Bare-Metal / VMware / Hyper-V

Runs entirely within your own data centre. Managed jointly by your IT team and ClearConsent support. Air-gapped deployment available via USB license for defence and government.

Best for: Banks, PSU, Defence, Healthcare
Air-gap: Available — USB license
Data boundary: 100% client infrastructure
POPULAR
Private Cloud

Client AWS / Azure / GCP VPC

Deployed inside your own cloud account VPC. Managed by your cloud team alongside ClearConsent support. Full data sovereignty — we never touch your environment without permission.

Best for: IT companies, large enterprise
Air-gap: Not required
Data boundary: 100% client cloud account
Managed Private

Operated by ClearConsent

Your cloud account, managed by our operations team. No internal DevOps required. Data never moves to ClearConsent infrastructure — your account, your keys, our expertise.

Best for: Mid-size without internal DevOps
Air-gap: Not available
Data boundary: 100% client-owned account

Only a quarterly 500-byte license ping leaves your network — no telemetry, no PII outbound.

How It Works

From setup to governance in 3 phases.

No six-month implementations. No consultancy fees for basic setup. ClearConsent is designed to go live fast.

1

Discover

Map all personal data touchpoints across your technology stack, third-party vendors, and internal processes. Know exactly what you're processing and where within days of onboarding.

2

Configure

Deploy DPDPA-compliant consent journeys, rights request workflows, and breach protocols — all pre-built to Indian law and customisable to your organisation's specific needs.

3

Govern

Monitor processing activities with real-time dashboards, automated audit trails, and proactive alerts — so compliance is continuous, not a once-a-year scramble before an audit.

Industries We Serve

DPDPA compliance for India's regulated sectors.

Every data fiduciary that processes personal data of Indian citizens must comply with the DPDP Act 2023. We've designed for the most complex regulated industries first.

BFSI & Fintech
Healthcare & Pharma
E-Commerce & Retail
EdTech & Education
HR & Staffing
IT & SaaS Platforms
Telecom & Media
Manufacturing
Government & PSUs
Any Data Fiduciary
Frequently Asked Questions

DPDPA compliance questions answered.

Everything you need to know about the DPDP Act 2023, compliance deadlines, penalties, and how ClearConsent helps data fiduciaries become compliant.

What is DPDPA compliance and why do Indian businesses need it?

DPDPA compliance refers to meeting the obligations under India's Digital Personal Data Protection Act 2023 (DPDP Act). Every organisation that processes personal data of Indian citizens — called a Data Fiduciary — must comply. The Act mandates purpose-specific consent, data principal rights (access, correction, erasure), breach notification within 72 hours, and reasonable security safeguards. Non-compliance can attract penalties of up to ₹250 crore per incident. Full enforcement begins May 2027, with the Consent Manager framework launching November 2026.

How many modules does the ClearConsent platform include?

ClearConsent includes 15 integrated modules: Data Discovery, Business Process Register, Consent Management, DSAR Portal, Breach Management, DPIA & RoPA, Vendor Compliance, Compliance Monitor, Governance Portal, Security & Audit, Notifications, Access Control & SSO, Data Principal Portal, Support System, and Billing & Licensing. All modules work together on your own infrastructure with zero PII leaving your data boundary.

Can ClearConsent be deployed on-premise or in air-gapped environments?

Yes. ClearConsent supports three deployment models: on-premise (bare-metal, VMware, Hyper-V), private cloud (your own AWS/Azure/GCP VPC), and managed private (operated by ClearConsent in your cloud account). Air-gapped deployment is available via USB license for defence, government, and banking organisations. Only a quarterly 500-byte license ping leaves your network — no telemetry, no PII outbound.

What is the penalty for DPDPA non-compliance in India?

Under the DPDP Act 2023, penalties can reach up to ₹250 crore for failure to implement reasonable security safeguards, ₹200 crore for failure to notify data breaches, and ₹50 crore for non-fulfilment of data principal rights. The Data Protection Board can enhance penalties up to twice the standard amount — meaning a serious breach could attract up to ₹500 crore.

Does ClearConsent support DSAR and Data Principal Rights management?

Yes. ClearConsent's DSAR Portal provides a self-service portal at privacy.yourdomain.com where data principals can submit access, correction, erasure, and portability requests. The system auto-locates data across all connected sources, propagates erasure to third parties, and supports OTP, DigiLocker, and Video KYC for identity verification and parental consent.

What databases and data sources does the Data Discovery module scan?

ClearConsent's Data Discovery module scans PostgreSQL, MySQL, Oracle, MongoDB, file systems, and cloud applications. It detects 22+ PII categories and PCI-DSS data using on-device ONNX AI with OCR support. Only SHA-256 hashes are transmitted — raw PII is never stored centrally or transmitted outside your network.

Is ClearConsent suitable for Significant Data Fiduciaries (SDFs)?

Yes. ClearConsent is built for Significant Data Fiduciary compliance. It supports all additional SDF obligations including appointing a Data Protection Officer (DPO), conducting annual Data Audits with independent auditors, and undertaking Data Protection Impact Assessments (DPIAs). The platform generates DPDP Annual Reports and RBI Banking compliance reports automatically.

What is the DPDP Act 2023 compliance deadline?

The DPDP Rules 2025 enforcement is phased: Phase 1 (November 2025) activated the Data Protection Board, Phase 2 (November 2026) opens Consent Manager registration, and Phase 3 (May 13, 2027) is the full enforcement deadline — all consent systems, privacy notices, security safeguards, breach protocols, and Data Principal rights infrastructure must be operational.

See the platform in action.

Book a personalised demo and we'll walk you through the modules most relevant to your organisation.