The Platform

One platform. Total DPDPA coverage.

15 integrated modules — complete privacy lifecycle on your own infrastructure. Zero PII leaves your boundary. On-premise, private cloud, or air-gapped.

Book a Demo →
All 15 Modules

Built for every DPDPA obligation.

Each module addresses a specific compliance requirement — and they all work together on your own infrastructure.

Module 01
🔍

Data Discovery

22+ PII categories and PCI-DSS detection using on-device ONNX AI. Scans PostgreSQL, MySQL, Oracle, MongoDB, files, and cloud apps with OCR. SHA-256 hash only — raw PII never transmitted or stored centrally.

✓ 22+ PII Categories ✓ On-Device ONNX AI ✓ OCR Support ✓ SHA-256 Only
Module 02
🗂️

Business Process Register

Map your full data lineage: Product → BPA → Data Elements → Third Parties. Auto-derives ROPA from your process register. Maker-checker workflow enforced on every change — complete governance trail.

✓ Data Lineage Graphs ✓ ROPA Auto-Derivation ✓ Maker-Checker Workflow ✓ Third-Party Mapping
Module 04
👤

DSAR Portal

Self-service portal at privacy.yourdomain.com. Auto-locates data across all sources and propagates erasure to third parties. Supports OTP, DigiLocker, and Video KYC for parental consent.

✓ Your Domain ✓ Auto Data Location ✓ Erasure Propagation ✓ DigiLocker / Video KYC
Module 05
🚨

Breach Management

Response timer starts from SIEM detection. Pre-built connectors for Splunk, Sentinel, QRadar, and CEF syslog. Auto-drafts regulatory notices to CERT-In, RBI, DPB, and SEBI — within the mandatory 72-hour window.

✓ Splunk / Sentinel / QRadar ✓ Auto-Draft Notices ✓ CERT-In / RBI / SEBI ✓ 72-Hour Window
Module 06
📋

DPIA & ROPA

Pre-filled from your BPA and discovery results. DPDP and native assessment templates. Risk heatmap for high-risk processing. Export to PDF, Excel, or CSV for regulators and auditors.

✓ Pre-Filled from BPA ✓ Risk Heatmap ✓ DPDP Templates ✓ PDF / Excel / CSV Export
Module 07
🤝

Vendor Compliance

8-dimension vendor scoring across 4 questionnaire types — sent via secure link, no vendor login required. Full DPA tracking and sub-processor chain alerts to manage third-party risk end-to-end.

✓ 8-Dimension Scoring ✓ No Vendor Login ✓ DPA Tracking ✓ Sub-Processor Alerts
Module 08
📡

Compliance Monitor

Always-on 6-hourly scans across your environment. Detects 12 violation types and writes to an append-only register. Feeds a real-time organisation maturity score visible to the DPO dashboard.

✓ 6-Hourly Scans ✓ 12 Violation Types ✓ Append-Only Register ✓ Maturity Score
Module 09
⚖️

Governance Portal

12 DPO screens, 10 auto-generated policy types, and an RFC 3161 evidence vault. 40+ widget dashboards. Builds DPDP Annual Reports and RBI Banking compliance reports automatically.

✓ 12 DPO Screens ✓ RFC 3161 Evidence Vault ✓ 40+ Dashboards ✓ RBI Report Builder
Module 10
🔐

Security & Audit

KMS with Shamir 3-of-5 unseal and 5 BYOK key slots. Hash-chained, ECDSA-signed, RFC 3161 timestamped audit logs retained for 7 years. AES-256 at rest, HMAC-SHA256 integrity throughout.

✓ Shamir 3-of-5 KMS ✓ 5 BYOK Key Slots ✓ ECDSA-Signed Logs ✓ 7-Year Retention
Module 11
🔔

Notifications

Email, SMS, WhatsApp, WebSocket, Slack, Teams, and PagerDuty. 38+ alert rules with escalation chains and digest mode — so the right person is notified at the right time.

✓ 7 Channels ✓ 38+ Alert Rules ✓ Escalation Chains ✓ Digest Mode
Module 12
🔑

Access Control & SSO

SAML 2.0 + OIDC with Entra ID, Okta, Google, ADFS, and Keycloak. FIDO2 hardware keys mandatory for DPO and CISO roles. SCIM 2.0, step-up auth, and break-glass access built in.

✓ SAML 2.0 + OIDC ✓ FIDO2 Hardware Keys ✓ SCIM 2.0 ✓ Break-Glass Access
Module 13
🧑‍💼

Data Principal Portal

White-label portal with magic link authentication. Data principals manage their own consent preferences, rights requests, and nominee designations — fully self-service, fully branded to your organisation.

✓ Magic Link Auth ✓ White-Label ✓ Consent Preferences ✓ Nominee Management
Module 14
🎫

Support System

L1/L2/L3 ticketing with integrated knowledge base. PII guard enforced on all support content end-to-end — ensuring personal data is never exposed in support communications.

✓ L1 / L2 / L3 Tiers ✓ Knowledge Base ✓ PII Guard ✓ End-to-End Protection
Deployment

Your infrastructure. Your boundary.

One codebase — three ways to deploy. Zero PII leaves your network regardless of which model you choose.

🏢
On-Premise

Bare-Metal / VMware / Hyper-V

Runs entirely within your own data centre. Managed jointly by your IT team and ClearConsent support. Air-gapped deployment available via USB license for defence and government.

🏛️ Best for: Banks, PSU, Defence, Healthcare
🔒 Air-gap: Available — USB license
📦 Data boundary: 100% client infrastructure
POPULAR
☁️
Private Cloud

Client AWS / Azure / GCP VPC

Deployed inside your own cloud account VPC. Managed by your cloud team alongside ClearConsent support. Full data sovereignty — we never touch your environment without permission.

💼 Best for: IT companies, large enterprise
🔒 Air-gap: Not required
📦 Data boundary: 100% client cloud account
🛠️
Managed Private

Operated by ClearConsent

Your cloud account, managed by our operations team. No internal DevOps required. Data never moves to ClearConsent infrastructure — your account, your keys, our expertise.

🏗️ Best for: Mid-size without internal DevOps
🔒 Air-gap: Not available
📦 Data boundary: 100% client-owned account

Only a quarterly 500-byte license ping leaves your network — no telemetry, no PII outbound.

How It Works

From setup to governance in 3 phases.

No six-month implementations. No consultancy fees for basic setup. ClearConsent is designed to go live fast.

1

Discover

Map all personal data touchpoints across your technology stack, third-party vendors, and internal processes. Know exactly what you're processing and where within days of onboarding.

2

Configure

Deploy DPDPA-compliant consent journeys, rights request workflows, and breach protocols — all pre-built to Indian law and customisable to your organisation's specific needs.

3

Govern

Monitor processing activities with real-time dashboards, automated audit trails, and proactive alerts — so compliance is continuous, not a once-a-year scramble before an audit.

Industries

Built for India's regulated sectors.

Any organisation that processes personal data of Indian citizens needs DPDPA compliance. We've designed for the most complex ones first.

🏦 BFSI & Fintech
🏥 Healthcare & Pharma
🛍️ E-Commerce & Retail
🎓 EdTech & Education
👥 HR & Staffing
💻 IT & SaaS Platforms
📡 Telecom & Media
🏭 Manufacturing
🏛️ Government & PSUs
🌐 Any Data Fiduciary

See the platform in action.

Book a personalised demo and we'll walk you through the modules most relevant to your organisation.