DPDP consent management that can prove the banner matches the code.

A consent management platform built for Data Fiduciaries under India's DPDP Act: notice, purpose-specific consent, withdrawal, records and rights requests. And one thing no other CMP has: a scanner that checks the banner against what your application and your live site actually collect.

01 · What the Act asks

Three sections, each one a control in the banner.

§5 · NOTICE

Before or with the request for consent, an itemised notice: which personal data, for which purposes, how to exercise rights and how to complain to the Board. The banner's View notice shows exactly that, versioned, in the visitor's language.

§6(1) · SPECIFIC CONSENT

Free, specific, informed, unconditional and unambiguous, by clear affirmative action, limited to the stated purpose. Nothing is pre-ticked except what is strictly necessary; each purpose is its own choice.

§6(4) · WITHDRAW AS EASILY

Withdrawal must be as easy as giving consent. A persistent preferences control on every page, Reject styled with the same prominence as Accept, and a withdrawal that is recorded, not just hidden.

02 · The record

A banner is not consent. The record is.

HASH-CHAINED RECORDS

Every decision becomes an immutable record linked to the previous one by a proof hash. Change one row and the chain breaks at that row; the console verifies the whole chain on demand.

A RECEIPT PER DECISION

A structured consent receipt for each record (ISO/IEC TS 27560:2023 structure), emailed to identified principals if you choose, and fetchable from the console for any record.

THE NOTICE THEY SAW

Each record names the notice version and language the person actually read. Publish a new notice and every visitor is re-prompted; switching language is not a new consent.

EVIDENCE PACK

Records, notice versions, purposes, chain verification and the coverage score in one exportable attestation for an auditor or the Board.

03 · What a CMP cannot do

Does the banner cover what the code collects? Do the tags obey it?

COVERAGE AGAINST THE CODE

Scrutora's scanner already knows which personal data the application collects. The coverage check maps each data element to the purpose that would cover it and scores the banner against it, with the gaps listed.

PROVEN ON THE LIVE SITE

The runtime monitor loads your page headless before consent, after Reject-All and after Accept-All, and lists every tracker that fired, including tags managed in a tag-manager container that never appear in your repository. Weekly, on a schedule.

HONOURED IN THE BACKEND

Before a marketing email is sent or a record is shared, your server asks one endpoint for the person's current consent. Cookie blocking is table stakes; this is enforcement.

04 · Operate

Languages, rights requests and a designer, without a project.

NINE INDIAN LANGUAGES

Hindi, Marathi, Gujarati, Tamil, Kannada, Telugu, Bengali, Malayalam and Punjabi, plus English and seven others, with an in-banner switcher that follows the browser language by default. Purpose names and your own copy translate per language.

RIGHTS QUEUE WITH A CLOCK

Access, correction, erasure, withdrawal and grievance requests land in one queue with identity verification, an SLA timer and signed webhooks. Fulfilling an erasure actually scrubs the identifier.

DESIGNED, NOT DEFAULT

Layout, colours, buttons, typography and logo set from a live designer, validated so a value can never break your page. It still passes the accessibility bar: dialog semantics, keyboard, labelled controls.

One script tag on your site. Everything else, purposes, notices, languages, design, webhooks and the evidence pack, is configured in the console. Included in Professional and Enterprise plans.

See the consent productIntegration guideDPDPA for engineering teams