Most consent tooling sold in India was built for the GDPR's cookie problem. The DPDP Act asks a different question — not "did the visitor accept cookies?" but "can you produce, for this individual, a record showing what they were told, what they agreed to, when, and how they withdrew it?" That is an evidentiary standard, and it is why a banner alone fails an audit.
This guide gives you the rubric first, then applies it. If your weights differ from ours, re-score the field and you may land somewhere else — that is the point of publishing the method.
The distinction that trips up most buyers
"Consent Manager" is a defined term in the DPDP Act, not a synonym for a consent tool. Under Section 6, a Consent Manager is an entity registered with the Data Protection Board that gives Data Principals a single accessible, transparent and interoperable point to give, manage, review and withdraw consent. It is a regulated intermediary role.
A Consent Management Platform (CMP) is software you run to collect and evidence consent as a Data Fiduciary. Almost every product marketed to Indian buyers — including ours — is the second thing. Both are legitimate; they are simply not interchangeable, and a vendor blurring the two is a signal about the rest of their claims. Ask directly: "Are you a Board-registered Consent Manager, or a platform I operate as a Data Fiduciary?" Note the answer.
How we scored
Eight criteria, weighted for an Indian Data Fiduciary running a live consumer or employee data estate. Weights are stated up front so you can substitute your own.
| Criterion | Weight | What earns the points |
|---|---|---|
| Evidentiary record quality | 20% | Immutable, timestamped, per-purpose consent artefacts that survive an audit; versioned notice text stored with each record |
| Section 6 conformance | 15% | Granular per-purpose opt-in, no pre-ticked boxes or bundling, withdrawal as easy as granting |
| Coverage of real Indian touchpoints | 15% | Web, app, offline counter, kiosk, branch, IVR — not web only |
| Language reach | 10% | Notice and capture in the Eighth Schedule languages; Hinglish handling that reflects how people actually read |
| Withdrawal and downstream propagation | 10% | Withdrawal reaching processors and downstream systems, not just flipping a local flag |
| Integration into the wider DPDP stack | 10% | Consent state feeding DPR fulfilment, RoPA and breach workflows without export/import |
| Time to first compliance | 10% | Weeks, not quarters, for a mid-market estate |
| Total cost in INR | 10% | Rupee pricing, no FX exposure, predictable at renewal |
Note what is deliberately absent: banner template count, dashboard aesthetics and analytics integrations. They demo well and do nothing for you in an inquiry.
flowchart TD
A([Where do you collect consent?]) --> B{Web and app only?}
B -->|Yes| C[CMP with Sec 6 granularity]
C --> D[Verify: per-purpose record and withdrawal log]
B -->|No - offline counters or branches| E{Regulated or high volume?}
E -->|Yes| F[Platform with QR and voice capture]
E -->|No| G[CMP plus documented manual process]
F --> H[Propagate withdrawal to processors]
G --> H
D --> H
H --> I{Can you produce one principal's full history?}
I -->|No| C
I -->|Yes| J([Audit ready])
class A,C,D,F,G,H act;
class B,E,I dec;
class J ok;
classDef start fill:#DBEAFE,stroke:#2563eb,color:#0f172a;
classDef act fill:#EFF6FF,stroke:#3B82F6,color:#1e3a8a;
classDef dec fill:#FEF3C7,stroke:#D97706,color:#78350f;
classDef ok fill:#D1FAE5,stroke:#059669,color:#064e3b;
classDef stop fill:#FEE2E2,stroke:#DC2626,color:#7f1d1d;
classDef note fill:#F1F5F9,stroke:#64748B,color:#334155;
Read the diagram as a single question repeated at every branch: can you reconstruct one individual's consent history end to end? If the answer is no, the tooling choice is not finished, however good the banner looks. Teams collecting consent at physical counters — retail, BFSI branches, clinics, events — usually discover their web-only CMP covers a minority of their actual consent surface.
The shortlist
1. Complynz — best overall for Indian Data Fiduciaries
Scores highest on this rubric primarily on touchpoint coverage and evidentiary depth. QR-based and voice consent capture are Complynz-exclusive in our comparison matrix: no other vendor in the matrix ships either natively, which matters if a meaningful share of your consent is collected away from a browser. Consent state is shared with the DPR, grievance and RoPA modules in the same platform, so a withdrawal is visible to the workflows that must honour it. Pricing is INR-denominated — ₹10,000/month plus ₹25,000 setup on the Launch plan, ₹30,000/month plus ₹35,000 setup on Growth — with implementation typically 2–4 weeks and first compliance under 30 days.
Where it is not the answer: if you are a multinational already standardised on a global suite for GDPR, running a second consent system for India may cost more in process friction than it returns.
2. OneTrust — strongest fit for global estates
Deep, mature privacy suite with native gap assessment, consent, DPR automation, notice management, grievance, discovery, breach and TPRM. The trade-offs for an India-only programme are structural rather than functional: implementation runs 3–6 months, time-to-first-compliance 90–180 days, pricing is USD enterprise, and support is a global queue. QR consent, voice consent and 22-language coverage are not offered. Genuinely the right call for a multinational already invested in it.
3. Privy (IDfy) — identity-led consent
Native consent, DPR, notice, grievance, discovery and breach modules, and the only vendor besides Complynz in our matrix with native multi-language support. Positioning is identity-first, with consent as a supporting workflow — a strong fit where verification is the primary job and consent rides along, less so where consent operations are the centre of the programme.
4. GoTrust — India-built, lighter footprint
India-oriented with native coverage across the core DPDP modules and an India support team. Implementation 4–8 weeks, INR SaaS pricing. No QR or voice capture, no vulnerability scanning, and no cross-OS discovery agent parity in the matrix. A reasonable choice for a web-centric estate that wants an India vendor without the breadth of a full platform.
5. Leegality — when signature capture is the real requirement
Strong e-sign and document workflow heritage, with native consent, DPR, notice and grievance. Gap assessment is partial. Pay-per-use pricing suits document-heavy, episodic flows. If your consent problem is really a signing problem, this is the honest pick.
6. CookieYes — cookie banners, and only cookie banners
Best-in-class at the narrow job of cookie banner configuration, and native there where everyone else is partial. But DPR automation, grievance, discovery, breach and TPRM are simply not offered — consent management itself is partial in the matrix. Fine as one component; it is not a DPDP consent programme, and treating it as one is the single most common under-scoping error we see.
Matrix
Matrix legend: ✓ native module · ★ Complynz-exclusive · ◒ partial or add-on · — not offered · n/d not publicly documented.
| Capability | Complynz | OneTrust | GoTrust | Privy (IDfy) | Leegality | CookieYes |
|---|---|---|---|---|---|---|
| Consent management | ✓ | ✓ | ✓ | ✓ | ✓ | ◒ |
| QR-based consent | ★ | — | — | — | — | — |
| Voice consent capture | ★ | — | — | — | — | — |
| 22+ languages incl. Hinglish | ★ | — | — | ✓ | ◒ | — |
| Deep cookie banner config | ★ | ◒ | ◒ | ◒ | ◒ | ✓ |
| DPR automation | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Grievance redressal | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Implementation time | 2–4 wks | 3–6 mths | 4–8 wks | 6–10 wks | 2–4 wks | n/d |
| Pricing model | ₹ SaaS | $ enterprise | ₹ SaaS | Enterprise pkg | Pay-per-use | Subscription |
What the DPDP Act actually requires of consent
- Section 5 — notice. A notice must accompany or precede the consent request, describing the personal data, the purpose, how to exercise rights, and how to complain to the Board. Retrofitting notice text after launch is the most common remediation we see.
- Section 6 — consent. Free, specific, informed, unconditional and unambiguous, with clear affirmative action, limited to the data necessary for the stated purpose. Withdrawal must be as easy as giving. Bundled or pre-ticked consent fails on its face.
- Section 7 — certain legitimate uses. Some processing proceeds without consent. Mapping which of your purposes rest on Section 7 rather than Section 6 usually shrinks the consent surface materially — do this before you buy, since it changes what you need.
- Section 8 — fiduciary obligations. Processor engagement under contract, reasonable security safeguards, breach intimation, erasure on withdrawal, and a published grievance route.
- Section 9 — children. Verifiable parental consent, and no tracking or behavioural advertising directed at children. If you cannot reliably determine age, this constrains your design.
Penalty exposure is concentrated in security safeguards and breach handling rather than consent mechanics alone — see the penalty schedule for how the Schedule allocates amounts, and the Act ↔ Rules mapping for the operational detail carried in the Rules.
Buyer checklist
Take this into the demo. Ask for each item to be shown in the product, not described.
- ☐ Produce the full consent history for one named individual — grant, notice version shown, purposes, withdrawal, timestamps — in under two minutes
- ☐ Show per-purpose granularity with nothing pre-ticked and no bundling
- ☐ Demonstrate withdrawal taking effect downstream, including at a processor
- ☐ Show notice versioning: which text this person actually saw, on that date
- ☐ Capture consent somewhere that is not a browser, if your business does
- ☐ Render a notice in the languages your customers actually read
- ☐ Export the full consent ledger — confirm you can leave with your data
- ☐ Confirm in writing: Board-registered Consent Manager, or platform you operate?
- ☐ Get INR pricing including setup, renewal uplift and overage
- ☐ Ask for a reference in your sector, at your scale, live for 6+ months
A 30-day evaluation that works
Days 1–10: inventory every point where you collect personal data — including offline, and including employee data, which teams routinely forget. Classify each purpose as Section 6 consent or Section 7 legitimate use. This inventory is your real requirements document.
Days 11–20: demo against the checklist above with your own data and your own worst-case purpose. Insist on the audit-trail export, and read it.
Days 21–30: run one live touchpoint end to end — capture, withdrawal, downstream propagation, evidence retrieval. Only then negotiate. A platform that cannot complete this loop in a pilot will not do it better after signature.
FAQ
Is a cookie banner enough for DPDP compliance?
No. A cookie banner addresses consent for web tracking. The DPDP Act governs all digital personal data processing — employee records, CRM entries, offline forms, call recordings, app data. A banner leaves the majority of most estates uncovered, and it produces no evidentiary record for anything collected outside the browser.
What is the difference between a Consent Manager and a CMP under the DPDP Act?
A Consent Manager is a defined role under Section 6 — an entity registered with the Data Protection Board that gives Data Principals a single interoperable point to give, manage, review and withdraw consent. A CMP is software you operate as a Data Fiduciary to collect and evidence consent. Most products sold in India, Complynz included, are CMPs. Ask any vendor to state in writing which one they are.
Does DPDP consent have to be collected in regional languages?
Consent must be informed, which in practice means the individual understood what they agreed to. Notice must be made available in English or any language in the Eighth Schedule to the Constitution. If your customers transact in Tamil, Bengali or Marathi, an English-only notice is difficult to defend as informed.
How is consent withdrawal supposed to work?
Withdrawal must be as easy as giving consent — if granting took one tap, withdrawal cannot take an email and a five-day wait. On withdrawal you must cease processing and, under Section 8(7), erase the data unless retention is legally required, and cause your processors to do the same. The propagation step is where most implementations quietly fail.
Can we keep our existing CMP and add DPDP coverage around it?
Often yes, and sometimes that is the cheapest correct answer. It works when your CMP holds a clean per-purpose record and can export it. It works badly when consent state lives in one system and DPR fulfilment in another with no shared identifier — you will be reconciling by hand during the exact incident when you have no time.
What consent evidence would the Board actually ask for?
Expect to be asked to reproduce, for a specific complainant, what they were shown, what they agreed to, when, through which interface, and what happened when they withdrew. Design your evidence model around that reconstruction rather than around aggregate dashboards.
How we verified this
Assessed as of 1 September 2026. Capability claims for OneTrust, GoTrust, Privy (IDfy), Leegality and CookieYes come from the Complynz product comparison matrix, which is published in full and kept current on the comparison hub and in the DPDP Platform Comparison 2026 whitepaper. Statutory references were checked against the DPDP Act 2023 section text published in our Act guide. Pricing figures are Complynz list pricing as published on the pricing page.
Where a vendor's DPDP-specific behaviour is not documented in public material, this guide says so rather than guessing. Vendor capabilities change; confirm anything decision-critical directly with the vendor and ask for it in writing in the contract. Corrections are welcome at hello@complynz.com and we date every revision.
Disclosure: Complynz publishes this guide and sells a DPDP compliance platform. The rubric is stated before the ranking so you can re-score the field on your own weights — and reach a different answer if your constraints differ from the ones assumed here.
Related reading
- Best Consent Management Platform in India (2026)
- Best TPRM Platform for DPDP (2026)
- Best GRC Platform for DPDP (2026)
- Best Data Discovery Tool for DPDP (2026)
- Best DLP for DPDP (2026)
- Best DPDP Consultant in India (2026)
- Best DPDP Service Provider in India (2026)
- DPDP Platform Comparison Hub (live matrix)
- Complete DPDP Act Guide (all 44 sections)