Solutions

Consent Management

Consent Management

The full consent lifecycle, in all 22 scheduled languages, provably propagated.

The full lifecycle

CaptureReceiptRenewalWithdrawal

Built on

MeitY’s Business Requirement Document for a full-stack consent protocol, covering every touchpoint your organisation collects from.

MeitY’s Business Requirement Document for a full-stack consent protocol, covering every touchpoint your organisation collects from.

In every language

All 22 scheduled languages, with each record tied to the language the consent was actually given in.

All 22 scheduled languages, with each record tied to the language the consent was actually given in.

Provable by

Hash-linked consent receipts and HMAC-SHA256 signed webhooks with replay protection, so withdrawal is verifiable and not just logged.

Hash-linked consent receipts and HMAC-SHA256 signed webhooks with replay protection, so withdrawal is verifiable and not just logged.

Data privacy & consent×
YOUR LOGO & COLOURS HERE
Sign-up notice
Version 3.0
Your consent status
Promotional MessagingActive
Data: name, mobile, email
Retention: 730 days
Since: 24 Jul 2026  ·  Expires: 23 Jul 2028
Withdraw
Personalised RecommendationsActive
Data: name, mobile, email
Retention: 365 days
Since: 24 Jul 2026  ·  Expires: 24 Jul 2027
Withdraw

Shown with placeholder branding. Once the platform is integrated with your systems, every notice, colour and mark carries your identity, not ours.

The problem

What it costs to run consent on spreadsheets and cookie banners

What it costs to run consent on spreadsheets and cookie banners

What it costs to run consent on spreadsheets and cookie banners

No proof

Organisations relying on manual logs or bolt-on cookie banners have no reliable way to prove, to a regulator or to a Data Principal, what was consented to and when. A screenshot or a database export is not evidence.

Organisations relying on manual logs or bolt-on cookie banners have no reliable way to prove, to a regulator or to a Data Principal, what was consented to and when. A screenshot or a database export is not evidence.

One bundled yes

Consent is usually captured as one bundled yes or no. When purposes aren’t separated, a withdrawal from marketing can’t be distinguished from a withdrawal of service-essential processing, so teams either over-withdraw or ignore the request.

Consent is usually captured as one bundled yes or no. When purposes aren’t separated, a withdrawal from marketing can’t be distinguished from a withdrawal of service-essential processing, so teams either over-withdraw or ignore the request.

Stops at the edge

Even where consent is withdrawn correctly, it often never reaches every downstream system, vendor or processor that received the data, leaving the organisation exposed long after the individual believes they’ve opted out.

Even where consent is withdrawn correctly, it often never reaches every downstream system, vendor or processor that received the data, leaving the organisation exposed long after the individual believes they’ve opted out.

Two systems, two teams

Consent records and grievance logs typically sit in separate tools maintained by separate teams, so a complaint about unwanted processing can’t be resolved against the actual consent history without a manual hunt across systems.

Consent records and grievance logs typically sit in separate tools maintained by separate teams, so a complaint about unwanted processing can’t be resolved against the actual consent history without a manual hunt across systems.

Built into the platform

Speaks the language your user signed up in

Speaks the language your user signed up in

Consent notices switch instantly across all 22 scheduled Indian languages, with the record itself tied to the language it was given in.

Consent01 / 22
+10

One record, not two systems

One record, not two systems

Consent Management runs on the same platform as DPR Management, so grievances are logged and tracked against the same consent history, not reconciled after the fact.

Consent
Grievance
REC-4471one shared record

A chain the regulator can verify

A chain the regulator can verify

Every consent event is hash-linked to the one before it: a cryptographically chained trail that stands as verifiable proof, not just a log entry.

a1f9
7bc2
e40d
CHAIN INTACT· 1240 events

How IndiSec solves it

How IndiSec solves it

How IndiSec solves it

No pre-ticked consent. Consent defaults to off, everywhere

No pre-ticked consent. Consent defaults to off, everywhere

No pre-ticked consent. Consent defaults to off, everywhere

Every consent point ships unchecked by default. No pre-ticked boxes, no bundled opt-ins. A Data Principal has to actively switch each one on.

Every consent point ships unchecked by default. No pre-ticked boxes, no bundled opt-ins. A Data Principal has to actively switch each one on.

Every switch loads off. Try one.
Withdrawing one does not touch the others.

Purpose-level granularity. Consent, purpose by purpose

Purpose-level granularity. Consent, purpose by purpose

Purpose-level granularity. Consent, purpose by purpose

Data Principals consent to each purpose (marketing, analytics, service delivery) separately, not as one bundled toggle.

Data Principals consent to each purpose (marketing, analytics, service delivery) separately, not as one bundled toggle.

Withdrawal, propagated and provable

Withdrawal, propagated and provable

Withdrawal, propagated and provable

Withdrawals propagate downstream via HMAC-SHA256 signed webhooks with replay protection, so acknowledgement isn’t just logged, it’s cryptographically verifiable.

Withdrawals propagate downstream via HMAC-SHA256 signed webhooks with replay protection, so acknowledgement isn’t just logged, it’s cryptographically verifiable.

Withdrawal requestedHMAC 9f3c8a · nonce ok
Promotional Messaging19:12:04 IST
CRM200 · 38ms
Email platform200 · 61ms
Data warehouse200 · 92ms
Ad network200 · 154ms
4/4 acknowledgedreceipt cn-8842 · chain verified
Promotional messagingActive ✓
Personalised recommendationsActive ✓
AnalyticsWithdrawn
Hover a row to withdraw it.

A consent dashboard, visible to the people it belongs to

A consent dashboard, visible to the people it belongs to

A consent dashboard, visible to the people it belongs to

Once integrated with your existing systems, Data Principals get a direct view into their own consent history, reviewable and revocable.

Once integrated with your existing systems, Data Principals get a direct view into their own consent history, reviewable and revocable.

See where your consent flows actually break

See where your consent flows actually break

See where your consent flows actually break

A scored view of where consent is captured, where it is still bundled, and where withdrawal stops short of the systems that hold the data.

A scored view of where consent is captured, where it is still bundled, and where withdrawal stops short of the systems that hold the data.