Compliance is not the product.Evidence of compliance is.
Any tool can record a consent. The hard part is proving, on demand, that a specific consent was validly obtained, for a specific purpose, at a specific time, and honoured throughout its life. Sec 6(10) puts that burden of proof on the Data Fiduciary. TruPriv exists to discharge it.
Privacy you can prove.
Data protection law is territorial.
A platform designed around one statute carries that statute's assumptions in its data model, its vocabulary and its defaults.
India wrote its own.
The Digital Personal Data Protection Act, 2023, and the DPDP Rules, 2025. Not a translation of anything, and not a dialect of the GDPR.
TruPriv was built here.
Consent-centric processing, the Consent Manager construct, notice in Eighth Schedule languages, and a burden of proof that sits on the Data Fiduciary.
An outline of India, marking the territory the DPDP Act, 2023 applies to. It is a stylised emblem rather than a survey map and is not to scale.
Every consent becomes a record that cannot be quietly rewritten.
An artefact carries who consented, to which purposes, when, by what method, under which notice version and in which language, with a signature over all of it. Change anything and you get a new version; the old one stays retrievable.
Each write is hashed and chained to the one before it, so a record cannot be altered after the fact without breaking the chain. That is what makes the log evidence rather than a list. Sec 6(10)
- Versioned
- Never overwritten
- Chained
- Hash links every write
- Exportable
- As a file, on demand
- Attributable
- Notice version and language
- principal_id
- dp_9f2c41ab
- purpose_ids
- billing.invoice · support.contact
- timestamp
- 2027-05-14T11:04:19+05:30
- capture_method
- web · affirmative · default-deny
- notice_version
- v4.2 · en-IN, hi-IN, ta-IN
- signature
- sha256:8b41…c7d0
Prior versions remain retrievable. Every write is hash-chained to the one before it.
Before any processing act, the gate is asked four questions.
The Data Fiduciary calls the validation API before it processes. If any one of the four conditions fails, the gate refuses and the processing does not happen. It fails closed: silence is a refusal, not an approval. Sec 6(10)
Flip any condition to see what the gate does. This is an illustration of the specified behaviour, not a live API.
Four modules, one platform. Each one also runs standalone.
Start with the module where you are most exposed. Onboarding data is shared across the suite, so adding the next one is configuration rather than a fresh implementation.
Consent Management
The full consent lifecycle: capture, validation, update, renewal, withdrawal and expiry. Plus Data Principal rights, grievance redressal and a policy engine.
Open Consent ManagementScroll, drag or use arrow keys · Enter opens
- Module 01Consent ManagementThe full consent lifecycle: capture, validation, update, renewal, withdrawal and expiry. Plus Data Principal rights, grievance redressal and a policy engine.
- Module 02Cookie ManagementScans your site for every cookie and tracker at source, categorises them, and blocks non-essential scripts until consent is given.
- Module 03Data GovernanceDiscovery, classification and mapping of personal data across databases, applications and platforms, with a visual record of processing activities.
- Module 04Privacy GovernanceDPIAs linked to real processing activities, a third-party register with risk scoring, and incident management with notification assessment.
Built for the DPDP Act, not adapted from the GDPR.
A platform designed around a different statute carries that statute's assumptions. The DPDP Act's notice requirements, its Eighth Schedule language obligations, its Consent Manager architecture and its burden of proof are specific, and a retrofit shows.
Even companies that have bought a global privacy platform have not solved consent.
- Notice in Eighth Schedule languages
- Served in English plus Eighth Schedule languages, with the language shown recorded on the artefact. Sec 5(1).
- Withdrawal as easy as giving
- Real-time halt, downstream processors instructed to cease, and an acknowledgement required back from each of them. Sec 6(4).
- Burden of proof discharged
- Every action writes to a tamper-evident, immutable audit log with cryptographic hashing. Sec 6(10).
- No per-language fees
- Annual contracts, and every Eighth Schedule language is included in every tier. Serving more of them should not cost you more.
Six places to go from here.
Move sideways along the rail, then select a plinth to enter.
The substantive obligations come into force on 13 May 2027.
The Rules were notified and the Data Protection Board was constituted on 13 November 2025. Penalties of up to ₹250 crore attach to a failure to take reasonable security safeguards. Sec 8(5)
Read the DPDP hubFive foundational places are open. Partners shape the roadmap, get the founders on their implementation, and keep preferential terms into general availability.
