Skip to content
TruPriv
DPDP Act, 2023 · DPDP Rules, 2025

Compliance is not the product.Evidence of compliance is.

Any tool can record a consent. The hard part is proving, on demand, that a specific consent was validly obtained, for a specific purpose, at a specific time, and honoured throughout its life. Sec 6(10) puts that burden of proof on the Data Fiduciary. TruPriv exists to discharge it.

Privacy you can prove.

Where the law applies

Data protection law is territorial.

A platform designed around one statute carries that statute's assumptions in its data model, its vocabulary and its defaults.

India wrote its own.

The Digital Personal Data Protection Act, 2023, and the DPDP Rules, 2025. Not a translation of anything, and not a dialect of the GDPR.

TruPriv was built here.

Consent-centric processing, the Consent Manager construct, notice in Eighth Schedule languages, and a burden of proof that sits on the Data Fiduciary.

Act 22 of 2023Jurisdiction of the Data Protection Board

An outline of India, marking the territory the DPDP Act, 2023 applies to. It is a stylised emblem rather than a survey map and is not to scale.

The object

Every consent becomes a record that cannot be quietly rewritten.

An artefact carries who consented, to which purposes, when, by what method, under which notice version and in which language, with a signature over all of it. Change anything and you get a new version; the old one stays retrievable.

Each write is hashed and chained to the one before it, so a record cannot be altered after the fact without breaking the chain. That is what makes the log evidence rather than a list. Sec 6(10)

Versioned
Never overwritten
Chained
Hash links every write
Exportable
As a file, on demand
Attributable
Notice version and language
Consent artefactv3 · current
principal_id
dp_9f2c41ab
purpose_ids
billing.invoice · support.contact
timestamp
2027-05-14T11:04:19+05:30
capture_method
web · affirmative · default-deny
notice_version
v4.2 · en-IN, hi-IN, ta-IN
signature
sha256:8b41…c7d0

Prior versions remain retrievable. Every write is hash-chained to the one before it.

The validation gate

Before any processing act, the gate is asked four questions.

The Data Fiduciary calls the validation API before it processes. If any one of the four conditions fails, the gate refuses and the processing does not happen. It fails closed: silence is a refusal, not an approval. Sec 6(10)

Flip any condition to see what the gate does. This is an illustration of the specified behaviour, not a live API.

Processing request
Exists✓ Pass
Active✓ Pass
Not expired✓ Pass
In scope✓ Pass
✓ Processing permitted
Permitted · processing may proceed
audit_entry.sha256 = computing…
The platform

Four modules, one platform. Each one also runs standalone.

Start with the module where you are most exposed. Onboarding data is shared across the suite, so adding the next one is configuration rather than a fresh implementation.

Why India-native

Built for the DPDP Act, not adapted from the GDPR.

A platform designed around a different statute carries that statute's assumptions. The DPDP Act's notice requirements, its Eighth Schedule language obligations, its Consent Manager architecture and its burden of proof are specific, and a retrofit shows.

Even companies that have bought a global privacy platform have not solved consent.

Notice in Eighth Schedule languages
Served in English plus Eighth Schedule languages, with the language shown recorded on the artefact. Sec 5(1).
Withdrawal as easy as giving
Real-time halt, downstream processors instructed to cease, and an acknowledgement required back from each of them. Sec 6(4).
Burden of proof discharged
Every action writes to a tamper-evident, immutable audit log with cryptographic hashing. Sec 6(10).
No per-language fees
Annual contracts, and every Eighth Schedule language is included in every tier. Serving more of them should not cost you more.

The substantive obligations come into force on 13 May 2027.

The Rules were notified and the Data Protection Board was constituted on 13 November 2025. Penalties of up to ₹250 crore attach to a failure to take reasonable security safeguards. Sec 8(5)

Read the DPDP hub
Time to full enforcement ·
--Days
--Hours
--Minutes
--Seconds
Early Access Partner Programme

Five foundational places are open. Partners shape the roadmap, get the founders on their implementation, and keep preferential terms into general availability.