- How do I compare DPDP compliance platforms?
- Compare on enforcement rather than features. Ask whether downstream systems must check consent before processing, whether discovery reaches unstructured sources, whether the audit trail is generated by running the controls or assembled on request, and whether the modules share one catalogue or integrate with each other. A feature checklist will not separate vendors; those four questions will.
- What is the difference between a Consent Manager and a Consent Management Platform?
- A Consent Manager is an entity registered with the Data Protection Board that gives a Data Principal one interoperable place to manage consent across many Data Fiduciaries, and carries a minimum net-worth requirement. A Consent Management Platform is the software an organisation runs internally to capture, enforce and evidence consent on its own channels. You deploy a CMP; you register as, or integrate with, a Consent Manager.
- Do we need a separate tool for cookies and for consent?
- No, and separating them is usually the cause of the defect. Cookie consent is one capture channel for the same purpose-scoped consent object. When the banner keeps its own store, the preference a visitor sets there never reaches the systems that process their data.
- How long does a DPDP compliance programme take?
- Typically nine to twelve months from gap assessment to audit readiness for an enterprise. The sequence matters more than the duration: discovery first, because every other obligation is undeliverable without a catalogue, then masking and breach detection because they carry the largest penalty exposure, then consent, then rights and audit.