Skip to content
FaceOff Technologies

Data Privacy · Module 01

Consent Management

Obtain, record and manage explicit permission for every processing purpose — across every channel, in every jurisdiction, from a single record of truth.

Platform capabilities

  • Purpose-level consent ledger
  • Multi-language notice engine
  • Real-time enforcement API

Primary DPDP sectionsSec. 5, 6, 9

Notice languages served

23

Notice languages served

Consent check at query time

< 1s

Consent check at query time

Purposes with a receipt

100%

Purposes with a receipt

Blanket consents possible

0

Blanket consents possible

Figures illustrative.

How it works

Consent Management, end to end

Consent captured on any channel — digital, assisted or paper — flows through one engine, is written to an append-only ledger, and propagates downstream in real time. Every consumer returns an acknowledgement.

Capture channels

  • Web & banner

  • Mobile SDK

  • API / server

  • Agent · IVR · branch

  • Paper · thumb impression

    Digitised at ingestion

Privacy engine

  1. Gateway
  2. Normalize
  3. Policy & purpose
  4. Consent ledger
  5. Event publisher

Downstream consumers

  • CRM / MDM

    ack ↩

  • Analytics / BI

    ack ↩

  • Processors & vendors

    ack ↩

  • Data warehouse

    ack ↩

  • Ad / martech

    ack ↩

Sentinel trail — append-only proof of notice, choice, policy version and every downstream acknowledgement.

Capability

What Consent Management does

Transparency & communication

Plain-language notice at the point of collection, plus a self-service centre where an individual can see and change every consent given.

  • Notice templates versioned per purpose
  • 22 Eighth Schedule languages plus English
  • Every notice served is replayable
  • Preference centre in any channel

Granular consent & control

Purpose-level opt-in rather than a single blanket toggle — and withdrawal made exactly as easy as the original consent.

  • Consent object scoped to one purpose
  • Affirmative capture with timestamp
  • Consent bound to the notice version shown
  • One-click withdrawal, parity enforced

Automated & centralised management

One consent store, updated in real time, that every downstream system must query before it processes.

  • Real-time consent API at query time
  • Event fan-out to processors on change
  • Consent Manager-ready interoperability
  • Age-band gating and guardian flows

Outcome

Consent that is not merely recorded but enforced — every downstream system checks before it processes, and withdrawal actually stops the processing.

DPDP alignment

Consent Management — section by section

What the Digital Personal Data Protection Act, 2023 requires, and the control that satisfies it.

SectionWhat the Act requiresHow the product satisfies it
Sec. 5Itemised notice describing the personal data, the purpose, how to exercise rights and how to complain to the Board — in English or any Eighth Schedule language.A templated notice engine renders per purpose, versioned and localised into all 22 scheduled languages. Every notice served is stored and replayable against the Principal who saw it.
Sec. 6(1)Consent must be free, specific, informed, unconditional and unambiguous, by clear affirmative action, limited to data necessary for the specified purpose.Consent is captured as a purpose-scoped object with an affirmative-action event, an immutable timestamp and a binding to the exact notice version displayed. Blanket consent is structurally impossible.
Sec. 6(4)–(6)Withdrawal must be as easy as giving. Processing must cease within a reasonable time, and processors must be made to cease too.One-click withdrawal with click-parity enforced against the give-flow. Revocation fans out to every processor that inherited the consent; cessation is tracked to an SLA and evidenced.
Sec. 6(7)–(9)A Consent Manager registered with the Board must give the Principal an accessible, transparent and interoperable platform to manage consent.Consent artefacts are emitted in an interoperable format with Consent Manager-ready APIs, so registration and integration are configuration rather than a rebuild.
Sec. 9Verifiable parental consent for children and persons with a guardian; no tracking or behavioural advertising directed at children.Age-band assurance gates the flow into a guardian consent path, and a child flag suppresses tracking and behavioural advertising downstream automatically.

Exposure avoided

Sec. 9 failures carry up to ₹200 Cr under the Schedule. Consent defects also invalidate the lawful basis for every downstream processing activity — one control gap becomes estate-wide exposure.

Solutions by industry

Where Consent Management lands first

The sectors carrying the most DPDP exposure for this control, each with its own threat model and regulators.

See it running against your estate.

A DPDP readiness walkthrough maps your obligations to the controls that already exist, and names the gaps that do not.