DPDP Rules 2025 in force, consent, RoPA & DPIA obligations active Enforcement: 13 May 2027 Deep discovery across every app on your site, Scan my site DPDP Rules 2025 in force, consent, RoPA & DPIA obligations active Enforcement: 13 May 2027 Deep discovery across every app on your site, Scan my site

DPDP Act 2023 · Discovery-first compliance

See what's actually on your site.

Generic scanners map the obvious. We do deep, platform-native discovery, auto-detecting the ~130 apps really running on your site, then finding PII by content, not column names, so Aadhaar & PAN are caught and flagged §9 sensitive, building an evidence-backed RoPA and capturing consent at the source.

SCANNING · deep discovery in progress 0 found
  • Membersemail, phonePII
  • Checkout formsaadhaar_no§9 SENSITIVE
  • Contacts CRMpan_number§9 SENSITIVE
  • Stores / Ordersbilling_addressPII
  • Google Analyticsclient_idTRACKER · gated
  • Bookingscustomer_namePII
Mapped to purposes · consent required at each collection point
Reality check

Does the DPDP Act apply to you?

13 May 2027 Obligations expected to bite. Start early.
₹250 cr Maximum penalty for non-compliance.
Consent Now required at every point you collect data.

If your site collects personal data (sign-ups, orders, forms, bookings) the Act applies. Here’s how we make it zero-touch.

See it find your dataWatch discovery detect PII & §9-sensitive fields, by content Built for your industryBFSI, hospitals, pharma, education, e-commerce, retail The 6 steps, done for youDiscover → classify → record → consent → rights → prove

Built for regulated industries

  • Banking & Fintech
  • Healthcare
  • SaaS
  • Ecommerce
  • Travel
  • Logistics
  • Telecom
  • Education

Regulation coverage

DPDP 2023, ready today GDPR, on the roadmap HIPAA, on the roadmap

One discovery engine, multiple frameworks. We ship DPDP first; GDPR and HIPAA are next.

Generic discovery guesses. We have the evidence.

Most compliance tools scan generic data sources and name-match columns. DPDPA.support is built into the platform your data actually lives in, so it sees the long-tail others miss, and proves what it finds.

Platform-native deep discovery

We auto-detect the ~130 apps really installed on a site, the true processing long-tail, not just the generic data sources a bolt-on scanner can reach.

PII found by content, not guesswork

We read the actual data to identify PII by content, not by column name, including India-specific Aadhaar and PAN, flagged as §9 sensitive. Evidence you can defend, not a guess.

One catalog, whole-estate scale

Every source maps into one living data catalog, so assessment scales from a single site to an organisation's entire data estate, not a one-off report.

Consent captured at source

Consent is collected at each collection point and scoped to that activity, required only where it's needed, recorded per purpose with proof.

Built for regulated industries

Your industry's data, discovered, traced, governed.

Pick a sector. Watch us find where personal data lives, classify what's sensitive, map it to a processing record, and gate it behind consent, the full lineage, end to end.

Sources found
    PII classified
      RoPA activity
        Consent gate

        Financial identifiers and account data are §9-sensitive under the DPDP Act, flagged, mapped, and never processed without consent.

        Live on any site today. Rolling out everywhere your data lives.

        DPDPA.support is built platform-by-platform to deliver zero-touch integration on all major ecosystems. Our live marquee below highlights the platforms we support, starting with WordPress, Shopify, BigCommerce, HubSpot, Webflow, and more coming soon. The same robust consent ledger, privacy portals, and DPO consoles work seamlessly wherever your business runs.

        Live Now

        Consent & Cookie Control

        Connect your site in minutes. Automatically syncs contacts and order data, and gates third-party trackers based on visitor consent.

        • Automatic Consent Banner
        • Cookie Gating & Pixel Control
        • Automated RoPA Ledger
        Coming Soon

        WordPress & WooCommerce

        Native WordPress plugin with out-of-the-box integrations for WooCommerce checkout consent, Gravity Forms, and Contact Form 7 compliance.

        • WooCommerce Checkout Consent
        • Forms Compliance Engine
        • Zero-config Asset Gating
        Coming Soon

        Shopify App

        Fully embedded Shopify app designed to align with Shopify Customer Privacy APIs. Dynamic third-party script gating before checkout.

        • Shopify API Harmonized
        • Cart Page Consent Gates
        • Direct Customer Data Deletion
        Coming Soon

        Custom SDK & API

        Standard JSON SDK and REST API for bespoke, headless, or server-side frameworks. Complete programmatic control over the consent lifecycle.

        • Headless Node/Go/Python SDKs
        • Event-driven JS Consent Hook
        • Append-only Ledger API
        Any websiteLive WordPressSoon ShopifySoon HubSpotSoon BigCommerceSoon
        WebflowSoon SquarespaceSoon MagentoSoon SalesforceSoon Custom APISoon

        How DPDPA.support works.

        Explore how our platform automatically maps your data, intercepts active tags, records consent, and gates everything under the DPDPA.center console.

        dpdpa.support · your compliance console
        SIMULATION RUNNING

        Automatic Database Field & PII Discovery

        Scanning fields...
        Database Table: Members
        email PII Detected
        phoneNumber PII Detected
        createdAt Safe
        Database Table: Orders
        billingAddress PII Detected
        customerName PII Detected
        totalAmount Safe

        Auto-Scan: DPDPA.support maps where personal data lives automatically on install. PII is discovered, classified, and kept securely isolated for your site from the first minute.

        Active Tag Interception & Scripts Gating

        Consent enforcement
        GA

        Google Analytics

        Enforced, blocked until consent
        INTERCEPTED
        FB

        Meta Pixel

        Enforced, blocked until consent
        INTERCEPTED
        HS

        HubSpot Tracker

        Consent-gated API
        INTERCEPTED

        Strict Gating: All marketing tools and tracking tags are intercepted at load. No script fires, and no personal data is transferred, until the visitor explicitly gives consent.

        Append-Only Consent Ledger & DPIA Mapping

        Cryptographically Signed
        Just Now
        Consent Captured: Member (61272ccd)
        Purpose: Marketing
        Signed & verified
        1 min ago
        Consent Withdrawn: Guest visitor
        Purpose: Analytics
        Signed & verified
        DPIA Report Auto-Generated Ready for Data Protection Board export

        Audit Proof: Every consent decision is recorded per purpose with cryptographic proof. Privacy policies and Data Protection Impact Assessments (DPIA) are compiled automatically from actual processing activities.

        Secured & Gated through DPDPA.center

        Tenant Vault Locked
        DPDPA.center Active
        • Secrets isolated securely
        • Grievance redressal workflows online
        • Built to support your DPDP Act readiness

        Total Security: Your data fiduciaries' operations are managed under the DPDPA.center dashboard. Your compliance workflows run continuously and stay audit-ready, helping you meet your DPDP obligations.

        Be ready as the rules take effect

        Get ahead of the DPDP Act.

        India’s DPDP Act 2023 is enacted, and the detailed Rules are still being finalised by the government. The timeline below is our reading of the anticipated phasing, these are expected milestones, not officially confirmed deadlines, and they may change. Mapping data, capturing per-purpose consent with proof, and honouring erasure requests takes time, getting the workflows in place early puts you ahead. One install, not a legal project.

        Consent Manager integration · anticipated

        Anticipated: around late 2026

        Estimated window, not a confirmed date

        Consent Manager integration, via a separate Board-registered entity, not DPDPA.support, is widely anticipated to become a requirement once the government finalises the DPDP Rules. The exact timing is not officially confirmed and is subject to change.

        All substantive obligations · anticipated

        Anticipated: around mid 2027

        Estimated window, not a confirmed date

        Lawful consent, breach reporting, data-principal rights, and security safeguards are expected to apply once the Rules take effect. The phasing and dates have not been officially confirmed and may change as the government finalises the DPDP Rules.

        DPDP ACT 2023 · STATUTORY ENFORCEMENT

        Strict enforcement. Substantial accountability.

        The Data Protection Board of India (DPB) is empowered to levy severe penalties for non-compliance, while the law mandates a structured approach to Grievance Redressal and Data Protection Officers (DPO).

        Data Protection Board (DPB)

        Fines up to ₹250 Crores

        The DPB adjudicates on personal data breaches and non-compliance. Under Section 33 & Schedule of the DPDP Act, failure to implement reasonable security safeguards to prevent data breaches attracts statutory penalties up to ₹250 Crore. Our immutable, audit-ready consent logging system gives you clear evidence of compliance when requested.

        Data Protection Officer (DPO) Command

        Statutory Grievance Redressal

        Significant Data Fiduciaries must appoint a DPO based in India, who acts as the point of contact for grievance redressal under Section 10. Our dashboard provides a dedicated command console for your DPO to manage data principal requests, resolve complaints within statutory timelines, and compile verified Record of Processing Activities (RoPA) logs.

        The Digital Personal Data Protection Act 2023 is not just a policy update. It is a statutory reality. Every consent must be free, specific, informed, unconditional, and unambiguous. DPDPA.support is the first consent-ledger built specifically to keep your platforms compliant without rebuilding your backend.

        DPDP Act 2023 Roadmap

        How India reached the DPDP compliance era.

        Data protection is no longer optional. See the milestones of data issues, judgments, and statutory mandates leading up to enforcement.

        2017

        Privacy is a Fundamental Right

        The Supreme Court of India delivers the landmark Puttaswamy judgment, declaring the right to privacy as an intrinsic part of life and personal liberty under Article 21.

        News: "Landmark privacy verdict sets stage for regulatory laws."
        2018

        National Database Security Debates

        Reports of Aadhaar database vulnerabilities and leaks emerge in national media. Public interest litigation demands strict regulatory enforcement over database fields and PII storage.

        Media: "Aadhaar leaks spark urgent calls for data security bill."
        2020

        Pandemic Digital Health Data Exposures

        Rapid deployment of digital tracing, health surveys, and pandemic travel systems leads to widespread data exposures. Regulatory gaps become critical issues on national news reports.

        Reports: "Unprecedented patient health logs leaked online."
        2023

        DPDP Act Passed by Parliament

        India's Digital Personal Data Protection Act 2023 becomes law. It establishes the Data Protection Board (DPB) of India with statutory penalties up to ₹250 Crores for data breaches.

        Official: "DPDPA 2023 enacted, introducing high penalties."
        2026

        Expected Consent Milestones

        As the DPDP rules are finalised, businesses will need to capture per-purpose consent with proof. Consent Manager integration, via a separate Board-registered entity, is expected to follow.

        Now

        Zero-Touch Onboarding

        DPDPA.support launches to automate compliance. WordPress, Shopify, and more sites can deploy a secure ledger, DPO console, and cookie banner instantly.

        Live: "DPDPA.support enables instant one-click compliance."

        Every DPDP obligation, in a single circle.

        Consent, rights, erasure, audit and discovery, installed at the centre of your site and working together, not stitched from point tools. Live on any site today, built for your whole data estate.

        • Consent ledgerEvery grant & withdrawal recorded per purpose, with proof.
        • Cookie & tracker gatingAnalytics and ad scripts blocked until the visitor consents.
        • My Data self-serviceMembers manage consent & rights on your own site, in their language.
        • Access & erasureOne-click access reports across 12 sources; erasure with legal-hold.
        • DPO consoleRespond to grievances, run the erasure queue, look up principals.
        • Discovery & RoPAAuto-find where PII lives, classify it, build your RoPA for export.

        It maps your data, builds the records, and runs the rights, for you.

        On install, DPDPA.support discovers where personal data lives across your site, classifies it, and auto-builds your compliance artifacts. No spreadsheets, no consultants.

        Zero-touch discovery

        Scans members, contacts, orders, bookings, forms and more, finds every place personal data lives and classifies it automatically.

        RoPA, auto-built

        Your Record of Processing Activities is generated from what's actually on your site, and exported for the Data Protection Board on demand.

        DPO console & consent ledger

        A per-purpose consent ledger with proof, plus a DPO console to respond to grievances and run access / erasure with legal-hold.

        DPIA reports Coming soon

        Guided Data Protection Impact Assessments built from your discovered data map, on the roadmap as part of the Intelligence tier.

        Cookie & tracker gating

        Analytics and advertising scripts stay blocked until the visitor consents, enforced, not just a banner.

        Get ahead of the DPDP Act

        One install gets your site ahead of India’s DPDP Act obligations, without a compliance project.

        Verified on a real tenant

        Trackers stay blocked until consent.

        Analytics and advertising scripts do not fire until the data principal consents, actually enforced, not just hidden behind a banner.

        4
        overrides created
        7
        trackers gated
        0
        duplicates on re-run

        Zero-touch onboarding. Transparent plans.

        Deploy DPDPA.support in under 3 minutes. Choose the plan that fits your business, and keep your site audit-ready for the Data Protection Board.

        The Onboarding Flow

        1

        One-Click Platform Install

        Install the DPDPA.support app directly from your platform store (dpdpa.support, WordPress Plugin repo, or Shopify App Store).

        2

        Input DPO & Business Details

        Specify your Data Protection Officer's name, email, and localized business address to populate statutory notice headers.

        3

        Go Live & Discover Data

        Your cookie banner goes live instantly, trackers are gated, and our backend auto-scans database fields to compile your RoPA.

        Compliance Pricing

        Consent
        $9/mo
        • Per-purpose consent ledger with Section 8(2) append-only audit proof
        • Consent events captured from your website and recorded with proof
        • Cookie and tracker gating, enforced, not cosmetic
        • Analytics and advertising scripts blocked until consent
        Get DPDP-compliant
        Rights
        $19/mo
        • Everything in Consent
        • your-site/my-data self-service (tenant-themed, EN + HI)
        • Member auto-resolve + OTP step-up, no typed emails
        • Per-purpose toggles, grouped + individual, accept/decline-all
        • Section 11 access & portability report and Section 12 erasure
        • Grievance, correction & portability request filing (Section 13)
        Get DPDP-compliant
        Intelligence
        $79/mo
        • Everything in Audit
        • AI-assisted classification (bring your own model key)
        • Governance & risk posture
        • Auto-map PII to DPDP purposes + breach-scope
        • Your data, your model, BYO-key control
        Get DPDP-compliant

        A compliance platform, not a cookie banner.

        Consent ledger

        Every decision recorded per purpose with proof of who, what, when and how, an append-only audit trail built for accountability.

        My Data self-service

        At your-site/my-data, members are auto-resolved from your login with OTP step-up, per-purpose toggles, in English and Hindi.

        Access & erasure

        One-click access reports across twelve data sources; erasure that stops processing, with legal-hold and proof-of-purge.

        DPO console

        A grievance respond-and-action flow for grievances, an erasure queue, and principal lookup, resolved in one place, not a spreadsheet.

        Discovery & RoPA

        Auto-discover where PII lives, classify it, and map it to DPDP purposes and a Record of Processing Activities, ready for DPB export.

        Private & isolated

        Your data is kept private to your site, sessions stay scoped to your site, isolation is enforced by default, and every consent event is verifiably recorded.

        FAQ

        DPDP questions, answered plainly.

        Yes. DPDPA.support is a consent management and compliance platform: a per-purpose consent ledger with proof, tracker gating that is actually enforced, data-principal self-service for access and erasure, and a DPO console. A banner records a click; this records compliance.
        Your data is hosted securely on our infrastructure, kept private and isolated to your site, with sessions scoped to your site and consent events verifiably recorded. You stay on your site; the system of record is a secure, add-only audit trail you can prove and export.
        On erasure, processing stops instantly, consents withdrawn, marketing consent revoked, subscriptions cancelled, marketing labels stripped. Records then freeze under a documented legal-hold and auto-purge with proof when the retention clock expires. Withdrawal is two-way, flowing back into your website so marketing genuinely stops.
        Every plan is billed monthly, with no setup fees and no contracts. Plans start at $9/mo for consent capture and scale into full DPO tooling and AI-assisted classification as your compliance programme matures.
        No. To be precise about roles: this is the fiduciary's own consent management and compliance platform, not a Board-registered Consent Manager.

        Ready to automate your DPDPA compliance?

        Deploy a complete per-purpose consent ledger, cookie gating, and visitor rights self-service in minutes. No complex integration or legal overhead.