Skip to content
DPDP Shield Consent

DPDP Shield Consent — DPDP-Ready Consent Banner & Audit Trail

Consent, integrated as easily as Google Analytics.

Drop one async script tag. Get a tamper-evident, auditor-ready consent ledger — built for India's DPDP Act.

1script tag
S.6(10)burden of proof covered
100%audit-trail retention
~2027enforcement deadline
Hindi + English notices todayConsent Mode v2 for GoogleHash-chained append-only ledgerDSAR queue with 90-day SLA trackingNo dark patternsNot legal advice — designed with counsel

How it works

Three steps from install to audit-ready

No multi-day integration. No SDK gymnastics. Paste, configure, verify — and your consent ledger starts building itself.

01

Drop one async snippet

Paste a single async script tag before your closing </body>. No npm package, no framework lock-in, no rebuild required.

<script
  async
  src="https://www.bachao.ai/cmp.js"
  data-site="BC-XXXXXXXX"
></script>
02

Visitors choose — freely

A DPDP-aligned banner appears with equal-weight Reject / Accept buttons, per-purpose toggles, and your notice in Hindi and English. Consent Mode v2 signals go to Google automatically.

03

You get the proof

Every decision is appended to a hash-chained ledger: who gave consent, for which purpose, when, under which notice version (and its hash), and the affirmation text shown. Export CSV or JSON. Run "verify chain" for auditors.

DPDP S.6(10)

The law puts the burden of proof on you. We carry it.

Section 6(10) of the DPDP Act 2023 is explicit: the Data Fiduciary must be able to demonstrate that a valid notice was provided and that freely-given consent was obtained. A cookie banner that vanishes without a trace is not proof.

DPDP Rules 2025 have been notified. Enforcement is expected around May 2027. That is not far, and gap-closing takes time — especially if your notice content needs legal review.

DPDP Shield Consent captures: the Data Principal's identity token, the purpose(s) consented to (or rejected), the timestamp, the notice version and its hash, and the affirmation text shown. Every record is appended to a hash-chained ledger. DSAR requests are queued with a 90-day SLA timer.

Notices are served in Hindi and English today — with more Indian languages on the way.

DPDP S.6(10)Burden of proof — covered
Consent Mode v2Google signals — automatic
Audit trailHash-chained, append-only
Banner designEqual-weight, no dark patterns
DSARQueue + 90-day SLA tracking
LanguagesHindi + English today
WithdrawalAs easy as giving consent

What's included

Everything your DPO needs, nothing your team doesn't

One product. End-to-end consent lifecycle — from first impression to regulator verification.

One-snippet install

A single async <script> tag — no npm, no rebuild, no framework dependency. Live in under 5 minutes.

Auto-block trackers until consent

Third-party scripts (analytics, ads, pixels) are held until the visitor has made an explicit, free choice. No silent pre-loading.

Equal-weight banner

Reject and Accept render at identical visual weight. No dark patterns. Compliant with DPDP Rules 2025 by default.

Tamper-evident audit log

Every consent event is hash-chained (SHA-256 linking each record to the previous). "Verify chain" endpoint for auditors and regulators.

DPO dashboard

Consent rates by purpose, withdrawal counts, active vs expired consents — all in one dashboard your Data Protection Officer can present.

DSAR intake queue

Data Subject Access Requests land in a managed queue with 90-day SLA tracking and one-click acknowledgement emails.

Withdrawal as easy as giving

A persistent "Manage your consent" link lets visitors withdraw any consent at any time. The withdrawal is recorded to the ledger immediately.

Multi-language notice

Hindi and English today. More Indian languages on the way — served from your site's domain, not a cross-origin frame.

Learn more

Why DPDP S.6(10) matters to you

Section 6(10) of the Digital Personal Data Protection Act 2023 places the burden of proving valid notice and consent squarely on the Data Fiduciary — that is, your organisation. If a regulator or a Data Principal challenges a consent record, you must produce evidence: what notice was shown, in what language, when, to whom, and what the person chose. DPDP Shield Consent generates and preserves that evidence for every interaction, automatically.

Consent Mode v2 and Google Analytics

Google Consent Mode v2 requires explicit signals before Analytics, Ads, and other Google tags process personal data. DPDP Shield Consent sends these signals automatically when a visitor accepts or rejects, so your Google stack stays compliant without any additional integration work.

What "hash-chained" means in practice

Each consent record includes a SHA-256 hash of the previous record in the ledger. Changing or deleting any past record breaks the chain — making tampering detectable. Auditors can run a single verification request to confirm the entire ledger is intact, from the first record to the most recent.

Not legal advice

DPDP Shield Consent is a technical product. It helps you implement DPDP-aligned consent capture and produce an audit-ready trail. Whether your notice content and data processing practices satisfy the law is a question for your legal counsel. We strongly recommend engaging a qualified privacy attorney to review your notices before launch.

Be audit-ready before enforcement

Your consent ledger starts building the moment you paste the snippet.

DPDP Rules 2025 are notified. Enforcement is coming. The work of getting your notice content legally reviewed takes time — start the technical layer now.

DPDP Shield Consent is a technical product that helps you implement DPDP-aligned consent capture and maintain an audit-ready ledger. This is not legal advice. Whether your notice content and data processing practices satisfy the DPDP Act 2023 and DPDP Rules 2025 depends on your specific circumstances and requires review by qualified legal counsel. Compliance depends on your notice content and counsel — not this product alone.

Find your vulnerabilitiesStart free scan →