Comprehensive DPDP Compliance with Leegality’s Consent Infrastructure

Achieve complete transparency and control over your personal data flows and offer delightful consent and privacy rights experiences across all your customer touchpoints.

consent-homepage-product-statsconsent-homepage-stats-list
consent-homepage-product-data-mapping-itemsconsent-homepage-data-mapping-controlsconsent-homepage-data-mapping-connectors
consent-homepage-product-notice

Delight your users and build trust

Provide integrated consent collection, update and data principal rights flows across digital, physical, assisted and third-party channels. Implement cookie banners on your website

consent-homepage-product-consent-notice
consent-homepage-product-privacy-center

Know your personal data, minimise risks

Create detailed data lineages with automated discovery and classification. Manage data retention schedules and send automated deletion instructions to internal and third party systems

consent-homepage-product-statsconsent-homepage-stats-list

Master Privacy Compliance and implement privacy by design

Implement privacy by design and conduct thorough PIAs, DPIAs, TPRAs and more with our unified assessments and risks module

consent-homepage-product-privacy 1consent-homepage-product-risk-2consent-homepage-product-risk-1

Always be audit ready

Maintain verifiable and Immutable records of consent, data principal rights requests and data deletion instructions. Reports and Analytics module to support audits and reviews

consent-homepage-product-consent-records 1consent-homepage-product-request-records.svg

Manage Third Party Risks and enforce compliance across all processors

Collect consent through third parties, send deletion instructions, conduct thorough assessments and manager personal data breaches

consent-homepage-product-systems 1
icon

Compliance & Privacy

Compliance & Privacy for Seamless Data Protection

icon

Third Party Risk Management

Comprehensive third-party Risk Management for all your Data

icon
Consent Management

End to End Consent Management built for DPDP Compliance

icon
Data Lifecycle Management

Automate Identification and Classification of Personal Data

Frequently asked questions

Still have questions? Book demo with us.

What is a Consent Manager?

Under the DPDP Act, a Consent Manager is a person registered with the Data Protection Board who acts as a single point of contact to enable a user to give, manage, review, and withdraw their consent through an accessible, transparent, and interoperable platform.

In simpler terms, a Consent Manager ensures that individuals have full control over their personal data and how it is processed.

When do I need to take user consent?

Under the DPDP Act, you must take user consent when processing personal data in digital form unless the processing falls under specific exemptions provided by the Act. Key scenarios requiring user consent include:

- Collecting Personal Data: When collecting personal data for any purpose.Sharing Data with Third Parties: Before

- Sharing user data with external entities or Using Data for New Purposes: If the purpose of processing changes from what was initially communicated.

- Retention Beyond Purpose: If data needs to be retained for reasons other than the original purpose of collection.

Is the DPDP Act in force?

The DPDP Act, 2023, has been enacted but is not fully in force yet. The government is expected to notify its provisions in phases, and has released the Draft DPDP Rules to guide implementation.

The Draft Rules are out for public consultation but the final version of these rules are yet to be notified. Additionally, the Act establishes the Data Protection Board (DPB), which will oversee enforcement, handle grievances, and impose penalties for non-compliance.

Organizations are advised to proactively prepare by understanding the Act, updating data protection practices, and monitoring notifications for the DPDP Rules and operationalization of the DPB.

What is the penalty for processing personal data without Consent?

Under the DPDP Act, processing personal data without obtaining valid consent can result in a penalty of up to ₹50 crores per instance.

Do I need to take consents for cookies on my website?

The requirement to take consent for cookies under the DPDP Act is currently uncertain. However, if cookies are interpreted as “personal data” under the Act (as they can identify and profile users), the following steps may be necessary for compliance:

- Display a Cookie Notice: Clearly explain the use, types, and purposes of cookies, ensuring the notice is available in local languages.

- Obtain Explicit Consent: Use unambiguous actions, such as an “Accept Cookies” button, to collect clear, explicit, and informed consent.

- Provide an Opt-Out Option: Allow users to easily reject or withdraw their consent for cookies at any time.

- Use a Consent Manager: Integrate a Consent Manager to streamline cookie consent collection and ensure compliance with DPDP Act standards.

Until further clarification or enforcement under the DPDP Act, aligning cookie practices with global standards like GDPR can help mitigate compliance risks.

Sign up for our custom demo

In our custom demo, we will
icon
Discuss your use case for 20 minutes before demo day
icon
We’ll prepare a custom demo tailored for your use case - you can ask us anything
icon
We’ll give you a free sandbox testing account
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.