HomeOctoVaultOctoAssistOctoFlowOctoForgeOctoDeskOctoCredAll products ServicesAboutBlogContact Talk to an expert
All articles
Compliance

What a DPDP consent manager actually has to do (and how OctoCred does it)

6 min readThird Octopus Team
What a DPDP consent manager actually has to do (and how OctoCred does it)

Under India's Digital Personal Data Protection Act, 2023, consent is not a checkbox at the bottom of a form. It is a lifecycle with a legal record at every step. A consent manager is the software that keeps that record honest.

Start with the notice

Section 5 of the Act requires that every request for consent is preceded by a notice stating what personal data is being collected and for what purpose, and telling the individual (the "data principal") how to exercise their rights and how to complain. A notice buried in a privacy policy does not meet that bar; it has to be itemised and presented at the point of collection.

OctoCred renders a bilingual notice, English and Hindi, listing the exact data points, the purpose and the principal's rights, every time consent is requested. The notice text is versioned, so the organisation can show which wording a person saw on which date.

Consent has to be granular, and withdrawal has to be as easy as giving it

Section 6 requires consent that is free, specific, informed and unambiguous, given for a stated purpose, and withdrawable with the same ease with which it was given. That last clause is the one most systems fail. If a person can opt in with one tap but must email a support desk to opt out, the consent is not compliant.

In OctoCred each purpose has its own toggle. Withdrawing consent for marketing while keeping consent for service delivery is one switch, and the withdrawal is written to the ledger the moment it happens.

Keep a record that cannot be quietly edited

The data fiduciary carries the burden of proving that consent existed. A row in a database that any administrator can update is weak evidence. OctoCred generates a SHA-256 integrity hash for every consent grant, change or withdrawal and chains it into an immutable compliance ledger, so an auditor can verify that the trail has not been altered after the fact.

Correction and erasure are rights, not favours

Data principals can ask for their personal data to be corrected, completed, updated or erased. OctoCred gives them a portal to raise those requests; when a request is approved, the data is corrected or purged, the associated consents are revoked, and the ledger records the outcome.

Grievances need an owner and a clock

Every data fiduciary has to publish a way for principals to raise grievances and to respond within the prescribed time. OctoCred includes a grievance desk that routes each complaint to the nominated Grievance Officer with a timeline attached.

The Act does not ask whether you collected consent. It asks whether you can prove it, for this person, for this purpose, on this date.

Two views of the same ledger

OctoCred exposes the same record to two audiences: a data principal portal where individuals see and control their consents, and a compliance panel where officers see consent states across principals, open grievances and pending correction or erasure requests. Nothing is shown to one side that contradicts the other, because both read from the same ledger.

If you are a bank, NBFC, fintech or any organisation onboarding Indian customers, this is the shape of the obligation. OctoCred is Third Octopus's implementation of it, and a walkthrough of both portals takes under an hour.

TO
Third Octopus TeamThird Octopus
More articles

Ready to put this into practice?

Talk to our team about your cloud, security and backup goals — we'll map out a clear next step, free of charge.