Home
OctoVault
OctoAssist
OctoFlow
OctoForge
OctoDesk
OctoCred
All products Services About Blog Contact Talk to an expert
DPDP consent management

Consent management for India's DPDP Act.

OctoCred is Third Octopus's consent management platform for India's Digital Personal Data Protection Act, 2023. It gives data principals a portal to see and control their consent, and gives data fiduciaries a compliance panel with an immutable ledger of every notice, consent, withdrawal, correction and erasure.

Notice — Section 5Consent — Section 6Compliance ledger — Section 8Correction and erasure — Section 11Grievance redressal — Section 12
What OctoCred does

Privacy & Compliance, module by module.

Consent management for India's DPDP Act 2023: bilingual notices, granular opt-in consent, a tamper-evident ledger, correction and erasure, and a grievance desk.

Notice — Section 5

Every consent prompt is backed by a bilingual (English / Hindi) itemised notice: the exact data points collected, the purpose, and the user's rights.

Consent — Section 6

Granular toggles to give or withdraw consent per purpose. Withdrawing consent is as simple as switching a toggle off.

Compliance ledger — Section 8

Every consent grant, change or withdrawal generates a SHA-256 integrity hash, so the audit trail is verifiably untampered.

Correction and erasure — Section 11

Data principals submit correction or erasure (right-to-be-forgotten) requests; when approved, personal information is purged and consents revoked.

Grievance redressal — Section 12

A direct ticketing channel to the nominated Grievance Officer, so queries are resolved within the timelines the Act requires.

Data principal portal

A self-service view for the individual: current consents, history, and the ability to change or withdraw them.

Compliance panel

The fiduciary's view: consent states across principals, ledger entries, open grievances and pending rectification or erasure requests.

Consent lifecycle flow

Data collection event → notice → opt-in or reject → ledger entry → service activation → correction or erasure → ledger — one auditable chain.

Built for regulated sectors

Designed with financial-services onboarding in mind, where consent, purpose limitation and erasure must be provable.

How it works

From first step to closure.

1

Serve the notice

At the data collection event, the principal sees a bilingual, itemised notice of what is collected and why.

2

Record the choice

Opt-in consent is committed with a SHA-256 ledger signature; a rejection halts the flow and nullifies permissions.

3

Activate the service

Downstream processing proceeds only for the purposes consented to, and every change re-attests the ledger.

4

Honour the rights

Correction and erasure requests, and grievances to the Grievance Officer, are tracked to closure and written to the same ledger.

Who it is for

Built for teams that must show their work.

OctoCred maps each control to the section of the DPDP Act it satisfies — Notice (S.5), Consent (S.6), Ledger (S.8), Correction and Erasure (S.11), Grievance Redressal (S.12) — so a compliance officer can show an auditor exactly where each obligation is met.

  • Banks, NBFCs and fintechs onboarding Indian customers
  • Any data fiduciary that must evidence consent under the DPDP Act
  • Compliance officers who need a tamper-evident consent record
octocred · console
Notice servedBilingual · itemised · Section 5
logged
Consent: marketingWithdrawn by principal · Section 6
revoked
Ledger entry #4821SHA-256 a9f3…c21e · Section 8
sealed
Erasure requestApproved · data purged · Section 11
closed
Frequently asked

Questions about OctoCred.

What is the DPDP Act?

India's Digital Personal Data Protection Act, 2023 governs how organisations (data fiduciaries) collect and process the personal data of individuals (data principals), including notice, consent, correction, erasure and grievance redressal.

Which DPDP obligations does OctoCred cover?

Notice (Section 5), consent and withdrawal (Section 6), the compliance ledger (Section 8), correction and erasure (Section 11) and grievance redressal (Section 12).

How is the consent ledger protected from tampering?

Every consent grant, change or withdrawal generates a SHA-256 integrity hash, so any alteration of the audit trail is detectable.

Are notices available in Indian languages?

Notices are bilingual, English and Hindi, and itemise the data points, the purpose and the principal's rights.

Can I see a demonstration?

Yes — contact Third Octopus for a walkthrough of the data principal portal and the compliance panel.

See OctoCred on your own data.

Book a personalised walkthrough with the team that builds it — free of charge.