OctoCred is Third Octopus's consent management platform for India's Digital Personal Data Protection Act, 2023. It gives data principals a portal to see and control their consent, and gives data fiduciaries a compliance panel with an immutable ledger of every notice, consent, withdrawal, correction and erasure.
Consent management for India's DPDP Act 2023: bilingual notices, granular opt-in consent, a tamper-evident ledger, correction and erasure, and a grievance desk.
Every consent prompt is backed by a bilingual (English / Hindi) itemised notice: the exact data points collected, the purpose, and the user's rights.
Granular toggles to give or withdraw consent per purpose. Withdrawing consent is as simple as switching a toggle off.
Every consent grant, change or withdrawal generates a SHA-256 integrity hash, so the audit trail is verifiably untampered.
Data principals submit correction or erasure (right-to-be-forgotten) requests; when approved, personal information is purged and consents revoked.
A direct ticketing channel to the nominated Grievance Officer, so queries are resolved within the timelines the Act requires.
A self-service view for the individual: current consents, history, and the ability to change or withdraw them.
The fiduciary's view: consent states across principals, ledger entries, open grievances and pending rectification or erasure requests.
Data collection event → notice → opt-in or reject → ledger entry → service activation → correction or erasure → ledger — one auditable chain.
Designed with financial-services onboarding in mind, where consent, purpose limitation and erasure must be provable.
At the data collection event, the principal sees a bilingual, itemised notice of what is collected and why.
Opt-in consent is committed with a SHA-256 ledger signature; a rejection halts the flow and nullifies permissions.
Downstream processing proceeds only for the purposes consented to, and every change re-attests the ledger.
Correction and erasure requests, and grievances to the Grievance Officer, are tracked to closure and written to the same ledger.
OctoCred maps each control to the section of the DPDP Act it satisfies — Notice (S.5), Consent (S.6), Ledger (S.8), Correction and Erasure (S.11), Grievance Redressal (S.12) — so a compliance officer can show an auditor exactly where each obligation is met.
India's Digital Personal Data Protection Act, 2023 governs how organisations (data fiduciaries) collect and process the personal data of individuals (data principals), including notice, consent, correction, erasure and grievance redressal.
Notice (Section 5), consent and withdrawal (Section 6), the compliance ledger (Section 8), correction and erasure (Section 11) and grievance redressal (Section 12).
Every consent grant, change or withdrawal generates a SHA-256 integrity hash, so any alteration of the audit trail is detectable.
Notices are bilingual, English and Hindi, and itemise the data points, the purpose and the principal's rights.
Yes — contact Third Octopus for a walkthrough of the data principal portal and the compliance panel.
Book a personalised walkthrough with the team that builds it — free of charge.