India now has a working privacy law. The DPDP Rules 2025 were notified in November 2025, the compliance deadline is May 2027, and the Data Protection Board of India will begin enforcement. Indian businesses need a consent management platform — and need to choose the right one.
The challenge: most CMPs in the market were designed for GDPR. They do that job well. But India's Digital Personal Data Protection Act 2023 is not GDPR. The legal basis model is different, the vocabulary is different, the obligations are different, and there is an entirely new Consent Manager registration framework with no GDPR equivalent launching in November 2026. A platform built for European compliance will not automatically cover your Indian obligations.
This guide gives you a practical evaluation framework — the questions to ask, the capabilities to verify, and the red flags to watch for.
Why GDPR-First Platforms Create Gaps for DPDPA
Before diving into what to look for, it helps to understand where the structural differences lie.
Legal basis model: GDPR offers six lawful bases for processing personal data. 'Legitimate interest' alone covers a large share of commercial processing without requiring explicit consent. DPDPA does not offer legitimate interest as a general commercial basis. For most Indian businesses, consent is the primary required legal basis. A platform designed around GDPR's six bases will surface options and workflows that simply have no equivalent in DPDPA.
Vocabulary and documentation: GDPR uses 'Data Controller,' 'Data Subject,' and 'Data Processor.' DPDPA uses 'Data Fiduciary,' 'Data Principal,' and 'Data Processor.' These are not cosmetic differences — the legal obligations attached to each role are defined in the Act. If your consent logs and audit reports use GDPR terminology, they do not map cleanly to what you would present to the Data Protection Board of India.
Indian language requirements: The DPDPA requires notices in a language the Data Principal understands. India has 22 official scheduled languages. An English-only consent banner does not meet this requirement for large portions of the Indian population.
Consent Manager framework: From 13 November 2026, the DPDPA introduces a registered Consent Manager framework — entities registered with the Data Protection Board that allow Data Principals to manage consent across multiple Data Fiduciaries centrally. This is uniquely Indian with no GDPR equivalent.
The 7 Capabilities to Evaluate
1. Consent capture — opt-in, purpose-specific, per-recipient
Section 6 of the DPDPA requires consent that is free, specific, informed, unconditional, and unambiguous. This means: no pre-ticked boxes, no bundled consent for multiple purposes, and no implied consent from continued use. The platform must support separate consent for each processing purpose and record each independently.
2. Withdrawal enforcement — not just recording
This is where most implementations quietly break down. Consent withdrawal is not a communication exercise — it is a system control problem. When a Data Principal withdraws consent, processing must stop across all connected systems and data processors. Ask the vendor: what happens downstream when a withdrawal is recorded? If the answer is "we log it and you manage the rest," that is not a compliant withdrawal mechanism.
3. Data Principal rights fulfilment
The DPDPA gives Data Principals rights beyond consent: right to access, right to correction, right to erasure, right to grievance redressal, and the right to nominate. Your platform needs a structured workflow for each — intake, verification, SLA tracking, fulfilment, and audit trail.
4. Audit trail and proof of consent
The DPDPA requires Data Fiduciaries to demonstrate that consent was obtained, what it covered, when it was given, and what notice was shown. You need a tamper-evident log: timestamp, purposes consented to, the exact notice version shown, withdrawal events, and downstream propagation records.
5. Data processor (TPRM) management
Section 8 of the DPDPA places obligations on Data Fiduciaries to ensure their data processors also comply. Many CMPs stop at the Data Principal-facing layer and leave third-party risk management to you.
6. DPIA support
Significant Data Fiduciaries and high-risk processing activities require Data Protection Impact Assessments. A DPIA is not a one-time exercise — it needs to be repeatable, documented, and linked to the processing activities it assessed.
7. Indian language coverage — verified, not machine-translated
Ask specifically which Indian scheduled languages the consent notice supports, and whether translations were done by human translators or generated by machine translation. Machine translation of legal notices does not reliably meet the DPDPA's standard.
Questions to Ask Any Vendor
- Does your platform use DPDPA vocabulary — Data Fiduciary, Data Principal — in notices, logs, and reports, or does it use GDPR terminology?
- Show me withdrawal enforcement in action — when a Data Principal withdraws consent, what happens to downstream systems and data processors, and how quickly?
- Which Indian scheduled languages do you support natively, and are these human-verified translations?
- How does your platform handle the Consent Manager framework launching in November 2026?
- Where is consent and audit data stored — is it in Indian data centres?
- Does the platform cover DPIA, rights fulfilment, breach management, and TPRM — or only consent capture?
What 'Unified' Actually Means for DPDPA
The DPDPA is not just a consent law. It is a comprehensive data protection framework with obligations across the full lifecycle: notice and consent, rights fulfilment, breach notification (72-hour clock to the DPBI), DPIA for high-risk activities, data processor oversight, and security safeguards.
A platform that handles only consent capture means you are managing rights, breach, DPIA, and TPRM in separate tools — each with its own audit trail and its own gaps. That fragmentation is itself a compliance risk.
The make-or-break question: After your demo, ask this: "If a Data Principal withdraws consent today, and six months later the Data Protection Board asks me to prove that processing stopped across all my systems and vendors — can your platform give me that evidence?"