Encryption and access control are table stakes. These six criteria are where DPDP consent platforms actually diverge — and where a Data Protection Board inquiry will find the gaps. Score any vendor against them, including us.
01 Consent evidence mechanism
An editable log row is an assertion. A SHA-256 hash chain with RSA signatures and an RFC 3161 timestamp is evidence. Demand the mechanism by name.
Can the vendor name the exact cryptographic mechanism behind a consent record?YN
Are records hash-chained (each record bound to the one before it)?YN
Is each event independently timestamped (e.g. RFC 3161)?YN
02 Tamper-evidence / alterability
Can a database administrator silently change a consent flag and its timestamp with nothing in the record revealing it? Tampering must be self-evident, not deniable.
Does any post-hoc change to a record visibly break verification?YN
Is storage append-only (UPDATE / DELETE refused at the schema level)?YN
Can a third party verify integrity without trusting the vendor?YN
03 India-incorporation & Rule 4 eligibility
DPDP Rule 4 Consent Manager registration is open only to India-incorporated entities meeting residency and interoperability obligations. A foreign-incorporated tool cannot register.
Is the vendor an India-incorporated entity?YN
Is personal data resident in India (e.g. ap-south-1) by default?YN
Could the vendor itself participate in the Consent Manager regime?YN
04 Eighth Schedule language coverage
Rule 3 notices must be available in English plus any of the 22 Eighth Schedule languages. English-only templates with manual translation are a compliance gap.
Are notices authored natively across all 22 Eighth Schedule languages?YN
Is there a per-language content hash so a notice replays exactly what the principal saw?YN
05 DPR SLA automation
Access, correction, erasure, grievance, and nomination requests carry statutory clocks. Spreadsheet tracking cannot evidence on-time fulfilment when the Board asks.
Are all rights requests (§§11–14) tracked against a defined SLA?YN
Is there automated escalation and evidenced fulfilment per request?YN
Is the 30-day grievance window (§13) enforced with DPBI escalation?YN
06 Breach 72h countdown discipline
§8(6) gives 72 hours to notify the DPBI. Ad hoc breach handling burns the window. The platform must run a live countdown with templates, approvals, and an evidence trail.
Is there a live 72-hour DPBI notification countdown on every incident?YN
Is the CERT-In 6-hour deadline tracked for critical incidents?YN
Are DPBI / CERT-In notification templates and an evidence trail built in?YN
How to score: count the "Yes" answers per vendor (16 questions total). 14–16 = evidence-grade and DPBI-ready · 9–13 = partial, expect gaps under inquiry · 0–8 = records consent but cannot prove it. Ask every vendor the same questions — including Vishwaas AI.