FOCTTA CONSENT DPDP Act 2023 and Rules 2025, section by section

Consent you can prove.
Withdrawal you can enforce.

FOCTTA Consent is consent management software for India's DPDP ActDPDP Act (Digital Personal Data Protection Act, 2023): India's law on how organisations collect and use personal data, and the rights people have over it.: it collects and proves consent, handles data rights requests and tracks breach deadlines. In English and all 22 scheduled languages, and ready for GDPR and CCPA.

Made in India, for IndiaHosted in India Consent, in every scheduled languageConsentसहमतिসম্মতিஒப்புதல்సమ్మతిसंमतीಸಮ್ಮತಿസമ്മതംસંમતિਸਹਿਮਤੀସମ୍ମତିرضامندی
Consent receipt issuedhash-chained · tamper-evident
Purpose withdrawn. Query blocked.At the database, with FOCTTA Detection
Data access requestS.11 · day 62 of 90, on track
Languages
English plus 22 Indian languages
Industry packs
1,229 ready-made purposes
Assessment templates
Ready-made privacy risk assessments DPIA · PIA · TIA
System event types
Signed updates to your other systems Webhooks
Regulator clocks
Breach reporting deadlines, tracked together CERT-In · RBI · SEBI · IRDAI · Board
The life of one consent

From a tap on a banner to proof a regulator accepts.

NoticeS.5 · Rule 3
The banner speaks their language and names who to complain to.
Language Tamil · தமிழ்
Notice version v4 · published
Complaint route Data Protection Board
A DPDPA notice cannot be published without the fiduciary name and the Board complaint route.
ConsentS.6 · S.6(10)
Every choice, including a refusal, is its own record with a receipt.
Offers and updates declined · receipt
Improve the service granted · receipt
Receipt a7b3…f2e1 · notice v4
Clicks retry and queue offline for up to 7 days, and duplicates never create a second record.
Consent checkS.4
Any system can ask "may I?" and get the current answer.
crm.campaigns purpose: marketing → no
app.analytics purpose: service → yes
Change feed webhook delivered · signed
346 signed event types reach your systems, with a delivery log.
WithdrawalS.6(4) · S.6(6)
Withdrawal is as easy as giving, and it lands everywhere at once.
Cached "yes" answers retired on every server
Downstream systems withdrawal event sent
Live database sessions ended
Ending live database sessions needs FOCTTA Detection in the data path. With FOCTTA Detection
EnforcementS.6(6) · S.8(7)
A query for a purpose without consent is masked or blocked, with a reason.
SELECT name, pan … masked · purpose not consented
SELECT * FROM kyc … blocked · BLK-7F2C
SELECT plan, city … allowed
Allow, mask a column or block, through the FOCTTA Detection gateway on PostgreSQL. With FOCTTA Detection
ErasureS.12 · S.8(7)
A legal decision tree erases what it should and keeps what the law requires.
Marketing CRM erased · flagged
Loan ledger retained · tax law citation
Processor confirmed by link
Flag-and-suppress by default, hard delete only if you opt in, with a certificate anyone can verify.
EvidenceS.6(10)
Prove what this person agreed to, and when, in one click.
Audit chain verified · unbroken
Consent history 3 receipts · notice v3 → v4
Evidence pack DPDPA · signed manifest
Hash-chained audit events, receipts on every consent, and a verification page for certificates.
Built on the Act, not adapted to itEvery screen, clock and citation is organised the way the DPDP Act 2023 and the 2025 Rules are written.

Pick a section. See what FOCTTA does for it.

Each section of the DPDP ActDPDP Act (Digital Personal Data Protection Act, 2023): India's law on how organisations collect and use personal data, and the rights people have over it. sets a duty. Pick one to see what the law asks and how FOCTTA helps.

S.6 · Consent
The Act asks: Free, specific, informed and unambiguous consent, and withdrawal as easy as giving it.
A consent ledger that proves yes, proves no, and enforces withdrawal.
One record per person, purpose and business unit
Refusals recorded as evidence
Withdrawal applied on every server at once
16 capability areas

Everything a privacy programme runs on, in one console.

Pick an area to see what FOCTTA Consent does in it. An orange tag marks a stated limit.

S.4 · S.6 · S.6(10)
Prove exactly what each person agreed to, and that they said no when they did.
One record per purposeEach purpose a person agrees to is recorded separately.Per person, purpose, regulation and business unit, with lawful basis and notice version.
Refusals as evidenceA "no" gets its own record and receipt too.
Expiry and renewalConsents expire after 12 months by default, with reminders.Alerts at 30, 7 and 2 days.
Withdrawal everywhereA withdrawal retires saved "yes" answers on every server at once.
38 consent templatesReady-made consent forms for 21 industries, plus a generic set.Including a minor-and-guardian template.
Consent by email linkCollect consent from people who never visit your website.Add-on
For groups of companies

One platform for the whole group. Each company keeps its own consents.

One tag, every brandOne website snippet recognises each brand from its domain.
Keys and notices stay putEach company keeps its own notices, keys and settings.Keys, webhooks, notices and preference centres stay with their company.
Withdrawals never crossIt stays with its company unless the person asks.
Bank Insurance Securities NBFC
Evidence, not assertions

Every change leaves a receipt, chained to the one before.

Each record is linked to the one before it, so any later change shows. That is proof a regulator can check.

Tamper-evident audit trailA receipt for every change, and any later edit shows.Hash-chained
Proof per personShow everything one person agreed to, in one click.
Signed evidence packsSigned bundles of proof, ready for an auditor or regulator.With FOCTTA Discovery: packs for DPDPA, SEBI CSCRF, GDPR and CCPA.
Accessibility report (WCAG 2.2 AA) on requestCompany sign-in and two-step loginPersonal details encrypted
Consent granted · marketingprev 9c1d… → a7b3…
#846
Notice v4 publishedprev a7b3… → 4f1e…
#847
Consent withdrawn · marketingprev 4f1e… → c09d…
#848
Erasure certificate issuedprev c09d… → 31b7…
#849