Run every obligation of India's Digital Personal Data Protection Act in one place, and keep evidence your auditor can check without taking your word for it.
The Act makes every Indian business that handles personal data a Data Fiduciary with hard clocks and hard penalties. Spreadsheets, a cookie banner and a privacy policy do not meet it. Working software with evidence does.
Every clock on one screen
If you hold an Indian resident's name, phone, email or Aadhaar, the Act applies to you. Here is what it looks like in your sector.
Itemised consent at sign-up and checkout, withdrawal that stops the WhatsApp campaign, erasure that reaches the CRM and the ad audiences.
Legal-obligation purposes for KYC and tax records next to consent purposes for cross-sell, each with its own retention. Breach drills on PAN and bank data.
Sensitive categories flagged in discovery, bilingual notices for patients, rights requests with identity verified before any record is disclosed.
Purposes involving children flagged for the s.9 duties, notices parents can read, retention that erases a leaver's data on schedule.
Consent on web, app, kiosk and front desk with the same ledger; guest data erased when the purpose is served, not kept for the next season's campaign.
A processor register with every sub-processor and its agreement; a signed webhook so your own platform honours withdrawals; a Privacy Centre in your brand.
Nine modules, one ledger. Each one exists because the Act or the Rules asked for it, and each writes its evidence to the same place.
Purposes, notice versions in 23 languages, a widget that cannot be made dark, every channel.
s.5 · s.6 · Rule 3 02Equal choices, real blocking, a cookie register, decisions recorded server-side.
s.6 03OTP-verified portal, five request types, the 30- and 90-day clocks, erasure that reaches processors.
s.11–s.14 · Rule 14 04The 72-hour clock, ordered steps, a drafted Board report, bilingual notices to affected people.
s.8(6) · Rule 7 05Retention per purpose, inactivity warnings 48 hours ahead, review or automatic mode.
s.8(7) · Rule 8 06A register with agreements and reviews; twenty connectors that deliver withdrawals and erasures.
s.8(2) 07Ten data sources scanned read-only for thirteen Indian identifier types; inventory and data-flow map; import.
s.8(4) · s.8(5) 08Scored questionnaires linked to purposes, stores and processors, with owners and review.
s.10 · Rule 13 09Hash-chained ledger with one-click verification, nine reports, an audit log, a score with a published formula.
s.6(10) · s.10Every consent decision is a hash-linked record: who, which purpose, which notice version, which language, when, and the hash before it. Two chains, one per person and one for the whole organisation, and a button that checks them all.
The console recomputes every chain on demand. The ledger-proof report exports it, and the hash construction is published, so an auditor can check it without Nyvika.
People are identified by keyed hashes. Email addresses and phone numbers live only in an encrypted vault, used to act on the person's own instruction and shredded after erasure.
Record of processing, consent ledger, request register, breach register, processor register, cookie register, audit log and the ledger proof, as CSV or JSON whenever you want them.
Most privacy tools watch for mistakes after the fact. Nyvika is built so the common mistakes cannot be made.
A notice nobody can read is not a notice. Nyvika speaks the customer's language in the widget, the Privacy Centre and every message it sends, and it sends them where people actually are.
Each purpose carries its own translations; a missing one falls back to English rather than to silence.
One-time codes, request updates, breach notices and retention warnings go out through Gupshup, Interakt, MSG91, Kaleyra, Exotel, Twilio or Amazon SES, with DLT templates where India requires them.
IVR, kiosk, call-centre and paper consent get their own wording and land in the same ledger as the website's.
Your privacy team sets it up from the console. Your developers add one line. Nothing to install on your side, and nothing to maintain.
Each purpose, its lawful basis, the data it needs, how long you keep it and whom you share it with. The record of processing writes itself from here.
Publish the notice and drop nyvika.js into your site or app. The widget shows the right notice on the right screen, in the customer's language.
Decisions land in the ledger, withdrawals reach your processors, and requests arrive in a queue with a countdown on each one.
Verify the ledger, export the reports and show the Board, your auditor or your customer exactly what happened and when.
Connectors for the systems an Indian business already runs, security controls your InfoSec team will recognise, and documentation they can read before they sign.
Where each duty of a Data Fiduciary lives in Nyvika. No feature exists that the Act or the Rules did not ask for.
Itemised, purpose-by-purpose, in the person's language, with the data each purpose needs and how to withdraw.
Free, specific, informed, unambiguous; withdrawal as easy as giving it; nothing switched on by default.
Intimate the Board and the affected people; file the report within 72 hours; keep the record.
Erase when the purpose is served or consent withdrawn; warn before inactivity erasure; instruct processors.
Access, correction, erasure, nomination and grievance, through a Privacy Centre and a worked queue.
Thirty days to respond, ninety for a grievance, shown on every request and reported on every register.
A processor register with agreements and reviews; encryption, roles, two-factor and an audit log.
Data protection impact assessments linked to purposes, stores and processors, with a review workflow.
Nyvika is a Data Fiduciary's own system of record. It is not a Consent Manager under Rule 4 and does not act for the Data Protection Board. It makes your compliance real; your counsel confirms it is complete.
Full-stack privacy suites are real products with real strengths. Here is an honest account of when each is the better buy.
| You need | A full-stack suite | Nyvika |
|---|---|---|
| The obligations of the Act running, with proof, in weeks | Yes, after an enterprise implementation | Yes; one script tag and a console |
| Evidence your auditor can verify without the vendor | Usually a claim, rarely a procedure | Published hash format, exportable proof |
| Withdrawals that reach your CRM, campaign and support tools | Through integrations, often custom | Twenty connectors and a signed webhook |
| Retention that actually erases, including at processors | Policy tracking; execution varies | Scheduled, warned, executed, logged |
| Discovery across hundreds of systems, scanned documents, audio | Yes; that is their core | Ten common sources, text only, plus import |
| Data lineage, security posture, masking and tokenisation services | Yes, as separate modules | Not offered; buy a specialist and import |
| An AI co-pilot that scans your journeys for dark patterns | Yes | No; the widget cannot produce one |
| A vendor with bank references and a Consent Manager designation | Yes | Not yet; we offer a paid pilot with an exit clause |
| Documentation your team can read before buying | On request | A guide and a proposal, public, before you buy |
| Pricing a mid-market business can carry | Enterprise, on request | By number of people whose consent you manage |
If you are a bank with hundreds of data stores and a privacy office, buy the suite. If you need the Act done properly, with proof, this year, talk to us.
India's law on how organisations collect and use the personal data of individuals, passed in August 2023, with the DPDP Rules, 2025 setting out the detail: what a notice must contain, how a breach is reported, how long a request may take. It applies to digital personal data processed in India and to processing outside India connected with offering goods or services to people in India.
If you decide why and how personal data is processed, yes. A shop with a customer list, an app with sign-ups, a clinic with patient records and a lender with KYC files are all Data Fiduciaries. A company that only processes on another's instructions is a Data Processor, and the fiduciary stays responsible for it.
The Schedule sets maximums per breach: up to ₹250 crore for failing to keep reasonable security safeguards, ₹200 crore for not notifying a breach or for failing the duties towards children, ₹150 crore for a Significant Data Fiduciary's additional duties, and ₹50 crore for other contraventions. The Board decides the amount on the facts.
A Consent Manager is an India-incorporated intermediary registered with the Board through which a person can give, manage and withdraw consent across many fiduciaries. Nyvika is not one and does not try to be. It is a Data Fiduciary's own system for capturing and proving the consent that fiduciary obtains and for running its obligations, which every fiduciary needs whether or not a Consent Manager exists.
Nyvika is hosted in India by Quills Interstice. Each customer has its own organisation partition. People are identified by keyed hashes; contact addresses and connector credentials are encrypted in a vault. Every console action is in an audit log you can export, and the ledger, registers and reports export as CSV or JSON whenever you want a copy outside.
A notice on your real website within the first fortnight is the usual pilot target. Purposes are registered in a workshop, the widget is one script tag, and the Privacy Centre is hosted by us in your name. Connecting processors takes as long as it takes to get API keys from your own teams.
Twenty processor connectors cover the common CRM, engagement, email, WhatsApp, support, payment and advertising platforms, and a signed webhook covers your own systems. Ten discovery connectors read the usual databases, object stores, drives and warehouses. The REST API is documented end to end.
Yes. The hash construction of the ledger is documented, with test vectors, and we share it with your auditor. Export the ledger and the proof, recompute the chains, and any alteration shows as a break. That is the whole point of the design.
It does not do data lineage, security posture management or masking services for your own systems, does not scan images or audio, has no AI co-pilot, and is not a Consent Manager. The cookie crawler is simulated in this release and the processor connectors are verified against stand-ins until your onboarding. We would rather you heard it here.
Still have a question? Write to us.
Step-by-step, screen-by-screen guides for the jobs that touch another system's settings. Linked from the console too.
Open the guides →Twelve questions across notice, consent, rights, breaches, retention and processors. A score out of 100 and what to fix first.
Start the check →The privacy team's handbook: from the invitation email to the first breach drill, with every screen.
Download →What a pilot looks like, what it costs in your team's time, and what you have at the end of it.
Download →An hour, online. We register three of your real purposes, publish a notice on a test page, scan a test database if you bring credentials, and verify the ledger in front of you.