Up to ₹250 crore per breach. Notice, consent, rights, breach reporting and erasure become enforceable on 13 May 2027.–weeks leftCheck your readiness →
Notice & consent · DPDP s.5, s.6, Rule 3
Consent that is itemised, by construction.
A purpose register drives the notice; the widget shows each purpose with the data it needs and a switch that starts off. People choose; Nyvika records exactly what they saw and in which language.
s.5 Notices.6 ConsentRule 3 Notice contents22 scheduled languages
The challenge
Where consent goes wrong.
Most organisations have a privacy policy, a cookie banner and a tick-box. The Act asks for something else: a notice per purpose, a choice per purpose, and proof of both.
One box for everything
Bundled consent is no consent
A single "I agree" covering marketing, analytics and sharing with partners fails s.6(1): consent must be specific to a purpose and limited to the data that purpose needs.
English only
A notice the person cannot read
Rule 3 requires the notice in English or any language in the Eighth Schedule, at the person's option. A form that only speaks English is not giving notice to most of India.
No record
Consent nobody can prove
When the Board or a customer asks what someone agreed to, a database flag set to true is not evidence. You need the notice version, the wording, the language, the time and a record that cannot have been edited since.
What Nyvika does
A notice that writes itself from your purposes.
Describe each purpose once. Everything downstream, from the widget to the record of processing, follows from that description.
Purpose register
Each purpose carries its lawful basis, data categories, retention period, recipients and translations.
Consent, legitimate use or legal obligation per purpose
Retention in days drives erasure later
Translations per purpose, falling back to English
Notice versions
A notice is published as a frozen version. Changing it creates the next version and, if you choose, asks people again.
Draft, diff and publish from the console
Re-consent on the next visit when a version requires it
Every consent record names the version the person saw
The widget
One script tag. The notice appears on the right screen, in the person's language, and cannot be configured into a dark pattern.
Every switch starts off; accept and reject are equal
Closing the box is not a yes
Business processes route each journey to its purposes
Every channel
Web and app journeys use the widget; IVR, kiosk, call centre and paper use the API with their own wording.
Per-channel wording on each purpose
Operator-recorded consent with the script shown
The same ledger for all of them
Status before use
Ask before you act.
Consent is only useful if the systems that send the email or share the data check it first. Nyvika answers that question in one call, and pushes withdrawals to the systems that would otherwise keep going.
Real-time status
A server asks whether a person's consent for a purpose is active, withdrawn or never given; the widget asks on sign-in.
Withdrawal that propagates
A withdrawal is queued to every connected processor: CRM, engagement platform, email tool, WhatsApp provider, ad audience.
A public key cannot probe
Status for a person needs your secret key or that person's own session. Nobody can enumerate your customers from the browser.
One ledger
How it connects.
Every module writes to the same registers and the same hash-chained evidence, so nothing is re-keyed and nothing is lost between teams.
Do we have to translate every notice into 22 languages?
No. You add translations for the languages your customers use; a purpose without a translation falls back to English. Rule 3 asks that the notice be available in the person's chosen language, and the widget switches languages per person.
Can our designers change how the notice looks?
Colours, fonts and placement, yes. The rules the Act requires cannot be switched off: switches start off, the reject and accept actions are equally prominent, and closing the notice is never treated as consent.
What happens to consent given before we installed Nyvika?
You can import earlier decisions through the API with their original time and source, marked as imported. Most customers instead ask people again on their next visit, which produces a clean, provable record.
Does this work for an app, not just a website?
Yes. The widget runs in a web view, and native apps call the same API with their own screens. Business processes let an app ask for exactly the purposes a screen needs.