Technical buyers scoring DPDPA compliance software architecture on a demo banner are measuring the wrong surface. The Digital Personal Data Protection Act, 2023 asks whether you can reconstruct a lawful ground on a named day — not whether a toggle looked clean in July.

TL;DR

  • DPDPA compliance software architecture is an evidence problem: a sealed PII vault, append-only consent records, and an audit trail a third party can inspect. A cookie banner is a capture widget.
  • The Digital Personal Data Protection Act, 2023 puts the Section 6(10) burden of proving consent on the Data Fiduciary. An admin who can silently edit the log cannot discharge that burden.
  • Identifying data sealed and tokenised maps to Rule 6(1)(a) and 6(1)(b) of the DPDP Rules, 2025, and to Section 8(5) reasonable security. Tokenised data is still personal data under Section 2(t).
  • Privigo is a Data Processor to your organisation. You remain the Data Fiduciary. Software is not your Section 8(9) contact, not your DPO, and not your Section 10(2)(b) independent auditor.
  • Substantive duties phase in on 13 May 2027. A leak still starts the dual clock: CERT-In (6 hours) and the Data Protection Board of India (DPB) under Rule 7 (72 hours). Section 8(5) sits under the ₹250 crore Schedule slab.

What is DPDPA compliance software architecture supposed to prove?

DPDPA compliance software architecture is supposed to prove a fact the Data Protection Board of India (DPB) can query: for this person, on this day, which Section 5 notice, which purposes, which Section 6 consent or named Section 7 legitimate use, who accessed the identifier, and when it was erased.

That is not a feature list. It is three properties that have to stay linked:

  1. Where identifying data sits — not copied into every LOS, ERP, HIS, ATS, and WhatsApp export.
  2. Whether the consent record can change after the fact — grant, refusal, and withdrawal as facts, not as a CMS row.
  3. Whether the trail is evidentiary — notice version, channel, timestamp, verification method, export a third party can read.

Privigo’s published design is built around those three: a sealed PII vault, immutable (append-only, cryptographically chained) consent records, and an evidentiary audit trail. The platform page is the product walkthrough. This article is the Act mapping for CAs and technical buyers. It is not a claim that installing software discharges the Act.

The DPDPA does not revive the old SPDI “sensitive personal data” category. Aadhaar, KYC, lab results, and student files are personal data under Section 2(t). Architecture is how you protect one class of data; it is not a second legal tier.

How does a sealed PII vault map to Rule 6 and Section 8(5)?

A sealed PII vault holds identifying data in a separate, access-controlled store. Operational systems — LOS, ERP, LMS, ATS — hold tokens, not the underlying identifier. The consent layer operates on those tokens.

That maps onto Rule 6(1)(a), which names encryption, obfuscation, masking, and virtual tokens mapped to the personal data as expected safeguards, and Rule 6(1)(b) on controlling access to the computer resources used. Section 8(5) is the parent duty: reasonable security safeguards. Failure of that duty is the ₹250 crore slab.

DPDPA compliance software architecture: sealed PII vault holds identifiers; operational systems hold tokens

Storage patternWhat the Board can askWhat usually fails
Identifiers copied into CRM, LOS, shared drives, vendor CSVsWho had Aadhaar on 14 March, and which export left the building?No access log; copies you cannot recall
Encrypted blob inside the same application databaseShow access control distinct from the app adminOne password is not Rule 6(1)(b)
Sealed vault + tokens in ops systemsReconstruct access to the identifier without spreading itStill personal data; processor contract still required

Two corrections technical buyers miss.

Tokens do not exit the Act. If a token can be linked back to an identifiable person, it is personal data. Downstream processor data is still personal data. Section 8(2) still wants a valid contract; Rule 6(1)(f) still wants security provisions in that contract. Privigo supplies a processor contract to customers. You still need contracts with every other processor — bureau, HIS, ERP, photographer.

The vault does not perform erasure for you. Section 8(7) is a fiduciary duty. Architecture helps you find and delete; a person still owns the retention trigger. For the NBFC-shaped version of this evidence pack, see DPDPA compliance for NBFCs.

This article uses the published sealed-store and token model only. Confirm current encryption, key-management, and backend construction with product in a demo.

Section 6 says what valid consent is: free, specific, informed, unconditional, unambiguous, given by clear affirmative action, limited to the specified purpose. Section 6(4) makes withdrawal as easy as giving consent. Section 6(10) puts the burden of proving that consent on the Data Fiduciary.

An audit log the vendor — or your own admin — can edit is evidence of a process. It is not evidence of a fact. Privigo’s published consent record is append-only and cryptographically chained: each entry captures the notice version served, the purposes granted and refused, the timestamp, the channel, and the verification method where a guardian is involved. Each entry is linked to the one before it so a later alteration is detectable rather than silent.

DPDPA compliance software architecture: append-only chained consent versus an editable admin log

Question the Board actually asksEditable CMS / spreadsheetAppend-only chained record
Which notice text did this person see?Latest template, maybeVersion tied to the event
Which purposes were granted or refused?Overwritten rowGrant and refusal as separate facts
When was withdrawal effective?A ticket, if you kept itTimestamped event in the same chain
Can a later admin silently “fix” the log?YesDetectable

Software does not make bundled consent valid. A screen that withholds a loan, a seat, or a job until the person accepts marketing still fails Section 6. Architecture records the choice; it cannot launder an unconditional-consent failure.

Notice language is Rule 3: English or any Eighth Schedule language. Confirm current Privigo language coverage in a demo. Do not assume full Eighth Schedule parity from this page.

Children remain a separate overlay. Section 9(1) and Rule 10 still require verifiable parental consent. A chain that stores the verification method is useful; it does not invent the guardian check.

What does an evidentiary audit trail change in a Board inquiry or breach?

The Board’s question is not “do you have a consent management system.” It is: prove the state of consent for this individual on a named date, and show the notice they were served. An analytics dashboard of opt-in rates answers a marketing question.

The same trail has to feed a breach. Clocks are cumulative, not alternatives: CERT-In within 6 hours of noticing; Rule 7 intimation to affected Data Principals without delay; initial Board intimation without delay; detailed Board report within 72 hours. Queryable consent and vault access logs let you scope the affected population instead of notifying everyone. They do not file CERT-In for you. A person still owns the dual clock. The runbook shape is in DPDPA compliance for NBFCs.

Rights are the third test. Access, correction, erasure, and grievance sit in Sections 11–14, Section 8(7), Section 8(9) / Rule 9, Section 8(10), and Rule 14 (including the Rule 14(3) 90-day ceiling). A Data Principal portal that can show history and take withdrawal is how Section 6(4) becomes operational. The portal is not the named Section 8(9) person. Name a human.

Rule 13 does not sit in this stack. Annual DPIA and independent audit start only after Section 10 notification. Software does not hold that office. SDF extras are in Significant Data Fiduciary under DPDPA. Sequence the rest of the work with the 90-day DPDPA readiness roadmap.

What should a technical buyer put in the evaluation pack before 13 May 2027?

Score the architecture, then the contract, then the demo theatre.

AreaOwnerStatus ☐
Map each component to a section/rule (vault → Rule 6 / s.8(5); consent chain → s.6 / 6(10); trail → Rule 7 + CERT-In)InfoSec / architect☐
Confirm identifiers are not duplicated into LOS / ERP / HIS after go-liveEng☐
Silent-edit test: can an admin change a past consent event without detection?InfoSec☐
Point-in-time reconstruct: notice version + purposes + channel for one named principalCompliance☐
Processor contract: s.8(2) + Rule 6(1)(f) security, sub-processing, deletion on exit, hours-based incident SLALegal / CA☐
Dual-clock drill using the trail to scope affected principalsInfoSec + ops☐
Named Section 8(9) contact (not titled DPO unless notified)Founder / compliance☐
Do not treat the platform as Rule 13 auditor or statutory DPOFinance / CA☐

If you evaluate a banner-first CMP against a vault-first platform, you are comparing different jobs. Website tags and Eighth Schedule notices are one risk. KYC, lab results, student files, and employee records are another. Rank the tool against the data you actually hold.

What should a CA or compliance officer do this month instead of buying a banner?

Three moves, in order:

  1. Write the fiduciary sentence — “We are the Data Fiduciary. Vendors, including any compliance platform, are processors. We are / are not a notified SDF as of [date].” Put it in the Board pack.
  2. Run the silent-edit test on whoever you already use — if a past consent row can be overwritten with no trace, Section 6(10) is already weak, banner or no banner.
  3. Pick one identifier class and stop copying it — Aadhaar, PAN, or patient ID out of the ops database and behind a token. One closed gap beats a 40-page RFP.

Book a 30-minute DPDPA discovery call →

Sources

  1. Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), MeitY — Sections 2, 5–10, 11–14, 33 and the Schedule: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
  2. Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), MeitY — Rules 3, 6, 7, 9, 10, 13, 14: https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
  3. DPDP Act commencement, G.S.R. 843(E), 13 November 2025, MeitY: https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf
  4. Press Information Bureau — Digital Personal Data Protection (DPDP) Rules, 2025: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014
  5. CERT-In — Directions under section 70B(6) of the IT Act, 2000, No. 20(3)/2022-CERT-In, 28 April 2022: https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf

This article is operational commentary for technical buyers, CAs, and compliance officers evaluating tools, not legal advice and not a determination that any named entity’s deployment satisfies the DPDPA. Privigo acts as a Data Processor to customer Data Fiduciaries. Confirm positions with qualified Indian counsel.

FAQ

Does DPDPA compliance software replace a Data Protection Officer?

No. Software is not a Section 10(2)(a) Data Protection Officer. Ordinary Data Fiduciaries publish a Section 8(9) contact, read with Rule 9, and run Section 8(10) grievance redressal. A Board-reporting DPO starts only after Section 10 notification.

If identifiers are tokenised in a sealed PII vault, is that data still personal data under DPDPA?

Yes. Tokenised or derived data remains personal data under Section 2(t) if it can be linked back to an identifiable individual. The Data Fiduciary stays accountable; a processor vault does not move the data outside the Act.

Does buying DPDPA compliance software discharge Rule 13?

No. Rule 13 of the DPDP Rules, 2025 — the twelve-month DPIA and audit — applies only after Section 10 notifies you as a Significant Data Fiduciary. Software is not the independent data auditor under Section 10(2)(b). People still sign the DPIA.

No. Section 6(10) puts the burden of proving valid consent on the Data Fiduciary. An admin-editable log is evidence of a process, not of a fact. You need a reconstructable record: who, when, which purposes, which notice version, and whether it was later withdrawn.