DPDPA (India)
India's Digital Personal Data Protection Act — captured, stored and served correctly, with the consent-manager framework supported out of the box.
The Digital Personal Data Protection Act, 2023 is India's first comprehensive privacy law — and it introduces a "consent manager" role that global privacy stacks weren't designed for. Gravito is the platform that lets teams operating in India comply with DPDPA on day one, without a bespoke integration project.
What the platform gives you.
Purpose taxonomy aligned with DPDPA's specified-purpose requirement — no bundling, no generalised claims.
Integrates with the DPDPA Consent Manager framework as the ecosystem stabilises. No parallel implementation.
Every consent flow rendered in the languages your Indian users actually speak — accessible, tested, translated.
Consent withdrawal is one click, in the same place consent was given. DPDPA's ease-of-withdrawal requirement met by default.
What we hear from teams like yours
- The DPDPA consent manager framework is unfamiliar territory for global stacks
- Localised notices need to reach every property without a fresh engineering cycle
- Cross-border data transfer rules keep evolving
- Withdrawal of consent under DPDPA has to be as easy as giving it — most CMPs make it harder
Compatible with India's emerging Consent Manager role, not just adjacent to it.
DPDPA introduces the Consent Manager as a regulated intermediary — a role most global consent stacks don't map to. Gravito's architecture accommodates that role natively, so as the Consent Manager framework stabilises your Indian operation is already positioned to plug in.
- ◆ Purpose taxonomy aligned to DPDPA specificity requirements
- ◆ Consent artefacts ready to hand off to a Consent Manager
- ◆ Withdrawal flows meeting the DPDPA parity requirement
Every Indian language your users speak, at the fidelity DPDPA expects.
Adding India to your compliance map is a configuration change, not a rebuild — but the localisation has to be real. Gravito ships with translation workflows for every Indian language your users speak, tested for accessibility, versioned per purpose, reviewable before promote.
- ◆ Translation workflows for every relevant Indian language
- ◆ Per-purpose translation with legal review flow
- ◆ Accessibility tested for every locale
What customers see
DPDPA-ready from the same platform
Adding India to your compliance map should be a configuration change, not a rebuild — and the localisation should be real, not a Google Translate output. Gravito gets you both.
Where to start
Native consent for iOS, Android and CTV — one policy source across every surface, every store review passed on the first submission.
This is how to do cookie consent properly — a modular, enterprise-grade CMP with built-in identity resolution.
A self-service hub where your customers manage consent, preferences and data-subject rights — and your DPO watches the queue disappear.