DPDP compliance for Data Fiduciaries

The Proven Consent.

Run every obligation of India's Digital Personal Data Protection Act in one place, and keep evidence your auditor can check without taking your word for it.

  • Itemised consent in 22 Indian languages
  • Rights requests closed inside the 30-day clock
  • Breaches reported to the Board within 72 hours
22+1Languages
72hrsBreach clock
20Processor connectors
9:41▂▄▆ ●
acme retailहिन्दी ▾
आपकी सहमति
Acme Retail asks for your consent, one purpose at a time. Nothing is on until you turn it on.
Orders & deliveryName, phone, address · kept 3 years
Offers on WhatsAppPhone · kept 2 years · shared with HubSpot
Product analyticsIP address · kept 1 year
Reject allSave choices
Withdraw any time from the Privacy Centre · Notice v3 · English / हिन्दी
WA
Acme RetailYour consent was recorded at 9:41. Reference NV-7F2A. Reply STOP to withdraw.
What your customer sees
Ledger verified
72-hour clock
Notice in Hindi
WhatsApp & SMS
Erasure delivered
DPDP Act 2023 · Rules 2025Every feature maps to a section
Hosted in IndiaYour organisation's own partition
Evidence you can exportVerifiable without the vendor
Documented, end to endA guide your team can read first
By Quills IntersticeMakers of Nayandi
Why Nyvika

Your customers deserve honest consent.

The Act makes every Indian business that handles personal data a Data Fiduciary with hard clocks and hard penalties. Spreadsheets, a cookie banner and a privacy policy do not meet it. Working software with evidence does.

Section 33, Schedule
Up to ₹250 crore for failing to keep reasonable security safeguards
And up to ₹200 crore for not notifying a breach, or for failing in your duties towards children's data.
Section 6, Rule 3
Consent must be free, specific, informed and itemised, with an equally easy withdrawal
A notice in English or any of the 22 scheduled languages, listing each purpose and the data it needs. Pre-ticked boxes and buried "no" buttons are out.
Rules 7 and 14
72 hours to report a breach to the Board. 30 days to answer a rights request. 90 days for a grievance.
Every clock starts whether or not anyone is watching it.
The Nyvika compliance overview: a health score, the open deadlines, overdue requests and the breach report due Every clock on one screen
Industries

Built for every Data Fiduciary.

If you hold an Indian resident's name, phone, email or Aadhaar, the Act applies to you. Here is what it looks like in your sector.

Retail & D2C

Itemised consent at sign-up and checkout, withdrawal that stops the WhatsApp campaign, erasure that reaches the CRM and the ad audiences.

Fintech & lending

Legal-obligation purposes for KYC and tax records next to consent purposes for cross-sell, each with its own retention. Breach drills on PAN and bank data.

Healthcare providers

Sensitive categories flagged in discovery, bilingual notices for patients, rights requests with identity verified before any record is disclosed.

Education & edtech

Purposes involving children flagged for the s.9 duties, notices parents can read, retention that erases a leaver's data on schedule.

Hospitality & travel

Consent on web, app, kiosk and front desk with the same ledger; guest data erased when the purpose is served, not kept for the next season's campaign.

SaaS & marketplaces

A processor register with every sub-processor and its agreement; a signed webhook so your own platform honours withdrawals; a Privacy Centre in your brand.

What Nyvika does

The obligations, executed.

Nine modules, one ledger. Each one exists because the Act or the Rules asked for it, and each writes its evidence to the same place.

Evidence

Proof you can recompute.

Every consent decision is a hash-linked record: who, which purpose, which notice version, which language, when, and the hash before it. Two chains, one per person and one for the whole organisation, and a button that checks them all.

  • Verified in one click, or offline

    The console recomputes every chain on demand. The ledger-proof report exports it, and the hash construction is published, so an auditor can check it without Nyvika.

  • Blind to your customers by design

    People are identified by keyed hashes. Email addresses and phone numbers live only in an encrypted vault, used to act on the person's own instruction and shredded after erasure.

  • Nine audit-ready reports

    Record of processing, consent ledger, request register, breach register, processor register, cookie register, audit log and the ledger proof, as CSV or JSON whenever you want them.

A person's consent record: the hash-linked ledger entries and the verification result
Why it is different

Prevention, not detection.

Most privacy tools watch for mistakes after the fact. Nyvika is built so the common mistakes cannot be made.

The usual way

  • A banner the designers made pretty, with reject in grey
  • A privacy policy that drifts away from what the systems actually do
  • Consent stored as a flag that anyone with database access can flip
  • Withdrawals noted in a ticket and forgotten by the campaign tool
  • A breach plan in a document nobody has opened since it was written
  • An AI that scans your site for dark patterns and sends a report

The Nyvika way

  • A widget whose switches start off and whose buttons are equal, and cannot be configured otherwise
  • A notice generated from the same purpose register your processing runs on, so it cannot drift
  • Consent as a hash-chained ledger entry; alteration breaks the chain
  • Withdrawals queued to twenty kinds of processor, with a delivery log
  • A breach sequence the software will not let you run out of order
  • Nothing to detect, because the pattern was never possible
Reach

Notices that reach people.

A notice nobody can read is not a notice. Nyvika speaks the customer's language in the widget, the Privacy Centre and every message it sends, and it sends them where people actually are.

  • English plus the 22 scheduled languages

    Each purpose carries its own translations; a missing one falls back to English rather than to silence.

  • WhatsApp, SMS and email, bilingual

    One-time codes, request updates, breach notices and retention warnings go out through Gupshup, Interakt, MSG91, Kaleyra, Exotel, Twilio or Amazon SES, with DLT templates where India requires them.

  • Any channel, same evidence

    IVR, kiosk, call-centre and paper consent get their own wording and land in the same ledger as the website's.

The Privacy Centre in Hindi
How it works

Live in weeks, not quarters.

Your privacy team sets it up from the console. Your developers add one line. Nothing to install on your side, and nothing to maintain.

01
Register

Describe your purposes

Each purpose, its lawful basis, the data it needs, how long you keep it and whom you share it with. The record of processing writes itself from here.

02
Publish

Add one script tag

Publish the notice and drop nyvika.js into your site or app. The widget shows the right notice on the right screen, in the customer's language.

03
Operate

Customers consent and exercise rights

Decisions land in the ledger, withdrawals reach your processors, and requests arrive in a queue with a countdown on each one.

04
Prove

Hand over the evidence

Verify the ledger, export the reports and show the Board, your auditor or your customer exactly what happened and when.

Technology

The compliance stack is already built.

Connectors for the systems an Indian business already runs, security controls your InfoSec team will recognise, and documentation they can read before they sign.

20
Processor connectors
HubSpot, Salesforce, Zoho, Freshsales, WebEngage, MoEngage, CleverTap, Mailchimp, Brevo, SendGrid, Gupshup, Interakt, WATI, Zendesk, Freshdesk, Razorpay, PayU, Google Ads, Meta, and a signed webhook.
10
Data-source connectors
PostgreSQL, MySQL, MongoDB, S3, Azure Blob, Google Drive, SharePoint, BigQuery, Snowflake and your CRM, scanned read-only for Aadhaar, PAN, UPI and ten more identifier types.
23
Languages
English and all 22 languages of the Eighth Schedule, in the widget, the Privacy Centre and every notice that goes out.
100%
Of the ledger verifiable
Every consent record and every request timeline is hash-chained. The format is published; the check runs on demand.
Single sign-on: OpenID Connect and SAML 2.0 Two-factor with recovery codes Encrypted vault for contacts and credentials Full audit log of every console action Documented REST API for everything Hosted in India
Built on the Act

Every section, somewhere in the product.

Where each duty of a Data Fiduciary lives in Nyvika. No feature exists that the Act or the Rules did not ask for.

s.5 · Rule 3

Notice

Itemised, purpose-by-purpose, in the person's language, with the data each purpose needs and how to withdraw.

s.6

Consent

Free, specific, informed, unambiguous; withdrawal as easy as giving it; nothing switched on by default.

s.8(6) · Rule 7

Breach

Intimate the Board and the affected people; file the report within 72 hours; keep the record.

s.8(7) · Rule 8

Erasure

Erase when the purpose is served or consent withdrawn; warn before inactivity erasure; instruct processors.

s.11 – s.14

Rights

Access, correction, erasure, nomination and grievance, through a Privacy Centre and a worked queue.

Rule 14

Clocks

Thirty days to respond, ninety for a grievance, shown on every request and reported on every register.

s.8(2) · s.8(5)

Processors & safeguards

A processor register with agreements and reviews; encryption, roles, two-factor and an audit log.

s.10

Significant Data Fiduciaries

Data protection impact assessments linked to purposes, stores and processors, with a review workflow.

Nyvika is a Data Fiduciary's own system of record. It is not a Consent Manager under Rule 4 and does not act for the Data Protection Board. It makes your compliance real; your counsel confirms it is complete.

Choosing

Nyvika, or a privacy suite?

Full-stack privacy suites are real products with real strengths. Here is an honest account of when each is the better buy.

You needA full-stack suiteNyvika
The obligations of the Act running, with proof, in weeksYes, after an enterprise implementationYes; one script tag and a console
Evidence your auditor can verify without the vendorUsually a claim, rarely a procedurePublished hash format, exportable proof
Withdrawals that reach your CRM, campaign and support toolsThrough integrations, often customTwenty connectors and a signed webhook
Retention that actually erases, including at processorsPolicy tracking; execution variesScheduled, warned, executed, logged
Discovery across hundreds of systems, scanned documents, audioYes; that is their coreTen common sources, text only, plus import
Data lineage, security posture, masking and tokenisation servicesYes, as separate modulesNot offered; buy a specialist and import
An AI co-pilot that scans your journeys for dark patternsYesNo; the widget cannot produce one
A vendor with bank references and a Consent Manager designationYesNot yet; we offer a paid pilot with an exit clause
Documentation your team can read before buyingOn requestA guide and a proposal, public, before you buy
Pricing a mid-market business can carryEnterprise, on requestBy number of people whose consent you manage

If you are a bank with hundreds of data stores and a privacy office, buy the suite. If you need the Act done properly, with proof, this year, talk to us.

Questions

About the Act, and about us.

What is the Digital Personal Data Protection Act, 2023?

India's law on how organisations collect and use the personal data of individuals, passed in August 2023, with the DPDP Rules, 2025 setting out the detail: what a notice must contain, how a breach is reported, how long a request may take. It applies to digital personal data processed in India and to processing outside India connected with offering goods or services to people in India.

Is my business a Data Fiduciary?

If you decide why and how personal data is processed, yes. A shop with a customer list, an app with sign-ups, a clinic with patient records and a lender with KYC files are all Data Fiduciaries. A company that only processes on another's instructions is a Data Processor, and the fiduciary stays responsible for it.

What are the penalties?

The Schedule sets maximums per breach: up to ₹250 crore for failing to keep reasonable security safeguards, ₹200 crore for not notifying a breach or for failing the duties towards children, ₹150 crore for a Significant Data Fiduciary's additional duties, and ₹50 crore for other contraventions. The Board decides the amount on the facts.

What is a Consent Manager, and is Nyvika one?

A Consent Manager is an India-incorporated intermediary registered with the Board through which a person can give, manage and withdraw consent across many fiduciaries. Nyvika is not one and does not try to be. It is a Data Fiduciary's own system for capturing and proving the consent that fiduciary obtains and for running its obligations, which every fiduciary needs whether or not a Consent Manager exists.

Where is our data hosted, and who can see it?

Nyvika is hosted in India by Quills Interstice. Each customer has its own organisation partition. People are identified by keyed hashes; contact addresses and connector credentials are encrypted in a vault. Every console action is in an audit log you can export, and the ledger, registers and reports export as CSV or JSON whenever you want a copy outside.

How long does it take to go live?

A notice on your real website within the first fortnight is the usual pilot target. Purposes are registered in a workshop, the widget is one script tag, and the Privacy Centre is hosted by us in your name. Connecting processors takes as long as it takes to get API keys from your own teams.

Does it integrate with the tools we already use?

Twenty processor connectors cover the common CRM, engagement, email, WhatsApp, support, payment and advertising platforms, and a signed webhook covers your own systems. Ten discovery connectors read the usual databases, object stores, drives and warehouses. The REST API is documented end to end.

Can our auditor verify the evidence independently?

Yes. The hash construction of the ledger is documented, with test vectors, and we share it with your auditor. Export the ledger and the proof, recompute the chains, and any alteration shows as a break. That is the whole point of the design.

What does Nyvika not do?

It does not do data lineage, security posture management or masking services for your own systems, does not scan images or audio, has no AI co-pilot, and is not a Consent Manager. The cookie crawler is simulated in this release and the processor connectors are verified against stand-ins until your onboarding. We would rather you heard it here.

Still have a question? Write to us.

Resources

Read before you buy.

Request a demo

See it on your data.

An hour, online. We register three of your real purposes, publish a notice on a test page, scan a test database if you bring credentials, and verify the ledger in front of you.

This opens an email to hello@nyvika.in with your details filled in. We do not store anything from this form on the website.