FAQ
Q1: Is Consent Manager DPDP compliant?
Yes. It is built specifically for DPDP requirements including:
- Explicit consent capture
- Revocation support
- Audit trail
- Verifiable receipts
Q2: Can consent be revoked?
Yes. Users can revoke anytime via:
- Redirect flow
- Direct API (if enabled)
Q3: How long are consent records stored?
Consent records are stored as per regulatory retention requirements and client configuration.
Q4: Are receipts tamper-proof?
Yes. Receipts are:
- Hashed (SHA-256)
- Digitally signed
- Logged in immutable ledger
Q5: Does Consent Manager support consent for minors?
Yes. Consent Manager supports parental consent for children's personal data:
- Set
subjectTypetoMINORand add adelegationwithtypeasPARENTin the consent request (Step 4) - The minor is never asked to log in; their parent or guardian verifies their own mobile number with an OTP
- The parent or guardian grants or revokes consent on the child's behalf
- The consent receipt records that a parent or guardian acted for the minor
See Step 7 for what the parent or guardian sees.
Q6: What happens when a minor turns 18?
Send a new consent request for the same dpHash with subjectType set to ADULT. When the user opens it and logs in with their own mobile number, Consent Manager asks whether they want to take over managing their own consents. Until they do, the parent or guardian stays in control. The child's existing consents and receipts are not affected.