Consently Blog
Expert insights on DPDPA 2023 compliance, data protection, and privacy best practices
DPDP Compliance for AI Chatbots and LLM Apps Built in India
Your chatbot is a data collection surface with a text box. Users paste Aadhaar numbers, medical histories, and card details into it, your prompts go to a model provider abroad, and every conversation is logged. Here is what the DPDP Act requires of an LLM application built in India — and the architecture that satisfies it.
DSAR Automation in 2026: Running Data Principal Rights Requests at Volume
The first Data Principal rights request is a curiosity. The five hundredth is an operational crisis. Under the DPDP Act you must verify identity, search every system, respond within your published timeline, and prove you did. Here is how to build a rights workflow that survives volume.
Data Retention and Erasure Under the DPDP Rules: The Three-Year Clock and How to Automate It
The DPDP Rules attach a hard erasure clock to specified classes of data fiduciary: three years of Data Principal inactivity and the data must go, with 48 hours' notice before deletion. Most Indian companies have never deleted anything. Here is what the rule requires and how to build the machinery.
Google Consent Mode v2 and the DPDP Act: How Indian Websites Should Configure Tags in 2026
Consent Mode v2 is a Google Ads requirement. The DPDP Act is Indian law. They are not the same thing, and configuring one does not satisfy the other. A practical setup guide for Indian websites running GA4, Google Ads, and Tag Manager under DPDP.
How to Automate Cookie Scanning for DPDPA Compliance: 2026 Guide
Manual cookie audits take days and miss 30–40% of trackers. This guide shows how to automate cookie scanning for DPDPA 2023 compliance — what to scan, how to classify cookies, and how to build an auto-updating cookie policy without touching code.