Frequently asked questions
Answers about Consentry and the DPDP Rules
Direct answers to the questions compliance and engineering teams ask before evaluating consent infrastructure.
- What is Consentry?
- Consentry is a consent decision and enforcement layer for Data Fiduciaries operating under India's DPDP Act. It carries a person's consent decision across named systems and retains an auditable record of what was permitted, when, and why.
- Is Consentry a registered Consent Manager?
- No. Consentry is not a registered Consent Manager. It operates on the Data Fiduciary side and is designed to interoperate with registered Consent Managers rather than compete with them.
- When do the DPDP Rules phases take effect?
- The DPDP Rules were notified on 13 November 2025. Consent Manager registration and oversight take effect on 13 November 2026. The core operational obligations in Rules 3, 5–16, 22, and 23 take effect on 13 May 2027.
- How long does Consentry retain decision records?
- Consentry retains consent decision records for seven years. Each record captures what was permitted, for which purpose, when the decision applied, and which systems obeyed it.
- Does Consentry retain personal data for seven years?
- No. The seven-year period applies to the consent decision record, not the personal data governed by that decision. When consent is withdrawn and the purpose is served, the governed personal data is erased on the schedule required by the Act.
- Where is Consentry customer data stored?
- Consentry keeps customer data in a single India region and does not replicate it outside India. This is a product choice; the DPDP Rules use a negative-list model for cross-border transfers rather than requiring India-only storage by default.
- Who is Consentry built for?
- Consentry is built for compliance, DPO, platform, and privacy engineering teams that need to enforce consent decisions across analytics, processors, personalization, warehouses, and customer data platforms.