Skip to main content
Full feature guide: DPDP Compliance | Regulatory reference: DPDP Act 2023

Overview

The Grantex DPDP routes help a Data Fiduciary keep evidence for its obligations under India’s Digital Personal Data Protection Act 2023 and the DPDP Rules 2025, and answer GDPR access requests, for AI agent deployments. They are a technical control, not legal advice: Grantex is not a registered Consent Manager and does not notify the Data Protection Board or data principals on your behalf. Most DPDP obligations apply from 13 May 2027.

Key Capabilities

  • Consent records bind a data principal’s consent to an active grant and a versioned consent notice, with a signed proof (JWS, EdDSA)
  • Consent notices are versioned per language and content-hashed; a validation block reports which DPDP Rules 2025 r.3 elements a notice carries
  • Withdrawal marks the record withdrawn, can revoke the record’s grant (the full grant cascade with DPDP_REVOCATION_CASCADE=true), and can emit a dpdp.data_deletion.requested webhook to your application
  • Erasure revokes the principal’s grants, marks records erased, and reports what is retained and why; with DPDP_ERASURE_EXPANDED=true it also redacts grievances and deletes stored exports
  • Grievances carry a reference number, the response period you publish (1 to 90 days) as responsePeriodDays, an expectedResolutionBy date, and a submitted -> in_review -> resolved or rejected workflow. Grantex computes and stores these dates; meeting them is your process
  • Breach register records breaches and computes boardDetailedReportDueAt (awareness + 72 hours, or a granted extension), tracks principal intimations, and emits deadline webhooks
  • Exports: dpdp-audit, gdpr-article-15 (with a per-person Art. 15 block), and the eu-ai-act-evidence pack

API Endpoints

Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.
Last modified on September 30, 2026