Full feature guide: DPDP Compliance | Regulatory reference: DPDP Act 2023
Overview
The Grantex DPDP routes help a Data Fiduciary keep evidence for its obligations under India’s Digital Personal Data Protection Act 2023 and the DPDP Rules 2025, and answer GDPR access requests, for AI agent deployments. They are a technical control, not legal advice: Grantex is not a registered Consent Manager and does not notify the Data Protection Board or data principals on your behalf. Most DPDP obligations apply from 13 May 2027.Key Capabilities
- Consent records bind a data principal’s consent to an active grant and a versioned consent notice, with a signed proof (JWS, EdDSA)
- Consent notices are versioned per language and content-hashed; a
validationblock reports which DPDP Rules 2025 r.3 elements a notice carries - Withdrawal marks the record withdrawn, can revoke the record’s grant (the full grant cascade with
DPDP_REVOCATION_CASCADE=true), and can emit adpdp.data_deletion.requestedwebhook to your application - Erasure revokes the principal’s grants, marks records erased, and reports what is retained and why; with
DPDP_ERASURE_EXPANDED=trueit also redacts grievances and deletes stored exports - Grievances carry a reference number, the response period you publish (1 to 90 days) as
responsePeriodDays, anexpectedResolutionBydate, and asubmitted->in_review->resolvedorrejectedworkflow. Grantex computes and stores these dates; meeting them is your process - Breach register records breaches and computes
boardDetailedReportDueAt(awareness + 72 hours, or a granted extension), tracks principal intimations, and emits deadline webhooks - Exports:
dpdp-audit,gdpr-article-15(with a per-person Art. 15 block), and theeu-ai-act-evidencepack