Product Datasheet  |  CompliSeal

DPDP Compliance.
Operational,
not advisory.

CompliSeal is a purpose-built compliance platform for Indian businesses navigating the Digital Personal Data Protection Act 2023. It combines a website scanner, document generator, consent management system, and data rights workflow into one product.

Start Free
At a Glance
13
DPDP Act checkpoints per scan
8+
Compliance modules across the full lifecycle
72h
Breach notification window supported
Free
Entry plan with scanning and report

Rs 250 Cr
Maximum DPDP Act 2023 penalty for security failures

What the DPDP Act requires of your business

The Digital Personal Data Protection Act 2023 and DPDP Rules 2025 impose direct legal obligations on every Indian business that collects or processes digital personal data. Penalties reach Rs 250 crore and regulators can act without prior notice.

Consent before collection

Free, specific, and informed consent must be obtained before any personal data is processed.

Breach notification

Personal data breaches must be reported to the Data Protection Board and affected individuals without undue delay.

Data rights fulfilment

Data Principals can request access, correction, erasure, and nomination. Businesses must respond within defined timelines.

Grievance Officer

A Grievance Officer with published contact details must be reachable by Data Principals at all times.

Processing records

Records of all data processing activities must be maintained and available for regulatory review.

Security safeguards

Appropriate technical and organisational measures must be implemented to protect personal data at all times.

Workflow

From scan to compliance in five steps

CompliSeal follows a structured workflow that maps directly to DPDP Act obligations. Each step builds on the previous one.

1

Scan your website

Enter your URL. CompliSeal checks 13 DPDP requirements automatically in under 60 seconds.

2

Review the report

Every gap is identified with a severity label and a specific remediation recommendation.

3

Generate documents

Use the policy generator, consent notice builder, and grievance officer template to close gaps.

4

Install the SDK

Deploy the consent banner with one script tag. Consent events are logged automatically.

5

Operate ongoing

Manage DSARs, log consent, respond to breaches, and track your compliance calendar.

Website Scanner

13 DPDP checkpoints in one scan

The automated scanner checks your website against the following DPDP Act 2023 requirements. Results are available immediately, no account required for the first scan.

Privacy policy present and accessible
Purpose of data collection stated
Data Principal rights disclosed
Grievance Officer contact published
Data retention periods stated
Consent banner present on entry
Cookies categorised (necessary vs analytics)
Tracking blocked before consent is given
Multilingual consent notice available
Consent withdrawal mechanism present
Consent events logged with timestamp
Preference centre accessible post-consent
Privacy policy in plain, readable language
Feature Modules

Everything the DPDP Act requires, in one place

Each module addresses a specific DPDP Act obligation. Free modules are available on all plans. Pro modules require a paid subscription.

Free

Compliance Scanner

Automated website scan against 13 DPDP Act requirements. Reports findings with severity labels and remediation steps.

  • Enter any URL, results in under 60 seconds
  • Pass / Fail / Needs Review per checkpoint
  • Downloadable PDF compliance report
  • 3 free scans per account
Pro

Privacy Policy Generator

Generates a DPDP-aligned privacy policy based on your business type, data categories, and processing activities.

  • Business-type questionnaire drives output
  • Covers all DPDP Act notice requirements
  • Plain-language drafting standard
  • HTML and text export formats
Pro

Consent Notice Builder

Creates the layered consent notice required under Section 6 of the DPDP Act, structured for granular per-purpose consent.

  • Purpose-specific consent blocks
  • Multilingual output supported
  • Links to withdrawal mechanism automatically
  • Preview before publishing
Pro

Consent SDK

A lightweight JavaScript SDK that installs a DPDP-compliant consent banner on your website. Blocks tracking before consent is recorded.

  • Single script tag deployment
  • Blocks analytics and ad scripts pre-consent
  • Logs every consent event with timestamp
  • Preference centre for post-consent changes
Pro

DSAR Dashboard

Centralised inbox for Data Subject Access Requests. Manages requests for access, correction, erasure, and nomination.

  • Public submission form with email verification
  • Deadline tracking per DPDP Act timelines
  • Status workflow: received, in review, resolved
  • Full audit trail for regulatory evidence
Pro

Breach Response

Structured 72-hour response workflow covering internal triage, Data Protection Board notification, and data principal notification.

  • Step-by-step guided response checklist
  • Prewritten notification templates
  • Severity classification and escalation paths
  • Timeline tracking against DPDP Act deadlines
Free

Compliance Calendar

A task calendar pre-populated with DPDP Act compliance milestones and DSAR deadlines.

  • Pre-loaded DPDP Act compliance schedule
  • Add custom internal review milestones
  • Visual overdue and upcoming indicators
  • Marks days with active DSAR deadlines
Free

Audit Log

Immutable log of all compliance actions taken in the platform. Provides an evidence trail for regulatory inspections.

  • Records scans, DSAR actions, breach events
  • Timestamp and user attribution on every entry
  • Filterable by event type and date range
  • CSV export for external review
Pro

ROPA Builder

Record of Processing Activities builder. Documents each processing purpose, legal basis, data categories, and retention periods.

  • Guided form per processing activity
  • Maps to Schedule I of the DPDP Act
  • Exportable as PDF or structured data
  • Tracks last review date per activity
Platform Architecture

How CompliSeal is built

Fully managed cloud infrastructure. No self-hosting required. Data is stored in isolated, encrypted databases per account.

User Layer
Web Dashboard Consent SDK (JS) DSAR Public Form Report Download
App Layer
Scanner Engine Policy Generator DSAR Workflow Breach Response Consent Logger DPIA / ROPA
Data Layer
PostgreSQL Database Row-Level Security Encrypted at Rest Isolated per Account
Integrations
Payment Processing Document Generation Engine Email (DSAR Notifications)
Pricing

Free to start. Pro when you need it.

The Free plan covers initial assessment and basic tooling. The Pro plan covers full operational compliance across all DPDP Act obligations.

Feature Free — Rs 0/month Pro — Paid subscription
Website compliance scans3 scansUnlimited
Compliance report (PDF)YesYes
Compliance calendarYesYes
Audit logYesYes
Privacy policy generatorNoYes
Consent notice builderNoYes
Consent SDK (website banner)NoYes
DSAR dashboardNoYes
Breach response workflowNoYes
ROPA builderNoYes
DPIA builderNoYes
Grievance officer templateNoYes
Vendor risk assessmentNoYes
Children's data controlsNoYes

See full pricing details for plan limits and billing options.

Penalty Reference

DPDP Act 2023: penalty schedule

Penalties are assessed by the Data Protection Board of India. Each violation is assessed independently. Multiple breaches can be cumulative.

Violation Maximum Penalty Severity CompliSeal Coverage
Failure to implement adequate security safeguards Rs 250 crore Critical DPIA, ROPA, vendor assessment
Processing children's data without verifiable consent Rs 200 crore Critical Children's data module
Failure to notify a breach to the Board or Data Principals Rs 200 crore Critical Breach response workflow
Failure to fulfil a Data Principal's rights request Rs 150 crore Critical DSAR dashboard and audit log
Processing data without obtaining valid consent Rs 50 crore Important Consent SDK, consent logger
Failure to maintain a Grievance Officer Rs 10,000 Important Grievance officer template, scanner
Violation of any other DPDP Act provision Rs 50 crore Important Full platform compliance coverage

This table is for informational reference only and does not constitute legal advice. Consult a qualified legal counsel for advice specific to your situation.

Who It Is For

Built for Indian businesses of every size

The DPDP Act applies to every Data Fiduciary operating in India. CompliSeal is designed for teams without a dedicated legal or compliance department.

Startups and early-stage companies

Establish compliant data practices from day one. The Free plan covers initial assessment so you know where to start.

E-commerce businesses

Consent management, cookie compliance, and DSAR handling are day-to-day operational requirements for any store collecting customer data.

SaaS and technology companies

ROPA, DPIA, and vendor risk tools cover the full data processing lifecycle for platforms with complex data flows.

Healthcare and EdTech

Platforms handling sensitive data or children's data have heightened obligations. Purpose-specific tools address each requirement.

FinTech and lending platforms

Consent before data sharing with credit bureaus and lending partners, combined with a clear DSAR process, is now a regulatory requirement.

SMBs with a website or app

If you have a contact form, newsletter sign-up, or any login, the DPDP Act applies. The scanner identifies your gaps in under a minute.

About Cogenz Cybertech

CompliSeal is developed and operated by Cogenz Cybertech, an Indian technology company focused on cybersecurity and compliance software. The platform was designed specifically for the DPDP Act 2023, not adapted from a generic privacy tool built for GDPR or CCPA.

All data processed through CompliSeal is stored within India on managed cloud infrastructure. No data is transferred to third-party servers beyond what is necessary for payment processing.

Incorporated in India DPDP Act 2023 native Data stored in India No GDPR carry-over

Start your DPDP compliance check now

Enter your website URL and get a full 13-checkpoint compliance report in under 60 seconds. No registration required for the initial scan.