Frequently Asked Questions
Technical, cryptographic, and statutory guidance on how ConsentPlix creates audit-ready, tamper-evident consent records under the DPDP Act 2023, GDPR, and CCPA.
Definition
What is ConsentPlix?
ConsentPlix is consent infrastructure that turns every consent decision into a signed, Merkle-sealed receipt stored in an append-only ledger. It combines a consent widget and SDK in 22 languages, a rights portal, signed webhooks and a site scanner, and it stores only pseudonymous consent records, hosted on AWS Mumbai by default.
How it works
From notice to proof in four steps
- 01
Notice is shown
The widget renders the notice for the visitor's jurisdiction and language, and records a hash of the exact text displayed.
- 02
Decision is signed
Each grant, rejection or withdrawal becomes a pseudonymous receipt signed with HMAC-SHA256.
- 03
Receipt is sealed
Receipts are appended to the ledger and rolled into periodic Merkle checkpoints, so later edits are detectable.
- 04
Proof is exported
Signed webhooks push every receipt to your own systems, ready for an audit or a regulator request.
20 answers
All questions
20 questions shown
- 01
ConsentPlix stores pseudonymous consent receipts only. Each receipt contains a pseudonymous session ID, timestamp, the exact policy notice hash displayed to the visitor, granular purposes granted or rejected, and an HMAC-SHA256 signature. We do not store visitor IP addresses, browsing histories, behavioral analytics, or personal customer profiles.
- 02
No. The ConsentPlix client SDK is ultra-lightweight (under 12 KB gzipped), has zero external runtime dependencies, and loads asynchronously so it does not block rendering or compete with your Core Web Vitals (INP and LCP). It is served from an edge CDN close to your visitors.
- 03
Installation requires adding a single asynchronous <script> tag to your site’s HTML <head>, placed before Google Tag Manager or any third-party marketing tags. ConsentPlix intercepts script injection automatically and holds trackers until explicit consent is logged.
- 04
Yes. ConsentPlix provides native, out-of-the-box dispatching for Google Consent Mode v2 signals (ad_storage, analytics_storage, ad_user_data, and ad_personalization). It integrates seamlessly with GTM dataLayer triggers and server-side tagging containers.
- 05
ConsentPlix supports India’s Digital Personal Data Protection Act (DPDP Act 2023), the European Union GDPR, UK GDPR, California CCPA / CPRA, Brazil LGPD, Singapore PDPA, and Canada PIPEDA. Our geolocation rules engine dynamically serves the statutory notice required for the visitor’s jurisdiction.
- 06
Under Section 6 of the DPDP Act 2023, consent must be free, specific, informed, unconditional, and unambiguous with clear affirmative action. Data fiduciaries bear the statutory burden of proof. Traditional cookie banners that store simple unauthenticated browser cookies cannot prove what notice was shown, which purpose was authorized, or provide verifiable proof to the Data Protection Board of India.
- 07
- 08
Yes. For visitors from California, ConsentPlix automatically switches to an opt-out model, rendering the statutory "Do Not Sell or Share My Personal Information" link and automatically honoring Global Privacy Control (GPC) browser headers.
- 09
Under strict regulatory scrutiny (such as inquiries by the Data Protection Board of India or European DPAs), a database row can be challenged as altered or backdated. A cryptographically signed receipt using HMAC-SHA256 and periodic Merkle root publishing creates audit-ready, tamper-evident evidence of exactly what was consented to and when.
- 10
Every consent receipt is hashed and inserted into a Merkle tree structure. Periodically (hourly or daily, depending on tier), the root hash of the tree is timestamped and anchored into an immutable log. This proves that no historical consent record can be inserted, altered, or deleted retroactively without invalidating the cryptographic chain.
- 11
No. Any change to a notice hash, timestamp, or purpose bitfield creates an immediate mismatch with the HMAC signature and the published Merkle root. Enterprise customers can also manage their own private KMS keys so that even ConsentPlix cannot forge a receipt.
- 12
All data is hosted in India by default on AWS Mumbai (ap-south-1), keeping consent records in India by default. Enterprise customers can request dedicated private VPC deployment or multi-region failover.
- 13
No. We store only pseudonymous, signed receipts of consent events. We do not store names, emails, IP addresses, credit card numbers, or end-user browsing logs. We are a specialized consent verification ledger, not a tracking network.
- 14
Yes. ConsentPlix provides real-time signed webhooks. Every consent grant, update, or withdrawal is pushed directly into your own data warehouse (Snowflake, BigQuery, PostgreSQL, S3) with the complete HMAC receipt payload.
- 15
Yes. We execute statutory Data Processing Agreements (DPAs) incorporating standard contractual clauses (SCCs). Our architecture fully aligns with GDPR Article 28 data processor obligations and Article 7 conditions for consent.
- 16
Yes. Under DPDP Section 6(4) and GDPR Article 7(3), withdrawing consent must be as effortless as giving it. ConsentPlix provides a persistent, discreet preference trigger that allows visitors to adjust or revoke their permissions in one click at any time.
- 17
ConsentPlix includes a hosted, white-labeled Data Subject Rights intake portal. Citizens can submit requests for data access, correction, or erasure. Each request is tracked against a response deadline you configure and is checked for legal retention holds before processing.
- 18
All subscriptions are billed in INR and include compliant tax invoices under SAC Code 998313 (Information Technology Software Services). Registered Indian businesses receive 18% GST input credit directly via their GSTIN.
- 19
Yes. We offer a 14-day production sandbox trial with full access to the embed script, all 22 Indian languages, and receipt verification tools. No credit card is required to begin evaluation.
- 20
Yes. Plan upgrades and domain add-ons are applied instantaneously with prorated billing for the remainder of your billing cycle. You can manage subscriptions directly from your ConsentPlix dashboard.
Keep reading
Related pages
Still have questions?
Walk through your consent setup with our team
We can review your current tags, data flows and DPDP gaps on a short call, and show how receipts are signed and verified.