#1 Ranked in MeitY-NeGD
DPDP Innovation Challenge

Validated for building a Consent Management System (CMS) that integrates into real platforms while meeting the full operational demands of DPDP compliance.

Privy by IDfy was evaluated across real-world scenarios in the DPDP Innovation Coding Challenge by MeitY and NeGD

MeitY DPDP Innovation Challenge Results PDF Screenshot

A Multi-Stage DPDP Innovation Challenge

Privy progressed through a rigorous evaluation process across design, demonstration, and final presentation stages.

Round 1

Design Submission

June 2025

Participants
50+Participants

Evaluated on

High-level technical design

System architecture

UI prototype

Round 2

Detailed Evaluation & Live Demonstration

November 2025

Shortlisted
6Shortlisted

Evaluated on

DPDP-aligned consent design

Technical architecture

Live system working at scale

WCAG compliance

Round 3

Final Presentation

December 2025

Finalists
2Finalists

Final presentation to panelists from

NeGD

CTO Uidai

NASSCOM

DigiLocker

Cyber Law and Governance Division

Other ecosystem stakeholders

laurelWinnerlaurel

March 2026

Winner Badge
Inner Background

Privy by IDfy

Ranked
#1 Rank
Code for Consent Challenge

Why This Challenge Matters

The MeitY- NeGD DPDP Innovation Challenge was a national initiative to evaluate real, deployable Consent Management Systems (CMS) aligned with the Digital Personal Data Protection Act.

It moved beyond conceptual approaches to assess working systems across design, architecture, security, interoperability, and enterprise readiness.

In the broader industry context, consent is often implemented through point solutions across systems. While these address specific use cases, they typically operate in isolation, making it important to evaluate how well integrated, system-level CMS solutions perform in real-world conditions.

The challenge reflects this shift toward validating production-ready consent infrastructure that can operate across complex, enterprise-scale environments.

Consent Intelligence Stack

What Privy Was Recognised For

  • tick

    Innovation, technical robustness, practical applicability, and citizen-centric design.

  • tick

    Ability to enable a Digital Personal Data Protection Act (DPDPA)-compliant ecosystem for real-world deployment.

  • tick

    #1 ranking validating production-ready architecture and interoperability readiness.

  • tick

    Alignment with national-level implementation efforts for DPDPA operationalisation.

  • tick

    Positioned to support interoperability across consent systems as DPDPA adoption scales.

  • tick

    Built as practical, DPDP-aligned infrastructure for enterprise and government use.

Built for DPDP Execution at Scale

Privy by IDfy helps organizations move from intent to execution by operationalising privacy and consent workflows across systems.

With Privy, enterprises can build stronger readiness around:

Consent governance

Consent governance

DPDP-aligned workflows

DPDP-aligned workflows

Audit-ready evidence

Audit-ready evidence

Data principal rights

Data principal rights

Third-party accountability

Third-party accountability

Practical privacy operations at scale

Practical privacy operations at scale

illustration

Strengthening India’s DPDP ecosystem

This recognition also opens the opportunity to contribute to broader interoperability standards for consent and consent management systems.

As India’s DPDP ecosystem matures, interoperability between systems will be critical for adoption, accountability, and citizen trust.

Privy is committed to supporting this shift through practical technology, strong governance workflows, and continued collaboration with ecosystem stakeholders.

Frequently Asked Questions

The evaluation followed a multi-stage process designed for real, working systems. It began with over 100 registrations, narrowed to 50 plus systems for initial evaluation, and then to 6 shortlisted solutions for deep technical validation.

Across these stages, systems were assessed on lifecycle management, enforcement, interoperability, and auditability under increasingly complex conditions.

Privy ranked #1 based on overall system capability.

Unlike typical assessments that focus on policies or interfaces, this evaluation examined how systems behave in practice.

It tested whether consent works across systems and not just at the point of capture, whether behaviour remains consistent in real-world conditions, and whether system actions can be clearly traced during audits.

Consent was evaluated as a control layer and not just a checkbox.

Consent capture is only the starting point. What determines compliance is whether consent continues to govern how data is used across systems.

A Consent Management System ensures consent is applied consistently, updated in real time, aligned with actual data processing, and demonstrable when required during audits.

No, the NeGD DPDP Innovation Challenge was not scoped for Consent Managers. Under the Digital Personal Data Protection Act, a Consent Manager is a registered entity that provides users with a platform to give, manage, review, and withdraw consent across multiple apps and services, whereas a Consent Management System (CMS) is the underlying infrastructure layer that enables consent capture, lifecycle management, auditability, and enforcement.

The challenge was specifically designed to evaluate Consent Management Systems, focusing on DPDP-aligned consent design, technical robustness, and the ability to operationalize consent at enterprise scale within real environments with legal demonstrability.

Still have a question?