#1 Ranked in MeitY-NeGD
DPDP Innovation Challenge
Validated for building a Consent Management System (CMS) that integrates into real platforms while meeting the full operational demands of DPDP compliance.
Privy by IDfy was evaluated across real-world scenarios in the DPDP Innovation Coding Challenge by MeitY and NeGD

A Multi-Stage DPDP Innovation Challenge
Privy progressed through a rigorous evaluation process across design, demonstration, and final presentation stages.
Design Submission
June 2025
Evaluated on
High-level technical design
System architecture
UI prototype
Detailed Evaluation & Live Demonstration
November 2025
Evaluated on
DPDP-aligned consent design
Technical architecture
Live system working at scale
WCAG compliance
Final Presentation
December 2025
Final presentation to panelists from
NeGD
CTO Uidai
NASSCOM
DigiLocker
Cyber Law and Governance Division
Other ecosystem stakeholders
March 2026


Privy by IDfy
Built for DPDP Execution at Scale
Privy by IDfy helps organizations move from intent to execution by operationalising privacy and consent workflows across systems.
With Privy, enterprises can build stronger readiness around:

Consent governance

DPDP-aligned workflows

Audit-ready evidence

Data principal rights

Third-party accountability

Practical privacy operations at scale

Strengthening India’s DPDP ecosystem
This recognition also opens the opportunity to contribute to broader interoperability standards for consent and consent management systems.
As India’s DPDP ecosystem matures, interoperability between systems will be critical for adoption, accountability, and citizen trust.
Privy is committed to supporting this shift through practical technology, strong governance workflows, and continued collaboration with ecosystem stakeholders.
Frequently Asked Questions
The evaluation followed a multi-stage process designed for real, working systems. It began with over 100 registrations, narrowed to 50 plus systems for initial evaluation, and then to 6 shortlisted solutions for deep technical validation.
Across these stages, systems were assessed on lifecycle management, enforcement, interoperability, and auditability under increasingly complex conditions.
Privy ranked #1 based on overall system capability.
Unlike typical assessments that focus on policies or interfaces, this evaluation examined how systems behave in practice.
It tested whether consent works across systems and not just at the point of capture, whether behaviour remains consistent in real-world conditions, and whether system actions can be clearly traced during audits.
Consent was evaluated as a control layer and not just a checkbox.
Consent capture is only the starting point. What determines compliance is whether consent continues to govern how data is used across systems.
A Consent Management System ensures consent is applied consistently, updated in real time, aligned with actual data processing, and demonstrable when required during audits.
No, the NeGD DPDP Innovation Challenge was not scoped for Consent Managers. Under the Digital Personal Data Protection Act, a Consent Manager is a registered entity that provides users with a platform to give, manage, review, and withdraw consent across multiple apps and services, whereas a Consent Management System (CMS) is the underlying infrastructure layer that enables consent capture, lifecycle management, auditability, and enforcement.
The challenge was specifically designed to evaluate Consent Management Systems, focusing on DPDP-aligned consent design, technical robustness, and the ability to operationalize consent at enterprise scale within real environments with legal demonstrability.
Still have a question?








