Meru Retail
DPDP Act 2023 · Live walkthrough

One customer. One purchase.
Every obligation the Act creates.

Follow Meru Retail, a fictional Indian D2C brand, and Aarav Menon, one of its shoppers — from the first cookie on the homepage to a signed erasure certificate. Every screen here is a faithful mock of what DPDP Comply actually ships. Your choices carry forward through all seventeen chapters.

S.5 · S.6
Notice & consent
Granular, purpose-level, multilingual, with Google Consent Mode v2 and GPC.
S.9
Children's data
Age gate, verifiable guardian consent, tracking and ad-targeting blocked.
S.6(4) · S.6(6)
Withdrawal
As easy as giving it — with downstream erasure signals to processors.
S.11 – S.14
Principal rights
Access, correction, erasure, nomination and grievance, identity-verified.
S.8(7)
Retention & erasure
Per-purpose clocks that delete or anonymise without anyone remembering to.
S.8(6)
Breach register
Incident timeline, Board and principal notifications, evidence pack.
S.16
Cross-border
Transfer register and enforcement against the Government's restricted list.
S.10
Significant Data Fiduciary
India-based DPO, independent auditor, DPIA, algorithmic due diligence.
Proof
Tamper-evident audit
Hash-chained events, signed receipts, external timestamp anchoring.
Beyond DPDP
CERT-In & e-signature
6-hour cyber incident reporting, and signing the DPAs and consents this platform already generates.
This walkthrough is a product demonstration, not legal advice. Section references describe how the platform is designed to map to the DPDP Act 2023; where the Act leaves a matter to the DPDP Rules, the demo says so rather than inventing a number.
Act I · Before the visitor arrives

What are we actually collecting?

Meru Retail's marketing team has added tags over three years and nobody kept a list. Before you can give a lawful notice you have to know what is on the page. The scanner loads the site in a real headless browser and reports what it finds.

Cookie & tracker scan meruretail.in

A runtime scan opens the page, accepts nothing, and records every cookie, script and network beacon that fires anyway — including the ones that fire before any consent is given.

The obligation

A Data Fiduciary must give notice describing the personal data sought and the purpose for which it is to be processed. You cannot describe what you have not inventoried.

DPDP Act 2023 · S.5
What the platform did
  • Nothing yet — run the scan.
Buyer's question

"Our tags change weekly."
Schedule the scan. Any new tracker that appears without a matching purpose raises a drift alert, and the cookie policy page is regenerated from the scan rather than hand-maintained.

Act II · The visitor

Is this visitor a child?

Aarav opens meruretail.in. Before a single tracker fires, the widget has to resolve a question the Act treats as decisive: is this person under eighteen? Choose either path — the rest of the walkthrough adapts to what you pick.

https://meruretail.in

The monsoon edit

Handloom cotton, made in Bhagalpur. Free returns.

Indigo kurta · ₹2,490
Linen shirt · ₹3,200
Block print stole · ₹1,150

Before we continue

Meru Retail asks every visitor to confirm their age. If you are under 18, a parent or guardian must approve any data use.

The obligation

Before processing a child's personal data a Data Fiduciary must obtain verifiable consent of the parent or lawful guardian, and must not undertake tracking, behavioural monitoring, or targeted advertising directed at children.

DPDP Act 2023 · S.9(1) S.9(3)
What the platform did
  • Waiting for the visitor's answer.
Buyer's question

"What happens when the child turns eighteen?"
If a date of birth was declared, a background worker expires the consent on the eighteenth birthday and re-prompts as an adult. The event is written to the audit chain as MINOR_AGED_OUT.

Act II · The visitor

Asking properly

Consent under the Act must be free, specific, informed, unconditional and unambiguous — a clear affirmative action, for a stated purpose. That rules out pre-ticked boxes, bundled purposes, and a "Reject" button that is harder to find than "Accept". Toggle the settings and watch the banner and the tag signals respond.

Widget configuration no redeploy required
Symmetric reject button
"Reject all" carries the same weight as "Accept all".
Google Consent Mode v2
Emit ad_storage / analytics_storage signals to gtag.
Honour Global Privacy Control
Treat a browser Sec-GPC: 1 header as a standing opt-out.
Simulate a GPC browser
Aarav's browser sends the opt-out signal before the banner renders.
https://meruretail.in

The monsoon edit

Handloom cotton, made in Bhagalpur. Free returns.

Indigo kurta · ₹2,490
Linen shirt · ₹3,200
Block print stole · ₹1,150
Live tag signals
window.dataLayer
// waiting for a consent decision…

Scripts in the analytics and marketing buckets stay inert until the matching signal flips to granted. Denied is the default state on first load, so nothing leaks in the gap before the visitor answers.

The obligation

Consent must be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and be limited to such personal data as is necessary for the specified purpose.

DPDP Act 2023 · S.6(1)
What the platform did
  • Banner rendered. No data collected yet.
Buyer's question

"Our shoppers read Hindi and Tamil."
The Act requires the notice be available in English or any language in the Eighth Schedule. Switch languages in the banner header — the chosen language is stored on the consent record, so you can prove which text the person actually saw.

Act II · The visitor

Proof the visitor can keep

A screenshot of a banner proves nothing. The moment consent is recorded, the platform issues a signed consent receipt: a portable document stating who collected what, for which purposes, under which notice version, and how to withdraw. Signed with the project's own Ed25519 key, verifiable by anyone.

Consent receipt ISO/IEC 29184 · Kantara CR v1.1

No consent recorded yet. Go back to Chapter 3 and make a choice in the banner — the receipt is generated from what you actually pick.

Why a signature and not a database row
Without a receipt
"Our system says he consented." The other side asks you to prove the record was not edited after the dispute began. You cannot.
With a receipt
The signature is computed over canonical JSON with the project's private key. Change one character and verification fails — for you as much as for anyone else.
  • The public key ships inside the receipt, so a regulator or the principal can verify it without contacting you.
  • The email is masked in the receipt body — the proof does not itself become a data spill.
  • Every receipt names the exact notice version displayed, linking back to the immutable notice record.
  • A public verification endpoint accepts a pasted receipt and returns valid or invalid, with no login.
The obligation

The Data Fiduciary bears the burden: the Data Fiduciary shall be responsible for … demonstrating that a notice was given and consent was obtained in accordance with the Act.

DPDP Act 2023 · S.8(1) read with S.5
What the platform did
  • Awaiting a consent decision.
Act III · The record

What the compliance team sees

Meru's DPO opens the console. This is the same consent Aarav just gave, resolved into a record that can be searched, exported, audited and — critically — explained to someone who was not in the room.

meru-retail / storefront / consent / PN Priya N. · DPO

No consent record yet — complete Chapter 3 first.

The rest of the estate
48,219
active consents
61.4%
analytics opt-in rate
1,833
withdrawn (last 90 days)
312
guardian-verified minors
27
auto-denied by GPC
4
notice versions live

Opt-in rate is a compliance metric, not just a marketing one: a rate near 100% usually means the banner is coercing, and a rate near zero means the value exchange was never explained. The A/B testing module lets you test banner copy against both consent rate and complaint rate.

The obligation

A Data Fiduciary must implement appropriate technical and organisational measures to ensure effective observance of the Act, and remains accountable regardless of any contract with a processor.

DPDP Act 2023 · S.8(4) S.8(2)
What the platform did
  • Awaiting a consent decision.
Act III · The record

Can you trust your own logs?

Every consent event is sealed into an append-only chain: each row's SHA-256 hash includes the hash of the row before it. An edit anywhere breaks every link after it. Try it — edit a row below and re-run verification.

Consent audit chain consent_audit_events

The chain fills as events occur. Complete Chapter 3 to seed it.

External anchoring

A hash chain proves internal consistency. It does not, by itself, prove the whole chain was not rebuilt last night. So the head of the chain is periodically anchored to an RFC 3161 timestamp authority outside your control.

Anchored atChainSeqHead hashMethod
2026‑07‑25 04:00 ISTCONSENT_AUDIT_EVENT1,204,8818f3c1a…d20bRFC 3161
2026‑07‑24 04:00 ISTCONSENT_AUDIT_EVENT1,198,4022ba77e…91f4RFC 3161
2026‑07‑24 04:00 ISTAUDIT_LOG884,113c0e5b2…7a3dRFC 3161
The practical effect: to forge a consent record you would have to break SHA-256, or persuade an independent timestamp authority to backdate a token. Both are meaningfully harder than editing a row.
Why this matters

The Board may direct production of records during an inquiry. Records that could have been silently edited invite the question of whether they were.

DPDP Act 2023 · S.28
Chain status
  • Awaiting events.
Act IV · The principal acts

Aarav changes his mind

Six weeks later the marketing emails have worn thin. The Act sets a hard design rule: withdrawing consent must be as easy as giving it. No login wall, no retention call, no five-step form.

https://privacy.meruretail.in/withdraw/…

Complete Chapter 3 to generate a withdrawal link.

The obligation

"The Data Principal shall have the right to withdraw her consent at any time, with the ease of doing so being comparable to the ease with which such consent was given."

DPDP Act 2023 · S.6(4)
And then

On withdrawal the Fiduciary must cease processing within a reasonable time, and cause its Data Processors to do the same, unless retention is required by law.

DPDP Act 2023 · S.6(6)
What the platform did
  • Awaiting withdrawal.
Act IV · The principal acts

"Show me everything you hold"

Withdrawal was the easy one. Now Aarav exercises a statutory right through Meru's privacy portal. The hard part is not the form — it is verifying he is who he claims to be before handing over a file of personal data.

https://privacy.meruretail.in/rights
01Choose right
02Identify
03Verify email
04Confirm ID
05Track
The five rights, and what each one triggers
RightSectionWhat the platform does
AccessS.11Assembles a machine-readable export: consent history, purposes, processors the data was shared with, and the identities of any further recipients.
Correction & completionS.12Routes the change to the record owner, then propagates it to processors that received the earlier value.
ErasureS.12(3)Deletes or anonymises, minus anything a law requires you to keep — and records which exemption was relied on.
NominationS.14Stores a nominee who may exercise the rights on death or incapacity, with the relationship on record.
GrievanceS.13Opens a grievance thread against the named Grievance Officer, with its own escalation ladder — see the next chapter.
The obligation

A Data Principal has the right to obtain a summary of personal data being processed and the processing activities undertaken, and the identities of other Fiduciaries and Processors with whom it has been shared.

DPDP Act 2023 · S.11(1)
Getting the law right

The Act itself sets no numeric deadline for responding to a rights request — that is left to the DPDP Rules. The platform therefore tracks a target you configure, defaulted for you, rather than asserting a statutory number on your behalf.

What the platform did
  • Awaiting a request.
Act IV · The principal acts

Someone has to answer

A request that lands in a shared inbox is a request that gets missed. Meru's Grievance Officer works a queue with a visible clock, an escalation ladder that fires without anyone remembering, and a full communication trail per request.

meru-retail / storefront / rights RS Rohan S. · Grievance Officer
7
open requests
2
inside escalation window
0
past target
RequestTypePrincipalStatusTime to target
Escalation ladder runs on a background worker, not a reminder
  • T − 5 days
    REMINDER
    Assigned handler is nudged. Nothing leaves the team yet.
  • T − 2 days
    ESCALATED
    Owners and admins are alerted; the request is pinned to the top of the queue.
  • T + 0
    OVERDUE_FINAL
    Status flips to OVERDUE automatically and the DPO is notified. The flip is written to the audit log — you cannot quietly reset the clock.
  • Next report
    BREACH_LOGGED
    Recorded in the compliance report as a missed target, with the delay in days.
The tiers are keyed to your configured target, not to an invented statutory figure. Set it to whatever the DPDP Rules ultimately require, or tighter if your policy commits to more.
The named officer, published

The Act requires you to publish the business contact of the person who answers questions about processing. The platform hosts that page, versions it, and logs every change of officer.

Officer
Rohan Sharma
Contact
grievance@meruretail.in
Published at
/meru-retail/grievance-officer
Last change
14 Mar 2026 logged
Grievance change log
  • 14 Mar 2026
    Officer changed
    M. Iyer → R. Sharma. Notice auto-patched on 4 documents.
  • 02 Jan 2025
    Officer appointed
    M. Iyer named at go-live.
The obligation

A Data Fiduciary must publish the business contact information of a Data Protection Officer or a person able to answer questions about processing, and provide an effective mechanism to redress grievances.

DPDP Act 2023 · S.8(9) S.13
What the platform did
  • Awaiting a request from Chapter 8.
Act V · The organisation's own obligations

The notice nobody rewrites by hand

A privacy notice that drifts from the purpose registry is worse than none — it is documented evidence of a mismatch. Meru's notice, cookie policy and terms are generated from the same registry the banner reads, versioned on every change, and hosted on Meru's own domain.

Document library all published
DocumentVersionPublishedLanguagesStatus
Privacy Policyv412 Jun 2026EN · हिं · தLive
Consent Notice (shown in banner)v712 Jun 2026EN · हिं · தLive
Cookie Policy (from scanner)v1125 Jul 2026EN · हिंLive
Terms of Servicev302 Jan 2026ENLive
Data Retention Policyv202 Jan 2026ENLive
Children's Data Policyv214 Mar 2026EN · हिंLive
Grievance Redressal Policyv314 Mar 2026ENLive
Data Processing Agreement (template)v102 Jan 2026ENTemplate
Why versioning is not filing

When the Grievance Officer changed in March, every document naming the old officer was auto-patched and re-versioned. Aarav's consent record still points at notice v6 — the text he actually saw — not at today's v7.

  • 12 Jun 2026 · v7
    New purpose added: Personalised recommendations
    Existing consents flagged REQUIRES_RECONSENT for that purpose only. The other purposes stay valid — you do not re-prompt for everything.
  • 14 Mar 2026 · v6
    Grievance Officer changed
    Auto-patched across 4 documents. Logged as NOTICE_AUTO_PATCHED.
  • 02 Jan 2026 · v5
    Retention shortened on marketing data
    730 → 365 days. Retention worker recalculated 22,908 expiry dates overnight.
Published under Meru's own name
  • Privacy Centre on privacy.meruretail.in — a customer-facing hub, not a vendor page.
  • TLS provisioned automatically for the custom domain.
  • Meru's logo, colours and typography on the banner, the portal and every email.
  • A public trust page summarising posture, live document versions and the named officer.
privacy.meruretail.in

Your data, your controls.

Manage cookie preferences
Download my data
Make a request or complaint
Read the privacy notice
The obligation

The notice must be presented in clear and plain language, with the option to access it in English or any language in the Eighth Schedule to the Constitution.

DPDP Act 2023 · S.5(3)
What the platform did
  • Documents generated from the live purpose registry.
  • Every version retained and addressable.
  • Consent records pinned to the version displayed.
  • Officer change propagated automatically.
Act V · The organisation's own obligations

Where the data actually goes

Meru's shopper data touches nine external systems on three continents. Two obligations bite here: you may only engage a processor under a valid contract, and you may not transfer to a country the Central Government has restricted.

Processor register 1 DPA expiring
VendorRoleCountryPurposesDPARisk
Google Analytics 4Processor🇺🇸 USAnalyticsActive → 20273/10
Meta AdsJoint controller🇺🇸 USMarketingActive → 20276/10
RazorpayProcessor🇮🇳 INPaymentsActive → 20282/10
DelhiveryProcessor🇮🇳 INFulfilmentActive → 20272/10
FreshdeskProcessor🇮🇳 INSupportExpires in 41 days3/10
KlaviyoProcessor🇺🇸 USMarketingActive → 20275/10
AWS MumbaiProcessor🇮🇳 INHostingActive → 20291/10

Each vendor carries its DPA document, a risk score from the last audit, its own DPO contact, and the list of purposes it is linked to — which is what makes the downstream erasure signal in Chapter 7 possible at all.

Cross-border transfer register
How S.16 actually works. The Act permits transfer of personal data outside India except to a country or territory the Central Government notifies as restricted. It is a negative list, not a GDPR-style adequacy whitelist — so the platform enforces against the notified restriction list rather than asking you to justify every destination.
DestinationRecipientDataBasisStatus
🇺🇸 United StatesGoogle LLCDevice ID, page eventsConsent (Analytics)Permitted
🇺🇸 United StatesKlaviyo Inc.Email, order historyConsent (Marketing)Permitted
🇸🇬 SingaporeMeru APAC PteOrder recordsIntra-groupPermitted
🇮🇳 IndiaAWS ap-south-1AllHostingDomestic
The notified list is centrally maintained and pushed to every tenant.
Records of Processing Activities

Each purpose in the registry generates a ROPA entry — data categories, principal categories, recipients, retention, sensitivity, cross-border flag. Reviewed on a cycle, snapshotted on every review, exportable as CSV or PDF for an auditor.

6
ROPA entries
2
flagged SENSITIVE
3
cross-border
The obligation

A Data Fiduciary may engage a Processor only under a valid contract, and remains responsible for compliance in respect of any processing undertaken on its behalf.

DPDP Act 2023 · S.8(2)
And

Transfer outside India is permitted except to such country or territory as the Central Government may … notify as restricted.

DPDP Act 2023 · S.16(1)
What the platform did
  • 7 processors registered with DPAs on file.
  • Expiry alert raised 41 days ahead.
  • Transfers checked against the notified list.
Act V · The organisation's own obligations

Forgetting on schedule

The most commonly ignored obligation in the Act, because it requires deleting data nobody asked you to delete. Once the purpose is served and no law requires retention, the data must go — including at your processors.

Retention clocks, per purpose
PurposeRetentionOn expiryDue in 30 daysActioned this year
Order fulfilment8 yearsManual review00
Site analytics395 daysAnonymise4,12038,004
Marketing & retargeting365 daysHard delete1,87721,455
Personalised recommendations180 daysHard delete2,90444,190
Support transcripts3 yearsManual review611,208
Security & fraudStatutoryExempt — retain
"Manual review" is a deliberate default. Automatic deletion of order records would collide with tax and consumer-law retention. The platform surfaces the expiry and makes a human decide, rather than silently destroying records you are required to keep.
Last night's retention run
retention.worker · 02:00 IST
02:00:01 scan 6 purposes · 48,219 active consent records
02:00:04 expired 1,204 items · purpose=Personalised recommendations
02:00:09 delete 1,204 rows purged · downstream signal → Klaviyo, Meta Ads
02:00:11 expired 388 items · purpose=Site analytics
02:00:14 anonymise 388 records · identifiers stripped, aggregates retained
02:00:15 review 3 items queued for DPO · purpose=Support transcripts
02:00:16 audit 1,595 RETENTION_ACTION events sealed · chain head 8f3c1a…d20b
02:00:16 done run complete in 15.4s

Anonymise and delete are different obligations with different business consequences. Analytics keeps its value once identifiers are stripped; a marketing profile does not, so it is destroyed outright.

The obligation

Where consent is withdrawn or the purpose is no longer being served, the Fiduciary shall erase the personal data, and cause its Processors to erase it, unless retention is necessary for compliance with law.

DPDP Act 2023 · S.8(7)
What the platform did
  • Expiry computed per purpose, per principal.
  • 1,595 actions taken unattended last night.
  • Every action sealed into the audit chain.
  • Statutory-retention purposes exempted explicitly.
Act V · The organisation's own obligations

The bad Tuesday

A misconfigured storage bucket at a logistics partner exposes 12,400 delivery addresses. From this moment, two clocks start and a lot of people ask for documents. The register is the difference between a controlled disclosure and a scramble.

Incident INC‑2026‑014 HIGH · CONTAINED
Title
Partner storage bucket exposed delivery manifests
Discovered
21 Jul 2026, 09:14 IST
Contained
21 Jul 2026, 11:47 IST
Severity
HIGH
Affected
12,400 data principals
Data types
Name, delivery address, phone, order ID
Projects
storefront, mobile-app
Root cause
Processor misconfiguration (Delhivery)
  • 21 Jul · 09:14
    Detected
    Reported by external researcher. Incident opened; severity set HIGH. Both clocks start here — CERT-In and DPDP.
  • 21 Jul · 09:22 T+8 min
    CERT-In notified
    "Data breach" is a reportable cyber incident under the CERT-In Directions, with a 6-hour window from noticing. Filed via the designated point of contact; acknowledgement reference stored.
  • 21 Jul · 09:31
    Board of India intimated
    Initial intimation filed without delay on becoming aware. Acknowledgement reference stored on the incident.
  • 21 Jul · 11:47
    Contained
    Bucket ACL corrected; partner credentials rotated; access logs preserved.
  • 21 Jul · 16:20
    Affected principals notified
    12,400 notices sent in EN and हिं, describing the breach, its likely consequences, the measures taken, and how to contact the Grievance Officer.
  • 23 Jul · 18:00
    Detailed report to the Board
    Full particulars, remediation and findings filed within the window set by the DPDP Rules.
  • Open
    Vendor audit & DPA review
    Delhivery risk score raised 2 → 6; out-of-cycle audit scheduled; DPA amendment requested.
Two regimes, two clocks, one incident

This is the point most breach registers miss. A data breach at an Indian company is simultaneously a DPDP event and a CERT-In cyber incident, under different statutes, to different authorities, on different clocks. Miss either and the other one does not save you.

TrackAuthorityTriggerWindowThis incident
CERT-InCERT-InReportable cyber incident
incl. data breach / data leak
6 hours of noticingFiled T+8 min
DPDP — BoardData Protection BoardPersonal data breachForm & timing per the RulesFiled T+17 min
DPDP — principalsEach affected principalPersonal data breachForm & timing per the Rules12,400 notified
The CERT-In window is a hard 6 hours from noticing, set by Directions issued under the IT Act — not by DPDP, and not configurable by you. The DPDP windows are set by the Rules. The platform holds them as separate tracks precisely so that a change to one does not silently move the other.
The standing CERT-In obligations

Reporting is the visible part. The Directions also impose continuous obligations that only matter on the day you need them — which is this day.

  • 180-day log retention, within India. Logs for the incident window were available because they were already being kept — not recovered afterwards.
  • Clock synchronisation to NIC / NPL time servers, so the timeline above is defensible rather than approximate.
  • Designated point of contact registered with CERT-In, kept current and versioned like the Grievance Officer.
  • Evidence preserved at containment, before remediation destroyed the access logs.
The evidence pack

One button produces what an inquiry asks for, assembled from records that already existed rather than reconstructed after the fact.

  • Incident record with the full timeline and every status change, attributed and timestamped.
  • Copies of both notifications — to the Board and to principals — with delivery receipts.
  • The exact list of affected principals and the data categories involved.
  • The processor's DPA, its audit history, and the risk score before and after.
  • Audit-chain extract covering the incident window, with its anchor proof.
The obligation

In the event of a personal data breach, the Data Fiduciary shall give the Board, and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed.

DPDP Act 2023 · S.8(6)
And separately

Directions issued under section 70B(6) of the IT Act 2000 require specified cyber incidents — including data breach and data leak — to be reported to CERT-In within 6 hours of noticing.

CERT-In Directions, 28 Apr 2022
Getting the law right

The form, manner and timing of DPDP breach intimation are set by the DPDP Rules, not by a number in the Act. The CERT-In 6-hour window is fixed and comes from a different statute. The platform tracks both as separate configurable tracks and dates every filing, so the record speaks for itself.

What the platform did
  • Immutable timeline from detection to closure.
  • All three notification tracks recorded separately.
  • CERT-In filed inside the 6-hour window, evidenced.
  • Linked back to the processor and its DPA.
Act V · The organisation's own obligations

When the rules get heavier

Meru has grown. The Central Government may notify any Data Fiduciary as a Significant Data Fiduciary, and that designation adds obligations no amount of good banner hygiene will satisfy: an India-resident DPO answerable to the Board, an independent auditor, and impact assessments done before processing starts rather than after something goes wrong.

Would Meru be designated? toggle what applies

The Act lets the Government weigh volume and sensitivity of data, risk to data principals' rights, and impact on sovereignty, electoral democracy, State security and public order. Designation is not something you opt into — but it is something you can see coming.

Data Protection Impact Assessment

A DPIA is not a form you file. It is the record of a decision: here is what we intend to process, here is what could go wrong for the people involved, here is what we changed as a result. Toggle the mitigations and watch residual risk move.

Processing
Personalised recommendations from browse history
Principals
All storefront visitors, incl. minors
Data
Browse history, wishlist, device ID
Assessor
Priya N. · DPO
Reviewed
25 Jul 2026
Next review
25 Jan 2027
Independent audit & algorithmic due diligence
Independent data auditor
Firm
Kaveri Assurance LLP
Engaged
02 Feb 2026
Last audit
14 Jun 2026
Findings
3 open 11 closed
DPO, based in India
Officer
Priya Nair
Reports to
Board of Directors
Also
Grievance point of contact
Published
Yes
Algorithmic due diligence. The Rules contemplate that a Significant Data Fiduciary verify that algorithmic software it deploys does not pose a risk to data principals' rights. In practice that means a register of models: what each one is trained on, which purposes feed it, whether a decision it makes affects a person, and who signed off. Meru's recommendation model is registered against the pur_personalisation purpose, so the link between consent and training data is not a matter of anyone's memory.
ModelFed by purposeAffects a person?Human reviewDPIA
Recommendation ranker v4pur_personalisationContent shownNot requiredDone
Fraud scoring v2pur_necessaryOrder can be refusedMandatoryDone
Support triage LLMpur_supportRouting onlyNot requiredDue
The obligation

A Significant Data Fiduciary shall appoint a Data Protection Officer … based in India who shall be responsible to the Board of Directors, appoint an independent data auditor, and undertake periodic Data Protection Impact Assessment and periodic audit.

DPDP Act 2023 · S.10(2)
Getting the law right

Designation is by Government notification under S.10(1) — it is not a threshold you cross automatically at some number of records. The checker above estimates exposure against the statutory factors; it does not tell you that you are an SDF.

What the platform did
    Act V · The organisation's own obligations

    Getting things actually signed

    Look back at what the last fourteen chapters produced: a DPA that must be executed with each processor, a guardian who must be verifiably identified, a principal whose identity must be checked before data is released, and a DPIA that must be signed off. Every one of those ends in a signature — and today, every one of them leaves the platform to get it.

    Where a signature closes a compliance loop
    ArtefactWho signsTodayWith signing built in
    Data Processing Agreement
    Ch 11 · S.8(2)
    Vendor's signatoryExported, emailed, signed elsewhere, re-uploaded as a PDF nobody verifiesRouted for signature, countersigned, returned to the vendor record — status moves DRAFT → ACTIVE on its own
    Verifiable parental consent built
    Ch 2 · S.9(1)
    Parent or guardianEmail OTP — proves control of a mailbox, not identityAadhaar eSign — a signature bound to a verified identity, which is a materially stronger reading of "verifiable". Try both paths in Ch 2 →
    Rights request identity built
    Ch 8 · S.11
    Data principalUpload a scan of a government ID, which you then have to store and protectDigiLocker — you get the issuer-verified assertion without ever holding the document. Try both paths in Ch 8 →
    DPIA sign-off & audit
    Ch 14 · S.10(2)
    DPO, auditor, BoardA name typed into a fieldAn attested signature on a specific version of a specific document
    Breach report
    Ch 13 · S.8(6)
    DPOFiled, attribution by loginSigned filing, dated, in the evidence pack
    Note the pattern: this is not a general document-signing product. It is signature applied to artefacts this platform already generates, where the missing signature is the reason the compliance record has a hole in it. The two rows marked built are live in this walkthrough — both offer the weaker path alongside the stronger one, so you can see what changes on the record.
    Execute a DPA
    01Draft generated
    02Sent for signature
    03Signed
    04On the vendor record
    What makes it legally a signature
    • Aadhaar eSign — an electronic signature under the IT Act's Second Schedule, delivered through a CCA-licensed eSign Service Provider. Bound to a verified identity, which is what makes it useful for guardian consent.
    • Digital Signature Certificate — a token-based DSC from a licensed Certifying Authority, for signatories who already hold one.
    • Electronic signature with audit trail — click-to-sign with IP, timestamp, and a hash of the exact document version. Weaker, but appropriate for low-risk internal attestations.
    • Stamping and stamp duty — handled by the same providers where the instrument requires it.
    Delivered through a licensed provider, not by us. Aadhaar eSign is issued by CCA-licensed entities. This platform integrates with one and holds the resulting artefact against the compliance record — it does not attempt to be a Certifying Authority. Which tier of signature is adequate for which document is a legal question for your counsel, not a product setting.
    The legal basis

    The IT Act 2000 gives legal recognition to electronic signatures and provides that a contract shall not be deemed unenforceable solely on the ground that electronic form was used.

    IT Act 2000 · S.3A S.5 S.10A
    Where it does not apply

    The IT Act's First Schedule excludes certain instruments from electronic execution — negotiable instruments other than cheques, powers of attorney, trusts, wills, and contracts for sale or conveyance of immovable property. None of them arise in a compliance workflow, but the exclusion is worth knowing before promising "sign anything".

    What the platform did
      Act V · The organisation's own obligations

      Does the app actually obey?

      Everything so far records what Aarav agreed to. None of it stops Meru's own backend from doing something else. The data sits in Meru's database, and an engineer with a psql prompt can do as they please. So the honest question a technical buyer asks is: what actually enforces this?

      The gap, stated plainly
      What a consent record proves
      That the data principal was asked, and what they answered. Evidentiary, and necessary — but it is a statement about the past.
      What it does not prove
      That the nightly campaign job checked before it selected every user and handed the list to an email provider. That is a statement about behaviour, and it needs a different mechanism.
      No consent platform can close this completely — and any vendor who says otherwise is overselling. Under S.8(2) the Data Fiduciary stays responsible regardless of any contract with a processor. What a platform can do is make the compliant path the cheap path, and make not asking visible by its absence.
      The decision point server-to-server, before processing

      Meru's backend asks before it acts. The answer below is computed from the consent you gave back in Chapter 3 — change it there and this changes with it.

      No consent on record yet. Complete Chapter 3 first.

      Make the gated path the lazy path

      A control that costs a developer extra keystrokes is a control that gets skipped under deadline. So the SDK is written so that checking is shorter than not checking.

      // One principal, one purpose
      if (await dpdp.allows({ externalId: user.id }, "marketing")) {
        await sendCampaignEmail(user);
      }
      
      // The case that actually bites — filter before a bulk send
      const sendable = await dpdp.filterAllowed(allUsers, (u) => u.id, "marketing");
      await esp.send(sendable);
      • Fails closed. If the gate is unreachable the SDK denies — not being able to establish that processing is permitted is a reason to stop, not to continue.
      • Cached both sides, so a check costs less than the branch you would have written anyway.
      • Withdrawal is immediate. Withdrawing drops the cached snapshot, so the very next check reflects it.
      • Never a bare boolean. Every answer carries a reason, so a refusal is actionable and a support ticket is answerable.
      The decision log, six months on

      This is the sentence that changes the conversation with a regulator. Not "we hold 48,219 consents" — a claim about paperwork — but "the application asked 4.2 million times and was refused 380,000 times", a claim about behaviour, with counts to back it.

      42,14,880
      authorization checks
      38,34,102
      allowed
      3,80,778
      refused
      PurposeChecksAllowedRefusedTop reason for refusal
      Counted, not itemised. Decisions are rolled up hourly per purpose. A row per check would name a data principal every single time — rebuilding exactly the personal-data pile the gate exists to avoid, and becoming the largest table in the system inside a week. The evidentiary weight is in the counts.
      Verify, don't trust

      A gate only governs the code that calls it. The layer above it is reconciliation — comparing what consent permits against what the world actually observed.

      drift detection · nightly
      02:40:01 reconcile purpose=marketing · consents=12,400 · vendor-reported sends=12,388 OK
      02:40:03 reconcile purpose=analytics · consents=29,551 · GA4 events=29,512 OK
      02:40:04 egress declared processors=7 · observed destinations=8
      02:40:04 drift undeclared destination: api.sendgrid.net — no vendor record, no DPA
      02:40:05 alert DPO notified · vendor register flagged for review

      The cookie scanner in Chapter 1 is this same idea pointed at the browser. This is it pointed at the server.

      The obligation

      A Data Fiduciary shall implement appropriate technical and organisational measures to ensure effective observance of the provisions of this Act.

      DPDP Act 2023 · S.8(4)
      Where the boundary is

      Under S.8(2) the Fiduciary remains responsible for any processing done on its behalf, whatever the contract says. This platform supplies the measure and the evidence. You remain the Fiduciary. That boundary is in the docs and the contract, not just this slide.

      What the platform did
        Act V · Close

        Everything, on one page

        Seventeen chapters, one shopper, one platform. Here is the full surface — including the parts that never appear in a demo but decide whether your security team signs off.

        Your walkthrough, replayed
        Enterprise & platform
        • SSO — SAML 2.0 and OIDC, per organisation, with domain-based routing.
        • SCIM 2.0 — automatic user provisioning and deprovisioning from your IdP.
        • MFA — TOTP with recovery codes, enforceable org-wide.
        • Custom roles — granular permissions beyond Owner / Admin / Viewer.
        • REST API — scoped keys, IP allow-lists, rate tiers, per-request logging.
        • Webhooks — signed delivery with retries for consent, rights and breach events.
        • Multi-tenant — organisations, projects, isolated keys and documents per project.
        • Admin console — tenant oversight, impersonation with audit, restricted-country list.
        Measurement
        • Consent analytics — opt-in by purpose, by geography, by notice version.
        • Banner A/B testing — variants measured on consent rate and complaint rate.
        • Compliance reports — rights volumes, targets met, retention actions, breaches.
        • Audit log — every administrative action, hash-chained and exportable.
        Coverage map
        SectionObligationWhere you saw it
        S.5Notice: data sought, purpose, how to withdraw, how to complainCh 1, Ch 10
        S.6(1)Free, specific, informed, unambiguous consentCh 3
        S.6(4)Withdrawal as easy as giving consentCh 7
        S.6(6)Cease processing on withdrawal, including at processorsCh 7, Ch 12
        S.8(2)Processors engaged only under valid contractCh 11
        S.8(4)Technical and organisational measuresCh 5, Ch 6
        S.8(6)Breach intimation to the Board and to principalsCh 13
        S.8(7)Erasure when purpose is served or consent withdrawnCh 12
        S.8(9)Published contact for the DPO or responsible personCh 9
        S.9Verifiable parental consent; no tracking or targeted ads at childrenCh 2
        S.11Right to access information about processingCh 8
        S.12Right to correction, completion, updating and erasureCh 8
        S.13Right of grievance redressalCh 9
        S.14Right to nominateCh 8
        S.16Cross-border transfer, restricted-country modelCh 11
        S.10Significant Data Fiduciary: India-based DPO, independent auditor, DPIACh 14
        Beyond DPDP
        IT Act 70B(6)CERT-In cyber incident reporting, 6-hour window; 180-day logsCh 13
        IT Act 3AElectronic signature: DPA execution, guardian consent, attestationsCh 15
        Demonstration only. Section references describe design intent and are not legal advice; where the Act delegates a matter to the DPDP Rules, this walkthrough says so instead of stating a number. Meru Retail, Aarav Menon and all figures shown are fictional.
        Session summary
          Next step

          Run this walkthrough against your site: point the cookie scanner at your domain, and the first three chapters become a real inventory instead of a demo.