CampusPlugin uses DPDPA-aligned consent workflows for every student record we hold on behalf of an institution. The Indian Digital Personal Data Protection Act 2023 §9(2) requires that a consent record name the data principal, the purpose, the categories of personal data, the entities the data is shared with, and the channel by which the consent was captured.
Every student consent we issue carries a receipt id and a sha256 fingerprint of the consent text the student saw. The receipt is stored alongside the consent and can be re-pulled at any time — by the student through the wallet, by the institution through the placement workbench, or by a regulator through a CAG export bundle.
We do not claim DPDPA compliance. Compliance is a finding made by a competent authority against an operator end to end. What we claim is that the workflow is aligned with the Act and that the receipt format matches what an auditor would expect to see.
A consent withdrawal is irreversible from our side. Withdrawing consent on a category invalidates downstream chain seals that depended on that category and re-issues a fresh seal flag the institution can act on.