Skip to main content

DPDPA-aligned consent — what we collect and why

Updated 2026-06-09 · 5 min read · CampusPlugin compliance desk

CampusPlugin uses DPDPA-aligned consent workflows for every student record we hold on behalf of an institution. The Indian Digital Personal Data Protection Act 2023 §9(2) requires that a consent record name the data principal, the purpose, the categories of personal data, the entities the data is shared with, and the channel by which the consent was captured.

Every student consent we issue carries a receipt id and a sha256 fingerprint of the consent text the student saw. The receipt is stored alongside the consent and can be re-pulled at any time — by the student through the wallet, by the institution through the placement workbench, or by a regulator through a CAG export bundle.

We do not claim DPDPA compliance. Compliance is a finding made by a competent authority against an operator end to end. What we claim is that the workflow is aligned with the Act and that the receipt format matches what an auditor would expect to see.

A consent withdrawal is irreversible from our side. Withdrawing consent on a category invalidates downstream chain seals that depended on that category and re-issues a fresh seal flag the institution can act on.

Related

A note on language

This article aligns with the platform compliance language module. We do not claim "official", "certified", or "compliant" status anywhere unless an authority has specifically issued that finding. Where we say "aligned with", we mean the workflow matches the format an auditor would expect to see — not that an audit has been done.

CampusPlugin is not a regulator. We provide tools and frameworks aligned with known regulator schemas. Compliance, filing and regulator acceptance remain the responsibility of the institution, corporate or scheme owner.

Read what we do and don't claim →