A consent artefact is a structured, machine-readable record of a single consent: who consented, to what purpose, over what data, for how long, against which version and language of the notice, and when. It is what turns a claim that consent was obtained into evidence that it was.
The concept comes from India's account-aggregator and DEPA work, where consent has to travel between parties in a form each can verify. The same idea is what makes DPDP consent auditable.
The test of an implementation is withdrawal: a consent artefact should carry its own revocation, and revoking it should stop the processing it authorised rather than simply marking a row inactive.
General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.
Dinkar Singh — Dinkar covers privacy engineering at ProtectComply — discovery, consent propagation and the evidence trail behind them.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →