
India’s DPDP Act: what consent managers must get right
The Digital Personal Data Protection Act, 2023 recasts consent as a recorded, purpose-bound choice. Here is how platforms should operationalize it.
Sep 2, 2026 · 8 min read
Blogs
Stay relevant with news of DPDP Act.

The Digital Personal Data Protection Act, 2023 recasts consent as a recorded, purpose-bound choice. Here is how platforms should operationalize it.
Sep 2, 2026 · 8 min read

Article 6 is not a menu of convenience. Consent and legitimate interest have different tests, different UX, and different failure modes.
Aug 28, 2026 · 7 min read

Privacy policies describe intent. A consent manager enforces it — across banners, SDKs, vendors, and audits.
Aug 22, 2026 · 6 min read

California’s privacy law is opt-out first for sale and sharing. Your banner, GPC handling, and “Do Not Sell” link have to agree.
Aug 18, 2026 · 7 min read

Brazil’s LGPD looks familiar to GDPR teams, but ANPD guidance, Portuguese notices, and children’s rules still catch global brands off guard.
Aug 12, 2026 · 6 min read

Canada’s federal private-sector law asks whether a reasonable person would understand what they agreed to — not whether a box was ticked.
Aug 6, 2026 · 6 min read

Singapore’s PDPA allows exceptions, but notification and purpose limitation still require a disciplined consent and preference layer.
Jul 30, 2026 · 6 min read

Thailand’s PDPA is now an enforcement reality. Transfers, cookies, and consent records need the same rigor as EU programs.
Jul 24, 2026 · 6 min read

Korea’s PIPA is known for detailed, purpose-specific consent. Generic EU banners usually fail on day one.
Jul 18, 2026 · 7 min read

APPI amendments tightened sharing rules. Cookie and advertising programs still need a clear, Japan-specific story.
Jul 12, 2026 · 6 min read

Reforms around children’s privacy, consent, and OAIC enforcement are pushing Australian programs beyond a static policy page.
Jul 6, 2026 · 6 min read

UK GDPR still looks like EU GDPR, but ICO guidance, PECR cookies, and the Data (Use and Access) trajectory deserve their own configuration.
Jun 28, 2026 · 6 min read

POPIA puts a premium on responsible parties, operator agreements, and conditions for processing. Consent is only one of several paths.
Jun 20, 2026 · 6 min read

The UAE’s PDPL sits alongside DIFC and ADGM regimes. Multi-entity groups need jurisdiction-aware consent, not one Gulf-wide banner.
Jun 12, 2026 · 6 min read

Saudi Arabia’s PDPL and SDAIA regulations raise the bar on consent quality, sensitive data, and when data should stay in-kingdom.
Jun 4, 2026 · 6 min read

PIPL expects separate consent for sensitive personal information, public disclosure, and many cross-border transfers. Bundling is a liability.
May 28, 2026 · 7 min read

Reject as easily as accept, no pre-ticked boxes, real blocking before consent, and receipts you can produce in an investigation.
May 20, 2026 · 7 min read

When a regulator or customer asks “prove it,” screenshots of a banner are not enough. Here is the evidence pack a CMP should produce.
May 12, 2026 · 8 min read

DPDP, GDPR, and LGPD all expect withdrawal without detriment. That is a preference-center problem, not a help-desk ticket.
May 4, 2026 · 6 min read

Banners capture a moment. Preference centers manage a relationship — channels, purposes, and vendors over the life of an account.
Apr 26, 2026 · 6 min read

TCF strings are how many European ad ecosystems hear consent. GPP extends that idea to US state signals. Your CMP should speak both.
Apr 18, 2026 · 8 min read

Minors’ data is not a smaller GDPR. It is a different regime — parental authority, restricted processing, and age assurance.
Apr 10, 2026 · 7 min read

SCCs, adequacy, and localization sit beside consent. Mixing them up is how global products fail DPIAs.
Apr 2, 2026 · 7 min read

Most “consent failures” are actually vendor-graph failures: a pixel nobody owned, on a purpose nobody mapped.
Mar 24, 2026 · 6 min read

Web banners do not cover iOS App Tracking Transparency or Play policy. Apps need the same purpose model with a different runtime.
Mar 16, 2026 · 6 min read

One product, many laws. The winning pattern is a shared purpose catalog plus jurisdiction rules — not 12 unrelated banners.
Mar 8, 2026 · 8 min read

Access, deletion, and portability requests stall when consent logs live in a tag manager and CRM lives somewhere else.
Feb 28, 2026 · 6 min read

Regulators want age-appropriate design. Users want to finish signup. The middle path is risk-based assurance plus a guardian flow.
Feb 18, 2026 · 6 min read

When software acts on a user’s behalf, yesterday’s cookie toggle is not enough. Agent permissioning needs purpose, scope, and revocation.
Feb 8, 2026 · 7 min read

From DPDP and GDPR to CPRA, LGPD, PIPL, and PDPL regimes, the common thread is choice you can enforce. Here is the map.
Jan 28, 2026 · 9 min read
Create an account, add a website, and publish a consent banner. A public mailing list is not open yet.
Product updates ship in the workspace. A public mailing list is not open yet.