{"id":1956,"date":"2025-06-21T15:19:40","date_gmt":"2025-06-21T15:19:40","guid":{"rendered":"https:\/\/frslabs.com\/frsblog\/?p=1956"},"modified":"2025-06-23T02:57:19","modified_gmt":"2025-06-23T02:57:19","slug":"consent-management-brd-useful-guide-or-narrow-vision","status":"publish","type":"post","link":"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/","title":{"rendered":"Consent Management System BRD \u2013 Useful Guide or Narrow Vision?"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large is-resized is-style-rounded\"><a href=\"https:\/\/frslabs.com\/frsblog\/wp-content\/uploads\/2025\/06\/Firefly_Two-indian-programmers-in-casual-clothes-discussing-with-a-lot-of-flowcharts-written-533881.jpg\"><img loading=\"lazy\" src=\"https:\/\/frslabs.com\/frsblog\/wp-content\/uploads\/2025\/06\/Firefly_Two-indian-programmers-in-casual-clothes-discussing-with-a-lot-of-flowcharts-written-533881-750x400.jpg\" alt=\"Consent Management BRD\" class=\"wp-image-1957\" width=\"838\" height=\"447\"\/><\/a><\/figure>\n\n\n\n<p>There is a lot of buzz around a Business Requirements Document (BRD) that was published by NeGD (National e-Governance Division) and MeitY as a guide to build Consent Management Systems. This was released as part of the DPDP Innovations Challenge on 15 April 2025 \u2013 You can find the full details <a href=\"https:\/\/msh.meity.gov.in\/whatsnew\">here<\/a>. The idea being, the final version selected through the competition will be released as public good (open-sourced) for people to pick up and work on further.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote\"><p><br>Here\u2019s the disclaimer from MEITY: \u201cBy participating in this coding challenge, contributors agree to grant MeitY a nonexclusive, royalty-free license to use, publish, and distribute their submitted code as open-source under a suitable license and General Licensing Arrangement. Selected submissions will be hosted on a public repository for free community use and further development. Contributors retain the right to continue working on their code and confirm that their submissions are original and do not infringe on any third-party rights\u201d.<\/p><\/blockquote>\n\n\n\n<p><\/p>\n\n\n\n<p>Some say this is meant for \u201cConsent Managers\u201d \u2013 a different concept altogether in the DPDPA \u2013 interpreted based on the inconsistent wordings within the document perhaps. Our take is that this is meant to act as a guide for developers building the consent management layer within the ambit of the larger DPDPA landscape. Even better for those who already have a consent management system to see if they are able to cover most, if not all, if the functional requirements. However, this definitely is not a holy grail of a CMS (as it\u2019s missing several crucial features) or an extension to the DPD Act or DPDP Rules.<br><br>So, let\u2019s dive in.<\/p>\n\n\n\n<p>There are broadly three aspects to Data Privacy compliance \u2013 a data discovery module (know your systems and the policies and purposes that govern the data you collect, process, store, and share), a consent registry module (the entire consent lifecycle from collection through to expiry), and a data residency module (ensure data resides safely and is handled securely). While the BRD covers the mid-segment of the DPDPA like consent lifecycle, grievance redressal, logging processing activities, and so on, it doesn\u2019t cover aspects such as gap assessment, data discovery, system lifecycle, data mapping, vendor risk management, breach notification, periodic impact assessment, right to nominate, age verification, and so on \u2013 so it\u2019s a bit narrow in its scope.<br><br>Let\u2019s look at a short summary here.<\/p>\n\n\n\n<p><strong>Consent Management Lifecycle<\/strong> \u2013 This is pretty clear in the DPDP Act and the DPDP Rules, which have detailed notes on providing clear, multilingual, independently understood (no links or consent groupings) consent with itemised description, purpose, and user rights over modifications, withdrawal, and revocation. So, the BRD just elaborates on it with a ton of assumptions that most Fiduciaries will find perplexing. We recommend using the DPDP Act and the Rules as a foundation rather than the BRD.<\/p>\n\n\n\n<p><strong><br>Cookie Consent<\/strong> \u2013 While the DPDP Act does not explicitly talk about cookies, it is wise to consider them as a source of PII data collection on websites and hence provide a cookie banner with the option to accept or deny such cookies. We recommend having a simple cookie banner to start with, along with their purpose and retention period, to build trust. Multi-language support would be overkill for cookie banners, but it\u2019s a choice for individual Fiduciaries.<\/p>\n\n\n\n<p><strong><br>User Dashboard<\/strong> \u2013 A lot of attention has been given to having a self-service portal for consent management. This would surely make most Bankers run like their heads were on fire. The path I see is that most regulated entities would at least like to provide this behind a security wall such as online banking or a mobile banking app under a Privacy Centre function (with all of the internal plumbing within the DMZ). This would avoid phishing links and other threats that could allow bad actors to exploit innocent customers in the name of consent updation (much like how KYC updation was hijacked by fraudsters). A self-service portal is not mandated in the DPDP Act, so DFs can use this at their discretion.<\/p>\n\n\n\n<p><strong><br>Consent Notifications<\/strong> \u2013 These are general transaction notifications as one navigates the consent lifecycle (as and when the consent record is changed). The BRD talks about notifications such as consent expiry in Section 4.1.4, which states: <em>\u201cFor consents with predefined expiration dates, provide renewal options prior to expiration; Notify the user 30 days before consent expiry and provide a seamless renewal process.\u201d <\/em>The whole idea of consent and data minimisation and purpose limitation is to ensure that the data is used only up to the necessary period and erased thereafter. So not quite sure intimating to renew consent is a good idea. And would citizens even care?<\/p>\n\n\n\n<p><strong><br>Grievance Redressal<\/strong> \u2013 The BRD covers a detailed workflow of a typical grievance workflow of initiation, recording, assignment, escalation, etc., so it is a good starting point for anyone trying to develop this module into their CMS. There is a mention of pre-defined workflows that cater to different complaint categories, but to start with, we recommend having a really simple way for users to raise a complaint \u2013 email, portal or app. The same is recorded and a Case ID is assigned for tracking purposes. The case is then assigned automatically to the right stakeholder group to investigate and respond. Once the case is resolved, it should be closed. And the system should maintain all of the audit logs. Notifications can be sent to the users once the case is created and once the case is closed (or intermediate ones if there is more information needed from the requestor). There should certainly be an option to escalate if the grievance is not resolved within a certain time period or if the resolution is not satisfactory to the data principal.<br><br><\/p>\n\n\n\n<p><strong>System Administration<\/strong> \u2013 These are the standard bells and whistles any good system worth their salt should have by default. These things cover details such as user management, role management, audit logs, and so on. One important function mentioned under System Administration is the <\/p>\n\n\n\n<p><br><strong>Data Retention Policy<\/strong>. We strongly recommended that this is taken up alongside system, policies, and purposes \u2013 way up the development chain, as it is a crucial function to be tackled by the business and not by the administrators.<br><\/p>\n\n\n\n<blockquote class=\"wp-block-quote\"><p>If you are looking for an end to end DPDPA solution &#8211; not just bits and pieces &#8211; then look no further than <strong>ATLAS DPDP<\/strong> solution that covers the entire gamut of DPDPA compliance covering Assessments, Data Discovery, Data Classification, Consent Lifecycle, Processing Activities, Requests and Grievances, Breach Management, Admin Functions and many more. You can get an overview <a href=\"https:\/\/www.frslabs.com\/dpdp\/\">here<\/a> and book a demo <a href=\"https:\/\/www.frslabs.com\/book-demo\/\">here<\/a>. <br><\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>There is a lot of buzz around a Business Requirements Document (BRD) that was published by NeGD (National e-Governance Division) and MeitY as a guide to build Consent Management Systems. This was released as part of the DPDP Innovations Challenge on 15 April 2025 \u2013 You can find the full details here. The idea being, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_s2mail":"yes"},"categories":[144,146,157],"tags":[140,149,155],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v16.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Consent Management System BRD \u2013 Useful Guide or Narrow Vision? - FRSLABS<\/title>\n<meta name=\"description\" content=\"A Consent Management System Business Requirements Document (BRD) published by NeGD and MEITY to encourage open source CMS technology.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Administrator\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.frslabs.com\/frsblog\/#website\",\"url\":\"https:\/\/www.frslabs.com\/frsblog\/\",\"name\":\"FRSLABS\",\"description\":\"Privacy Protection | Identity Verification | Fraud Managment\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.frslabs.com\/frsblog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/frslabs.com\/frsblog\/wp-content\/uploads\/2025\/06\/Firefly_Two-indian-programmers-in-casual-clothes-discussing-with-a-lot-of-flowcharts-written-533881-750x400.jpg\",\"contentUrl\":\"https:\/\/frslabs.com\/frsblog\/wp-content\/uploads\/2025\/06\/Firefly_Two-indian-programmers-in-casual-clothes-discussing-with-a-lot-of-flowcharts-written-533881-750x400.jpg\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/#webpage\",\"url\":\"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/\",\"name\":\"Consent Management System BRD \\u2013 Useful Guide or Narrow Vision? - FRSLABS\",\"isPartOf\":{\"@id\":\"https:\/\/www.frslabs.com\/frsblog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/#primaryimage\"},\"datePublished\":\"2025-06-21T15:19:40+00:00\",\"dateModified\":\"2025-06-23T02:57:19+00:00\",\"author\":{\"@id\":\"https:\/\/www.frslabs.com\/frsblog\/#\/schema\/person\/657ea203e71d3e4b66e9f38978a07106\"},\"description\":\"A Consent Management System Business Requirements Document (BRD) published by NeGD and MEITY to encourage open source CMS technology.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.frslabs.com\/frsblog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Consent Management System BRD \\u2013 Useful Guide or Narrow Vision?\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.frslabs.com\/frsblog\/#\/schema\/person\/657ea203e71d3e4b66e9f38978a07106\",\"name\":\"Administrator\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.frslabs.com\/frsblog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/87e672de14f97b42ba0ccc3bf96d4c1f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/87e672de14f97b42ba0ccc3bf96d4c1f?s=96&d=mm&r=g\",\"caption\":\"Administrator\"},\"url\":\"https:\/\/www.frslabs.com\/frsblog\/author\/administrator\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Consent Management System BRD \u2013 Useful Guide or Narrow Vision? - FRSLABS","description":"A Consent Management System Business Requirements Document (BRD) published by NeGD and MEITY to encourage open source CMS technology.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/","twitter_misc":{"Written by":"Administrator","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/www.frslabs.com\/frsblog\/#website","url":"https:\/\/www.frslabs.com\/frsblog\/","name":"FRSLABS","description":"Privacy Protection | Identity Verification | Fraud Managment","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.frslabs.com\/frsblog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/#primaryimage","inLanguage":"en-US","url":"https:\/\/frslabs.com\/frsblog\/wp-content\/uploads\/2025\/06\/Firefly_Two-indian-programmers-in-casual-clothes-discussing-with-a-lot-of-flowcharts-written-533881-750x400.jpg","contentUrl":"https:\/\/frslabs.com\/frsblog\/wp-content\/uploads\/2025\/06\/Firefly_Two-indian-programmers-in-casual-clothes-discussing-with-a-lot-of-flowcharts-written-533881-750x400.jpg"},{"@type":"WebPage","@id":"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/#webpage","url":"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/","name":"Consent Management System BRD \u2013 Useful Guide or Narrow Vision? - FRSLABS","isPartOf":{"@id":"https:\/\/www.frslabs.com\/frsblog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/#primaryimage"},"datePublished":"2025-06-21T15:19:40+00:00","dateModified":"2025-06-23T02:57:19+00:00","author":{"@id":"https:\/\/www.frslabs.com\/frsblog\/#\/schema\/person\/657ea203e71d3e4b66e9f38978a07106"},"description":"A Consent Management System Business Requirements Document (BRD) published by NeGD and MEITY to encourage open source CMS technology.","breadcrumb":{"@id":"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.frslabs.com\/frsblog\/2025\/06\/21\/consent-management-brd-useful-guide-or-narrow-vision\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.frslabs.com\/frsblog\/"},{"@type":"ListItem","position":2,"name":"Consent Management System BRD \u2013 Useful Guide or Narrow Vision?"}]},{"@type":"Person","@id":"https:\/\/www.frslabs.com\/frsblog\/#\/schema\/person\/657ea203e71d3e4b66e9f38978a07106","name":"Administrator","image":{"@type":"ImageObject","@id":"https:\/\/www.frslabs.com\/frsblog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/87e672de14f97b42ba0ccc3bf96d4c1f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/87e672de14f97b42ba0ccc3bf96d4c1f?s=96&d=mm&r=g","caption":"Administrator"},"url":"https:\/\/www.frslabs.com\/frsblog\/author\/administrator\/"}]}},"_links":{"self":[{"href":"https:\/\/www.frslabs.com\/frsblog\/wp-json\/wp\/v2\/posts\/1956"}],"collection":[{"href":"https:\/\/www.frslabs.com\/frsblog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.frslabs.com\/frsblog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.frslabs.com\/frsblog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.frslabs.com\/frsblog\/wp-json\/wp\/v2\/comments?post=1956"}],"version-history":[{"count":7,"href":"https:\/\/www.frslabs.com\/frsblog\/wp-json\/wp\/v2\/posts\/1956\/revisions"}],"predecessor-version":[{"id":1964,"href":"https:\/\/www.frslabs.com\/frsblog\/wp-json\/wp\/v2\/posts\/1956\/revisions\/1964"}],"wp:attachment":[{"href":"https:\/\/www.frslabs.com\/frsblog\/wp-json\/wp\/v2\/media?parent=1956"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.frslabs.com\/frsblog\/wp-json\/wp\/v2\/categories?post=1956"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.frslabs.com\/frsblog\/wp-json\/wp\/v2\/tags?post=1956"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}