Launch Overview

Protean eGov Technologies Limited unveiled its Enterprise DPDP Governance & Consent Platform at the Global Fintech Fest in Mumbai on 24 September 2026. The inauguration was performed at the Protean pavilion by Shri Suvendu Pati, Chief General Manager of the FinTech Department at the Reserve Bank of India, who highlighted consent as a design principle for India’s digital financial ecosystem.

Platform Architecture and Features

At the core of the solution is a consent stack that embeds DPDP‑compliant consent journeys directly within an enterprise’s existing web, mobile, branch, contact‑centre and partner channels, ensuring the customer never leaves the transaction flow. When a customer grants, updates, or withdraws consent, a policy engine validates the request, automatically propagates it to every mapped enterprise application and third‑party processor, tracks acknowledgements, and records an immutable artefact in a consent vault. This creates regulator‑ready evidence without a separate reconciliation exercise.

Governance Pillars

The platform consolidates the eight statutory obligations of a Data Fiduciary into four operating pillars:

  • Internal Privacy Governance – data discovery, Record of Processing Activities (ROPA), data‑flow mapping, gap assessment and governance dashboards.
  • Processor Risk Governance – Data Protection Impact Assessments (DPIA), a central processor registry, third‑party risk assessment and remediation tracking.
  • Data Principal Governance – consent management, rights‑management portal, grievance redressal, and dedicated workflows for minors and nominees.
  • Regulatory Operations – retention and deletion, breach management, audit monitoring and compliance reporting.

Compliance Automation

Retention runs on configurable, purpose‑based timelines with automated deletion triggers that propagate to processors and generate deletion evidence. Breach management follows a 72‑hour notification workflow, escalates to regulator communication, and proceeds through root‑cause analysis to closure. Relationship‑based workflows enforce verifiable guardian consent for minors, with age validation and automatic transition upon attaining majority, and enable nominee registration with identity validation and auditable rights access upon a defined invocation event.

Six‑Stage Maturity Path

Protean outlines a six‑stage path to compliance maturity: (1) data discovery and ROPA, (2) data‑flow mapping, (3) DPIA and processor assessment, (4) gap remediation, (5) continuous privacy operations, and (6) advisory, governance, process design and technology enablement combined in a single engagement.

Protean Background

Incorporated in December 1995, Protean eGov Technologies Limited develops citizen‑centric, population‑scale e‑governance solutions and holds an Account Aggregator licence. Over two decades, it has built and operated national digital public infrastructure and implemented consent‑management capabilities for initiatives such as Bima Sugam and CERSAI. The company collaborates extensively with the Indian government on digital public‑infrastructure projects.

Executive Remarks

  • Shri Suvendu Pati (RBI) emphasized that the DPDP Act shifts consent from paperwork to design, urging the financial sector to make consent verifiable, revocable and auditable at scale.
  • Ajay Rajan, MD & CEO, Protean eGov Technologies, stated that privacy is an enterprise capability that builds trust, allowing firms to do more rather than less.
  • Rakesh Dosi, Chief Business & Product Officer, Protean, highlighted that while many enterprises can publish privacy policies, few can demonstrate per‑customer consent traceability across downstream systems—capability the new platform provides.