> ## Documentation Index
> Fetch the complete documentation index at: https://docs.grantex.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Consent Notice

> Register a version of a consent notice (DPDP Act s.5, DPDP Rules 2025 r.3). Consent records name the version shown; its content hash is bound into the record's signed proof.

## Endpoint

```
POST /v1/dpdp/consent-notices
```

## Authentication

Requires a developer API key in the `Authorization` header.

## Request Headers

| Header | Value |
| - | - |
| `Authorization` | `Bearer <api_key>` |
| `Content-Type` | `application/json` |

## Request Body

| Field | Type | Required | Description |
| - | - | - | - |
| `noticeId` | `string` | Yes | A developer-chosen identifier for the notice (e.g., `"privacy-notice"`) |
| `version` | `string` | Yes | Version string (e.g., `"2.0"`) |
| `title` | `string` | Yes | Human-readable notice title |
| `content` | `string` | Yes | Full consent notice content (HTML or plain text) |
| `purposes` | `object[]` | Yes | Array of purpose objects (`{ code, description }`) |
| `language` | `string` | No | ISO language code (default: `"en"`). One `noticeId` and `version` may be registered once per language |
| `dataFiduciaryContact` | `string` | No | Contact information for the data fiduciary |
| `grievanceOfficer` | `object` | No | Grievance officer details (`{ name, email, phone? }`) |
| `itemisedPersonalData` | `object[]` | No | `{ category, description }` for each item of personal data |
| `purposeDetails` | `object[]` | No | `{ code, description, goodsOrServices }` for each specific purpose; `code` must be one of `purposes` |
| `withdrawalUrl` | `string` | No | Where consent is withdrawn (http or https URL) |
| `rightsUrl` | `string` | No | Where the principal exercises their rights |
| `boardComplaintUrl` | `string` | No | How to complain to the Data Protection Board |
| `contact` | `object` | No | DPO or contact person: `{ name?, designation?, email?, phone?, address? }`, with an email or a phone |

The structured fields and the `validation` block in the response are
described in [Consent Notice Content](/api-reference/dpdp/consent-notice-content).

## Example Request

```bash theme={null}
curl -X POST https://api.grantex.dev/v1/dpdp/consent-notices \
  -H "Authorization: Bearer gx_..." \
  -H "Content-Type: application/json" \
  -d '{
    "noticeId": "privacy-notice",
    "version": "2.0",
    "title": "Data Processing Consent Notice",
    "content": "We collect and process your data for the following purposes...",
    "purposes": [
      { "code": "analytics", "description": "Usage analytics for service improvement" },
      { "code": "personalization", "description": "Personalized recommendations" }
    ],
    "language": "en",
    "grievanceOfficer": {
      "name": "Jane Doe",
      "email": "grievance@example.com"
    }
  }'
```

## Response -- 201 Created

```json theme={null}
{
  "id": "notice_01HXYZ...",
  "noticeId": "privacy-notice",
  "version": "2.0",
  "language": "en",
  "contentHash": "a1b2c3d4e5f6...",
  "noticeHash": "9f8e7d6c5b4a...",
  "createdAt": "2026-04-05T12:00:00.000Z",
  "validation": {
    "basis": "DPDP Rules 2025 r.3",
    "enforced": false,
    "complete": false,
    "present": ["language"],
    "missing": ["itemisedPersonalData", "specificPurposes", "withdrawalMeans", "rightsMeans", "boardComplaintMeans"],
    "language": { "tag": "en", "name": "English", "englishOrEighthSchedule": true }
  }
}
```

## Response Fields

| Field | Type | Description |
| - | - | - |
| `id` | `string` | Unique internal notice ID |
| `noticeId` | `string` | Developer-chosen notice identifier |
| `version` | `string` | Version string |
| `language` | `string` | ISO language code |
| `contentHash` | `string` | SHA-256 hash of the notice content |
| `noticeHash` | `string` | SHA-256 over the canonical JSON of the whole notice, structured fields, language and version included (see [Consent Notice Content](/api-reference/dpdp/consent-notice-content#the-notice-hash)) |
| `createdAt` | `string` | ISO-8601 creation timestamp |
| `validation` | `object` | Which DPDP Rules 2025 r.3 elements the notice has; see [Consent Notice Content](/api-reference/dpdp/consent-notice-content) |

## Error Responses

| Status | Code | Description |
| - | - | - |
| 400 | `BAD_REQUEST` | Missing or malformed fields (`noticeId`, `version`, `title`, `content`, a non-empty `purposes` array of `{ code, description }`; `content` up to 100,000 characters; malformed structured fields) |
| 400 | `NOTICE_INCOMPLETE` | Only with `DPDP_NOTICE_REQUIRE_RULE3=true`: an r.3 element is missing, or the language is not English or an Eighth Schedule language |
| 401 | `UNAUTHORIZED` | Invalid or missing API key |
| 409 | `CONFLICT` | This `noticeId` already has this `version` in this `language`. Only that conflict is a 409; other failures are errors, not conflicts |

The notice is recorded on the audit chain as `grantex.dpdp.notice_created`.
List notices with [List Consent Notices](/api-reference/dpdp/list-consent-notices)
and read every version of one with [Get Consent Notice](/api-reference/dpdp/get-consent-notice).

## SDK Examples

<CodeGroup>
  ```typescript TypeScript theme={null}
  import { Grantex } from '@grantex/sdk';

  const grantex = new Grantex({ apiKey: 'gx_...' });

  const notice = await grantex.dpdp.createConsentNotice({
    noticeId: 'privacy-notice',
    version: '2.0',
    title: 'Data Processing Consent Notice',
    content: 'We collect and process your data...',
    purposes: [
      { code: 'analytics', description: 'Usage analytics' },
    ],
    grievanceOfficer: {
      name: 'Jane Doe',
      email: 'grievance@example.com',
    },
  });
  ```

  ```python Python theme={null}
  from grantex import CreateConsentNoticeParams, Grantex

  grantex = Grantex(api_key="gx_...")

  notice = grantex.dpdp.create_consent_notice(
      CreateConsentNoticeParams(
          notice_id="privacy-notice",
          version="2.0",
          title="Data Processing Consent Notice",
          content="We collect and process your data...",
          purposes=[{"code": "analytics", "description": "Usage analytics"}],
          grievance_officer={"name": "Jane Doe", "email": "grievance@example.com"},
      )
  )
  ```
</CodeGroup>

To send the structured r.3 fields (`itemisedPersonalData`, `purposeDetails`,
`withdrawalUrl`, `rightsUrl`, `boardComplaintUrl`, `contact`), use the REST
call above unless your SDK version lists them.

## Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: [sanjeev@orchestrum.in](mailto:sanjeev@orchestrum.in) or [mishra.sanjeev@gmail.com](mailto:mishra.sanjeev@gmail.com).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.