> ## Documentation Index
> Fetch the complete documentation index at: https://docs.grantex.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# DPDP & GDPR Compliance

> DPDP Act 2023 and GDPR evidence tooling for AI agent deployments: consent records bound to grants, versioned notices, withdrawal, erasure, grievances, a breach register and exports.

<Info>Full feature guide: [DPDP Compliance](/features/dpdp-compliance) | Regulatory reference: [DPDP Act 2023](/compliance/dpdp-act-2023)</Info>

## Overview

The Grantex DPDP routes help a Data Fiduciary keep evidence for its obligations under India's Digital Personal Data Protection Act 2023 and the DPDP Rules 2025, and answer GDPR access requests, for AI agent deployments. They are a technical control, not legal advice: Grantex is not a registered Consent Manager and does not notify the Data Protection Board or data principals on your behalf. Most DPDP obligations apply from 13 May 2027.

### Key Capabilities

* **Consent records** bind a data principal's consent to an active grant and a versioned consent notice, with a signed proof (JWS, EdDSA)
* **Consent notices** are versioned per language and content-hashed; a `validation` block reports which DPDP Rules 2025 r.3 elements a notice carries
* **Withdrawal** marks the record withdrawn, can revoke the record's grant (the full grant cascade with `DPDP_REVOCATION_CASCADE=true`), and can emit a `dpdp.data_deletion.requested` webhook to your application
* **Erasure** revokes the principal's grants, marks records erased, and reports what is retained and why; with `DPDP_ERASURE_EXPANDED=true` it also redacts grievances and deletes stored exports
* **Grievances** carry a reference number, the response period you publish (1 to 90 days) as `responsePeriodDays`, an `expectedResolutionBy` date, and a `submitted` -> `in_review` -> `resolved` or `rejected` workflow. Grantex computes and stores these dates; meeting them is your process
* **Breach register** records breaches and computes `boardDetailedReportDueAt` (awareness + 72 hours, or a granted extension), tracks principal intimations, and emits deadline webhooks
* **Exports**: `dpdp-audit`, `gdpr-article-15` (with a per-person Art. 15 block), and the `eu-ai-act-evidence` pack

## API Endpoints

| Method | Path | Description |
| - | - | - |
| `POST` | `/v1/dpdp/consent-records` | [Create consent record](/api-reference/dpdp/create-consent-record) |
| `GET` | `/v1/dpdp/consent-records` | [List consent records](/api-reference/dpdp/list-consent-records) (pages when `limit` or `cursor` is sent) |
| `GET` | `/v1/dpdp/consent-records/:recordId` | [Get consent record](/api-reference/dpdp/get-consent-record) |
| `POST` | `/v1/dpdp/consent-records/:recordId/withdraw` | [Withdraw consent](/api-reference/dpdp/withdraw-consent) |
| `GET` | `/v1/dpdp/data-principals/:principalId/records` | [List a principal's records](/api-reference/dpdp/list-principal-records) |
| `POST` | `/v1/dpdp/data-principals/:principalId/erasure` | [Request erasure](/api-reference/dpdp/request-erasure) |
| `GET` | `/v1/dpdp/erasure-requests/:requestId` | [Get erasure request](/api-reference/dpdp/get-erasure-request) |
| `POST` | `/v1/dpdp/consent-notices` | [Create consent notice](/api-reference/dpdp/create-consent-notice) |
| `GET` | `/v1/dpdp/consent-notices` | [List consent notices](/api-reference/dpdp/list-consent-notices) |
| `GET` | `/v1/dpdp/consent-notices/:noticeId` | [Get consent notice](/api-reference/dpdp/get-consent-notice) (every version) |
| `POST` | `/v1/dpdp/grievances` | [File grievance](/api-reference/dpdp/file-grievance) |
| `GET` | `/v1/dpdp/grievances` | [List grievances](/api-reference/dpdp/list-grievances) |
| `GET` | `/v1/dpdp/grievances/:grievanceId` | [Get grievance](/api-reference/dpdp/get-grievance) |
| `PATCH` | `/v1/dpdp/grievances/:grievanceId` | [Update grievance](/api-reference/dpdp/update-grievance) |
| `POST` | `/v1/dpdp/breaches` | [Record breach](/api-reference/dpdp/record-breach) |
| `GET` | `/v1/dpdp/breaches` | [List breaches](/api-reference/dpdp/list-breaches) |
| `GET` | `/v1/dpdp/breaches/:breachId` | [Get breach](/api-reference/dpdp/get-breach) |
| `PATCH` | `/v1/dpdp/breaches/:breachId` | [Update breach](/api-reference/dpdp/update-breach) |
| `POST` | `/v1/dpdp/breaches/:breachId/principal-intimations` | [Record principal intimation](/api-reference/dpdp/record-breach-intimation) |
| `POST` | `/v1/dpdp/exports` | [Create export](/api-reference/dpdp/create-export) |
| `GET` | `/v1/dpdp/exports/:exportId` | [Get export](/api-reference/dpdp/get-export) |

## Links

* [Full Feature Guide](/features/dpdp-compliance)
* [DPDP Act 2023 Reference](/compliance/dpdp-act-2023)
* [EU AI Act Reference](/compliance/eu-ai-act)

## Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: [sanjeev@orchestrum.in](mailto:sanjeev@orchestrum.in) or [mishra.sanjeev@gmail.com](mailto:mishra.sanjeev@gmail.com).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.