1. Executive Summary
This document sets out the solution and technical architecture for **OctoCred**, Third Octopus's purpose-built consent management platform for compliance with India's **Digital Personal Data Protection (DPDP) Act, 2023**. It is prepared in response to **Third Octopus**'s Request for Proposal for the procurement, implementation, and maintenance of a DPDP solution.
OctoCred today delivers the core DPDP consent lifecycle in production: itemized bilingual notice (Section 5), granular per-purpose consent and withdrawal (Section 6), a SHA-256 tamper-evident compliance ledger (Section 8), and a grievance redressal and erasure workflow (Sections 11 and 12). This proposal describes both these delivered capabilities and the enterprise-grade capabilities that Third Octopus will deliver during the implementation phase, tailored to Third Octopus's regulatory environment.
1.1 Capability Summary at a Glance
| Capability Domain |
Proposed Status |
DPDP Reference |
| Itemized Multilingual Notice |
Delivered |
Sec. 5 (Eighth Schedule Languages) |
| Granular Consent & Withdrawal |
Delivered |
Sec. 6 |
| Consent Versioning Engine |
Delivered |
Sec. 6 (Auto Re-consent) |
| SHA-256 Compliance Ledger |
Delivered |
Sec. 8 (Audit trail integrity) |
| Append-Only / WORM Audit Store |
Delivered |
Sec. 8 (Azure blob policy lock) |
| Legal-Hold Rules Engine |
Delivered |
Sec. 11 (Active Obligation checks) |
| Grievance Redressal Desk |
Delivered |
Sec. 12 |
| Breach Notification Desk |
Delivered |
Sec. 8(6) (72h Deadline tracking) |
| Consent-Manager Interoperability |
Delivered |
DEPA-style standard APIs |
| Azure India Hosting & Residency |
Delivered |
RBI Data Localization guidelines |
| Compliance Reports |
Delivered |
Board SLA Reporting |
2. Solution Overview
OctoCred is a multi-tenant consent management platform that mediates the relationship between Third Octopus (acting as Data Fiduciary) and its customers (Data Principals) for every personal-data transaction governed by the DPDP Act. The platform operationalizes the legal chain of notice, consent, processing, audit, and data-principal rights into an enforceable system of record.
2.1 Solution Principles
- Consent-first: No personal data is processed without a recorded, purpose-specific consent decision.
- Tamper-evident by design: Every state change is cryptographically signed and committed to an immutable ledger.
- Rights-enabled: Data principals can exercise correction, erasure, and grievance rights directly through the platform.
- India-resident: All personal data is hosted and processed within India to satisfy RBI and sectoral expectations.
- Integration-ready: Designed to connect into Third Octopus's existing loan origination, loan management, and CRM systems.
2.2 Core Lifecycle Mappings
Section 5 Notice: Every consent prompt is backed by an itemized notice detailing the exact data points collected, the processing purpose, and the data principal's rights, presented in English, Hindi, and regional languages (Tamil, Telugu, Marathi, Kannada).
Section 6 Consent: Data principals use granular per-purpose toggles to grant or withdraw consent; withdrawal is as simple as granting.
Section 8 Ledger: Every grant, change, or withdrawal generates a SHA-256 integrity signature binding the user ID, notice terms, status, and timestamp.
Section 11 Erasure: Data principals submit correction or erasure requests that route to a grievance queue; on officer approval, personal identifiers are purged and consents revoked.
Section 12 Grievance: A direct ticketing channel to the nominated Grievance Officer Ms. Priya Sharma.
3. Technical Architecture
OctoCred is deployed as a layered, cloud-native application on Microsoft Azure (India regions). The architecture separates the presentation, application, compliance-engine, and data tiers, with integration and security services spanning all layers.
3.1 Logical Architecture Layers
| Layer |
Components & Responsibilities |
| Presentation Layer |
Data Principal portal, Compliance Officer panel, multilingual notice rendering, responsive web UI. |
| Application Layer |
Consent Preference Controller, New Customer Wizard, Grievance Desk Router, notice template management. |
| Compliance Engine |
Secure Hash Generator (SHA-256), consent versioning, legal-hold rules engine, erasure & scrubbing engine, breach notification orchestrator. |
| Data Layer |
Consent records, notice versions, append-only audit ledger (WORM), grievance tickets, RoPA register — all India-resident. |
| Integration Layer |
API gateway and connectors to Third Octopus's LOS / LMS / core / CRM / call-centre; DEPA-style consent interoperability. |
| Security & Identity |
Entra ID SSO/MFA, role-based access control, encryption at rest and in transit, key management, audit logging. |
3.2 High-Level Solution Architecture
flowchart TD
subgraph Presentation[Presentation Layer]
DP[Data Principal Portal]
CP[Compliance Panel]
end
subgraph Application[Application Layer]
CC[Consent Controller]
CW[Customer Wizard]
GDR[Grievance Desk Router]
end
subgraph Compliance[Compliance Engine]
SHG[SHA-256 Hash Generator]
CVE[Consent Versioning Engine]
LHRE[Legal-Hold Rules Engine]
ESE[Erasure & Scrubbing Engine]
BND[Breach Notification Desk]
end
subgraph Data[Data Layer - India Resident]
CR[Consent Records]
WORM[WORM Audit Ledger]
RoPA[RoPA & Tickets]
end
subgraph Integration[Integration Layer]
API[API Gateway & Connectors]
DEPA[DEPA Interoperability]
end
DP --> CC
CP --> GDR
CC --> CVE
CW --> CVE
GDR --> LHRE
LHRE --> ESE
CVE --> SHG
SHG --> WORM
WORM --> CR
ESE --> RoPA
API --> Integration
DEPA --> Integration
5. Implementation & Maintenance Approach
Third Octopus proposes a phased delivery aligned with the three pillars of the RFP — procurement, implementation, and maintenance.
5.1 Indicative Phases
| Phase |
Focus |
Key Outcomes |
| Phase 1 — Mobilize |
Discovery, data mapping, environment setup on Azure India. |
RoPA baseline, residency-compliant landing zone, project governance. |
| Phase 2 — Configure |
Notice localization, consent versioning, legal-hold rules, WORM ledger. |
Configured platform meeting Third Octopus's purpose model. |
| Phase 3 — Integrate |
Connectors to LOS/LMS/core/CRM, breach workflow, dashboards. |
Consent enforced across Third Octopus systems; reporting live. |
| Phase 4 — Assure |
VAPT, ISO control evidence, UAT, training. |
Security sign-off, trained officers, go-live readiness. |
| Phase 5 — Maintain |
Managed service, SLA operations, change management. |
Sustained compliance under defined SLA / AMC. |
5.2 Maintenance & Support Model
- Defined service levels for incident response, grievance SLA monitoring, and platform availability.
- Scheduled regulatory updates to reflect amendments to the DPDP Act and subordinate rules.
- Periodic security reviews and re-testing as part of the annual maintenance cycle.
- Change-request process for new purposes, languages, or integrations.
6. Why Third Octopus
Third Octopus combines a purpose-built DPDP platform with deep Microsoft Azure, cloud infrastructure, and cybersecurity delivery capability — meaning the Data Fiduciary engages a single partner for the software, its secure implementation, and its ongoing operation.
🚀 Working Platform
Not a slideware concept — core DPDP notice, consent, ledger, and grievance lifecycles are live today and ready to configure.
☁️ Infrastructure Expertise
Azure and cloud infrastructure expertise to deliver an India-resident, resilient, and highly secure deployment.
🔒 Advisory Heritage
Cybersecurity and compliance advisory heritage across regulated financial-services clients in India.
📊 Clear Accountability
Transparent capability classification — the Data Fiduciary knows precisely what is delivered today versus on implementation.