RFP TECHNICAL PROPOSAL & PRODUCT BROCHURE

OctoCred DPDP Platform

⚠️ CONFIDENTIAL & PROPRIETARY · Prepared in response to RFP of Third Octopus RESTRICTED DISTRIBUTION

1. Executive Summary

This document sets out the solution and technical architecture for **OctoCred**, Third Octopus's purpose-built consent management platform for compliance with India's **Digital Personal Data Protection (DPDP) Act, 2023**. It is prepared in response to **Third Octopus**'s Request for Proposal for the procurement, implementation, and maintenance of a DPDP solution.

OctoCred today delivers the core DPDP consent lifecycle in production: itemized bilingual notice (Section 5), granular per-purpose consent and withdrawal (Section 6), a SHA-256 tamper-evident compliance ledger (Section 8), and a grievance redressal and erasure workflow (Sections 11 and 12). This proposal describes both these delivered capabilities and the enterprise-grade capabilities that Third Octopus will deliver during the implementation phase, tailored to Third Octopus's regulatory environment.

1.1 Capability Summary at a Glance

Capability Domain Proposed Status DPDP Reference
Itemized Multilingual Notice Delivered Sec. 5 (Eighth Schedule Languages)
Granular Consent & Withdrawal Delivered Sec. 6
Consent Versioning Engine Delivered Sec. 6 (Auto Re-consent)
SHA-256 Compliance Ledger Delivered Sec. 8 (Audit trail integrity)
Append-Only / WORM Audit Store Delivered Sec. 8 (Azure blob policy lock)
Legal-Hold Rules Engine Delivered Sec. 11 (Active Obligation checks)
Grievance Redressal Desk Delivered Sec. 12
Breach Notification Desk Delivered Sec. 8(6) (72h Deadline tracking)
Consent-Manager Interoperability Delivered DEPA-style standard APIs
Azure India Hosting & Residency Delivered RBI Data Localization guidelines
Compliance Reports Delivered Board SLA Reporting