Talk to us
by OneTrustTechBag Intel Page

Consent & Preferences

Collect it, and prove it. A click is not a consent record — OneTrust Consent & Preferences captures consent across every channel, honours withdrawal, and keeps the timestamped record that proves what a person actually agreed to.

The banner is the visible 10%DPDP: withdrawal as easy as consentPropagation is where it breaks

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
The obligation
notice and withdrawal, under DPDP
Consent
The product
not the banner
The record
Where it runs
integrates, does not replace
Your stack
Pricing
no published figure
Quote-only

Quick answer

OneTrust Consent & Preferences is where a privacy programme meets its customers: Universal Consent & Preference Management plus the Consent Management Platform. It captures consent across web, app and marketing channels, honours withdrawal, and keeps a defensible record of what was agreed and when. Under India's DPDP Act the consent notice and an equally easy way to withdraw are explicit obligations, so this is the module a regulator's questions land on first. It integrates into your existing marketing and IT stack rather than replacing it. Quote-only. Read more ↓ Show less ↑
Part 01 · Orient

The OneTrust platform family

This page covers Consent & Preferences — the customer edge. The rest of the platform:

Quick facts

30-second orientation
Product
Consent & Preferences — the customer edge
What it does
Collects consent, honours withdrawal, keeps the record
Inside it
Universal Consent & Preference Mgmt, plus the CMP
Where it sits
In your web, app and marketing stack
India
DPDP consent notice and withdrawal are explicit duties
Honest scope
A banner is the visible 10% — the record is the product
Pricing
Quote-only — no published price
In India via
TechBag — INR/GST, scoping and support
Part 02 · Learn

Understand consent management before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is OneTrust Consent & Preferences?

Consent captured, honoured and proved — across web, app and marketing, with purpose-level preferences, a withdrawal path, and a timestamped record of what was agreed.

A banner vs a consent record — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA banner that sets a cookieConsent & Preferences (OneTrust)
What you haveA banner that sets a cookieA record of what was agreed, and when
GranularityOne blanket yesPurpose-level choices a person can change
WithdrawalAn unsubscribe link, maybeAs easy as consent — a DPDP requirement
DownstreamThe choice stops at your databasePropagated to marketing, CDP and analytics
When challengedAn assertionEvidence with a timestamp and notice version
What it is NOTNot legal advice on your lawful basis

It records consent — it does NOT decide whether consent is the right legal basis for your processing. That is your counsel's judgement. And it cannot cover a channel nobody declared.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where it starts

Collection at the edge

Web, app, and every channel

Consent is captured wherever you meet a person — a website, a mobile app, a form, a call centre. The design question is coverage: a channel that collects data without collecting consent is the gap a regulator finds, and it is usually the one nobody owned.

02
The middle

The preference centre

What they actually chose

People consent to some things and not others, and change their minds. A preference centre holds that granularity — this purpose yes, that one no — rather than one blanket yes. Under DPDP purpose limitation is explicit, so granularity is not a nicety.

03
The actual product

The consent record

Proof, with a timestamp

What was shown, what was agreed, when, and under which version of the notice. This is what you produce when challenged, and it is why a homegrown banner usually fails: it collects a click but cannot prove what the click meant six months later.

04
Where it usually breaks

Downstream enforcement

Making the choice stick

A withdrawal that does not reach your marketing platform, CDP and analytics tools is not a withdrawal. This module integrates with what you already run — and mapping every downstream consumer of consent is the real implementation work.

One telemetry fabric across endpoint, cloud, and network — threats correlated once, not chased console to console.

Part 03 · Evaluate

Six capabilities. Collect, record, propagate.

OneTrust Consent & Preferences is where the programme meets your customers — capture, withdrawal and the portfolio, and paired with the human firewall.

Discover
Cookie & tracker scan

Know what is actually running

Scan the site for cookies and trackers, because you cannot write an honest notice about scripts you have not inventoried. Third-party tags added by marketing are the usual surprise here.

Discover
Consent capture

Collect across every channel

Web, mobile app, forms and offline capture feed one record. Coverage matters more than polish: an uncovered channel is a gap, however good the banner looks on the homepage.

Prioritise
Preference centre

Granular, and changeable

Purpose-level choices a person can revisit and change. DPDP treats withdrawal as a right that must be as easy as giving consent, which rules out a preference centre buried three clicks deep.

Prioritise
Proof of consent

The record that survives a challenge

Timestamp, notice version, what was presented and what was agreed. Without this a consent programme is an assertion; with it, it is evidence.

Remediate
Signal propagation

Push the choice downstream

Consent and withdrawal reach the marketing platform, CDP, analytics and ad tools that act on them. This integration work is where most implementations actually spend their time.

Remediate
Notice versioning

Re-consent when the terms change

When the notice changes materially, prior consent may no longer cover the new purpose. Versioning tells you who needs asking again — a question that is unanswerable from a homegrown banner.

See it, don’t just read it

Watch the platform in action

The platform demonstrated, and what changed in the 2026 releases.

OneTrust (official)·Demo

OneTrust Privacy Automation solution demo

The privacy core that consent records feed into.

OneTrust (official)·Release

Winter Release 2026: AI Assessment Automation

What changed across the platform this release.

OneTrust (official)·Release

Spring Release 2026 — Privacy Automation features

Feature detail from the spring release.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Consent & Preferences

A banner shows something. A record proves it.

Here’s what genuinely sets it apart — and exactly where it stops.

01

The banner is the visible ten per cent

Almost every organisation that thinks it has solved consent has solved the banner: a script that appears, collects a click and sets a cookie. The obligation is considerably larger. You have to be able to say what was shown to a specific person, what they agreed to, when, and under which version of the notice — and then prove it months later when someone asks. A homegrown banner collects the click but usually cannot answer any of those questions, because it was never designed to be evidence. That gap is invisible right up until the moment it matters, which is why organisations discover it during a regulator's enquiry rather than during an internal review.

02

DPDP makes withdrawal as easy as consent

India's Digital Personal Data Protection Act does not simply require consent — it requires a clear notice, purpose limitation, and a withdrawal path that is as straightforward as giving consent in the first place. That last clause has real design consequences. A preference centre buried three clicks into a footer does not meet it. Neither does a withdrawal that reaches your own database but never propagates to the marketing platform still sending emails. The Rules notified on 13 November 2025 attached an implementation timeline to all of this, which is why consent tooling moved up a lot of Indian roadmaps in 2026.

03

Enforcement is where implementations actually fail

Collecting consent is the easy half. The hard half is making the answer stick everywhere it has to: the marketing automation platform, the customer data platform, the analytics stack, the ad pixels, the internal systems that decide who gets contacted. A withdrawal that does not reach all of them is not a withdrawal, and the person who withdrew will notice before your compliance team does. Mapping every downstream consumer of consent — including the ones marketing added without telling IT — is the real project. TechBag scopes that integration work during evaluation, because it is what determines the timeline and it is never what a demo shows.

04

What it does not do

This module records and propagates consent. It does not decide whether consent is the right legal basis for your processing, it does not write your privacy notice, and it does not make your data collection lawful. Those are judgements your counsel makes about your specific processing, and no platform makes them for you. It also cannot fix a channel nobody told it about — the cookie scan finds what is on the site, but an app SDK or an offline capture process outside the implementation is simply outside it. What it genuinely delivers is that the consent you do collect becomes provable, granular and enforceable downstream, which is the part organisations reliably fail at on their own.

The obligation
Notice, purpose limits, withdrawal parity
The product
The record — not the banner
Where it breaks
Downstream propagation, every time
Proof, not promises

The numbers behind the platform

2 components
Universal Consent & Preference Management, plus the CMP
Vendor
2025
DPDP Rules notified — withdrawal as easy as consent
Gazette
0 legal advice
it records consent; your counsel decides the basis
TechBag
0 published prices
quote-only; aggregator figures are not vendor figures
TechBag

What your consent rollout looks like

Day 0Scope

Inventory the channels

Every place you collect personal data — site, app, forms, call centre, offline. A channel nobody lists is a gap the implementation will not cover.

Day 1Decide

Scan what is actually running

Cookies and trackers on the site, including the third-party tags marketing added without telling IT. You cannot write an honest notice about scripts you have not found.

Week 1Design

Design the preference centre

Purpose-level granularity, and a withdrawal path as easy as consent — DPDP requires the parity explicitly, so a buried footer link fails the test.

Week 2-6Deploy

Wire the downstream systems

Marketing automation, CDP, analytics, ad tools. This is the real project: a withdrawal that does not reach them all is not a withdrawal.

Month 2Operate

Test with a real withdrawal

Withdraw consent for a test identity and verify every downstream system stops. Demo environments never surface the tool marketing added last quarter.

OngoingReview

Version the notice

When terms change materially, prior consent may not cover the new purpose. Versioning tells you who to ask again — a question a homegrown banner cannot answer.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.4
140+ reviews*
89% would recommend
Consent capture coverage4.6
Proof and record-keeping4.6
Downstream propagation4.2
Implementation effort3.6
Pricing transparency2.9
5
58%
4
28%
3
8%
2
4%
1
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
We had a banner and thought consent was handled. The first time someone asked us to prove what a specific customer had agreed to in 2024, we could not — that is what we actually bought.
Data Protection Officer
BFSI
Insurance
DPDP requiring withdrawal to be as easy as consent forced a redesign. The preference centre and the propagation into our marketing stack were the whole project.
Head of Digital
Insurance
Retail
Solid platform. Budget for the integration — the consent capture went in quickly, wiring every downstream system that acts on consent took considerably longer.
Marketing Operations Lead
Retail
IT Services
It does what it says, but we could not get a straight price without a full sales cycle, and nothing public was close to our eventual quote.
Procurement Lead
IT Services
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the consent management market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Consent Management Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
OneTrust ConsentThis page

Deepest consent record and propagation.

Grid 02 · The architecture

Detection × Portfolio Integration

The grid nobody publishes — depth of the consent record vs how far the choice actually propagates.

Point toolsBest-of-breed platformLegacy AV/appliancesHeavy suites
OneTrust ConsentThis page

Purpose-level, versioned, propagated downstream.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Consent & Preferences vs the alternatives

Against a data-first platform, a homegrown banner, and doing nothing — on proof, granularity and propagation.

DimensionOneTrust ConsentSecuritiA homegrown bannerDoing nothing
Proof of consentTimestamped recordYesA clickNone
Granular preferencesPurpose-levelYesRarelyNone
Downstream propagationIntegrationsYesManualNone
DPDP withdrawal parityDesigned for itYesUsually failsFails
CostQuote-onlyQuote-onlyEngineering timeFree
Does it decide your legal basis?No — by designNoNoNo
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which cybersecurity approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Consent & Preferences if…

  • You need to PROVE what a specific person agreed to, not just that a banner appeared
  • DPDP withdrawal parity applies to you and a footer link will not meet it
  • Consent has to reach marketing, CDP and analytics — not stop at your own database
  • You have mapped, or will map, every channel that collects personal data

A homegrown banner may be enough if…

  • You collect very little personal data through very few channels, and can evidence it
  • Nobody downstream acts on consent, so propagation is not a problem you have
  • Be honest about this: most organisations that believe it discover otherwise under enquiry

Do not buy this expecting…

  • Legal advice — whether consent is your lawful basis is a judgement your counsel makes
  • Coverage of channels nobody told the implementation about; the scan sees the site, not your app SDK
  • A published price; there is none, and the quote depends heavily on scope
Do the math

What does an unprovable consent cost you?

Drag the sliders (monthly consent interactions; IT-hour cost as a loaded rate). Estimates model the engineering and legal time spent maintaining a homegrown banner and answering challenges without a record — the avoided regulatory exposure is the larger, unpriced win. Illustrative.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual cost of maintaining consent by hand
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote-only — OneTrust publishes no price. TechBag scopes the channels and downstream systems, then quotes in INR with GST.

Consent & Preferences

Best for provable consent

  • Capture across web, app and marketing
  • Purpose-level preference centre
  • Timestamped record with notice version

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ the wider platform

Best across several obligations

  • Consent records feed privacy operations
  • One inventory under every module
  • Only pays off beyond a single obligation

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Channels

Have you listed EVERY channel that collects personal data — including the mobile app SDK and offline capture?

2
Proof

Can you produce what a specific person agreed to, when, and under which notice version? If not, that is what you are buying.

3
Withdrawal parity

Is withdrawing as easy as consenting? DPDP requires it explicitly, and a footer link three clicks deep does not qualify.

4
Downstream

Which systems act on consent — marketing, CDP, analytics, ad tools? Every one must receive the withdrawal.

5
The tags

Do you know every third-party tag on your site? Marketing-added scripts are the usual surprise in the first scan.

6
Legal basis

Is consent even the right basis for this processing? The platform records it; your counsel decides it.

7
Re-consent

When the notice changes materially, who needs asking again? Versioning answers this; a banner cannot.

8
Pricing

Can you approve without a list price? There is none. Fix the metering metric in the FIRST contract.

FAQ

Questions buyers ask

It is the module that captures and manages consent, made up of Universal Consent & Preference Management and the Consent Management Platform. It collects consent across web, app and marketing channels, holds purpose-level preferences a person can revisit and change, honours withdrawal, and keeps a defensible record of what was agreed and when — including which version of the notice was shown. It also propagates the answer downstream, so a withdrawal reaches the marketing platform, CDP and analytics tools that act on it. It integrates into your existing stack rather than replacing it. TechBag scopes it and quotes in INR with GST.

Ready to evaluate OneTrust Consent & Preferences?

Scope the channel inventory and the downstream systems that act on consent, or let a TechBag advisor test your current banner against what DPDP actually requires.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.