Collect it, and prove it. A click is not a consent record — OneTrust Consent & Preferences captures consent across every channel, honours withdrawal, and keeps the timestamped record that proves what a person actually agreed to.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Consent & Preferences — the customer edge. The rest of the platform:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Consent captured, honoured and proved — across web, app and marketing, with purpose-level preferences, a withdrawal path, and a timestamped record of what was agreed.
What consolidation actually replaces, dimension by dimension.
| Dimension | A banner that sets a cookie | Consent & Preferences (OneTrust) |
|---|---|---|
| What you have | A banner that sets a cookie | A record of what was agreed, and when |
| Granularity | One blanket yes | Purpose-level choices a person can change |
| Withdrawal | An unsubscribe link, maybe | As easy as consent — a DPDP requirement |
| Downstream | The choice stops at your database | Propagated to marketing, CDP and analytics |
| When challenged | An assertion | Evidence with a timestamp and notice version |
| What it is NOT | — | Not legal advice on your lawful basis |
It records consent — it does NOT decide whether consent is the right legal basis for your processing. That is your counsel's judgement. And it cannot cover a channel nobody declared.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Consent is captured wherever you meet a person — a website, a mobile app, a form, a call centre. The design question is coverage: a channel that collects data without collecting consent is the gap a regulator finds, and it is usually the one nobody owned.
People consent to some things and not others, and change their minds. A preference centre holds that granularity — this purpose yes, that one no — rather than one blanket yes. Under DPDP purpose limitation is explicit, so granularity is not a nicety.
What was shown, what was agreed, when, and under which version of the notice. This is what you produce when challenged, and it is why a homegrown banner usually fails: it collects a click but cannot prove what the click meant six months later.
A withdrawal that does not reach your marketing platform, CDP and analytics tools is not a withdrawal. This module integrates with what you already run — and mapping every downstream consumer of consent is the real implementation work.
One telemetry fabric across endpoint, cloud, and network — threats correlated once, not chased console to console.
OneTrust Consent & Preferences is where the programme meets your customers — capture, withdrawal and the portfolio, and paired with the human firewall.
Scan the site for cookies and trackers, because you cannot write an honest notice about scripts you have not inventoried. Third-party tags added by marketing are the usual surprise here.
Web, mobile app, forms and offline capture feed one record. Coverage matters more than polish: an uncovered channel is a gap, however good the banner looks on the homepage.
Purpose-level choices a person can revisit and change. DPDP treats withdrawal as a right that must be as easy as giving consent, which rules out a preference centre buried three clicks deep.
Timestamp, notice version, what was presented and what was agreed. Without this a consent programme is an assertion; with it, it is evidence.
Consent and withdrawal reach the marketing platform, CDP, analytics and ad tools that act on them. This integration work is where most implementations actually spend their time.
When the notice changes materially, prior consent may no longer cover the new purpose. Versioning tells you who needs asking again — a question that is unanswerable from a homegrown banner.
The platform demonstrated, and what changed in the 2026 releases.
The privacy core that consent records feed into.
What changed across the platform this release.
Feature detail from the spring release.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Almost every organisation that thinks it has solved consent has solved the banner: a script that appears, collects a click and sets a cookie. The obligation is considerably larger. You have to be able to say what was shown to a specific person, what they agreed to, when, and under which version of the notice — and then prove it months later when someone asks. A homegrown banner collects the click but usually cannot answer any of those questions, because it was never designed to be evidence. That gap is invisible right up until the moment it matters, which is why organisations discover it during a regulator's enquiry rather than during an internal review.
India's Digital Personal Data Protection Act does not simply require consent — it requires a clear notice, purpose limitation, and a withdrawal path that is as straightforward as giving consent in the first place. That last clause has real design consequences. A preference centre buried three clicks into a footer does not meet it. Neither does a withdrawal that reaches your own database but never propagates to the marketing platform still sending emails. The Rules notified on 13 November 2025 attached an implementation timeline to all of this, which is why consent tooling moved up a lot of Indian roadmaps in 2026.
Collecting consent is the easy half. The hard half is making the answer stick everywhere it has to: the marketing automation platform, the customer data platform, the analytics stack, the ad pixels, the internal systems that decide who gets contacted. A withdrawal that does not reach all of them is not a withdrawal, and the person who withdrew will notice before your compliance team does. Mapping every downstream consumer of consent — including the ones marketing added without telling IT — is the real project. TechBag scopes that integration work during evaluation, because it is what determines the timeline and it is never what a demo shows.
This module records and propagates consent. It does not decide whether consent is the right legal basis for your processing, it does not write your privacy notice, and it does not make your data collection lawful. Those are judgements your counsel makes about your specific processing, and no platform makes them for you. It also cannot fix a channel nobody told it about — the cookie scan finds what is on the site, but an app SDK or an offline capture process outside the implementation is simply outside it. What it genuinely delivers is that the consent you do collect becomes provable, granular and enforceable downstream, which is the part organisations reliably fail at on their own.
Every place you collect personal data — site, app, forms, call centre, offline. A channel nobody lists is a gap the implementation will not cover.
Cookies and trackers on the site, including the third-party tags marketing added without telling IT. You cannot write an honest notice about scripts you have not found.
Purpose-level granularity, and a withdrawal path as easy as consent — DPDP requires the parity explicitly, so a buried footer link fails the test.
Marketing automation, CDP, analytics, ad tools. This is the real project: a withdrawal that does not reach them all is not a withdrawal.
Withdraw consent for a test identity and verify every downstream system stops. Demo environments never surface the tool marketing added last quarter.
When terms change materially, prior consent may not cover the new purpose. Versioning tells you who to ask again — a question a homegrown banner cannot answer.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We had a banner and thought consent was handled. The first time someone asked us to prove what a specific customer had agreed to in 2024, we could not — that is what we actually bought.”
“DPDP requiring withdrawal to be as easy as consent forced a redesign. The preference centre and the propagation into our marketing stack were the whole project.”
“Solid platform. Budget for the integration — the consent capture went in quickly, wiring every downstream system that acts on consent took considerably longer.”
“It does what it says, but we could not get a straight price without a full sales cycle, and nothing public was close to our eventual quote.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the consent management market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Deepest consent record and propagation.
The grid nobody publishes — depth of the consent record vs how far the choice actually propagates.
Purpose-level, versioned, propagated downstream.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against a data-first platform, a homegrown banner, and doing nothing — on proof, granularity and propagation.
| Dimension | OneTrust Consent | Securiti | A homegrown banner | Doing nothing |
|---|---|---|---|---|
| Proof of consent | Timestamped record | Yes | A click | None |
| Granular preferences | Purpose-level | Yes | Rarely | None |
| Downstream propagation | Integrations | Yes | Manual | None |
| DPDP withdrawal parity | Designed for it | Yes | Usually fails | Fails |
| Cost | Quote-only | Quote-only | Engineering time | Free |
| Does it decide your legal basis? | No — by design | No | No | No |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Drag the sliders (monthly consent interactions; IT-hour cost as a loaded rate). Estimates model the engineering and legal time spent maintaining a homegrown banner and answering challenges without a record — the avoided regulatory exposure is the larger, unpriced win. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote-only — OneTrust publishes no price. TechBag scopes the channels and downstream systems, then quotes in INR with GST.
Best for provable consent
Best for a broader rollout
Best across several obligations
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Have you listed EVERY channel that collects personal data — including the mobile app SDK and offline capture?
Can you produce what a specific person agreed to, when, and under which notice version? If not, that is what you are buying.
Is withdrawing as easy as consenting? DPDP requires it explicitly, and a footer link three clicks deep does not qualify.
Which systems act on consent — marketing, CDP, analytics, ad tools? Every one must receive the withdrawal.
Do you know every third-party tag on your site? Marketing-added scripts are the usual surprise in the first scan.
Is consent even the right basis for this processing? The platform records it; your counsel decides it.
When the notice changes materially, who needs asking again? Versioning answers this; a banner cannot.
Can you approve without a list price? There is none. Fix the metering metric in the FIRST contract.
Scope the channel inventory and the downstream systems that act on consent, or let a TechBag advisor test your current banner against what DPDP actually requires.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.