A notice register, consent recorded per data item, withdrawal in one action, and a record of every change.
Consent is not a checkbox at sign-up. It is a record of what a person agreed to, for which purpose, under which version of a notice, and whether they have since changed their mind. Akku holds all of that centrally, applies it as an authorisation state rather than a preference, and produces it on request.

Consent management is the capture, storage and enforcement of what a customer has permitted you to do with their data. Capture is the notice and the agreement. Storage is the record of it, including which version of the notice they saw. Enforcement is where consent that has been withdrawn actually stops the processing it was authorising.

Consent is captured against a register of what you collect and why, so each item of personal data has a stated purpose behind it. Notices are versioned, which means a consent record points at the exact text the person agreed to rather than at whatever the notice says today.

Consent is recorded per data item and per purpose against a lawful basis. That granularity is what allows a customer to permit one use of their data and refuse another, and it is what makes a consent record answer the question an auditor actually asks.

Withdrawal is made as easy as giving consent, in a single control in the self-service portal. When it happens, the signal propagates to your downstream systems and processors rather than stopping at Akku.

A summary of the data you hold on someone, produced on request. Disclosure of which third parties received what and why. Correction, completion and update. Erasure, which carries through to processors with confirmation from each one. Each of those is recorded with what changed, where the change reached and when it completed.

Verifiable parental consent applies where the data principal is a child. Purposes are marked as not permitted for children, and no advertising identifier is issued to a child's account.

A submission facility sits in the self-service portal, with the Data Protection Officer named as the owner and response times measured against the prescribed period.

Every consent event is held as a tamper-evident record. Preference management lets a customer see and change what they have agreed to across channels, and each change is a new record rather than an overwrite of the old one.

The controls above are most of what the DPDP Act asks of a data fiduciary, with consent under Sec. 6, parental consent under Sec. 9, erasure reaching processors under Sec. 8(7), and grievances under Sec. 8(10) and 13(2). They also cover all 18 of SOC 2's Privacy criteria, and answer GDPR's requirements on consent, data subject rights and erasure reaching processors.
