Consent Foundation
Consent Foundation is a non-profit Self-Regulatory Organization developing open standards and infrastructure for digital consent management, serving technology providers, privacy professionals, and policymakers through its CDPI framework, Artifact Standard, and DataVeda vocabulary via a tiered membership model.
- Company typePrivate
- Founded2024
- HeadquartersMumbai, India
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Consent Foundation does
Consent Foundation is a non-profit Self-Regulatory Organization (SRO) established in 2024 and headquartered in Mumbai, India, operating with a 7-person team. The foundation develops open standards, specifications, and reference tools for digital consent management, targeting technology providers, consent managers, privacy professionals, policymakers, academic researchers, and civil society organizations. Its stated mission is to address the absence of universal formats for expressing consent, the inability to verify that consent was given, and the lack of mechanisms for transferring consent across services. The foundation positions itself as a vendor-neutral alternative to top-down regulatory approaches, emphasizing radical transparency with all specifications, code, governance decisions, and finances publicly accessible.
The foundation's technology portfolio centers on the Consent Digital Public Infrastructure (CDPI), a four-layer architecture comprising the Consent Notice Layer, Consent Receipt Layer, Consent Verification Layer, and Consent Interoperability Layer. Supporting products include the Artifact Standard (currently at v0.4 draft, targeting V1.0 ratification in Q1 2026) for structured consent notices, receipts, verifications, and revocations; DataVeda, an open versioned vocabulary and taxonomy for privacy-related terms; the Purpose Directory, a machine-readable registry of data processing purposes with unique identifiers; the Personal Data Breach Artifact Standard for GDPR-compatible 72-hour breach notification workflows; and the Incident Reporting Standard. The Open-Source Consent Notice component is distributed via npm and CDN as a framework-agnostic, WCAG 2.1 AA accessible reference implementation.
Revenue is generated through a tiered membership model with Premier Members (appointed Governing Board seats, strategic leadership), General Members (full participation rights, voting eligibility), Associate Members (academic/nonprofit institutions), and Individual Contributors (freemium community access). The foundation has onboarded 7 member organizations including Founding Members Securelytix and Concur, Premier Members Privasea Summit and ComplyPlanet, and General Members ClearConsent, Certana, and Cloak. The organization operates primarily virtually with periodic in-person governance workshops at its Mumbai headquarters, and engages members through Slack, GitHub, working groups, weekly cadence meetings, and the annual Consent Summit. No revenue figures are disclosed in available source material.
Consent Foundation firmographics
Firmographics- Name
- Consent Foundation
- Legal name
- Consent Foundation
- Website
- https://consent.foundation
- Company type
- Private
- Founded year
- 2024
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Consent Foundation is a non-profit Self-Regulatory Organization developing open standards and infrastructure for digital consent management, serving technology providers, privacy professionals, and policymakers through its CDPI framework, Artifact Standard, and DataVeda vocabulary via a tiered membership model.
- Ownership category
- akta.pro rank
Consent Foundation industry classification
Industry- Product category
- Privacy and Consent Management Software
- NAICS
- Scientific Research and Development Services (5417), Research and Development in the Social Sciences and Humanities (54172)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Privacy Management (Consent, DSAR, RoPA) (HDADAFAH)
- akta.pro secondary industries
- Privacy Governance & Consent Management (HDADAIAI), Data Privacy, Consent & Compliance Management (HDAEADAG)
Keywords
Where Consent Foundation is headquartered
LocationHeadquarters
- HQ city
- Mumbai
- HQ country
- India
- HQ region
- Asia
Offices1 record
Markets served
Consent Foundation business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Membership Fees: Consent Foundation generates revenue through tiered membership fees. Premier Members receive strategic leadership benefits including appointed board seats. General Members receive full participation rights. Associate Members (academic/nonprofit institutions) and Individual Contributors access community resources and working groups.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Premier Members — Strategic leadership tier with board representation |
| Subscription | Annual | General Members — Full participation in Foundation initiatives |
| Subscription | Annual | Associate Members — Academic and nonprofit institutions |
| Freemium | Annual | Individual Contributors — Privacy professionals and enthusiasts |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
Consent Foundation product offering
Product offeringCore offering
Consent Foundation develops and distributes open standards, specifications, and reference implementations for digital consent management as a Self-Regulatory Organization. Its central offering is Consent Digital Public Infrastructure (CDPI), a four-layer protocol for expressing, recording, verifying, and interoperably exchanging consent across platforms and jurisdictions, supplemented by supporting standards (Artifact Standard, DataVeda taxonomy, Purpose Directory, PDBA Standard, Incident Reporting Standard) and a free open-source Consent Notice SDK.
Product overview
Consent Foundation operates as a Self-Regulatory Organization (SRO) developing open standards, specifications, and tools for consent management. The core product portfolio centers on CDPI (Consent Digital Public Infrastructure) — a four-layer architecture for universal consent management — complemented by supporting specifications including the Artifact Standard, Interoperability Standards, DataVeda (vocabulary taxonomy), and Purpose Directory (purpose registry). The organization also offers practical implementations including the Open-Source Consent Notice toolkit, the PDBA Standard for breach notifications, and the Incident Reporting Standard. All offerings are designed to work together as an integrated consent management ecosystem, with CDPI serving as the foundational infrastructure and other initiatives providing specialized functionality for interoperability, standardization, and incident response.
Differentiator
Problem solved
Functional benefit
Brands
- DataVeda: Open vocabulary and taxonomy layer for digital privacy — the knowledge layer that makes consent language consistent, machine-readable, and universally understood.
Products and services
- CDPI (Consent Digital Public Infrastructure) A universal consent protocol modeled after email, providing open, interoperable, and decentralized consent infrastructure. CDPI consists of four layers: Consent Notice Layer (standardized, machine-readable expression of data collection purposes), Consent Receipt Layer (cryptographic verification records), Consent Verification Layer (authenticating receipt integrity), and Consent Interoperability Layer (cross-platform consent portability). Designed for technology providers, platform operators, and privacy professionals seeking to replace fragmented consent systems with a shared open infrastructure.
- Interoperability Standards Cross-platform consent standards enabling consent to work across platforms, services, and jurisdictions. Components include a Universal Schema, Translation Layer, Verification Protocol, and Jurisdiction Profiles. Target users are technology providers, consent managers, and platform operators needing cross-platform, cross-jurisdictional consent interoperability without replacing existing systems.
- DataVeda An open, versioned taxonomy providing canonical definitions for privacy-related terms, data processing purposes, and jurisdiction mappings. Published in machine-readable formats (JSON-LD, CSV, YAML) for automated consumption. The knowledge layer that makes consent language consistent, machine-readable, and universally understood across organizations.
- Purpose Directory A universal, machine-readable registry of data processing purposes with unique identifiers, human-readable labels, and precise descriptions enabling consent notices to express exactly what they mean across platforms. Enables consistent purpose specification with machine-readable identifiers across the consent ecosystem.
- Artifact Standard Standardized data formats for consent notices, receipts, verifications, revocations, and breach notifications. Machine-first with human-readable representations, cryptographically verifiable, versioned and extensible, jurisdiction-aware. Currently at Version 0.4 Draft (August 2025), targeting V1.0 ratification in Q1 2026.
- Open-Source Consent Notice A free, open-source consent notice component implementing the Consent Foundation specification. Produces structured JSON-LD consent receipts, WCAG 2.1 AA accessible, and jurisdiction-aware (adapts to GDPR, CCPA). Framework-agnostic (React, Vue, vanilla JS) and installable via npm or CDN. For developers and product teams needing a drop-in, accessible consent UI that emits standard consent artifacts.
- PDBA Standard (Personal Data Breach Artifact Standard) Standardized format for privacy breach notifications to regulators and individuals. Defines four artifacts: Breach Notification Artifact, Regulatory Filing Format (GDPR Article 33 compatible), Individual Notification Template, and Incident Correlation ID that links all artifacts. Designed to ensure nothing critical is missed during the 72-hour GDPR notification window.
- Incident Reporting Standard Structured format for privacy incident reports enabling incidents to be comparable, trackable, and learnable across organizations. Includes structured reporting schema, severity classification framework, cross-organization correlation via shared identifiers, and post-incident learning format.
Quantifiable outcome
- Consent notices produce cryptographically verifiable consent receipts capturing who consented, to what, when, and under what conditions — enabling accountability rather than performative compliance
- +2 more outcomes
Companies that use Consent Foundation
Customer profileSegments6 records
Ideal customer profiles5 records
Consent Foundation technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature7 records
Consent Foundation partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered founding member, premier member and general member.
- Securelytixfounding memberFounding member of Consent Foundation. Securelytix is identified as a technology consent manager contributing to the foundation's technical initiatives and standards development. The company supports the open infrastructure for digital consent management.
- Concur - Consent Managerfounding memberFounding member of Consent Foundation. Concur is identified as a consent manager contributing to the foundation's ecosystem. Supports the development of open standards for consent management.
- Privasea Summitpremier memberPremier member of Consent Foundation with strategic leadership role including appointed seat on the Governing Board. Privasea Summit is a privacy-focused organization contributing to the foundation's governance and direction.
- ComplyPlanetpremier memberPremier member of Consent Foundation with strategic leadership role. ComplyPlanet provides compliance solutions and contributes to the foundation's mission of advancing privacy through industry collaboration.
- ClearConsentgeneral memberGeneral member of Consent Foundation with full participation rights in foundation initiatives. ClearConsent is a consent management provider engaging in working groups and governance processes.
- Certanageneral memberGeneral member of Consent Foundation. Certana presented its Trust Centre platform at the Member Spotlight webinar series, demonstrating how organizations can improve transparency and communicate security, privacy, and compliance posture.
- Cloakgeneral memberGeneral member of Consent Foundation with participation in foundation initiatives. Cloak is a consent-related technology provider contributing to the ecosystem.
Scale indicators7 records
Recent moves6 records
Expansion highlights5 records
Consent Foundation competitors and assessment
Company assessmentBroad incumbents
- TrustArc: TrustArc provides enterprise privacy management including consent, DSAR, and risk assessment. As an established incumbent in privacy program management, it is comparable to Consent Foundation in addressing the same regulated use cases through a commercial platform rather than open standards.
- Usercentrics: Usercentrics is a leading CMP operating globally with TCF integration, serving enterprises seeking certified consent compliance. Its commercial CMP offering competes directly with the Open-Source Consent Notice component for the same developer and enterprise integration budget.
- OneTrust: OneTrust is the dominant commercial consent and privacy management platform, offering CMP, DSAR, RoPA, and policy management across jurisdictions. It competes with Consent Foundation's open-source notice component for developer mindshare and represents the primary commercial entity whose adoption choices will shape CDPI's reach.
Others
- Future of Privacy Forum: FPF is a non-profit think tank producing research and policy guidance on privacy technology. Its research-funding, policy engagement, and multi-stakeholder convening model mirror Consent Foundation's stated research, policy, and community-building functions.
- IAPP (International Association of Privacy Professionals): IAPP is the leading global professional association for privacy practitioners, providing certifications, training, and policy engagement. Consent Foundation's education, training, and policy-engagement initiatives are functionally comparable as a non-commercial privacy ecosystem builder.
- W3C Privacy Community Group: The W3C Privacy Community Group develops web-platform-level privacy and consent specifications (e.g., Global Privacy Control). It is comparable as a multi-stakeholder standards body shaping consent protocols, although it operates at the web-standards layer rather than vertical consent artifacts.
Emerging players
- Cookiebot (Usercentrics subsidiary): Cookiebot provides a drop-in consent banner solution widely adopted across SMBs and CMS platforms. It overlaps directly with Consent Foundation's Open-Source Consent Notice toolkit as a comparable self-serve consent UX integration.
- Osano: Osano offers a consent management and privacy compliance platform with an emphasis on developer-friendly integration and transparency — closely aligned with Consent Foundation's open-source, developer-first philosophy and targeting similar mid-market customers.
Direct peers
- Kantara Initiative: Kantara Initiative is a non-profit industry consortia developing identity, consent, and privacy assurance standards with working groups and certification programs. It is the most structurally similar peer to Consent Foundation in operating model, governance, and standards-development approach.
- IAB Europe Transparency & Consent Framework (TCF): IAB Europe's TCF is the most established industry-led consent standard for digital advertising, providing a vendor-facing consent framework with machine-readable signals. It is the closest direct analogue to Consent Foundation's CDPI/Artifact Standard in the adtech vertical, and a likely interoperability partner or competitor depending on adoption dynamics.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
Consent Foundation social profiles
Digital presenceConsent Foundation financial estimates
Financial estimateRevenue estimate
Valuation estimate
Consent Foundation leadership team
Management profileNumber of profiles
Consent Foundation funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Consent Foundation M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Consent Foundation
What does Consent Foundation do?
Consent Foundation develops and distributes open standards, specifications, and reference implementations for digital consent management as a Self-Regulatory Organization. Its central offering is Consent Digital Public Infrastructure (CDPI), a four-layer protocol for expressing, recording, verifying, and interoperably exchanging consent across platforms and jurisdictions, supplemented by supporting standards (Artifact Standard, DataVeda taxonomy, Purpose Directory, PDBA Standard, Incident Reporting Standard) and a free open-source Consent Notice SDK.
Is Consent Foundation a public or private company?
Consent Foundation is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Consent Foundation founded?
Consent Foundation was founded in 2024. It employs 1 to 10 people.
Where is Consent Foundation based?
Consent Foundation is headquartered in Mumbai, India, in the Asia region.
How does Consent Foundation make money?
One revenue line is on record: membership Fees.
Who are Consent Foundation's main competitors?
Broad incumbents on record are TrustArc, Usercentrics and OneTrust. Others are Future of Privacy Forum, IAPP (International Association of Privacy Professionals) and W3C Privacy Community Group. Emerging players are Cookiebot (Usercentrics subsidiary) and Osano. Direct peers are Kantara Initiative and IAB Europe Transparency & Consent Framework (TCF).
Does Consent Foundation have an API?
No public API is recorded for Consent Foundation.
What industry is Consent Foundation in?
Consent Foundation's product category is Privacy and Consent Management Software. Its primary akta.pro industry code is HDADAFAH, Privacy Management (Consent, DSAR, RoPA), with a secondary code of HDADAIAI, Privacy Governance & Consent Management. Its NAICS code is 5417 and its SIC code is 7372.