CKYCRR 2.0 is going live this monthExplore

Building the Data Protection and Consent Infrastructure for GFF 2026

Digio.in
DPDPA.7 min Read

As Official Data Protection & Consent Partner for GFF 2026, Digio uses CoTrust to deliver localised, tamper-proof consent, cookie management and privacy workflows at scale.

Global Fintech Fest has become a defining gathering of the financial technology ecosystem. It’s where thousands of participants, institutions, innovators and policymakers converge around the technologies shaping the future of finance.

When a platform serves a vast, diverse audience, consent must work across languages, infrastructure must meet stringent security requirements, and every interaction has to remain reliable under load. For GFF 2026, Digio has brought that thinking into the event's data-protection architecture.

Background and Key Considerations

As the Official Data Protection and Consent Partner of GFF 2026, Digio is using CoTrust to power the consent, cookie-management and data-protection capabilities supporting the GFF digital experience.

The integration brought a deceptively simple question to the engineering team:

What does consent infrastructure look like when it has to operate at GFF's scale?

The answer starts with four considerations: localisation, deployment, scalability and security.

Designing for a Diverse Indian Audience

GFF brings together a large audience from across India, making language a fundamental consideration in the consent experience.

CoTrust supports localised consent notices with translations built into the underlying template. The system can identify a user's language and serve the appropriate version at runtime, while supporting multiple scripts, including right-to-left languages.

That architecture also makes the experience easier to maintain. Language updates can be made without waiting for a new application release, allowing the consent layer to evolve independently of the product itself.

For an audience as diverse as GFF's, that matters because a consent decision is meaningful only when the person giving it can understand what they are agreeing to.

On-Premise by Design

Data security was another core consideration. For organisations operating in regulated environments, the ability to deploy infrastructure within their own environment can be critical. CoTrust supports on-premise deployment alongside its cloud architecture, with the same core artefact capable of being built for either environment.

The engineering implications run deeper than deployment configuration.

The on-premises architecture is designed to operate without relying on the public internet at runtime. Consent assets, documentation and the tracker-blocking functionality can be packaged within the deployment itself. Giving organisations greater control over where the consent infrastructure runs and how it interacts with their data environment.

Engineering for Scale

At GFF's scale, performance becomes part of the consent experience.

CoTrust has been optimised to keep the client-side footprint lightweight, while its architecture reduces unnecessary network dependencies. Consent notices are fetched so that they render with the page rather than waiting for an additional round trip.

The backend architecture is optimised in parallel, including work to move enforcement closer to the data layer through database-level triggers.

The event model has also been designed with scale in mind. On consent update actions, specific events are triggered to the client with the respective payload in near real time. 

These details become increasingly important as the number of users, purposes and downstream systems grows.

Making Consent Records Tamper-Proof

A consent record may need to be relied upon long after the original interaction. CoTrust therefore treats the integrity of that record as a first-class engineering problem.

Every consent record is cryptographically signed when it is written, with signatures maintained at the organisation level. The resulting proof can be independently verified through the platform, which will result in a verified badge in the UI. 

The database model reinforces that approach. Previous consent records are not overwritten. On consent updates, we supersede the previous recorded consent; in that way, it is tamper-proof. 

Together, cryptographic signatures and an immutable record structure provide an auditable history of consent decisions, including what was decided and how that decision evolved. Users can also download this artefact from the ledger with granular detailing of consents given and which specific versions align with templates and their versions, along with a timestamp.

Overview of Key Modules Deployed

A Cookie Notice Built for the Modern Web

The consent notice is the most visible expression of the system, so its experience has to be designed with the same care as the infrastructure behind it. CoTrust combines accessibility, legibility and localisation with an architecture designed to coexist seamlessly with the host website. The notice is rendered inside a Shadow DOM, isolating it from the site's CSS and preventing styling conflicts in either direction. At the same time, a dedicated styling slot allows organisations to deliberately inherit the host site's fonts and styles when they want the notice to feel native to their brand. The result is a consent experience that is both robustly isolated and highly adaptable to the environment in which it appears.

Cookie Notice Scanning - Scan. Categorise. Control.

CoTrust can scan a domain and its subdomains to identify the cookies and trackers operating across the digital property.

Those cookies and trackers are then categorised according to their purpose, including necessary, analytics, marketing and functionality, allowing the organisation to build a corresponding consent policy.

From that inventory, CoTrust generates a self-contained blocking script. Trackers are blocked until the user has provided consent for the relevant category. Once consent is granted, the appropriate trackers can be activated without requiring a page reload. If an unapproved cookie is subsequently detected, the system can also remove it.

The result is a consent mechanism that actively enforces the policy established by the user. 

Scheduled Jobs - Keeping IT and Marketing in Sync

Cookie environments change constantly. Marketing teams add analytics tools. Campaigns introduce new tags. Vendors change tracking implementations.

CoTrust brings automation into that process through scheduled jobs and asynchronous deployment workflows. Changes can be propagated without requiring every update to become a manual handoff between marketing and IT.

The principle is straightforward: the team adding a tag shouldn’t be able to accidentally create a blind spot in the organisation's consent controls.

Data Flow and Data Lineage: From Consent to Data Protection

The CoTrust integration extends beyond the point at which someone selects a cookie preference.

The platform provides visibility into how personal data moves through an organisation, combining data flow and data lineage to connect what is collected with where it travels and which systems interact with it.

For users, this creates greater transparency around their data. For organisations, it provides a way to understand the operational reality behind their data-protection policies.

Progressive Consent

Consent evolves. New purposes can emerge, existing notices can change, and users may return to a service after their previous choices have already been recorded.

CoTrust supports progressive consent by maintaining the individual's previous decisions and presenting only the purposes for which a response is still required.

This creates a more precise experience: users aren't repeatedly asked to reconsider choices they have already made, while organisations retain a clear record of the purposes to which consent applies.

Access Control - Designed Around Responsibility

Privacy operations rarely involve a single administrator. Different people need different levels of visibility and authority. CoTrust provides role-based access across areas including consent management, privacy requests, data mapping and data-subject request fulfilment.

A DPO can have a different view from a Super Admin. A Compliance Auditor can be given broad visibility without being granted the ability to modify operational data. And organisations can create their own permission structures to reflect their internal responsibilities.

Turning Data Subject Rights into Workflows

The final layer is where privacy requirements become operational.

A request to access, modify or delete personal data can involve multiple purposes, systems and owners. Treating that process as an email or a form leaves too much room for manual interpretation.

CoTrust turns these requests into structured workflows.

A Data Subject Request can be broken down into the relevant actions across systems and purposes, assigned to the appropriate owners and routed through defined approval stages. SLA timelines can be tracked, with warnings and breach events generated as a request moves through the process.

In effect, the organisation can encode its privacy SOP directly into the workflow.

That matters because data protection increasingly depends on execution. The policy may define what should happen; the workflow determines whether it actually does.

Privacy Infrastructure for a Global Fintech Audience

GFF brings together one of the world’s most dynamic fintech ecosystems at an extraordinary scale. Building the digital infrastructure for that ecosystem means building trust into every layer of the experience.

Its scale demands performance. Its audience demands localisation. Its ecosystem demands strong security and operational controls. And its position at the centre of India's fintech community makes the quality of its data practices particularly important.

CoTrust provides the infrastructure behind that layer, from the first consent interaction, through cookie enforcement and data lineage, to the workflows that govern what happens when an individual exercises their rights.

For GFF 2026, the result is a digital experience where data protection is engineered into the platform from the ground up.

Read more Blogs

card image
DPDPA

Building the Data Protection and Consent Infrastructure for GFF 2026

As Official Data Protection & Consent Partner for GFF 2026, Digio uses CoTrust to deliver localised, tamper-proof consent, cookie management and privacy workflows at scale.

card image
Onboarding

AI, CKYC, and The Future of Identity Rails

India’s CKYC registry holds 1B+ verified identities, yet many lenders still use OCR-only ID checks. Digio combines CKYC, liveness, face match, and AI forgery checks into one fraud-proof flow.

card image
DPDPA

Cross-Border Data Transfers After DPDP: A Practical Guide

India’s Digital Personal Data Protection Act, 2023 (DPDPA) allows cross-border data transfers by default. This blog explains Section 16, where RBI and SEBI override DPDPA flexibility, and why consent notices, transfer disclosures, and offshore vendor contracts now matter operationally.

Digitally transform business operations with Digio!

Try first. Subscribe later.

Boost your legal ops efficiency by 80%

1

Get 1-on-1 business use case solutioning

Speak with our business consultants to get a solution walkthrough for your business requirement

2

Test the APIs

Let your development team test our API suite to understand configurability and product integration

3

Subscribe

Get the best in industry commercials for your business usecase