Solutions · Real estate & proptech

One enquiry.
Fifty brokers who dial.

A buyer’s enquiry is distributed to a channel-partner network of dozens to hundreds of brokers, each of whom calls independently — a distribution model built entirely on onward transfer nobody consented to, feeding the country’s most-complained-about consumer harm. Around it: RERA-mandated records that shield the agreement’s PAN but not the six phone numbers and the site-visit log in the CRM, across thirty-odd state rule sets nobody has mapped; and Aadhaar demanded at the sub-registrar by state mandate and photocopied at the sales office by habit, against a statute that restricts exactly that.

FROM THE SEPTEMBER 2026 PROBLEM REGISTER · 4 REAL-ESTATE PROBLEMS SWEPT · 4 SHOWN HERE, ONE LABELLED HYPOTHESISED · HOW THIS WAS BUILT

What the ground actually looks like

Three confirmed collisions, and one we label honestly.

Confirmed means two independent sources, at least one the instrument itself or a practitioner record. Where a half of a problem rests on secondary sources only, the card says so.

01 · THE CONSENTLESS BROADCAST

Developer and portal leads are bulk-distributed to channel-partner networks none of whom the buyer consented to — and the regulator of spam is already fighting the symptom.

Section 6(1) requires consent that is specific to a purpose. Sharing an enquiry with fifty partners who each dial is onward transfer the buyer never agreed to; the bundled “I authorise X and its partners” line is exactly the boilerplate s.6(1) is written against. TRAI’s telemarketing regulations and its 2024 direction disconnecting unregistered telemarketers already act on the symptom — real estate is among the top spam categories — while DPDP reaches the cause from mid-May 2027.

SOURCES · DPDP Act s.6(1) (statute) · PIB on TRAI’s spam-control measures (government, the enforcement record this feeds)

Confirmed · sweep of 2 Sep 2026 · this is the vertical’s revenue mechanic
02 · WHAT RERA ACTUALLY SHIELDS

RERA-mandated records collide operationally with erasure rights, and nobody has mapped which fields the law-in-force carve-out covers — across thirty-odd state rule sets.

RERA s.4 and s.11 require promoter disclosures; s.10(b) requires agents to preserve records “as may be prescribed” — state by state. DPDP s.8(7) and s.12(3) let a fiduciary refuse erasure only for what a law in force requires. The carve-out covers the buyer’s PAN in the agreement, not the phone numbers and site-visit log in the CRM. Over-honouring breaks RERA and tax; blanket refusal breaks DPDP; the published response period runs either way. Not a hard legal conflict — an unmapped one.

SOURCES · RERA 2016, s.10(b) (statute) · DPDP Act s.8(7), s.12(3) (statute) · Vinod Kothari on DPDP for non-financial entities (practitioner)

Confirmed as a mapping problem · the state periods themselves are not enumerated anywhere
03 · AADHAAR, MANDATED AND PHOTOCOPIED

Aadhaar authentication is becoming mandatory at the sub-registrar by state order, while builders photocopy the card into the booking file by habit — against the Aadhaar Act and DPDP minimisation.

Uttar Pradesh made Aadhaar authentication with biometric verification mandatory for property registration from 1 February 2026; other states are moving to Aadhaar-linked e-registration. That is the state acting under its own law. The private-side habit — a full photocopy in the sales office file — sits against the Aadhaar Act’s s.29 restrictions, the Supreme Court’s 2018 ruling on private authentication, and DPDP s.6 minimisation. Masked Aadhaar and offline-verification XML are the legally preferred forms; adoption at sales offices is near nil.

SOURCES · The UP mandate, as reported by the public broadcaster (state instrument, as reported) · Aadhaar Act s.29; DPDP Act s.6 (statute)

Confirmed for the mandate and the restrictions · the photocopy half is attested by secondary sources only
04 · ONE PROFILE, ONE BLANKET CONSENT

Proptech portals fuse listing, lead generation, tenant screening and KYC — rent agreements, police verification — into one profile under one consent.

The architecture is near-certain from the product surface: identity documents collected for a tenancy persist beside browsing and lead-generation data under a single signup consent, and the tenant’s Aadhaar outlives the tenancy. KYC-grade documents under lead-generation-grade governance is the shape. No second source yet establishes the cross-purpose reuse concretely, so this card is labelled rather than asserted.

SOURCES · DPDP Act s.6, s.8(7) (statute) · no practitioner record yet — stated as such

Hypothesised · the architecture is visible; the reuse is not yet on record
What the law actually says — and what it doesn’t

Claims we corrected before putting them here.

The register started from AI-drafted hypotheses and kept only what the instruments supported. These are the property-specific claims that changed on the way.

Builders do not collect biometrics. The sub-registrar does.

Biometric authentication at registration is a state actor acting under a state mandate. What the private side collects is document copies. The two halves need different lawful-basis analyses, and material that blurs them gets both wrong.

There is no central RERA retention period.

The duty to preserve records is prescribed state by state. Any page that quotes a single number for it is quoting a state rule or inventing one. The register lists the enumeration of the state periods as exactly the mapping nobody has done.

The carve-out is by field, not by file.

Section 8(7) protects what a law in force requires — the mandated disclosure fields — not the whole customer record they sit in. A refusal that cites RERA for the CRM is a refusal that will not hold.

No DPDP penalty can be imposed on anyone today.

The penalty provisions commence in mid-May 2027 and the Board had no members as of 1 August 2026. What is enforced today is the telemarketing regime on the calls themselves. The DPDP penalty schedule is stated plainly here, once.

RULES NOTIFIED MID-NOV 2025 · CONSENT-MANAGER REGISTRATION OPENS MID-NOV 2026 · DUTIES, RIGHTS AND PENALTIES MID-MAY 2027 · DATES STATED AS THE NOTIFICATIONS STATE THEM

Where Consent Tree fits today

Consent per partner,
not a line in the T&C.

Everything below is live today and maps to shipped code — the same rule as every page on this site. Capabilities we are still building are not listed here.

FOR 01 · THE BROADCAST

Purpose-level consent with the sharing named, versioned, and withdrawable

Onward sharing with channel partners becomes a specified purpose the buyer decides on separately from the enquiry itself — never bundled, never pre-ticked; the widget enforces that rather than trusting the form. Notices are versioned so a change forces re-consent and the old version stays on record; withdrawal is as easy as the grant. Each decision produces a receipt the buyer keeps and anyone can verify. Who was actually shared with is your CRM’s record to keep — and our processor register to hold.

Live: purpose-by-purpose consent · no pre-ticked purpose · versioned notices · PDF receipts
FOR 02 · THE FIELD-LEVEL REFUSAL

A rights request executed against the CRM, with the RERA refusal for the mandated fields evidenced

Every access, correction and erasure request carries a response deadline computed when it is filed and an escalation ladder when it slips. Erasure is executed against the stores you connect — a parameter-bound delete against the table and column you nominate, and deletion through connected CRM tools’ own APIs — and the destruction is recorded, not asserted. The refusal for the mandated fields lands in the same audit chain, citing the provision. Mapping the state rule is yours; the refusal that names it is evidenced here.

Live: DSR orchestration · SLA tracking · erasure connectors
FOR 03 AND 04 · FINDING THE COPIES

A data inventory with lineage, so the photocopy in the booking file and the tenant’s Aadhaar have a known location and a known owner

A single inventory of your data assets, with visual lineage tracing how personal data flows between systems and purposes, and a discovery layer that finds identity documents where they sit. Minimisation starts with knowing where the maximum currently is. Which documents you keep collecting is a policy decision this page does not make for you.

Live: unified data inventory + visual lineage · Sentin-AI discovery
FOR ALL OF IT · EVIDENCE, IN 22 LANGUAGES

Notices in the Eighth Schedule languages, and an audit trail a regulator can verify without trusting us

Notices and consent flows are rendered in twenty-two Indian languages by a self-hosted translation model — buyers across states are served one versioned notice. Every consent, erasure, refusal and notice publication is a linked record bound to the one before it, periodically stamped by an independent timestamp authority. Anyone can check it.

Live: 22 Indian languages · tamper-evident audit trail · verifiable receipts