DPDP Guide · Consent Manager
A Consent Manager is one of the genuinely new ideas in India's DPDP Act, and one of the most misunderstood. This guide sets out exactly what it is, what it does, who can register, and what it does not do, corrected against the notified Act and Rules.
In short
A DPDP Consent Manager is a Board-registered service that lets a person give, review, manage and withdraw consent across many businesses from one place. It is defined in Section 2(g), its role sits in Sections 6(7) to 6(9), and its registration conditions are in Rule 4 and the First Schedule of the DPDP Rules 2025. Registration, and the requirement to be registered, take effect on 13 November 2026; the right for individuals to actually use a Consent Manager takes effect on 13 May 2027. It is a distinct regulated role, not the same thing as a Consent Management Platform (CMP), and it does not take over a business's own responsibility for valid consent.
The single most common error about Consent Managers is treating the framework as if it switches on all at once in 2026. It does not. The Act and Rules commence in phases, and the Consent Manager pieces are split across two different dates a year apart.
| Provision | Commences | What it means |
|---|---|---|
| Definitions (Section 2), the Data Protection Board (Sections 18 onward), and Rules 1, 2 and 17 to 21 | 13 November 2025 | The legal definitions, including "Consent Manager," are live and the Board can be constituted. |
| Rule 4 and Section 6(9): registration of Consent Managers and the requirement to be registered | 13 November 2026 | A company can apply to register as a Consent Manager, and anyone operating as one must be registered. |
| Sections 6(7) to 6(8): the right to give, manage, review and withdraw consent through a Consent Manager, plus the wider consent, notice, security and rights regime (Rules 3, 5 to 16, 22 to 23) | 13 May 2027 | Individuals can actually use a Consent Manager, and the full compliance regime applies. |
Section 1 of the Act lets the Government bring different provisions into force on different dates. Registration (Rule 4 and Section 6(9)) commences a full year before the user-facing right to use a Consent Manager (Sections 6(7) to 6(8)). A commencement date is also not proof that an application portal, form or technical standard exists on that day.
In plain terms, a Consent Manager is a Board-registered intermediary that sits between individuals and the organisations that hold their data, and gives the individual one place to control consent across all of them.
Section 2(g) defines it as a person registered with the Board who acts as a single point of contact for a Data Principal to give, manage, review and withdraw consent, through an accessible, transparent and interoperable platform. Sections 6(7) to 6(9) then set out the role: a Data Principal may give or withdraw consent through a Consent Manager; the Consent Manager is accountable to the Data Principal and acts on their behalf; and every Consent Manager must be registered with the Board in the manner the Rules prescribe.
Consent Manager: defined in Section 2(g); role in Sections 6(7) to 6(9); registration conditions in Rule 4 and the First Schedule of the DPDP Rules 2025. Section 6(8) says it is accountable to the Data Principal and acts on their behalf, and the First Schedule says it acts in a fiduciary capacity in relation to the Data Principal.
Two statements about a Consent Manager are both true, and often confused with each other:
So the Act sets out the role in general terms, and the Rules set the eligibility gate. When people ask "who can become a Consent Manager," the practical answer is: an India-incorporated company that meets the Rule 4 conditions.
This matters for overseas providers. The Rules require the applicant to be a company incorporated in India. The notified text does not add further residency or ownership conditions beyond what Part A lists, so avoid reading in requirements that are not there, in either direction.
Rule 4 and the First Schedule turn the definition into a working platform specification. In practice, a registered Consent Manager:
Underneath, it is expected to run on an interoperable platform so that these interactions work consistently across the Data Fiduciaries that connect to it.
A Consent Manager is a narrower thing than the marketing around it suggests. It does not:
The most expensive misreading is treating a Consent Manager as a way to offload responsibility. Under Section 6(10), the burden of proving valid notice and consent stays with the Data Fiduciary, whichever channel the consent came through.
Part B of the First Schedule sets out what a Consent Manager must keep, and how data may move through it.
Records. It must maintain records of: consents given, denied or withdrawn; the notices that preceded or accompanied each consent request; and the sharing of data with any transferee Data Fiduciary. These records must be kept for at least seven years, or longer where the Data Principal agrees or another law requires it.
Access. On request, and subject to its terms of service, it must make the information in that record available to the Data Principal, including in machine-readable form.
The "data-blind" rule. Where personal data is made available or shared through the Consent Manager, the Rules require the method to ensure that the contents are not readable by the Consent Manager. "Data-blind" is a useful shorthand for this, but the statutory test is about the manner of sharing, not a complete technical design that the Rules prescribe.
Two phrases to avoid, and what to write instead. Not "data portability" (there is no general DPDP portability right) but "machine-readable consent and sharing records." And not "tamper-evident" or "immutable log" (the Rules do not use those words) but "the required records, plus effective audit mechanisms."
This is where most confusion, and most vendor marketing, lives. A statutory Consent Manager is not the same as a Consent Management Platform (CMP), and neither is a consent field in your CRM. They solve different problems, and only one of them is a registered legal entity.
| Consent Manager (statutory) | Consent Management Platform (CMP) | CRM consent field | |
|---|---|---|---|
| What it is | A Board-registered intermediary entity | Software you deploy to capture and manage consent | A data field inside a sales or marketing system |
| Registered with the Board? | Yes, mandatory under Section 6(9) and Rule 4 | No | No |
| Scope | Cross-fiduciary: one dashboard across many organisations | Single organisation: your own consent, across your systems | Single system, often marketing only |
| Who operates it | A specialist, registered company | Any Data Fiduciary, for itself | Any business, for itself |
| DPDP status | A defined role with its own obligations | An implementation tool, not named in the Act | Not named in the Act |
| When you need it | Only if you want to operate as a registered consent intermediary | When you collect or manage consent directly | Rarely enough on its own for proof of consent |
If your organisation collects consent from its own users, you are a Data Fiduciary. What you need is a compliant consent-management capability, which could be a CMP, a custom-built system, or another suitable process. That is not the same as registering as a Consent Manager, and a CMP is not a statutory requirement in itself. For help choosing between them, see the Consent Manager vs CMP vs build decision guide.
Most online coverage of Consent Managers is written by vendors selling consent software, so several inaccurate claims have become common. Here is what you will often read, set against what the notified Act and Rules actually say.
| What you will often read | The accurate position |
|---|---|
| "A Consent Manager keeps immutable, tamper-proof logs." | The Rules require records of consents, notices and data sharing, kept for at least seven years, together with effective audit mechanisms. They do not use the words "immutable" or "tamper-proof." The accurate phrasing is "the required records, plus audit," not "tamper-proof ledger." |
| "Under the DPDP Act consent is the only legal basis, so you always need consent." | Section 4 permits processing on consent or a legitimate use. Section 7 sets a closed list of legitimate uses (voluntary provision, certain State functions and benefits, legal obligations, medical emergencies, employment and others) where consent is not the basis at all. |
| "A Consent Manager is basically a CMP or a cookie-consent tool." | A Consent Management Platform is software a business runs for its own consent. A statutory Consent Manager is a separate, Board-registered entity that acts for the individual across many Data Fiduciaries. Different role, different accountability. |
| "Your business needs to register as a Consent Manager." | Registration is only for companies that want to operate as the intermediary. As a Data Fiduciary you may use one (optional) or collect consent directly. What you need is a compliant consent capability, not a Consent Manager registration. |
| "A Consent Manager gives individuals a data-portability right." | The Rules require machine-readable access to a specified record and consent-directed transfer of data to a transferee fiduciary. That is narrower than a general, GDPR-style portability right; "portability" is loose shorthand for a specific consent-directed function. |
| "Using a Consent Manager offloads your compliance liability." | Section 6(10) keeps the burden of proving valid notice and consent on the Data Fiduciary, and Section 8 keeps responsibility for the processing with it. Routing consent through a Consent Manager does not move that accountability. |
Every correction above traces to the notified DPDP Act, 2023 and DPDP Rules, 2025: Section 4 (lawful processing), Section 6 including 6(10) (burden of proof), Section 7 (legitimate uses), Section 8 (responsibility of a Data Fiduciary), and the First Schedule, Part B (records, audit, and data-blind sharing).
No, and the confusion usually comes from mixing up two different "mandatory" questions.
So using a Consent Manager is optional; being registered, if you are one, is not.
Section 6(7) uses "may." Section 6(9) requires every Consent Manager to be registered. Registering is a voluntary business decision, and only a small number of specialist companies are expected to do it.
An entity that wants to operate as a Consent Manager applies to the Board under Rule 4 and must satisfy the eligibility conditions in Part A of the First Schedule. The main ones:
| Condition | What it means |
|---|---|
| Company incorporated in India | The applicant must be an India-incorporated company, not an individual and not a foreign entity. |
| Sufficient technical, operational and financial capacity | A Board-assessed condition on whether it can actually run an interoperable consent platform, not merely a feature list. |
| Sound financial condition and general character of management | A standalone condition on the company's finances and on the standing of those who run it. |
| Net worth of at least ₹2 crore | Net worth means the aggregate value of total assets minus total liabilities as shown in the company's books. It is not a registration fee or a deposit. |
| Adequate business volume, capital structure and earning prospects | A separate viability test, distinct from the minimum net worth figure. |
| Reputation and integrity of directors, KMP and senior management | Their record of fairness and integrity is assessed. |
| Constitutional documents and policies | The memorandum and articles must contain the governance provisions in Part B, with supporting policies, and may be amended only with prior Board approval. |
| Operations in the interests of Data Principals | The proposed operations must be in Data Principals' interests, which the Board assesses. |
| Independent certification of the platform | Independent certification that the platform is interoperable and conforms to the data-protection standards or assurance frameworks the Board may publish. |
Several of these conditions reference standards and assurance frameworks that "the Board may publish." Until those are published, parts of the registration bar cannot be fully met in practice, which is one reason the registration provision commencing on 13 November 2026 does not, by itself, mean applications can be filed that day.
Part B of the First Schedule sets the duties a Consent Manager must meet on an ongoing basis, not just at the point of registration. Each row below is an express Rule requirement, put in plain English.
| # | Obligation | What it means |
|---|---|---|
| 1 | Enable consent to onboarded Fiduciaries | Enable a Data Principal's consent to reach an onboarded Data Fiduciary, directly or through another onboarded Fiduciary that holds the data. |
| 2 | Keep data unreadable to itself | Ensure the method of making data available or sharing it keeps the contents unreadable by the Consent Manager. |
| 3 | Keep records | Record consents given, denied and withdrawn; the notices involved; and any sharing with a transferee Data Fiduciary. |
| 4 | Provide record access and retain it | Give the Data Principal access to that record, machine-readable on request, and retain it for at least seven years or longer by agreement or law. |
| 5 | Maintain a website or app | Provide and maintain a website or application as the primary means of access for Data Principals. |
| 6 | Do not subcontract obligations | Do not subcontract or assign the performance of any of its obligations under the Act and Rules, not merely "core" ones. |
| 7 | Reasonable security safeguards | Take reasonable security safeguards to prevent a personal data breach. This is the Consent Manager's own duty; the Rules do not automatically apply every Rule 6 Data Fiduciary control to it. |
| 8 | Act as a fiduciary to the Data Principal | Act in a fiduciary capacity in relation to the Data Principal. |
| 9 | Avoid conflicts with Data Fiduciaries | Avoid conflicts of interest with Data Fiduciaries, including conflicts involving their promoters and key management personnel. |
| 10 | Prevent conflicts through its own people | Prevent conflicts arising from its directors, KMP and senior management holding directorships, financial interests, employment, beneficial ownership or material pecuniary relationships with a Data Fiduciary. |
| 11 | Publish transparency disclosures | Publicly disclose its promoters, directors, KMP and senior management; shareholders holding more than 2%; certain interests in other body corporates; and any Board-directed information. |
| 12 | Run effective audits and report to the Board | Establish effective audit mechanisms to review, monitor, evaluate and report specified outcomes to the Board, periodically and when directed. |
| 13 | Get approval before a change of control | Obtain prior Board approval before any sale, merger or other transfer of control. |
Several of the Part B duties are governance controls that matter to anyone assessing whether a Consent Manager is trustworthy, and to any company thinking of becoming one.
Conflicts of interest. A Consent Manager must avoid conflicts with Data Fiduciaries, including their promoters and key management personnel. Separately, its own directors, KMP and senior management must not have conflicts through directorship, financial interest, employment, beneficial ownership or a material pecuniary relationship with a Data Fiduciary.
Public disclosure. It must publish, and keep current, a defined set of ownership and control information:
| Must disclose | Detail |
|---|---|
| People in control | Promoters, directors, key management personnel and senior management. |
| Major shareholders | Each person holding more than 2% of the company's shareholding. |
| Related corporate interests | Specified interests the company or its people hold in other body corporates. |
| Board-directed information | Any further information the Board directs it to publish. |
Audit. It must establish effective audit mechanisms to review, monitor, evaluate and report to the Board, covering its technical and organisational controls, systems, processes and safeguards; its continuing compliance with the registration conditions; and its compliance with the Act and Rules. This is a Consent Manager duty in its own right, and is not the same as the independent data-auditor and data protection impact assessment regime that applies to a Significant Data Fiduciary.
A change of control is not a private matter for a Consent Manager. Any sale, merger or other transfer of control needs prior Board approval, and these Part B conditions are continuing, so failing them can put the registration itself at risk.
For most businesses, the arrival of Consent Managers changes less than the noise suggests. What stays true:
You stay accountable. Connecting to a Consent Manager does not move your DPDP responsibility onto it. Design your own consent capture, records and withdrawal handling as if the Consent Manager channel may never arrive, because your obligations do not depend on it.
The Consent Manager idea did not appear from nowhere. It builds on India's 2020 Data Empowerment and Protection Architecture (DEPA) and its first real-world implementation, the Account Aggregator framework in the financial sector, where regulated intermediaries already move financial data on the strength of user consent.
That lineage is useful for intuition. It is not a legal equivalence. The Account Aggregator regime is a sectoral, RBI-regulated financial-information framework; the DPDP Consent Manager is a distinct statutory role under the DPDP Act and Rules. Do not assume that how Account Aggregators work, who regulates them, or what they are permitted to do carries over to DPDP Consent Managers.
An Account Aggregator is not a DPDP Consent Manager, and RBI's Account Aggregator rules do not define the DPDP Consent Manager framework. Treat the resemblance as background, not authority.
Several things about the Consent Manager framework are not yet settled and should be checked against the Board's official notices before you rely on them:
Registration provisions (Rule 4 and Section 6(9)) are scheduled to commence on 13 November 2026. This guide will be updated as the Board publishes the process, standards, register or directions.
Whether or not you ever connect to a Consent Manager, your own notice, consent, records and withdrawal have to hold up. Start with the consent management guide, or check where you stand.
A Consent Manager is a Board-registered service, defined in Section 2(g), that lets a Data Principal give, review, manage and withdraw consent across many businesses through a single, interoperable platform. Its role is set out in Sections 6(7) to 6(9), and its registration conditions are in Rule 4 and the First Schedule of the DPDP Rules 2025.
No. The Act does not require a Data Fiduciary to use a Consent Manager. Section 6(7) says a Data Principal may use one. A business can collect and manage consent directly, as long as it is valid. Registration is only mandatory for a company that chooses to operate as a Consent Manager.
No. If you collect consent directly, you are a Data Fiduciary and you need a compliant consent-management capability, which could be a Consent Management Platform (CMP), a custom-built system or another suitable process. That is different from registering as a Consent Manager, and a CMP is not a statutory requirement in itself.
A Consent Manager is a Board-registered intermediary that works across many businesses on the individual's behalf. A Consent Management Platform is software a single business runs to manage its own consent. One is a regulated legal role; the other is an implementation tool. They are not interchangeable.
Under Rule 4 and Part A of the First Schedule, the applicant must be a company incorporated in India with net worth of at least ₹2 crore, sufficient technical, operational and financial capacity, sound finances, fit-and-proper management, and an independently certified interoperable platform, among other conditions.
A company applying to register must have net worth of at least ₹2 crore. Net worth broadly means total assets minus total liabilities as shown in the company's books. It is a financial-standing condition, not a registration fee or a deposit.
They are phased. Rule 4 and Section 6(9), covering registration and the requirement to be registered, commence on 13 November 2026. Sections 6(7) to 6(8), the right to actually use a Consent Manager, commence on 13 May 2027. The definitions came into force earlier, on 13 November 2025.
The Rules require the applicant to be a company incorporated in India. A foreign entity would need to register or operate through an India-incorporated company that meets the Part A conditions. The notified text does not add further conditions beyond those listed.
The First Schedule prohibits a Consent Manager from subcontracting or assigning the performance of any of its obligations under the Act and Rules. The notified text does not spell out where ordinary technology-vendor support ends and prohibited delegation begins, so a broad vendor carve-out should not be assumed.
No. Under Section 6(10), the Data Fiduciary must still be able to prove it gave valid notice and obtained valid consent, and it remains responsible for its processing under Section 8. A Consent Manager does not absorb that responsibility, and it does not make invalid consent valid.
Where personal data is made available or shared through a Consent Manager, the Rules require the sharing method to keep the contents unreadable by the Consent Manager. This is often called "data-blind." It applies to the manner of sharing, and the Rules do not prescribe every technical detail of how it is achieved.
Last reviewed: 20 August 2026. This is general information about the DPDP Act and Rules, not legal advice, and is not affiliated with any government body. Where the notified Rules leave a point open, this guide says so rather than filling the gap.