Readiness assessment

DPDP Implementation

Consent Manager, CMP, or Build In-House: How to Run DPDP Consent

If your organisation collects consent from its own users, the real decision is not whether to "get a Consent Manager." It is how to run your own consent obligations. This guide separates the questions people conflate, then helps you choose between a platform, building in-house, and a manual process.

In short

For a business that collects consent from its own users, the choice is how to run your own consent: adopt a Consent Management Platform (CMP), build it in-house, or use a disciplined manual process for very low volumes. A registered Consent Manager is a separate, optional channel, not something you become or must buy. Whichever route you take, you remain accountable under Sections 6(10) and 8, so the deciding factors are your consent volume, the number and complexity of your systems, your engineering capacity, and your sector.

First, separate two questions that get merged

Most of the confusion around this topic comes from collapsing two very different questions into one. Pull them apart before you decide anything.

  • "Do we need to register as a Consent Manager?" Almost certainly not. Registering is for specialist companies that want to operate the cross-fiduciary intermediary defined in the Act: a company incorporated in India, with a net worth of at least ₹2 crore and an independently certified interoperable platform, registered with the Data Protection Board under Rule 4. That is a business someone builds on purpose, not a compliance step for an ordinary Data Fiduciary.
  • "How do we run our own consent obligations?" This is the real question for nearly every business, and it is a build-or-buy decision about your own notice, consent, records and withdrawal.
Practice

When a vendor says "consent manager," they almost always mean consent software (a CMP), not the statutory registered role. Keep the two apart: one is a tool you run for yourself, the other is a separate regulated entity that acts for the individual across many businesses. The DPDP Consent Manager guide covers the statutory role in full.

Three ways to run your own DPDP consent

Once you are clear that the task is running your own consent, there are three practical routes. None of them is mandated by the Act; the Act sets the outcome (valid notice, valid consent, records, easy withdrawal) and leaves the method to you.

 Adopt a CMPBuild in-houseManual / process
What it isLicence a consent-management platform and configure it to your notices and systemsEngineer consent capture, records and withdrawal into your own productStructured forms, a records log and written procedures
Best forStandard web and app consent, several channels, limited engineering capacityBespoke data flows, a capable engineering team, a need for full controlVery small organisations with low volume and simple, single-purpose collection
StrengthsFast to deploy, maintained for you, ready-made notice, record and withdrawal featuresFits your architecture exactly, no per-seat fees, you control the roadmapCheap, no vendor, quick to start
Trade-offsRecurring cost, some lock-in, many tools over-index on cookie banners rather than full DPDP recordsBuild and maintenance burden, you own compliance-by-design and every edge caseWeak proof and audit trail, error-prone, does not scale

A fourth thing you will see marketed, a "consent field" bolted onto a CRM or marketing tool, is rarely enough on its own. It usually records a yes or no without the notice version, the purpose granularity, or the withdrawal trail you need to prove valid consent.

Which route fits your organisation

There is no universally correct answer. Match your situation to the route, and be honest about where you are heading, not just where you are today.

Your situationLikely best route
High volume, multiple apps or websites, limited engineering timeA CMP
Complex, bespoke systems and data flows, a strong engineering team, a need for controlBuild in-house, or a CMP with deep APIs and customisation
Very small, low volume, one or two simple purposesA disciplined manual process, with a plan to upgrade before you scale
A cross-entity ecosystem: financial services, health, credit, public benefitsRun your own consent now, and plan to connect to a registered Consent Manager later
You already rely on a CRM or marketing tool's consent fieldTreat it as insufficient on its own and add a proper consent capability

A vendor-neutral evaluation checklist

Whether you buy a CMP or build in-house, the same requirements apply, because they come from the Act and Rules, not from any vendor. Use this list to evaluate any option on equal terms.

  • Purpose-level, granular consent, not a single "Accept all" switch.
  • Each consent tied to the specific notice shown, with that notice version retained alongside the record.
  • Withdrawal that is as easy as giving consent, and that propagates to your processors and downstream systems.
  • Complete, queryable records: who consented to what, under which notice, when, and any later withdrawal.
  • Notices available in English and the other Eighth Schedule languages you actually need.
  • A clean export or report that lets you discharge the Section 6(10) burden of proving valid notice and consent.
  • Correct handling of children's data where relevant: verifiable parental consent, and no tracking or targeted advertising directed at children.
  • Room for legitimate-use processing, so you are not forced to treat everything as consent-based when Section 7 applies.
  • Reasonable security safeguards for the consent records themselves.
Want to pressure-test an existing setup? The consent audit checklist walks these controls one by one.
Run the consent audit →

What none of these choices change

The route you pick changes your effort and cost. It does not change who is on the hook.

  • You must be able to prove valid notice and consent. Section 6(10) keeps that burden on you, whether the consent came through your own form, a CMP or a Consent Manager.
  • You remain responsible for your processing. Section 8 keeps that responsibility with the Data Fiduciary. Buying a tool or connecting to an intermediary does not move it.
  • You must honour withdrawal. When consent is withdrawn you cease that processing within a reasonable time and cause your processors to stop, unless another law requires otherwise (Section 6(6)).
  • Not everything is consent. Section 7 sets a closed list of legitimate uses where consent is not the basis at all, so your setup should handle both paths.
Risk

"We bought a CMP, so we are compliant" is the most common and most expensive mistake here. A tool helps you meet the requirements; it does not meet them for you. Configuration, notice quality, records and withdrawal handling are what actually satisfy the Act.

Not sure which route you need?

Start by seeing where your current consent setup stands, then decide what to fix internally and where a platform or specialist would help.

Frequently asked questions

Do I need to register as a Consent Manager to run consent?

No. Registering as a Consent Manager is for specialist companies that want to operate the cross-fiduciary intermediary under Rule 4. To run your own consent as a Data Fiduciary, you adopt a CMP, build in-house, or use a disciplined manual process. Registration is not part of that.

Is a CMP mandatory under the DPDP Act?

No. The Act sets the outcome (valid notice, valid consent, records, easy withdrawal) and leaves the method to you. A Consent Management Platform is one common way to meet those requirements, not a statutory requirement in itself.

Should I build or buy DPDP consent management?

Buy a CMP if you need standard web and app consent quickly and have limited engineering time. Build in-house if you have bespoke data flows, a capable team and a need for control. A manual process only fits very small, low-volume, simple collection, and should be upgraded before you scale.

When would I connect to a registered Consent Manager?

It is optional, and most relevant in cross-entity ecosystems such as finance, health and credit. It is also a future decision: registration commences on 13 November 2026 and the user-facing right to use a Consent Manager commences on 13 May 2027. It supplements, and never replaces, your own consent capability.

Does buying a CMP make me compliant?

No. A tool helps, but you remain accountable under Section 6(10) and Section 8. Whether you are compliant depends on your notices, purpose granularity, records and withdrawal handling, which are configuration and process, not the mere presence of software.

What is the difference between a Consent Manager and a CMP?

A Consent Management Platform is software a business runs to manage its own consent. A statutory Consent Manager is a separate, Board-registered entity that acts for the individual across many businesses. One is an implementation tool; the other is a regulated role. See the Consent Manager guide for the full distinction.

Primary sources

  • Digital Personal Data Protection Act, 2023: Sections 4, 5, 6 (including 6(6), 6(7) and 6(10)), 7 and 8.
  • Digital Personal Data Protection Rules, 2025: Rule 3 (notice), Rule 4 and the First Schedule (Consent Manager registration and obligations).
  • Commencement notifications dated 13 November 2025, which set the phased dates of 13 November 2026 (Consent Manager registration) and 13 May 2027 (the right to use a Consent Manager and the wider consent regime).

Last reviewed: 20 August 2026. This is general information about implementing the DPDP Act and Rules, not legal advice, and is not affiliated with any government body or any consent-technology vendor.