Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
DPDP Act 2023 · Consent

DPDP Consent Manager vs Consent Management System: What's the Difference?

A Consent Manager is a Board-registered legal role. A consent management system is your own tooling. See how they differ, where the law stands today, and which one you need.

Now · since 13 Nov 2025
Act and Rules notified
On or about 13 May 2027
Core consent duties start
Consent tooling in India: four termsMind map: only the Consent Manager is a legal role under DPDP Act s2(g); CMS, CMP and cookie consent tool are not defined in the Act or Rules.Consent ManagerLegal role, Act s2(g)Board-registeredConsent managementsystem (CMS)Your own process and toolsNot defined in lawConsent managementplatform (CMP)Software categoryNot defined in lawCookie consent toolWebsite bannerNot defined in lawConsenttooling
Figure 1. Four terms, one legal role. Only the Consent Manager is defined in the DPDP Act (s2(g)); the other three are technology or process labels.

Consent Manager, CMS, CMP and cookie tool: the four terms at a glance

How the four terms differ
DPDP Consent ManagerConsent management system (CMS)CMPCookie consent tool
What is it?Board-registered intermediaryYour own mix of tools, records and processSoftware category; scope varies by vendorWebsite banner and preference tool
Legal statusDefined in Act s2(g)Not definedNot definedNot defined
RegistrationWith the Board under Rule 4None specific to DPDPNone specific to DPDPNone specific to DPDP

What is a consent management system (CMS)?

A consent management system is the combination of interfaces, records, rules and integrations an organisation uses to capture, evidence and act on consent. The Act and Rules do not define it or name it. They set outcomes, and a CMS is one way to meet them:

  • Required outcome, once operative: valid notice and consent (s5, s6, Rule 3), comparable-ease withdrawal (s6(4)), and proof (s6(10)).
  • Recommended: a versioned consent record, self-service withdrawal and automatic propagation to systems and processors.
  • Optional: dashboards, preference centres, expiry timers and cookie scanning.

DPDP Consent Manager vs consent management system: side by side

Consent Manager vs consent management systemComparison chart: definition in law, Board registration, main user and availability for a Consent Manager and a consent management system.Consent ManagerConsent managementsystemDefined in the Act or Rules?Yes, Act s2(g)No definitionBoard registration?Yes, under Rule 4NoneMain userData PrincipalThe organisationrunning itAvailable on 30 Sep 2026?Not yet. Rule 4 startson or about13 Nov 2026Yes, build or buy
Figure 2. Comparison chart. A Consent Manager is a registered, Principal-facing role that is not yet available; a consent management system is your own tooling, available now.

A Consent Manager helps a person control consent across many companies. A CMS helps one company honour and prove the consent it holds. They can work together: a fiduciary's CMS can act on a choice a person made through a registered Consent Manager. That is an architecture choice, not a duty the Rules spell out; the fiduciary stays responsible for its processors (s8(1)). Compare options in Consent Manager vs CMP vs build.

Is a CMP the same as a DPDP Consent Manager?

No, not by default. A cookie CMP records website tracker choices only. An enterprise consent platform keeps central records and syncs them to CRM and marketing systems, which helps you evidence consent but remains your own tooling. Only a Board-registered operator is a statutory Consent Manager.

Legal status of Consent Managers and consent duties on 30 September 2026

DPDP commencement timeline for consent provisionsTimeline: 13 November 2025 definitions and Board; on or about 13 November 2026 Consent Manager registration; on or about 13 May 2027 notice, consent, withdrawal and proof duties.Today:30 Sep 202613 Nov 2025Definitions andBoard provisions13 Nov 2026(on or about)Consent Managerregistration (Rule 4)13 May 2027(on or about)Notice, consent,withdrawal, proofand other duties
Figure 3. Commencement timeline. The shaded bar shows time elapsed as of 30 September 2026, about 10.5 of the 18 months.
Commencement position (Gazette G.S.R. 843(E) and Rule 1 of the DPDP Rules, 2025)
ProvisionsApplies fromStatus
Definitions (s2), Board provisions (ss18 to 26)Gazette publication, 13 November 2025Operative
Consent Manager registration: s6(9), s27(1)(d), Rule 4One year after publication, on or about 13 November 2026Enacted, not yet operative
Notice, consent, withdrawal, proof, fiduciary duties: ss4 to 8, s6(1) to (8) and (10); Rules 3, 5 to 16Eighteen months after publication, on or about 13 May 2027Enacted, not yet operative
January 2026 reports of shorter timelines for selected provisions (for example Rule 8(3) and Rule 13)Not applicableReported proposal, not enacted

Periods run from Gazette publication. The issue is dated 13 November 2025, but the e-Gazette file code shows 14 November, so some sources quote 14 November. Corrigendum G.S.R. 892(E) corrected the Rules; the durations are unchanged. Plan for the earlier date and re-check the Gazette before acting. See the DPDP Rules explained and the compliance timeline.

Consent lifecycle under DPDP: from notice to withdrawal

DPDP consent lifecycle in seven stepsProcess flow: notice, request consent, decision, record, process, withdraw, enforce, with the relevant DPDP Act sections.1NoticeItemised, before or with the request · s5, Rule 32Request consentAffirmative action, necessary data only · s6(1)3DecisionMade directly or via a Consent Manager · s6(7)4RecordProof of notice and consent · s6(10)5ProcessOnly for the specified purpose · s6(1)6WithdrawAny time, with comparable ease · s6(4)7EnforceStop processing, cause processors to stop · s6(6)
Figure 4. Consent lifecycle. Each step is tied to the section that governs it.

Notice comes first (notice vs consent). Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action (valid consent under s6). Earlier consent-based processing stays lawful after withdrawal (s6(5)).

Withdrawal is not a single "delete" button

What happens after a Data Principal withdraws consentFlow diagram: withdrawal received, status updated, processing stopped in marketing and processors, action logged, erasure unless law requires retention.Withdrawal receiveds6(4)Consent status updatedStop processing,also marketings6(6)Processors toldto stops6(6)Action loggedwith timestampErase unless law requiresretention, s8(7)(a)Legal dutyRecommended implementation
Figure 5. Withdrawal cascade. Solid boxes are legal duties; dashed boxes are recommended implementation. Rule 8(3) retention applies separately and needs counsel review.

Section 6(6) requires cessation of consent-based processing. Section 8(7)(a) requires erasure on withdrawal, or when the purpose is no longer served, unless retention is necessary to comply with law. Rule 8(3) separately sets a one-year minimum retention of personal data, traffic data and processing logs. Whether a given consent log falls within it is a question for counsel.

What should a consent record contain?

The Act requires the fiduciary to prove notice and consent (s6(10)) but prescribes no fields. Every field below is recommended, not prescribed: person reference, purpose, status (given, denied or withdrawn), timestamp, notice version, channel, withdrawal event and downstream sync status. See the DPDP consent form guide.

Do you need a DPDP Consent Manager or a consent management system?

Do you need a Consent Manager or a consent management system?Decision tree: if you rely on consent, and do not intend to serve Data Principals across companies, build, buy or extend a consent management system; registering as a Consent Manager is a separate choice under Rule 4.Do you rely on consentfor any processing?Consent toolingmatters less.Check other grounds:s4 and s7Will you serve Data Principalsacross many companies?Considerregistering as aConsent Manager(Rule 4)Build, buy orextend a consentmanagementsystemNoYesYesNo
Figure 6. Decision tree. Most Data Fiduciaries land on a consent management system; Consent Manager registration is a separate business choice.

You would register as a Consent Manager only to operate the role: an Indian company with ₹2 crore net worth, certification and Board approval. If you rely on consent, some consent-management capability is a practical necessity, because the law requires outcomes and not a product. Consent is one ground; s7 lists certain legitimate uses (s4).

Build, buy, extend or integrate (implementation options, not legal categories)
ApproachBest suited forBenefitRisk
Build internallyLarge or regulated firms with engineering capacityFit and controlCost, maintenance
Extend existing systems (CRM)Small firms with few purposesLow costWeak evidence of notice versions
Buy a platformMid-sized firms with many channelsFaster rollout, integrationsVendor dependence; verify claims
Integrate with a Consent ManagerFirms whose customers use one, once availableCustomer-side controlNot yet available; still your responsibility

Common mistakes and a starter checklist

  • Calling every CMP a Consent Manager, or a cookie banner a full consent system.
  • Assuming every company must register as a Consent Manager. Rule 4 says an eligible person may apply.
  • Storing only a yes/no flag with no notice version.
  • Not propagating withdrawal to processors and marketing tools.
  • Importing GDPR terms. The DPDP Act uses consent or certain legitimate uses (ss4, 7).

Starter checklist (recommended): list consent-dependent purposes and systems; version your notice; record every consent, denial and withdrawal; make withdrawal as easy as opting in; sync withdrawals downstream and log it. Use the consent audit checklist and the wider DPDP compliance checklist.

Frequently asked questions about DPDP Consent Managers and consent management

What is a DPDP Consent Manager?

A Consent Manager is a person registered with the Data Protection Board of India who acts as a single point of contact so a Data Principal can give, manage, review and withdraw consent through an accessible, transparent and interoperable platform (Act s2(g)). Registration is governed by s6(9) and Rule 4.

Is a Consent Manager mandatory under DPDP?

No. Section 6(7) says a Data Principal may give, manage, review or withdraw consent through a Consent Manager. The Act and Rules do not require a Data Fiduciary to appoint one or to register as one.

Is a Consent Manager the same as a CMP?

No. "Consent Manager" is a defined, Board-registered role. "CMP" is a software category the Act and Rules do not define, and its scope varies by vendor. A CMP is not a Consent Manager unless its operating company is registered with the Board.

Who can operate as a Consent Manager?

Under Rule 4 and First Schedule Part A, an applicant must be a company incorporated in India with net worth of at least ₹2 crore, sound management and an independently certified interoperable platform, and must be registered by the Board. Rule 4 is not yet operative on 30 September 2026.

How should consent withdrawal be handled?

Withdrawal must be possible at any time with ease comparable to giving consent (s6(4)). The fiduciary then ceases consent-based processing within a reasonable time and causes processors to cease (s6(6)), unless other law requires or authorises it. A common design updates status, suppresses downstream systems and logs the action.

Does withdrawal of consent mean deletion?

Not automatically. Withdrawal triggers cessation of processing (s6(6)) and an erasure duty under s8(7)(a), unless retention is necessary to comply with law. Rule 8(3) separately sets a one-year minimum retention for certain data and logs. Applying this to consent logs is a question for counsel.

Is Consent Manager registration open?

Not as of 30 September 2026. Section 6(9) and Rule 4 begin one year after Gazette publication, on or about 13 November 2026. No official list of registered Consent Managers has been verified.

Bottom line: what an Indian business should do

  1. Work out which processing relies on consent, and which uses another ground (s4).
  2. Build a reliable consent process: notice, record, withdrawal, propagation.
  3. Keep evidence that can prove notice and consent (s6(10)).
  4. Treat the statutory Consent Manager as a separate concept, and watch for Board publications before relying on a vendor's "registered" claim.
  5. Take legal advice on retention, especially Rule 8(3).

Sources

This guide is general information, not legal advice; verify with counsel before relying on it.