Ch IPreliminary
S.1 Short title and commencementS.2 DefinitionsS.3 Application and scopeCh IIObligations of Data Fiduciary
S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data FiduciaryCh IIIRights and duties of Data Principal
S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data PrincipalCh IVSpecial provisions
S.16 Transfer outside IndiaS.17 ExemptionsCh VData Protection Board of India
S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the ChairpersonCh VIBoard powers and procedure
S.27 Powers and functions of the BoardS.28 Procedure followed by the BoardCh VIIAppeal and dispute resolution
S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertakingCh VIIIPenalties
S.33 Penalties and the ScheduleS.34 Penalties to Consolidated FundCh IXMiscellaneous
S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other ActsRole
A Consent Manager is a Board-registered intermediary that gives people one interoperable dashboard to give, manage, review and withdraw consent.
TL;DR
A Consent Manager (Section 2(g)) is a Board-registered, interoperable intermediary that gives people a single dashboard to give, manage, review and withdraw consent across services. Consent Managers must register with the Board and are accountable to the Data Principal.
"Consent Manager" means a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform.
Think of a Consent Manager as a consent dashboard. Instead of tracking permissions company by company, a Data Principal manages them all in one accountable place.
Consent Managers must register with the Board and are accountable to the Data Principal. Section 6 lets people route consent through them, and the Rules set the registration conditions.
Rather than emailing five apps to withdraw consent, you use a Consent Manager to see and revoke each permission from one screen.
A statutory Consent Manager and a commercial consent management platform, or CMP, are not the same thing, and the two get confused constantly.
| Consent Management Platform (CMP) | Consent Manager (statutory role) | |
|---|---|---|
| What it is | Software a business deploys for its own consent collection | A Board-registered entity under Section 2(g) |
| Who operates it | The Data Fiduciary itself | An independent, registered third party |
| Registration required | No | Yes, with the Data Protection Board, under Rule 4 |
| Scope | One organization’s own website or app | Interoperable across multiple onboarded Data Fiduciaries |
| Data access | Set by the vendor’s own product | Must be “data-blind”: cannot read the content it shares |
| Legal accountability | Stays with the Data Fiduciary | Accountable to the Data Principal (Section 6(8)) |
The term “CMP” doesn’t appear anywhere in the Act or the Rules. A vendor can sell perfectly good CMP software to help a Data Fiduciary collect its own consent directly, without that vendor ever becoming a registered Consent Manager. A vendor cannot accurately claim to be a registered Consent Manager under the DPDP Act without Board registration, since that is a legal status, not a marketing label. For the complete walkthrough, see our full DPDP Act Consent Manager guide.
Where the idea comes from
The Consent Manager role builds on a model India had already tested. The 2017 Justice Srikrishna Committee report first proposed a trusted consent dashboard intermediary, and the Reserve Bank of India’s Account Aggregator framework, part of the wider Data Empowerment and Protection Architecture, or DEPA, already runs a similar model in finance: a licensed, data-blind intermediary that relays consent and data between institutions without being able to read it. The DPDP Act’s Consent Manager extends that same idea, sealed and auditable consent-driven data portability, across every sector, not just banking.
The DPDP Consent Manager framework does not switch on all at once. It comes into force in three stages, set by the Act’s commencement notification (G.S.R. 843(E)) and the DPDP Rules, 2025 (G.S.R. 846(E)), both notified 13 November 2025.
Sub-section (9) of section 6 and clause (d) of sub-section (1) of section 27 come into force one year from the date of publication.
In force since 13 November 2025: the Section 2(g) definition of Consent Manager itself, and the constitution of the Data Protection Board of India.
In force from 13 November 2026: Section 6(9), mandatory Board registration, the related inquiry power under Section 27(1)(d), and Rule 4 with its First Schedule, the actual registration mechanics and eligibility conditions.
In force from 13 May 2027: the core notice-and-consent framework, Section 6(7), (8) and (10), and most of the operative Rules, and the wider penalty machinery under Sections 28 to 34, including Section 33.
Where things stand today
The Data Protection Board has been established, but the registration framework itself has not yet commenced. There is no confirmed instance of a Consent Manager having been registered or approved.
No. The Act frames it as an option, not a requirement.
The Data Principal may give, manage, review or withdraw her consent to the Data Fiduciary through a Consent Manager.
The word is “may,” not “must.” A Data Fiduciary can continue collecting consent directly, without routing it through a registered Consent Manager, as long as it meets the Act’s own notice and consent requirements. Nothing in Section 6 or Rule 4 forces a business to integrate with one.
That said, collecting consent directly does not lighten the load. If a dispute reaches the Data Protection Board, the burden of proof still sits with the Data Fiduciary.
Where a consent given by the Data Principal is the basis of processing of personal data and a question arises in this regard in a proceeding, the Data Fiduciary shall be obliged to prove that a notice was given by her to the Data Principal and consent was given by such Data Principal to the Data Fiduciary in accordance with the provisions of this Act and the rules made thereunder.
So the real choice is not whether you need a Consent Manager. It is whether you can prove valid notice and consent happened, and today, that burden lands on the Data Fiduciary either way.
Not sure where your organization stands? Run the free DPDP readiness assessment, or read our guide on what counts as valid consent under Section 6.
Registration runs through Rule 4 and the First Schedule of the DPDP Rules, 2025. To be eligible, an applicant must meet nine conditions set out in Part A of the Schedule, including:
Be a company incorporated in India
Have sufficient technical, operational and financial capacity to fulfil its obligations
Have a sound financial condition and general character of management
Hold a net worth of not less than ₹2 crore, calculated as total assets minus liabilities
The remaining conditions cover the applicant’s likely business volume and earning prospects, the reputation and integrity of its directors and key managerial personnel, a requirement that its memorandum and articles of association lock in compliance with conflict-of-interest duties, amendable only with prior Board approval, that its proposed operations serve the interests of Data Principals, and independent certification that its platform meets the data-protection standards the Board publishes.
Once registered, a Consent Manager takes on ongoing duties under Part B of the same Schedule, among them:
Making shared personal data unreadable to itself, “data-blind” by design
Recording every consent given, denied or withdrawn, and every associated notice
Retaining those records for at least seven years, or longer if agreed or required by law
Not sub-contracting or assigning its statutory obligations
Taking reasonable security safeguards and acting in a fiduciary capacity toward the Data Principal
Maintaining an effective audit mechanism and reporting outcomes to the Board
Getting the Board’s prior approval before any change of control, by sale or merger
Considering registering as a Consent Manager, or need help assessing whether your organization qualifies? Talk to an advisor.
A Consent Manager that breaches its registration conditions or its duties to a Data Principal can face a monetary penalty, but the path there has real procedural steps. It is not automatic.
The Board can open an inquiry in two ways: on a Data Principal’s complaint about the Consent Manager’s handling of her personal data, or on an intimation of breach of a registration condition. Either way, a penalty only follows if the Board concludes, after that inquiry, that the breach is “significant,” and only after giving the Consent Manager an opportunity to be heard.
If the Board determines on conclusion of an inquiry that breach of the provisions of this Act or the rules made thereunder by a person is significant, it may, after giving the person an opportunity of being heard, impose such monetary penalty specified in the Schedule.
There is no penalty tier in the Schedule specifically labelled Consent Manager. A breach of a Consent Manager’s own obligations falls under the Schedule’s residual entry, breach of any other provision of the Act or the Rules, which carries a penalty of up to ₹50 crore. That is a ceiling the Board can impose, not an automatic fine, and it depends on Section 33 having come into force on 13 May 2027 and an inquiry actually concluding that the breach was significant.
Do Consent Managers register?
Yes, with the Data Protection Board, on the conditions prescribed in the DPDP Rules 2025.
Who does a Consent Manager answer to?
The Data Principal. Section 6(8) makes it accountable to the individual and requires it to act on their behalf.
What’s the difference between a Consent Manager and a Consent Management Platform (CMP)?
A Consent Manager is a Board-registered legal role under Section 2(g). A CMP is commercial software a business uses to collect its own consent. A vendor can sell CMP software without being a registered Consent Manager.
When does the Consent Manager framework actually come into force?
The definition has applied since 13 November 2025. Mandatory Board registration and the registration mechanics under Rule 4 take effect 13 November 2026. The core notice-and-consent obligations, and the wider penalty framework, take effect 13 May 2027.
Is it mandatory for a business to use a Consent Manager?
No. Section 6(7) says a Data Principal “may” route consent through one, so it is optional. Direct consent collection remains valid if it meets the Act’s own requirements.
What does it take to become a registered Consent Manager?
Incorporation in India, a minimum net worth of ₹2 crore, adequate technical and financial capacity, and Board sign-off on management integrity and platform certification, among other conditions in the First Schedule.
What happens if a Consent Manager breaches its obligations?
The Board can inquire into the breach, either from a Data Principal’s complaint or a reported registration breach, and if it finds the breach significant, after a hearing, it can impose a penalty of up to ₹50 crore under the Schedule’s residual entry.
Consultant-led and partner-backed.