DPDP Consent Manager vs Consent Management System: What's the Difference?
A Consent Manager is a Board-registered legal role. A consent management system is your own tooling. See how they differ, where the law stands today, and which one you need.
Consent Manager, CMS, CMP and cookie tool: the four terms at a glance
| DPDP Consent Manager | Consent management system (CMS) | CMP | Cookie consent tool | |
|---|---|---|---|---|
| What is it? | Board-registered intermediary | Your own mix of tools, records and process | Software category; scope varies by vendor | Website banner and preference tool |
| Legal status | Defined in Act s2(g) | Not defined | Not defined | Not defined |
| Registration | With the Board under Rule 4 | None specific to DPDP | None specific to DPDP | None specific to DPDP |
What is a DPDP Consent Manager?
A Consent Manager is a statutory role. It sits on the Data Principal's side, not inside a company's marketing stack. For the full role and registration story, read the Consent Manager guide.
What the law actually says
- Act s2(g): a "person registered with the Board" acting as a "single point of contact" through an accessible, transparent and interoperable platform.
- s6(7) to (9): the Data Principal may use one; it is accountable to her and acts on her behalf; it must be registered with the Board.
- Rule 4 and First Schedule Part A: the applicant is a company incorporated in India with net worth of at least ₹2 crore, and its platform is independently certified against standards the Board may publish.
- Part B: the Manager cannot read the contents of personal data it routes; it records consents given, denied or withdrawn, the notices, and sharing; it keeps that record at least seven years; it acts in a fiduciary capacity; it does not subcontract its obligations; and it has conflict-of-interest, disclosure and audit duties.
What this means in practice
- It is a regulated intermediary, not a product label. A website badge is not Board registration.
- The seven-year rule applies to the Manager's own platform records. It is not a general retention period for every Data Fiduciary's consent records.
- Rule 4 is not yet operative, and no official list of registered Consent Managers has been verified. Ask for the Board-published particulars before accepting any "registered" claim.
What is a consent management system (CMS)?
A consent management system is the combination of interfaces, records, rules and integrations an organisation uses to capture, evidence and act on consent. The Act and Rules do not define it or name it. They set outcomes, and a CMS is one way to meet them:
- Required outcome, once operative: valid notice and consent (s5, s6, Rule 3), comparable-ease withdrawal (s6(4)), and proof (s6(10)).
- Recommended: a versioned consent record, self-service withdrawal and automatic propagation to systems and processors.
- Optional: dashboards, preference centres, expiry timers and cookie scanning.
DPDP Consent Manager vs consent management system: side by side
A Consent Manager helps a person control consent across many companies. A CMS helps one company honour and prove the consent it holds. They can work together: a fiduciary's CMS can act on a choice a person made through a registered Consent Manager. That is an architecture choice, not a duty the Rules spell out; the fiduciary stays responsible for its processors (s8(1)). Compare options in Consent Manager vs CMP vs build.
Is a CMP the same as a DPDP Consent Manager?
No, not by default. A cookie CMP records website tracker choices only. An enterprise consent platform keeps central records and syncs them to CRM and marketing systems, which helps you evidence consent but remains your own tooling. Only a Board-registered operator is a statutory Consent Manager.
Legal status of Consent Managers and consent duties on 30 September 2026
| Provisions | Applies from | Status |
|---|---|---|
| Definitions (s2), Board provisions (ss18 to 26) | Gazette publication, 13 November 2025 | Operative |
| Consent Manager registration: s6(9), s27(1)(d), Rule 4 | One year after publication, on or about 13 November 2026 | Enacted, not yet operative |
| Notice, consent, withdrawal, proof, fiduciary duties: ss4 to 8, s6(1) to (8) and (10); Rules 3, 5 to 16 | Eighteen months after publication, on or about 13 May 2027 | Enacted, not yet operative |
| January 2026 reports of shorter timelines for selected provisions (for example Rule 8(3) and Rule 13) | Not applicable | Reported proposal, not enacted |
Periods run from Gazette publication. The issue is dated 13 November 2025, but the e-Gazette file code shows 14 November, so some sources quote 14 November. Corrigendum G.S.R. 892(E) corrected the Rules; the durations are unchanged. Plan for the earlier date and re-check the Gazette before acting. See the DPDP Rules explained and the compliance timeline.
Consent lifecycle under DPDP: from notice to withdrawal
Notice comes first (notice vs consent). Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action (valid consent under s6). Earlier consent-based processing stays lawful after withdrawal (s6(5)).
Withdrawal is not a single "delete" button
Section 6(6) requires cessation of consent-based processing. Section 8(7)(a) requires erasure on withdrawal, or when the purpose is no longer served, unless retention is necessary to comply with law. Rule 8(3) separately sets a one-year minimum retention of personal data, traffic data and processing logs. Whether a given consent log falls within it is a question for counsel.
What should a consent record contain?
The Act requires the fiduciary to prove notice and consent (s6(10)) but prescribes no fields. Every field below is recommended, not prescribed: person reference, purpose, status (given, denied or withdrawn), timestamp, notice version, channel, withdrawal event and downstream sync status. See the DPDP consent form guide.
Do you need a DPDP Consent Manager or a consent management system?
You would register as a Consent Manager only to operate the role: an Indian company with ₹2 crore net worth, certification and Board approval. If you rely on consent, some consent-management capability is a practical necessity, because the law requires outcomes and not a product. Consent is one ground; s7 lists certain legitimate uses (s4).
| Approach | Best suited for | Benefit | Risk |
|---|---|---|---|
| Build internally | Large or regulated firms with engineering capacity | Fit and control | Cost, maintenance |
| Extend existing systems (CRM) | Small firms with few purposes | Low cost | Weak evidence of notice versions |
| Buy a platform | Mid-sized firms with many channels | Faster rollout, integrations | Vendor dependence; verify claims |
| Integrate with a Consent Manager | Firms whose customers use one, once available | Customer-side control | Not yet available; still your responsibility |
Common mistakes and a starter checklist
- Calling every CMP a Consent Manager, or a cookie banner a full consent system.
- Assuming every company must register as a Consent Manager. Rule 4 says an eligible person may apply.
- Storing only a yes/no flag with no notice version.
- Not propagating withdrawal to processors and marketing tools.
- Importing GDPR terms. The DPDP Act uses consent or certain legitimate uses (ss4, 7).
Starter checklist (recommended): list consent-dependent purposes and systems; version your notice; record every consent, denial and withdrawal; make withdrawal as easy as opting in; sync withdrawals downstream and log it. Use the consent audit checklist and the wider DPDP compliance checklist.
Frequently asked questions about DPDP Consent Managers and consent management
What is a DPDP Consent Manager?
A Consent Manager is a person registered with the Data Protection Board of India who acts as a single point of contact so a Data Principal can give, manage, review and withdraw consent through an accessible, transparent and interoperable platform (Act s2(g)). Registration is governed by s6(9) and Rule 4.
Is a Consent Manager mandatory under DPDP?
No. Section 6(7) says a Data Principal may give, manage, review or withdraw consent through a Consent Manager. The Act and Rules do not require a Data Fiduciary to appoint one or to register as one.
Is a Consent Manager the same as a CMP?
No. "Consent Manager" is a defined, Board-registered role. "CMP" is a software category the Act and Rules do not define, and its scope varies by vendor. A CMP is not a Consent Manager unless its operating company is registered with the Board.
Who can operate as a Consent Manager?
Under Rule 4 and First Schedule Part A, an applicant must be a company incorporated in India with net worth of at least ₹2 crore, sound management and an independently certified interoperable platform, and must be registered by the Board. Rule 4 is not yet operative on 30 September 2026.
How should consent withdrawal be handled?
Withdrawal must be possible at any time with ease comparable to giving consent (s6(4)). The fiduciary then ceases consent-based processing within a reasonable time and causes processors to cease (s6(6)), unless other law requires or authorises it. A common design updates status, suppresses downstream systems and logs the action.
Does withdrawal of consent mean deletion?
Not automatically. Withdrawal triggers cessation of processing (s6(6)) and an erasure duty under s8(7)(a), unless retention is necessary to comply with law. Rule 8(3) separately sets a one-year minimum retention for certain data and logs. Applying this to consent logs is a question for counsel.
Is Consent Manager registration open?
Not as of 30 September 2026. Section 6(9) and Rule 4 begin one year after Gazette publication, on or about 13 November 2026. No official list of registered Consent Managers has been verified.
Bottom line: what an Indian business should do
- Work out which processing relies on consent, and which uses another ground (s4).
- Build a reliable consent process: notice, record, withdrawal, propagation.
- Keep evidence that can prove notice and consent (s6(10)).
- Treat the statutory Consent Manager as a separate concept, and watch for Board publications before relying on a vendor's "registered" claim.
- Take legal advice on retention, especially Rule 8(3).
All DPDP consent guides on this site
Start here
The law
Tools and downloads
Glossary
Sources
- Digital Personal Data Protection Act, 2023 (ss2, 4 to 8, 13)
- DPDP Rules, 2025, G.S.R. 846(E) (Rules 1, 3, 4, 8, 14; First Schedule)
- MeitY DPDP Rules 2025 index (commencement notification G.S.R. 843(E), corrigendum G.S.R. 892(E), enforcement timeline)
This guide is general information, not legal advice; verify with counsel before relying on it.