Written by

Sumeshwar Pandey

View Profile
12 min read
DPDP Act India Consent Manager

Consent Manager under the DPDP Act: Role, Registration and Obligations

As at 29 August 2026, the statutory definition is in force, but Section 6(9) and the Rule 4 registration framework are scheduled to commence on 13 November 2026. That distinction matters when assessing products described as “DPDP consent managers.”

Key takeaways
  • A statutory Consent Manager is a Board-registered entity acting on behalf of Data Principals, not simply consent-management software used by a business.

  • Section 2, including the definition, has been in force since 13 November 2025. Section 6(9), Rule 4 and the associated First Schedule framework are scheduled for 13 November 2026.[3]

  • Registration requires an Indian-incorporated company to meet financial, managerial, technical, operational and governance conditions, including a minimum net worth of ₹2 crore.[2]

  • Registered Consent Managers will face data-blindness, record-retention, non-subcontracting, conflict-management, audit, disclosure and change-of-control requirements.

  • Data Fiduciaries retain their own DPDP obligations when using or connecting to a Consent Manager; integration does not transfer statutory accountability.

The real decision behind a “DPDP Consent Manager” proposal

A product team receives a proposal for a “DPDP-ready Consent Manager.” The software can collect choices, store timestamps and pass withdrawal signals to downstream systems. The commercial description may be accurate at the product level, but it does not establish that the provider occupies the statutory role created by the Digital Personal Data Protection Act, 2023. That role depends on registration with the Data Protection Board of India under provisions that were not yet operative on 29 August 2026.

Current legal status and commencement dates as of August 2026

The current-status position is specific. The institutional architecture of the DPDP Act began operating from 13 November 2025, when the provisions establishing the Data Protection Board took effect and the Board was formally constituted by a separate notification. From that point, the statutory definition of “Consent Manager” existed in law even though the registration mechanism had not yet started to operate.[4]

Most of the surrounding consent provisions, including Sections 6(7), 6(8) and 6(10), are scheduled to commence 18 months after 13 November 2025, on 13 May 2027. Relevant operational rules such as Rule 6 on reasonable security safeguards and Rule 14 on Data Principal rights also sit within the later phase. The unusual result is that the registration provision is scheduled to switch on before much of the wider consent machinery. Legal, procurement and architecture documents should therefore distinguish present law, future-dated requirements and voluntary preparation.

Where the statutory Consent Manager sits in the DPDP framework

Section 2(g) defines a Consent Manager as a person registered with the Data Protection Board who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. Registration and action on behalf of the Data Principal are central elements of the definition. A tool that records consent but is not registered does not become a statutory Consent Manager merely because it performs similar technical functions.[1]

Sections 6(7) to 6(10) provide the main statutory context. Section 6(7) allows a Data Principal to give, manage, review or withdraw consent through a Consent Manager. Section 6(8) addresses the consequences of withdrawal for the Data Fiduciary and its processors, subject to processing that remains necessary or authorised by law. Section 6(9) makes the Consent Manager accountable to the Data Principal and requires it to act on the principal’s behalf in the prescribed manner. Section 6(10) allocates the consequences of withdrawal to the Data Principal, without removing the Data Fiduciary’s duty to stop consent-dependent processing.[1]

Rule 4 of the Digital Personal Data Protection Rules, 2025 and the First Schedule supply the institutional detail for this role. Rule 4 frames applications, registration, continuing compliance and the Board’s supervisory response, while the First Schedule sets out entry conditions in Part A and conduct obligations in Part B. Rule 14 is also relevant because it specifies how Data Principals may exercise statutory rights, including through a Consent Manager, once the relevant provisions commence.[2]

Eligibility and registration under Rule 4 and the First Schedule

Part A of the First Schedule begins with corporate eligibility. An applicant must be a company incorporated in India, with sufficient technical, operational and financial capacity, sound financial condition and management, and a net worth of at least ₹2 crore. Its volume of business and capital structure must be adequate for the proposed role, and the reputation and record of fairness and integrity of its directors, key managerial personnel and senior management are explicitly relevant.[2]

Constitutional documents must support compliance with the Part B obligations and restrict amendments that would undermine those arrangements without the Board’s prior approval. Proposed operations must be in the interests of Data Principals. The applicant must also be capable of supporting the interoperable platform contemplated by the Schedule and demonstrating conformity with standards published by the Board. As at 29 August 2026, your team should verify, rather than assume, that detailed technical standards or final application materials have been published, and base preparations on the latest official instruments you can locate.

Once Rule 4 is in force, registration is framed as a formal regulatory process rather than a label that a vendor can adopt unilaterally.

  1. Apply to the Data Protection Board in the prescribed form

    An eligible company applies to the Data Protection Board in the form and manner that the Board specifies. Rule 4 anticipates that the Board will prescribe the application format and supporting information, so internal planning should assume a structured filing process rather than informal expressions of interest.

  2. Expect regulatory scrutiny before any registration decision

    Before deciding whether to register an applicant as a Consent Manager, the Board may conduct inquiries to satisfy itself that the First Schedule conditions are met. Registration is therefore an evaluative regulatory decision, not a self-certification achieved by adopting a label or obtaining a general technology audit, and applicants must be given an opportunity to be heard where an application is not accepted.

  3. Plan for ongoing supervision, suspension or cancellation

    Registration is not permanent insulation from oversight. If a registered Consent Manager fails to meet prescribed conditions or obligations, the Board may seek information, require corrective measures and, following the applicable process, suspend or cancel registration. Contracts and integration plans need to address what happens to existing mandates, records and pending withdrawals if registration changes.

Ongoing obligations, conflicts, governance and security

Part B of the First Schedule is designed around the Consent Manager’s position of trust. The platform must enable Data Principals to give, manage, review and withdraw consent across participating Data Fiduciaries. The Consent Manager must act in a fiduciary capacity in relation to the Data Principal while ensuring that the contents of personal data are not readable by it. This data-blindness requirement does not mean that the service handles no information: account identifiers, instructions, timestamps and transaction logs may themselves require careful classification and protection.

The Schedule requires records of consent decisions, withdrawals, associated notices and relevant interactions to be retained for at least seven years, subject to any longer applicable period, and Data Principals must be able to access the records concerning them. The Consent Manager may not subcontract or assign the performance of its prescribed obligations, which differs materially from many conventional software or platform arrangements built on multiple sub-processors.[2]

Conflict controls extend beyond a general statement of independence. The Consent Manager must identify and avoid interests that could compromise its duty to Data Principals, including interests involving its leadership and relationships with Data Fiduciaries. Required public disclosures concerning ownership, management and related interests are intended to make those relationships visible. Annual audits, reporting to the Board and prior approval for specified changes in control create continuing governance requirements rather than one-time registration checks.

Security review should also separate the Consent Manager’s Part B duties from the general obligation to implement reasonable security safeguards. Rule 6 of the DPDP Rules, 2025 requires every Data Fiduciary to implement such safeguards for personal data held by or under its control. A Consent Manager may itself act as a Data Fiduciary for account, employment or service-administration data, depending on the facts, and connected Data Fiduciaries remain subject to Rule 6 in their own capacity once it commences.[2]

User journeys, interoperability and Data Fiduciary integration

A likely journey begins when a Data Principal establishes a relationship with a registered Consent Manager and selects a participating Data Fiduciary. The Data Fiduciary remains responsible for presenting a compliant notice and obtaining consent that meets the Act’s requirements. The Consent Manager records and transmits the principal’s instruction through its interoperable platform without reading the contents of the underlying personal data. The precise protocol, authentication method and evidence format will depend on standards and implementation arrangements that should not be presumed before the Board publishes them.

If the Data Principal later withdraws consent through the Consent Manager, the signal must reach the relevant Data Fiduciary in a form that can be authenticated and linked to the correct processing activity. When the withdrawal provisions in Section 6(8) apply, the Data Fiduciary must stop the consent-dependent processing and cause its processors to stop, unless continued processing is required or authorised by law. The Consent Manager communicates and records the instruction; it does not decide whether a separate legal basis or retention obligation applies.[1]

Rule 14’s rights framework also contemplates the Consent Manager as a route through which a Data Principal may approach a Data Fiduciary. The Consent Manager can facilitate and evidence transmission, but responsibility for searching systems, assessing the request and responding remains with the relevant Data Fiduciary. Integration designs consequently need separate message types for consent, withdrawal, correction, erasure, access and grievance-related activity rather than reducing every interaction to a preference toggle.[2]

The Act does not simply state that every Data Fiduciary must buy or outsource to a Consent Manager. An organisation may continue to require its own notice, consent ledger and withdrawal controls. It should nevertheless assess how its systems could recognise authorised Consent Manager instructions once the relevant provisions and standards apply. Useful design questions concern identity matching, purpose-level consent, versioned notices, timestamps, replay protection, withdrawal propagation, evidence portability, exception handling and service continuity.

Consent Manager versus CMP, DPO and Data Fiduciary

A statutory Consent Manager is a registered Indian company that acts on behalf of Data Principals through an accessible, transparent and interoperable platform. Its accountability runs to the Data Principal, and the First Schedule imposes entry conditions, data-blindness, conflict controls, record retention, audit and Board supervision. Describing the role as “independent” without qualification can be imprecise; the Rules instead impose structural conflict-management requirements and a fiduciary capacity.

A consent management platform, or CMP, is a technology category rather than a status created by the DPDP Act. It may collect consent, operate preference interfaces or orchestrate signals for a Data Fiduciary. Depending on the facts, its provider may be a processor, a Data Fiduciary in its own right or another type of service provider. It does not acquire statutory Consent Manager status unless the relevant legal entity is registered under Rule 4 and satisfies the First Schedule.

A Data Protection Officer is an individual appointed by a Significant Data Fiduciary under the applicable provisions. The DPO serves as a point of contact and performs governance and compliance functions for that fiduciary. The DPO does not act as an interoperable consent intermediary for Data Principals and is not registered under Rule 4. Organisational reporting lines and independence considerations for a DPO should not be confused with the corporate eligibility and conflict framework applicable to a Consent Manager.

The Data Fiduciary is the person that determines the purpose and means of processing personal data. It remains responsible for its notice, consent, security, processor, rights-handling and other statutory duties. Neither a CMP contract nor connection to a registered Consent Manager transfers that accountability. The architecture may distribute tasks and evidence, but the legal roles should be documented separately.

High-level comparison of a statutory Consent Manager, a CMP, a DPO and a Data Fiduciary under the DPDP framework.

Role / entity

Legal basis under DPDP

Primary accountability

Registration or appointment

Typical technical footprint

Statutory Consent Manager

Defined role in Section 2(g) of the DPDP Act and in Rule 4 plus the First Schedule of the DPDP Rules, 2025.

Acts in a fiduciary capacity for Data Principals and is subject to Board supervision and First Schedule obligations.

Requires formal registration with the Data Protection Board under Rule 4.

Accessible, transparent and interoperable platform that routes consent and withdrawal instructions while remaining data-blind to personal data contents.

Consent management platform (CMP)

Technology category; not a statutory role under the DPDP Act by itself.

Typically accountable to the Data Fiduciary that deploys it, often as a processor or service provider.

No statutory registration as a Consent Manager unless the underlying legal entity separately qualifies and is registered under Rule 4.

Implements consent and preference interfaces, cookies or signal orchestration for particular Data Fiduciaries or products.

Data Protection Officer (DPO)

Individual role required for Significant Data Fiduciaries under the DPDP Act and Rules.

Advises on and monitors DPDP compliance for the appointing Data Fiduciary.

Appointed by a Significant Data Fiduciary; not registered with the Board as a Consent Manager.

Governance and coordination functions; does not typically operate an interoperable consent platform.

Data Fiduciary

Core statutory role that determines the purpose and means of processing personal data under the DPDP Act.

Directly accountable to Data Principals and the Board for compliance with the DPDP Act and Rules.

No separate registration as a Consent Manager; may be subject to sectoral registrations outside the DPDP framework.

Own business systems and processing environment, including notices, consent capture, processing operations and responses to Data Principal rights.

Regulatory and market status in 2026: assessing registration claims, evidence and contract risk

As at 29 August 2026, the Data Protection Board of India had been legally established, but Section 6(9) had not yet commenced and remained scheduled for 13 November 2026 under the commencement notification. The legal establishment of the Board therefore did not, by itself, mean that Consent Manager registration applications were already being accepted.[3]

Status summaries that cross-reference the Gazette text and IndiaCode continued to indicate that Rule 4 of the DPDP Rules, 2025 on registration and obligations of Consent Managers had not been brought into force by mid-August 2026.[5]

No official live registry of registered Consent Managers was publicly available at that point. Any statement that a provider was already “registered”, “approved” or “recognised” in the statutory sense would therefore require specific, current evidence from an official Board or government source, rather than internal marketing material.

Regulatory status, claim substantiation and contract risk are distinct questions. Regulatory status concerns whether the identified legal entity has a valid registration and remains subject to any conditions. Claim substantiation concerns whether phrases such as “DPDP-ready”, “aligned” or “consent-manager compliant” fairly describe technical capability without implying government approval. Contract risk concerns whether the agreement allocates responsibilities, evidence and remedies in a way that matches the actual service.

Before the registration regime opens, an RFP response should at least identify the contracting entity and place of incorporation, provide net-worth evidence, ownership and management details, proposed conflict controls, audit arrangements and intended treatment of subcontractors. After commencement, the review should add the official registration number, registry entry, scope, conditions, effective date and any suspension or cancellation history. Screenshots, self-issued certificates and marketing announcements should not substitute for a live official record.

The contract should address notice versions, consent-event schemas, authentication, withdrawal delivery, record access, retention, security incidents, audit cooperation, conflicts, regulatory change, service availability and exit portability. It should also avoid representing an entity as registered before evidence supports that claim. Any commitment concerning future registration should distinguish an obligation to apply or use reasonable efforts from a warranty that the Board will grant approval, since the regulatory decision is outside the applicant’s control.

Planning for the November 2026 registration phase

Planning can begin before the registration regime formally opens, provided your team remains explicit about what is required now versus what depends on future commencement.

  1. Document current consent and withdrawal flows

    Start by documenting the legal basis and consent flow for each material processing activity. Identify where notices are generated, where consent evidence is stored, how withdrawals reach processors and which systems retain data under another legal requirement. This baseline remains useful whether the organisation later connects to a statutory Consent Manager or relies primarily on its own infrastructure.

  2. Design a neutral consent-event model and resilient interfaces

    Architecture planning can proceed without assuming unpublished standards. Define a neutral consent-event model covering the Data Principal, Data Fiduciary, purpose, notice version, instruction, timestamp and authentication evidence. Keep interfaces adaptable so future Board standards can be implemented without replacing the underlying consent ledger. Engineering and security teams should also test delayed messages, duplicated withdrawals, unavailable counterparties and migration from a suspended or failed intermediary.

  3. Assign governance owners across legal, product, engineering and procurement

    Governance work should assign separate owners for regulatory interpretation, vendor evidence, integration design and operational response. Procurement can prepare conditional diligence requirements for applicants and registered providers. Legal review can identify representations that depend on future registration, while privacy and product teams can specify how a Data Principal will understand whether an interface belongs to the Data Fiduciary, a software supplier or a statutory Consent Manager.

  4. Re-check commencement and Board materials before relying on registration

    After 13 November 2026, verify whether Rule 4 commenced as scheduled and consult the Board’s official application materials, registry and technical standards before changing public claims or production integrations. Further matters to monitor include platform certification, interoperability protocols, audit formats, conflict disclosures, control-change approvals and continuity directions following suspension or cancellation. Rule 6, Rule 14 and the remaining Section 6 provisions should be checked again ahead of their scheduled 13 May 2027 commencement.

Common questions about DPDP Consent Managers

FAQs

The DPDP Act does not contain a general requirement that every Data Fiduciary procure or outsource consent operations to a Consent Manager. Section 6(7) gives Data Principals a statutory route to manage consent through one when the provision applies. The practical integration expected of particular Data Fiduciaries may depend on commenced provisions, Board standards and the services involved, but a Data Fiduciary retains its own consent and withdrawal obligations in all cases.

Part A of the First Schedule requires the applicant to be a company incorporated in India. A foreign group would therefore need to assess whether an eligible Indian-incorporated entity could apply and independently satisfy the financial, governance, technical and operational conditions. Group affiliation or technology supplied from abroad would not by itself meet the incorporation requirement.[2]

Part B of the First Schedule requires the contents of personal data to be unreadable by the Consent Manager. The service will still need operational information to authenticate participants, route instructions and maintain consent records. Some of that metadata may itself be personal data, so data-blindness should not be interpreted as an exemption from security, retention or role-mapping analysis.[2]

Rule 4 contemplates corrective directions and, following the applicable process, suspension or cancellation of registration by the Board. Connected Data Fiduciaries should plan for the preservation and export of consent evidence, delivery of pending withdrawals and migration to another channel. The Data Fiduciary’s statutory responsibilities do not disappear because an intermediary becomes unavailable.

After the registration regime starts, your team should check the provider’s exact legal name and registration details against an official Board or government registry rather than relying on branding, a press release or a certificate supplied by the provider. Confirm the effective date, current status, conditions and scope of registration. If no official registry is available, request direct official correspondence and qualify any public or contractual statement accordingly.

Sources
  1. The Digital Personal Data Protection Act, 2023 (Act 22 of 2023) – Official Gazette PDF - Ministry of Law and Justice / IndiaCode
  2. Digital Personal Data Protection (DPDP) Rules, 2025 - IndiaCode / Ministry of Electronics and Information Technology
  3. Enforcement Timeline for the DPDP Act – Notification G.S.R. 843(E) dated 13 November 2025 - IndiaCode / Ministry of Electronics and Information Technology
  4. DPDP Rules 2025 – Fourth Schedule and Rule Status Overview - dpdprules.org
  5. Establishment of the Data Protection Board of India – Notification G.S.R. 844(E) dated 13 November 2025 - IndiaCode / Ministry of Electronics and Information Technology