Consent Manager Under DPDP: Roles, Rules & Registration
India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025, notified on 13 November 2025, put consent at the centre of how businesses handle personal data. Alongside the obligations that apply to every business, the framework creates a new regulated entity: the Consent Manager.
A Consent Manager under DPDP is a company registered with the Data Protection Board of India that operates an interoperable platform through which individuals can give, manage, review and withdraw their consent across multiple businesses from a single place. It is not a cookie banner, and it is not the consent tool a business uses internally. It is a separately registered intermediary with its own conditions of registration and legal obligations, which apply from 13 November 2026.
A Consent Manager is a company incorporated in India and registered with the Data Protection Board that acts as a single point of contact for Data Principals to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. It must have a net worth of at least ₹2 crore, act in a fiduciary capacity towards individuals, avoid conflicts of interest with Data Fiduciaries, keep consent records for at least seven years, and must not be able to read the personal data shared through its platform. Most businesses do not need to register as one.
This guide explains what a Consent Manager is, how it differs from a Data Fiduciary and an ordinary consent tool, its obligations under the notified Rules, the conditions for registration, and the practical steps an organisation would take to prepare.
What Is a Consent Manager Under the DPDP Act?
Section 2(g) of the DPDP Act defines a Consent Manager as a person registered with the Board who acts as a single point of contact to enable a Data Principal to give, manage, review or withdraw her consent through an accessible, transparent and interoperable platform. Under Section 6, a Data Principal may manage consent through a Consent Manager, the Consent Manager is accountable to the Data Principal, and every Consent Manager must be registered with the Board.
Three parties are involved:
- Data Principal: the individual whose personal data is processed.
- Data Fiduciary: the business that decides why and how that data is processed, such as a bank, insurer or e-commerce company.
- Consent Manager: the registered intermediary whose platform lets the individual control consent across Data Fiduciaries onboarded onto it.
In practice, a customer could use one Consent Manager app to see which onboarded businesses hold her consent, approve a new request, or withdraw consent, instead of visiting each company separately. Where the platform facilitates sharing of personal data between Data Fiduciaries, it must do so in a way that the Consent Manager cannot read the contents.
Under the Rules, the Consent Manager acts in a fiduciary capacity in relation to the Data Principal. That does not make it the Data Fiduciary for every processing activity it facilitates. The businesses that receive and use the data remain responsible for their own processing, and each party’s obligations depend on its actual role.
Consent Manager vs Data Fiduciary vs Consent Management Platform
| Feature | Consent Manager | Data Fiduciary | Ordinary Consent Management Platform |
|---|---|---|---|
| Primary role | Lets individuals give, manage, review and withdraw consent across onboarded Data Fiduciaries | Decides the purpose and means of processing personal data | Software a business uses to collect and record consent for its own processing |
| Regulatory position | Regulated entity under Section 6 of the Act and Rule 4 of the Rules | Primary obligations under the Act and Rules | A tool or vendor; no separate status as a Consent Manager |
| Relationship with individuals | Accountable to the Data Principal; acts in a fiduciary capacity | Owes obligations to Data Principals whose data it processes | Usually no direct legal relationship; acts for the business |
| Consent responsibilities | Maintains records of consents, notices and data sharing on its platform | Must obtain valid consent (or rely on a legitimate use), give notice and honour withdrawal | Supports the business in meeting its own consent obligations |
| Registration | Mandatory registration with the Data Protection Board | No registration as such | None, unless the provider separately registers as a Consent Manager |
Swipe the table sideways to see all columns.
A consent banner or a vendor’s consent management software used by a business to record its own consents is not a registered Consent Manager. Collecting consent does not, by itself, require any organisation to register as one.
Legal Framework for Consent Managers Under DPDP
The framework has three layers, and it is important to know which one you are reading:
- The Act. The DPDP Act, 2023 defines the Consent Manager in Section 2(g) and sets the core principles in Section 6(7) to 6(9): individuals may use a Consent Manager, the Consent Manager is accountable to them, and registration with the Board is mandatory.
- The Rules. The DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025) set out the detail. Rule 4 covers registration and Board oversight. Part A of the First Schedule lists the conditions for registration, and Part B lists the Consent Manager’s obligations.
- Explanatory material and Board publications. Government explainers help interpret the law but do not replace the Gazette text. Some operational details, such as the application particulars and the platform standards, are to be published by the Board on its website.
Commencement. The Rules came into force in phases. Under Rule 1, Rule 4 on Consent Managers comes into force one year after publication, which is 13 November 2026. Most other obligations for Data Fiduciaries, including notice and consent under Rule 3, come into force eighteen months after publication. Earlier draft Rules released in January 2025 should not be relied on for current obligations.
Roles and Responsibilities of a Consent Manager
Part B of the First Schedule sets out thirteen obligations. They fall into eight practical areas.
1. Enabling consent management
The platform must enable a Data Principal to give consent to processing by a Data Fiduciary onboarded onto the platform, either directly to that Data Fiduciary or through another onboarded Data Fiduciary that holds her data with her consent. Together with the definition in the Act, this means individuals must be able to give, manage, review and withdraw consent through the platform.
2. Maintaining consent records
The Consent Manager must maintain on its platform a record of:
- consents given, denied or withdrawn;
- notices preceding or accompanying requests for consent; and
- sharing of the individual’s personal data with a transferee Data Fiduciary.
These records must be kept for at least seven years, or longer if agreed with the Data Principal or required by law. Accurate timestamps and traceable, retrievable records are practical necessities for meeting this obligation.
3. Providing access to consent records
Data Principals must be given access to their records. On request, and in accordance with the Consent Manager’s terms of service, the information in the record must be made available to them in machine-readable form.
4. Protecting personal data
The Consent Manager must take reasonable security safeguards to prevent personal data breach. Separately, it must ensure that the manner of making personal data available or sharing it is such that the contents are not readable by the Consent Manager. The obligation is framed around the contents of the personal data being shared. How this applies to specific technical elements, such as routing information or consent metadata, will depend on platform design and any standards the Board publishes.
5. Independence and conflicts of interest
The Consent Manager must avoid conflicts of interest with Data Fiduciaries, including with their promoters and key managerial personnel. It must also have measures in place so that no conflict arises from its directors, key managerial personnel or senior management holding a directorship, financial interest, employment or beneficial ownership in Data Fiduciaries, or having a material pecuniary relationship with them.
6. Transparency and disclosures
The Consent Manager must publish, in an easily accessible manner on its website or app, information about:
- its promoters, directors, key managerial personnel and senior management;
- every person holding more than 2% of its shares;
- every body corporate in which any of its promoters, directors, key managerial personnel or senior management holds more than 2% of shares, as on the first day of the preceding calendar month; and
- any other information the Board directs it to disclose in the interests of transparency.
7. Audit and regulatory oversight
The Consent Manager must have effective audit mechanisms to review, monitor and evaluate its technical and organisational controls, its continued fulfilment of the registration conditions, and its adherence to the Act and Rules, and must report the outcome to the Board periodically and when directed. Under Rule 4, the Board may call for information, direct corrective measures after a hearing, and, where necessary in the interests of Data Principals, suspend or cancel registration after giving an opportunity to be heard. Control of the company cannot be transferred by sale, merger or otherwise without the Board’s prior approval.
8. Platform availability and non-delegation
The Consent Manager must develop and maintain a website or app, or both, as the primary means through which individuals access its services. It must not sub-contract or assign the performance of any of its obligations under the Act and Rules. Using technology vendors for infrastructure, such as cloud hosting, is a different question from handing over a statutory obligation. Whether a particular vendor arrangement is permissible should be assessed carefully, and accountability for the obligations stays with the Consent Manager.
Eligibility and Registration Requirements for a Consent Manager
Part A of the First Schedule sets out the conditions for registration. The applicant must:
- Be a company incorporated in India.
- Have sufficient technical, operational and financial capacity to fulfil its obligations as a Consent Manager.
- Have a sound financial condition and general character of management.
- Have a net worth of not less than ₹2 crore.
- Show adequate business prospects, including likely volume of business, capital structure and earning prospects.
- Have directors, key managerial personnel and senior management with a general reputation and record of fairness and integrity.
- Include conflict-of-interest and disclosure provisions in its memorandum and articles of association, with supporting policies, which can be amended only with the Board’s prior approval.
- Propose operations that are in the interests of Data Principals.
- Be independently certified that its interoperable platform is consistent with the data protection standards and assurance framework published by the Board, and that appropriate technical and organisational measures are in place.
Meeting the ₹2 crore net worth threshold does not by itself guarantee registration. The Board may make such inquiry as it considers fit, and will either register the applicant and publish its particulars or reject the application with reasons.
Details still to be published. The application particulars and documents, and the data protection standards and assurance framework against which platforms must be certified, are to be published by the Board on its website. Applicants should check the Board’s website for the current position before finalising their platform or application.
How to Set Up a DPDP-Compliant Consent Manager Platform
The steps below are a practical preparation framework. Items described as design or implementation considerations are recommendations, not additional legal requirements.
- Assess eligibility and structure. Confirm Indian incorporation, net worth of at least ₹2 crore, financial capacity, business prospects and management suitability.
- Establish governance and independence. Map the ownership and interests of promoters, directors, key managerial personnel and senior management against likely Data Fiduciaries. Amend the memorandum and articles of association to include the required conflict-of-interest and disclosure provisions, and adopt supporting policies.
- Design the consent architecture. Plan for Data Principal onboarding and authentication, consent requests from onboarded Data Fiduciaries, consent grant, denial, review and withdrawal, interoperable workflows, and traceable consent records.
- Build privacy and security safeguards. Consider data minimisation, access controls, encryption, secure authentication, incident response, audit trails and security testing. Design data-sharing flows so the Consent Manager cannot read the contents of personal data made available or shared.
- Implement recordkeeping and retention. Retain records of consents, notices and data sharing for at least seven years, with secure storage, controlled access, retrieval and machine-readable export for Data Principals.
- Arrange independent certification and audits. Independent certification against the Board’s published standards is a registration condition. Ongoing audit mechanisms, with reporting to the Board, are a separate continuing obligation. Run internal readiness reviews before seeking certification.
- Prepare registration documentation. Assemble corporate, financial, governance, technical, security and certification records. The exact list will be what the Board publishes, so treat this as a readiness checklist rather than a confirmed statutory list.
- Apply and prepare for oversight. Submit the application to the Board, respond to its inquiries, and be ready to furnish information and follow directions. Filing an application does not authorise an organisation to operate as a Consent Manager; only registration does.
Does Every Business Need a Consent Manager?
No. It helps to separate three situations:
- Businesses that want to operate as a Consent Manager. These must meet Part A conditions, register with the Board and comply with Part B obligations.
- Businesses acting as Data Fiduciaries. These must meet their own obligations on notice, consent or legitimate use, withdrawal, security, rights requests and retention. Registering as a Consent Manager is not one of them.
- Businesses using consent management software. Using a tool to record consent is a way of meeting your own obligations. It does not make you or your vendor a Consent Manager.
Data Fiduciaries should review their notices, lawful grounds for processing, consent withdrawal mechanisms, records and vendor contracts. If a Data Fiduciary chooses to onboard onto a registered Consent Manager’s platform, that does not transfer or remove its own legal responsibilities. See our DPDP Act 2023 compliance guide for the obligations that apply to every Data Fiduciary.
Common Consent Manager Compliance Mistakes to Avoid
- Confusing a consent banner with a registered Consent Manager. A banner is a notice-and-consent interface; a Consent Manager is a regulated entity.
- Assuming ₹2 crore net worth guarantees registration. The Board assesses all Part A conditions and may inquire further.
- Ignoring conflicts of interest. Undisclosed links between management and Data Fiduciaries go to the heart of the fiduciary role.
- Weak consent and sharing records. Records of consents, notices and sharing must be kept for at least seven years and be accessible to individuals.
- Designing a platform that can read shared data. Architecture decisions should be made early, with the “not readable” obligation in mind.
- Treating a routine security audit as certification. Registration requires independent certification against the Board’s published standards and assurance framework.
- Assuming registration ends oversight. The Board can seek information, issue directions, and suspend or cancel registration.
- Relying on draft Rules or unverified timelines. Work from the notified Gazette text and the Board’s current publications.
Legal review of the governance structure, early architecture decisions and documented controls help avoid most of these problems.
Frequently Asked Questions
What is a Consent Manager under the DPDP Act?
It is a person registered with the Data Protection Board of India that acts as a single point of contact for individuals to give, manage, review and withdraw their consent through an accessible, transparent and interoperable platform. Under the DPDP Rules, 2025, it must be a company incorporated in India and acts in a fiduciary capacity towards Data Principals.
Is Consent Manager registration mandatory for every company?
No. Registration is mandatory only for an organisation that wants to operate as a Consent Manager. Businesses that collect or process personal data for their own purposes are Data Fiduciaries and must meet their own consent and notice obligations, but they do not need to register as Consent Managers.
What is the minimum net worth required to become a Consent Manager?
Part A of the First Schedule to the DPDP Rules, 2025 requires a net worth of not less than ₹2 crore. This is one of several conditions. The Board also assesses capacity, financial soundness, management integrity, governance provisions, business prospects and independent platform certification before registering an applicant.
Who can apply for Consent Manager registration in India?
A company incorporated in India that meets all the conditions in Part A of the First Schedule can apply to the Data Protection Board. The application must include the particulars, information and documents the Board publishes on its website for this purpose.
What is the role of the Data Protection Board of India?
For Consent Managers, the Board registers or rejects applicants, publishes details of registered Consent Managers, can call for information, directs corrective measures, and can suspend or cancel registration after a hearing. More broadly, it inquires into breaches of the DPDP Act and can impose penalties.
How long must a Consent Manager maintain consent records?
At least seven years, or longer if the Data Principal and the Consent Manager agree or the law requires it. The records cover consents given, denied or withdrawn, the related notices, and sharing of personal data with a transferee Data Fiduciary.
Can a Consent Manager access the personal data it facilitates sharing?
The Rules require that personal data is made available or shared in a way that its contents are not readable by the Consent Manager. The Consent Manager still maintains records of consents, notices and sharing. How this applies to specific technical elements depends on platform design and the Board’s published standards.
What is the difference between a Consent Manager and a consent management platform?
A Consent Manager is a registered, regulated entity that serves individuals across multiple businesses. A consent management platform is typically software a business uses to collect and record consent for its own processing. Using such software does not make the business or the vendor a Consent Manager.
Does using a Consent Manager make a Data Fiduciary fully DPDP compliant?
No. A Data Fiduciary remains responsible for its own obligations, including valid notices, lawful processing, security safeguards, breach reporting, rights requests and data erasure. A Consent Manager can help individuals manage consent, but it does not transfer or remove the Data Fiduciary’s responsibilities.
Building Trust Through Effective Consent Management
The Consent Manager framework is designed to give individuals real control over their consent through a transparent, secure and independent platform. Registration is not a formality. It requires legal, financial, governance, technical and operational readiness, independent certification, and ongoing accountability to both Data Principals and the Board.
Organisations considering registration should work from the notified Act and Rules, track the Board’s publications, and take qualified legal and technical advice. Businesses that are Data Fiduciaries should focus on their own consent and notice obligations, which apply regardless of whether they use a Consent Manager.
This article is for general educational purposes only and is not a substitute for legal advice. Obligations depend on the facts, the entity involved and the notified law as it stands at the time.
Planning for DPDP Compliance?
Whether you are evaluating Consent Manager registration or preparing your business as a Data Fiduciary, AAPT & Associates provides DPDP Act compliance services, including readiness assessments and governance reviews.



