Do you need to register as a Consent Manager? Rule 4 and who it applies to
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 2 min read
Do I need to register as a Consent Manager under DPDP?
The short answer
Most ordinary businesses do not need to become a Consent Manager. Under the Act, a Consent Manager is a specific kind of registered intermediary: a person registered with the Data Protection Board that acts as a single point of contact for individuals to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. That is different from using consent management software on your own website, which the framework does not require to be registered. Registration under Rule 4 is for organisations that want to operate such a platform, and the First Schedule conditions include being a company incorporated in India and a net worth of at least 2 crore rupees, with obligations including keeping consent records and being unable to read the personal data passing through. Rule 4 comes into force 1 year after the Rules publication, which computes to 13 November 2026, interpretation until officially confirmed.

Consent Managers are the framework's most novel institution: consent infrastructure as a regulated business. This article answers the commercial question of whether your business needs to register as one. For the institution itself, its statutory definition and the full registration and obligation set, see what a Consent Manager is under the DPDP Act.
What the Act defines
"“Consent Manager” means a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform"
Interoperable is the load bearing word: the platform routes consent between individuals and the Data Fiduciaries onboarded onto it.
What Rule 4 sets up
Rule 4 creates the registration machinery: application to the Board against the conditions in Part A of the First Schedule, Board inquiry, registration or reasoned rejection, and Board powers to direct, suspend or cancel. The Part A conditions include being a company incorporated in India, sufficient technical, operational and financial capacity, a net worth of at least 2 crore rupees, and independent certification of the platform's data protection standards.
The Part B obligations shape the product. Two stand out. The Consent Manager must make personal data available or route its sharing in a manner where the contents are not readable by it: consent plumbing, blind to the payload. And it must keep records of consents given, denied or withdrawn, the notices, and the sharing, for at least 7 years, giving the individual access to that record, and on request the information in it in machine readable form.
The clock
Rule 4 is on its own commencement track: 1 year after the Rules publication, which computes to 13 November 2026 and is interpretation until officially confirmed. Financial data sharing businesses in particular should read the First Schedule closely before that date.
What to do
If consent flows are core to your product, read Rule 4's official text and factor the registration conditions into your planning. For most organisations the practical step is watching which Consent Managers register and deciding whether to integrate.