Skip to main content

Sources last verified on 20 August 2026. Methodology

What is a Consent Manager under the DPDP Act? Definition, registration and obligations

Consent

By Abhijeet Singh · Reviewed by dpdprules.org source verificationPublished · Last reviewed 6 min read

The short answer

A Consent Manager is a person registered with the Data Protection Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform (section 2(g)). Section 6 lets individuals route consent through one, makes it accountable to the Data Principal, acting on her behalf, and requires registration with the Board. Rule 4 supplies the machinery: Part A of the First Schedule sets registration conditions, including incorporation in India, sufficient technical, operational and financial capacity and a net worth of at least two crore rupees, and Part B sets obligations, including data blindness, seven year consent records, fiduciary duty, conflict of interest controls and Board supervised audits. Rule 4 commences on the computed date of 13 November 2026, interpretation until officially confirmed.

Most of the DPDP framework's cast has familiar ancestors in global privacy law. The Consent Manager does not: it is the framework's own invention, consent infrastructure operated as a registered, supervised business. This article maps the institution from the primary text: the definition, the section 6 channel, and what registration under Rule 4 with the First Schedule demands. A companion piece answers the narrower commercial question, whether your business needs to become one; for most the answer is no.

The definition in section 2(g)

The Act defines the term once, in the definitions section:

Official requirement · verbatim

"“Consent Manager” means a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform"

Four elements carry the weight. Registered with the Board: registration with the Data Protection Board of India is part of the definition, so an unregistered service is not a Consent Manager in law. A single point of contact: the individual deals with one platform, not with each Data Fiduciary separately. Give, manage, review and withdraw: the platform must cover the whole life of a consent, not just its capture. Accessible, transparent and interoperable: interoperable is the load bearing word; the platform only works if it spans the Data Fiduciaries onboarded onto it.

One boundary follows immediately. A consent banner or preference centre running on your own website serves one fiduciary and is registered with nobody. That is consent management software, not a Consent Manager.

Section 6, the consent section, gives the institution its function in three subsections. Subsection (7) opens the channel: the Data Principal may give, manage, review or withdraw her consent to the Data Fiduciary through a Consent Manager. The word is may: an optional route for the individual, not a mandatory intermediary for every consent in India.

Subsection (8) fixes the direction of loyalty:

Official requirement · verbatim

"The Consent Manager shall be accountable to the Data Principal and shall act on her behalf in such manner and subject to such obligations as may be prescribed."

Accountability runs to the individual, not to the Data Fiduciaries whose consent requests flow through the platform. Subsection (9) then makes registration compulsory and conditional:

Official requirement · verbatim

"Every Consent Manager shall be registered with the Board in such manner and subject to such technical, operational, financial and other conditions as may be prescribed."

Both subsections end in as may be prescribed. The DPDP Rules 2025 are the prescription: Rule 4 and the First Schedule.

Rule 4: registration with the Board

Rule 4 builds the machinery around the First Schedule. A person who fulfils the conditions in Part A may apply to the Board, furnishing the particulars the Board publishes on its website. After such inquiry as it sees fit, the Board either registers the applicant and publishes its particulars, or rejects the application with reasons communicated to the applicant.

Registration is where supervision begins. Under Rule 4(3) the registered Consent Manager carries the Part B obligations. Where the Board considers the conditions and obligations are not being adhered to, it may, after a hearing, direct corrective measures; in the interests of Data Principals it may suspend or cancel the registration by a reasoned written order and issue such directions as it deems fit; and it may require the Consent Manager to furnish such information as it calls for.

Part A: what it takes to register

Part A sets nine conditions, and they read like a licensing test for a financial intermediary. The applicant must be a company incorporated in India with sufficient technical, operational and financial capacity, sound financial condition and general character of management, and a net worth of not less than two crore rupees. Its likely business volume, capital structure and earning prospects must be adequate, its directors, key managerial personnel and senior management must have a general reputation and record of fairness and integrity, and its proposed operations must be in the interests of Data Principals.

Two conditions are structural. The memorandum and articles of association must lock in the Part B conflict of interest obligations, with policies and procedures to ensure adherence, amendable only with the previous approval of the Board. And the interoperable platform must be independently certified as consistent with the data protection standards and assurance framework the Board publishes on its website.

Part B: the operating obligations

Part B lists thirteen obligations, and together they describe the product. The platform must let a Data Principal give consent to an onboarded Data Fiduciary either directly or routed through another onboarded Data Fiduciary that already holds her personal data with her consent. The schedule's illustration uses banks: the individual either grants a requesting bank access to a statement kept in her digital locker, or routes consent through her own bank, instructing it to send the statement across.

The most distinctive obligation is data blindness: the manner of making available or sharing the personal data must be such that "the contents thereof are not readable by it". Consent plumbing that never sees the payload.

The record keeping obligations define the audit trail: consents given, denied or withdrawn, the notices preceding or accompanying consent requests, and the sharing of personal data with each transferee Data Fiduciary. The Data Principal gets access to that record, can ask for the information in it in machine readable form, and the record must be kept for at least seven years, or longer by agreement or under law.

The remaining obligations govern the company. A website or app, or both, as the primary means of access to its services. No subcontracting or assignment of any obligation. Reasonable security safeguards to prevent personal data breach, and a duty to "act in a fiduciary capacity in relation to the Data Principal". Avoidance of conflicts of interest with Data Fiduciaries, backed by measures against directorships, financial interests, employment or beneficial ownership creating such conflicts at director, key managerial personnel and senior management level. Published transparency about its promoters, directors, key managerial personnel, senior management and every shareholder above two per cent. Effective audit mechanisms reporting outcomes to the Board periodically and on demand. And no transfer of control by sale, merger or otherwise without the previous approval of the Board.

When each piece commences

The commencement picture is split, and every calendar date here is computed, interpretation until officially confirmed. Section 6(9), the registration duty, sits in the one year group of notification G.S.R. 843(E), which computes to 13 November 2026. Rule 4 is on its own matching track: Rule 1(3) of the Rules brings it into force one year after publication, computing to the same 13 November 2026. Rule 1(3) does not name the Schedules; the First Schedule operates through Rule 4, so it is presented as commencing with it, which is itself an interpretation. The rest of section 6, including the subsection (7) channel and the subsection (8) accountability duty, sits in the eighteen month group, computing to 13 May 2027.

Who actually needs to care

Three audiences. Businesses that want to become Consent Managers, most plausibly around financial data sharing, health or digital locker style services: Part A is the entry checklist, Part B the product specification, and the window opens with Rule 4. Data Fiduciaries that expect to receive consent through registered Consent Managers: section 6(7) lets the Data Principal give her consent to the Data Fiduciary through this channel, so integration is worth planning, and the role identifier confirms which side of the flow you sit on. And individuals, for whom the institution eventually means one dashboard for consents across services; the rights explorer covers what you can already demand directly.

The practical next step is to read Rule 4 and the First Schedule in the official text, and to let the company compliance plan tell you whether any of this lands on your own action list.

Section 6, official textRule 4, official textFirst Schedule, official textDo you need a Consent Manager?

Sources cited on this page

  1. [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 2(g), p. 2. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026
  2. [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 6, p. 5. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 6 begins on Gazette page 5 and concludes on page 6; subsections (7) to (9) appear on page 6. They provide for consent through a Consent Manager, its accountability to the Data Principal while acting on her behalf, and its registration with the Board subject to prescribed technical, operational, financial and other conditions.
  3. [3]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 4, p. 25. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Rule 4: application to the Board against the Part A conditions, Board inquiry and registration or reasoned rejection, the Part B obligations, and Board powers to direct adherence, suspend or cancel registration after a hearing, give directions and call for information.
  4. [4]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), First Schedule Schedule, p. 32. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026The First Schedule begins on Gazette page 32 and concludes on page 34. Part A sets the nine conditions for registration; Part B sets the thirteen obligations of a registered Consent Manager. Corrigenda G.S.R. 892(E) items (iv)(a) and (iv)(b) correct two misprints on page 34.
  5. [5]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (3), p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Rule 1(3): Rule 4 comes into force one year after the date of publication.
  6. [6]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (3), p. 24. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026Rule 1(3) names Rule 4 and does not name the Schedules. The First Schedule operates through Rule 4, so it is presented here as commencing with Rule 4; that reading is interpretation until officially confirmed.
  7. [7]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), (b), p. 2. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026
  8. [8]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), (c), p. 2. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Notification G.S.R. 843(E) places subsections (1) to (8) and (10) of section 6 in the group that comes into force eighteen months from publication.
  9. [9]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026The calendar dates 13 November 2026 for section 6(9) and 13 May 2027 for the remainder of section 6 are computed from the publication date printed on Gazette issue No. 757 and are presented as interpretation until officially confirmed.
  10. [10]Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026The calendar date 13 November 2026 for Rule 4 is computed from the publication date printed on Gazette issue No. 760 and is presented as interpretation until officially confirmed.

consent managerrule 4first scheduleregistration

Share this: