What is a Consent Manager under the DPDP Act? Definition, registration and obligations
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 6 min read
What is a Consent Manager under the DPDP Act and what are its obligations?
The short answer
Section 2(g), already in force, defines a Consent Manager as a person registered with the Data Protection Board who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform; none of its duties was in force at 2 October 2026. Once section 6(9) and Rule 4 are in force, on a computed 13 November 2026, every Consent Manager must be registered with the Board subject to prescribed technical, operational, financial and other conditions. Part A of the First Schedule sets 9 conditions, including that the applicant is a company incorporated in India, has sufficient capacity, including technical, operational and financial capacity, and has net worth of at least 2 crore rupees. Part B sets 13 obligations, including making available or sharing personal data so that its contents are not readable by the Consent Manager, keeping its record of consents, notices and data sharing for at least 7 years or longer if agreed or legally required, acting as a fiduciary for the Data Principal, avoiding conflicts of interest, and audit outcomes reported to the Board. This site reads the Schedule as commencing with Rule 4. Once sections 6(7) and 6(8) are in force, on a computed 13 May 2027, a Data Principal may give, manage, review or withdraw consent to a Data Fiduciary through a Consent Manager, accountable to her and acting on her behalf as prescribed. Both dates are interpretation until officially confirmed.

Most of the DPDP framework's cast has familiar ancestors in global privacy law. The Consent Manager does not: it is the framework's own invention, consent infrastructure operated as a registered, supervised business. This article maps the institution from the primary text: the definition, the section 6 channel, and what registration under Rule 4 with the First Schedule demands. A companion piece answers the narrower commercial question, whether you need to register as a Consent Manager; for most businesses the answer is no.
The definition in section 2(g)
The Act defines the term once, in the definitions section:
"“Consent Manager” means a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform"
Four elements carry the weight. Registered with the Board: registration with the Data Protection Board of India is part of the definition, so an unregistered service is not a Consent Manager in law. A single point of contact: the individual deals with one platform, not with each Data Fiduciary separately. Give, manage, review and withdraw: the platform must cover the whole life of a consent, not just its capture. Accessible, transparent and interoperable: interoperable is the load bearing word; the platform only works if it spans the Data Fiduciaries onboarded onto it.
One boundary follows immediately. A consent banner or preference centre running on your own website serves one fiduciary and is registered with nobody. That is consent management software, not a Consent Manager.
The consent channel in section 6
Section 6, the consent section, gives the institution its function in three subsections. Subsection (7) opens the channel: the Data Principal may give, manage, review or withdraw her consent to the Data Fiduciary through a Consent Manager. The word is may: an optional route for the individual, not a mandatory intermediary for every consent in India.
Subsection (8) fixes the direction of loyalty:
"The Consent Manager shall be accountable to the Data Principal and shall act on her behalf in such manner and subject to such obligations as may be prescribed."
Accountability runs to the individual, not to the Data Fiduciaries whose consent requests flow through the platform. Subsection (9) then makes registration compulsory and conditional:
"Every Consent Manager shall be registered with the Board in such manner and subject to such technical, operational, financial and other conditions as may be prescribed."
Both subsections end in as may be prescribed. The DPDP Rules 2025 are the prescription: Rule 4 and the First Schedule.
Rule 4: registration with the Board
Rule 4 builds the machinery around the First Schedule. A person who fulfils the conditions in Part A may apply to the Board, furnishing the particulars the Board publishes on its website. After such inquiry as it sees fit, the Board either registers the applicant and publishes its particulars, or rejects the application with reasons communicated to the applicant.
Registration is where supervision begins. Under Rule 4(3) the registered Consent Manager carries the Part B obligations. Where the Board considers the conditions and obligations are not being adhered to, it may, after a hearing, direct corrective measures; in the interests of Data Principals it may suspend or cancel the registration by a reasoned written order and issue such directions as it deems fit; and it may require the Consent Manager to furnish such information as it calls for.
Part A: what it takes to register
Part A sets 9 conditions, and they read like a licensing test for a financial intermediary. The applicant must be a company incorporated in India with sufficient technical, operational and financial capacity, sound financial condition and general character of management, and a net worth of not less than 2 crore rupees. Its likely business volume, capital structure and earning prospects must be adequate, its directors, key managerial personnel and senior management must have a general reputation and record of fairness and integrity, and its proposed operations must be in the interests of Data Principals.
2 conditions are structural. The memorandum and articles of association must lock in the Part B conflict of interest obligations, with policies and procedures to ensure adherence, amendable only with the previous approval of the Board. And the interoperable platform must be independently certified as consistent with the data protection standards and assurance framework the Board publishes on its website.
Part B: the operating obligations
Part B lists 13 obligations, and together they describe the product. The platform must let a Data Principal give consent to an onboarded Data Fiduciary either directly or routed through another onboarded Data Fiduciary that already holds her personal data with her consent. The schedule's illustration uses banks: the individual either grants a requesting bank access to a statement kept in her digital locker, or routes consent through her own bank, instructing it to send the statement across.
The most distinctive obligation is data blindness: the manner of making available or sharing the personal data must be such that "the contents thereof are not readable by it". Consent plumbing that never sees the payload.
The record keeping obligations define the audit trail: consents given, denied or withdrawn, the notices preceding or accompanying consent requests, and the sharing of personal data with each transferee Data Fiduciary. The Data Principal gets access to that record, can ask for the information in it in machine readable form, and the record must be kept for at least 7 years, or longer by agreement or under law.
The remaining obligations govern the company. A website or app, or both, as the primary means of access to its services. No subcontracting or assignment of any obligation. Reasonable security safeguards to prevent personal data breach, and a duty to "act in a fiduciary capacity in relation to the Data Principal". Avoidance of conflicts of interest with Data Fiduciaries, backed by measures against directorships, financial interests, employment or beneficial ownership creating such conflicts at director, key managerial personnel and senior management level. Published transparency about its promoters, directors, key managerial personnel, senior management and every shareholder above two per cent. Effective audit mechanisms reporting outcomes to the Board periodically and on demand. And no transfer of control by sale, merger or otherwise without the previous approval of the Board.
When each piece commences
The commencement picture is split, and every calendar date here is computed, interpretation until officially confirmed. Section 6(9), the registration duty, sits in the 1 year group of notification G.S.R. 843(E), which computes to 13 November 2026. Rule 4 is on its own matching track: Rule 1(3) of the Rules brings it into force 1 year after publication, computing to the same 13 November 2026. Rule 1(3) does not name the Schedules; the First Schedule operates through Rule 4, so it is presented as commencing with it, which is itself an interpretation. The rest of section 6, including the subsection (7) channel and the subsection (8) accountability duty, sits in the 18 month group, computing to 13 May 2027.
Who actually needs to care
3 audiences. Businesses that want to become Consent Managers, most plausibly around financial data sharing, health or digital locker style services: Part A is the entry checklist, Part B the product specification, and the window opens with Rule 4. Data Fiduciaries that expect to receive consent through registered Consent Managers: section 6(7) lets the Data Principal give her consent to the Data Fiduciary through this channel, so integration is worth planning, and the role identifier confirms which side of the flow you sit on. And individuals, for whom the institution eventually means one dashboard for consents across services; the rights explorer covers what you can already demand directly.
The practical next step is to read Rule 4 and the First Schedule in the official text, and to let the company compliance plan tell you whether any of this lands on your own action list.
Related tool
Role and Actor Checker
Work out your likely role for a processing activity, such as Data Fiduciary or Data Processor.
Open
Related tool
Compliance Plan
Generate 1 company level action plan and see the work for your role first.
Open
Related tool
Individual Rights Assistant
Understand your rights as an individual and the channels a Data Fiduciary must offer.
Open
Section 6, official text →Rule 4, official text →First Schedule, official text →Do you need a Consent Manager? →