What Is a Consent Manager Under the DPDP Act? Definition, Rules and How It Works
Definition, registration conditions, obligations, workflow and business impact.
What is a Consent Manager?
Consent Manager under Section 2(g) of the DPDP Act
Section 2(g) of the DPDP Act defines a Consent Manager as a person registered with the Data Protection Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. The concept borrows from India's Account Aggregator framework in financial services: a neutral intermediary that routes consent, not data.
The DPDP Rules 2025 (Rule 4 and the First Schedule) set the registration conditions and the operating obligations. Registration opens on 13 November 2026. Consent Managers are optional for Data Fiduciaries and Data Principals; the Act does not force any business to integrate with one, but the Central Government can shape adoption through sectoral guidance.
The organisation seeking the consent remains the accountable party throughout — see Data Fiduciary vs Data Processor under the DPDP Act, and our plain-English guide to the DPDP Act for the wider framework.
Consent Manager Definitions and Key Terms
The GDPR has no equivalent role at all, which is one of the sharper divergences in DPDP vs GDPR: key differences.
- Consent Manager
- A Board-registered Indian company operating a platform through which Data Principals give, manage, review and withdraw consent.
- Consent
- A free, specific, informed, unconditional and unambiguous indication of the Data Principal's wishes by clear affirmative action, limited to the specified purpose.
- Consent artefact
- The digital record of a consent event: who, what data, which purpose, when, through which channel, and its current status.
- Interoperability
- The requirement that a Consent Manager platform work with any Data Fiduciary through standard interfaces, rather than being tied to one ecosystem.
- Data-blind
- Design principle in the First Schedule: the Consent Manager routes consent and, where it routes data, does so in a manner that it cannot read the contents.
- Account Aggregator
- RBI-regulated NBFC that routes financial data on consent; the closest existing Indian analogue to a Consent Manager.
Who Can Register as a Consent Manager in India
| Condition | Requirement under the First Schedule |
|---|---|
| Legal form | Company incorporated in India. |
| Financial standing | Minimum net worth of INR 2 crore and sound financial condition. |
| Ownership and control | Must be independent; directors, key managerial personnel and senior management must be of adequate reputation and integrity, and free from conflicts with Data Fiduciaries served. |
| Governance | Certified interoperable platform; volume of business and capacity adequate to the role; compliance with technical and organisational standards prescribed by the Board. |
| Independence from Data Fiduciaries | Must avoid conflicts of interest; cannot be controlled by or act as an agent of Data Fiduciaries whose consents it manages. |
| Registration authority | Data Protection Board of India, which may suspend or cancel registration for non-compliance after inquiry. |
Consent Manager Obligations Under the DPDP Rules 2025
- Act only for the Data Principal. The Consent Manager owes its duty to the individual, not to the Data Fiduciary.
- Provide a single dashboard. Give, review, modify and withdraw consent across all connected Data Fiduciaries from one place.
- Maintain consent records. Keep an auditable record of every consent, notice and withdrawal, and make it available to the Data Principal, and to the Board on request. Records must be retained for at least seven years or as agreed.
- Stay data-blind. Where data flows through the platform, it must be encrypted such that the Consent Manager cannot access it.
- Avoid conflicts of interest. No commercial arrangements that would bias consent decisions; disclose promoters and ownership.
- Publish transparently. Ownership, governance, grievance process, security practices and pricing model on its website.
- Operate securely. Reasonable security safeguards, incident reporting, and business continuity measures.
- Provide grievance redressal. Effective mechanism for Data Principals with published timelines.
How a Consent Manager Works: Step-by-Step
- The Data Fiduciary integrates with a registered Consent Manager through standard APIs.
- At the point of data collection, the Data Fiduciary presents its itemised notice and requests consent through the Consent Manager, or the Data Principal initiates from the Consent Manager dashboard.
- The Data Principal gives consent; the Consent Manager creates a signed consent artefact and shares it with the Data Fiduciary.
- The Data Fiduciary processes only within the scope of the artefact and keeps its own copy as evidence.
- The Data Principal can review all active consents and withdraw any of them from the dashboard; the Consent Manager notifies the affected Data Fiduciary, which must stop processing and erase within a reasonable time.
- The Consent Manager retains the audit trail for the Board and for dispute resolution.
Consent Manager vs Consent Management Platform (CMP)
Businesses often confuse the statutory Consent Manager with the cookie-banner style consent management platforms sold by privacy-tech vendors. They are different things.
| Feature | Consent Manager (DPDP) | Consent Management Platform (CMP) |
|---|---|---|
| Legal status | Registered with the Data Protection Board; statutory role. | Commercial software; no registration. |
| Whose agent | Acts for the Data Principal. | Deployed by and acts for the Data Fiduciary. |
| Scope | Cross-fiduciary: one dashboard for many organisations. | Single organisation's websites and apps. |
| Independence | Must be independent from Data Fiduciaries. | Owned or licensed by the Data Fiduciary. |
| Access to data | Data-blind by design. | Typically stores preference data for the Fiduciary. |
| Mandatory? | Optional for Fiduciaries; expected in regulated sectors. | Not mandated, but a practical necessity for web and app consent. |
What Consent Managers Mean for Businesses
For Data Fiduciaries
- Design consent capture so that it can later route through a Consent Manager: structured purposes, machine-readable notices, unique consent IDs.
- Build a consent withdrawal workflow that can be triggered by an external signal, with downstream erasure across Processors.
- Plan integration budgets for 2027. Financial services, telecom and health are the most likely sectors for early Consent Manager adoption.
For companies planning to become a Consent Manager
- Prepare the corporate structure, INR 2 crore net worth, fit-and-proper governance and an interoperability-certified platform before 13 November 2026.
- Expect Board scrutiny on independence, security and financial viability similar to RBI oversight of Account Aggregators.
- Revenue models are still forming; per-consent fees paid by Data Fiduciaries are the most likely structure, mirroring the AA ecosystem.
Sectors most likely to be pulled in early are also the ones most likely to be notified as a Significant Data Fiduciary.
Frequently Asked Questions About Consent Managers
Key takeaways
- A Consent Manager is a Board-registered, independent, data-blind Indian company acting for individuals.
- It gives one dashboard to give, review and withdraw consent across many organisations.
- Use is optional for Data Fiduciaries, but consent architecture should be built to interoperate.
- Registration opens 13 November 2026; conditions include INR 2 crore net worth and certified interoperability.