Skip to main content
What Is a Consent Manager? DPDP Act Explained | AIZZENTEC — page loaded
Explainer

What Is a Consent Manager Under the DPDP Act? Definition, Rules and How It Works

Definition, registration conditions, obligations, workflow and business impact.

Section 01

What is a Consent Manager?

Quick answer
A Consent Manager under India's DPDP Act 2023 is a company registered with the Data Protection Board of India that gives individuals a single, transparent platform to give, review, manage and withdraw consent for the processing of their personal data across multiple Data Fiduciaries. It acts on behalf of the Data Principal, is interoperable with Data Fiduciaries, and cannot itself read the underlying personal data.

Consent Manager under Section 2(g) of the DPDP Act

Section 2(g) of the DPDP Act defines a Consent Manager as a person registered with the Data Protection Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. The concept borrows from India's Account Aggregator framework in financial services: a neutral intermediary that routes consent, not data.

The DPDP Rules 2025 (Rule 4 and the First Schedule) set the registration conditions and the operating obligations. Registration opens on 13 November 2026. Consent Managers are optional for Data Fiduciaries and Data Principals; the Act does not force any business to integrate with one, but the Central Government can shape adoption through sectoral guidance.

The organisation seeking the consent remains the accountable party throughout — see Data Fiduciary vs Data Processor under the DPDP Act, and our plain-English guide to the DPDP Act for the wider framework.

Section 02

Consent Manager Definitions and Key Terms

The GDPR has no equivalent role at all, which is one of the sharper divergences in DPDP vs GDPR: key differences.

Consent Manager
A Board-registered Indian company operating a platform through which Data Principals give, manage, review and withdraw consent.
Consent
A free, specific, informed, unconditional and unambiguous indication of the Data Principal's wishes by clear affirmative action, limited to the specified purpose.
Consent artefact
The digital record of a consent event: who, what data, which purpose, when, through which channel, and its current status.
Interoperability
The requirement that a Consent Manager platform work with any Data Fiduciary through standard interfaces, rather than being tied to one ecosystem.
Data-blind
Design principle in the First Schedule: the Consent Manager routes consent and, where it routes data, does so in a manner that it cannot read the contents.
Account Aggregator
RBI-regulated NBFC that routes financial data on consent; the closest existing Indian analogue to a Consent Manager.
Section 03

Who Can Register as a Consent Manager in India

Consent Manager registration conditions under the First Schedule to the DPDP Rules 2025
ConditionRequirement under the First Schedule
Legal formCompany incorporated in India.
Financial standingMinimum net worth of INR 2 crore and sound financial condition.
Ownership and controlMust be independent; directors, key managerial personnel and senior management must be of adequate reputation and integrity, and free from conflicts with Data Fiduciaries served.
GovernanceCertified interoperable platform; volume of business and capacity adequate to the role; compliance with technical and organisational standards prescribed by the Board.
Independence from Data FiduciariesMust avoid conflicts of interest; cannot be controlled by or act as an agent of Data Fiduciaries whose consents it manages.
Registration authorityData Protection Board of India, which may suspend or cancel registration for non-compliance after inquiry.
Section 04

Consent Manager Obligations Under the DPDP Rules 2025

  • Act only for the Data Principal. The Consent Manager owes its duty to the individual, not to the Data Fiduciary.
  • Provide a single dashboard. Give, review, modify and withdraw consent across all connected Data Fiduciaries from one place.
  • Maintain consent records. Keep an auditable record of every consent, notice and withdrawal, and make it available to the Data Principal, and to the Board on request. Records must be retained for at least seven years or as agreed.
  • Stay data-blind. Where data flows through the platform, it must be encrypted such that the Consent Manager cannot access it.
  • Avoid conflicts of interest. No commercial arrangements that would bias consent decisions; disclose promoters and ownership.
  • Publish transparently. Ownership, governance, grievance process, security practices and pricing model on its website.
  • Operate securely. Reasonable security safeguards, incident reporting, and business continuity measures.
  • Provide grievance redressal. Effective mechanism for Data Principals with published timelines.
Section 05

How a Consent Manager Works: Step-by-Step

  1. The Data Fiduciary integrates with a registered Consent Manager through standard APIs.
  2. At the point of data collection, the Data Fiduciary presents its itemised notice and requests consent through the Consent Manager, or the Data Principal initiates from the Consent Manager dashboard.
  3. The Data Principal gives consent; the Consent Manager creates a signed consent artefact and shares it with the Data Fiduciary.
  4. The Data Fiduciary processes only within the scope of the artefact and keeps its own copy as evidence.
  5. The Data Principal can review all active consents and withdraw any of them from the dashboard; the Consent Manager notifies the affected Data Fiduciary, which must stop processing and erase within a reasonable time.
  6. The Consent Manager retains the audit trail for the Board and for dispute resolution.
Section 06

Consent Manager vs Consent Management Platform (CMP)

Businesses often confuse the statutory Consent Manager with the cookie-banner style consent management platforms sold by privacy-tech vendors. They are different things.

Statutory Consent Manager compared with a commercial consent management platform
FeatureConsent Manager (DPDP)Consent Management Platform (CMP)
Legal statusRegistered with the Data Protection Board; statutory role.Commercial software; no registration.
Whose agentActs for the Data Principal.Deployed by and acts for the Data Fiduciary.
ScopeCross-fiduciary: one dashboard for many organisations.Single organisation's websites and apps.
IndependenceMust be independent from Data Fiduciaries.Owned or licensed by the Data Fiduciary.
Access to dataData-blind by design.Typically stores preference data for the Fiduciary.
Mandatory?Optional for Fiduciaries; expected in regulated sectors.Not mandated, but a practical necessity for web and app consent.
Section 07

What Consent Managers Mean for Businesses

For Data Fiduciaries

  • Design consent capture so that it can later route through a Consent Manager: structured purposes, machine-readable notices, unique consent IDs.
  • Build a consent withdrawal workflow that can be triggered by an external signal, with downstream erasure across Processors.
  • Plan integration budgets for 2027. Financial services, telecom and health are the most likely sectors for early Consent Manager adoption.

For companies planning to become a Consent Manager

  • Prepare the corporate structure, INR 2 crore net worth, fit-and-proper governance and an interoperability-certified platform before 13 November 2026.
  • Expect Board scrutiny on independence, security and financial viability similar to RBI oversight of Account Aggregators.
  • Revenue models are still forming; per-consent fees paid by Data Fiduciaries are the most likely structure, mirroring the AA ecosystem.

Sectors most likely to be pulled in early are also the ones most likely to be notified as a Significant Data Fiduciary.

Frequently Asked Questions About Consent Managers

No. The Act creates the role and the Rules regulate it, but no Data Fiduciary is obliged to use one. Sectoral regulators may encourage adoption.

The Data Protection Board of India registers, supervises and can suspend or cancel registration.

No. The First Schedule requires an Indian-incorporated company.

INR 2 crore, together with sound financial condition and adequate capacity.

13 November 2026, twelve months after the DPDP Rules were notified.

No. It is designed to be data-blind and must ensure it cannot read personal data that flows through it.

An Account Aggregator routes financial data among RBI-regulated entities on consent. A Consent Manager routes consent for any personal data across any Data Fiduciary. The design philosophy is the same; the scope and regulator differ.

Key takeaways

  • A Consent Manager is a Board-registered, independent, data-blind Indian company acting for individuals.
  • It gives one dashboard to give, review and withdraw consent across many organisations.
  • Use is optional for Data Fiduciaries, but consent architecture should be built to interoperate.
  • Registration opens 13 November 2026; conditions include INR 2 crore net worth and certified interoperability.