Consent

Consent Managers under the DPDP Act and Rules

Audience: product teams, fintech and platform operators, compliance owners · Last reviewed: October 2026

Consent Managers are one of the more distinctive features of India's data protection framework. They are a new kind of regulated intermediary that sits between individuals and the businesses that want their consent. This guide explains what the DPDP Act, 2023 and the DPDP Rules, 2025 require of them, and what they mean for ordinary Data Fiduciaries.

Section 2(g) defines a Consent Manager as a person registered with the Board who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform.

What the Act says

  • A Data Principal may give, manage, review or withdraw consent to a Data Fiduciary through a Consent Manager (section 6(7)).
  • The Consent Manager is accountable to the Data Principal and acts on her behalf, subject to prescribed obligations (section 6(8)).
  • Every Consent Manager must be registered with the Board on prescribed technical, operational, financial and other conditions (section 6(9)).
  • Data Principals have a right to grievance redressal from a Consent Manager, which must respond within the prescribed period (section 13(1) and 13(2)).
  • The Board can inquire into a Consent Manager's breach of its obligations on a complaint, and into breach of a condition of registration, and impose penalties (section 27(1)(c) and 27(1)(d)).

When the Consent Manager provisions start

Rule 4 comes into force one year after publication of the Rules on 13 November 2025 (Rule 1(3)). The commencement notification noted at section 1(2) also brings section 6(9) and section 27(1)(d) into force one year from 13 November 2025. Sections 6(7) and 6(8), and the rest of section 27, follow at eighteen months. In practice, registration can begin first, with the wider consent framework following later.

Registration conditions (First Schedule, Part A)

An applicant applies to the Board with the particulars the Board publishes on its website (Rule 4(1)). The Board may inquire and then either register the applicant and publish its particulars, or reject the application with reasons (Rule 4(2)). The conditions are:

  1. The applicant is a company incorporated in India.
  2. It has sufficient technical, operational and financial capacity.
  3. Its financial condition and general character of management are sound.
  4. Its net worth is not less than two crore rupees.
  5. Its likely volume of business, capital structure and earning prospects are adequate.
  6. Its directors, key managerial personnel and senior management have a general reputation and record of fairness and integrity.
  7. Its memorandum and articles require adherence to the conflict-of-interest obligations in items 9 and 10 of Part B, and those provisions can be amended only with the Board's prior approval.
  8. Its proposed operations are in the interests of Data Principals.
  9. It is independently certified that its interoperable platform meets the data protection standards and assurance framework the Board publishes, and that it has measures to meet its disclosure obligations.

Ongoing obligations (First Schedule, Part B)

Once registered, a Consent Manager must (Rule 4(3)):

  • Route consent to an onboarded Data Fiduciary, either directly or through another onboarded Data Fiduciary that holds the data (item 1). The Schedule's illustration uses two banks: a user can let one bank send her account statement to another.
  • Stay blind to content: the way data is made available or shared must be such that the Consent Manager cannot read it (item 2).
  • Keep records of consents given, denied or withdrawn, the notices that preceded them, and data sharing with transferee Data Fiduciaries (item 3), give the user access, provide them in machine-readable form on request, and keep them for at least seven years or longer if agreed or required by law (item 4).
  • Operate a website or app as the primary means of access (item 5).
  • Not sub-contract or assign any of its obligations (item 6).
  • Take reasonable security safeguards to prevent personal data breach (item 7).
  • Act in a fiduciary capacity towards the Data Principal (item 8).
  • Avoid conflicts of interest with Data Fiduciaries, including through directors' and managers' holdings or relationships (items 9 and 10).
  • Publish ownership information, including promoters, directors and anyone holding more than two per cent of its shares (item 11).
  • Run audits of its controls, registration conditions and compliance and report outcomes to the Board (item 12).
  • Not transfer control by sale, merger or otherwise without the Board's prior approval (item 13).

Like Data Fiduciaries, Consent Managers must publish how users can make rights requests and their grievance response period, which may not exceed ninety days (Rule 14(1) and 14(3)).

Board oversight

If the Board thinks a Consent Manager is not adhering to its conditions and obligations, it may, after a hearing, direct corrective measures (Rule 4(4)). Where necessary in the interests of Data Principals, it may suspend or cancel registration and give directions, by a reasoned order after a hearing (Rule 4(5)). It may also call for information (Rule 4(6)). Penalties for breaches not listed elsewhere in the Schedule may extend to fifty crore rupees (Schedule, item 7).

What this means for Data Fiduciaries

The Act frames the Consent Manager as an option for the Data Principal (section 6(7)). It does not oblige every Data Fiduciary to onboard onto a Consent Manager platform. But if your users or partners use one, your systems need to cope:

  1. Notice still matters. Consent requests must still be preceded or accompanied by a notice meeting section 5 and Rule 3; the Consent Manager records those notices (Part B, item 3(b)).
  2. Withdrawal must flow back. A withdrawal made through a Consent Manager must stop your processing and your processors' processing within a reasonable time (section 6(6)).
  3. Proof of consent is still yours. In a proceeding, the Data Fiduciary must prove notice and consent (section 6(10)). Keep your own records; see consent logs and recordkeeping.
  4. Data sharing is logged. Expect users to see, through the Consent Manager, which Data Fiduciaries received their data.

For the basics of valid consent, start with consent under DPDP and withdrawal of consent.

Frequently asked questions

What is a Consent Manager under the DPDP Act?

Section 2(g) defines it as a person registered with the Data Protection Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.

Who can register as a Consent Manager?

Under Rule 4 and Part A of the First Schedule, the applicant must be a company incorporated in India with net worth of at least two crore rupees, sound management, adequate capacity, conflict-of-interest provisions in its constitution, and independent certification of its platform against the Board's published standards.

When can Consent Managers register with the Board?

Rule 4 comes into force one year after the Rules were published on 13 November 2025 (Rule 1(3)). Section 6(9), which requires registration, follows the same one-year timeline under the commencement notification.

Must every business use a Consent Manager?

No. Section 6(7) says the Data Principal may give, manage, review or withdraw consent through a Consent Manager. It is an option for individuals, not a mandatory channel for every Data Fiduciary.

Can a Consent Manager see my personal data?

Part B, item 2 of the First Schedule requires a Consent Manager to ensure that data made available or shared through it is not readable by the Consent Manager.

How long must a Consent Manager keep consent records?

At least seven years, or longer if the Data Principal and Consent Manager agree or the law requires it (First Schedule, Part B, item 4(c)).

Practical next step

If you expect users or partners to arrive through a Consent Manager, check that your consent records, notices and withdrawal handling can accept consent signals from an outside platform.

Advertisement