Get a free consultation from our experts

What is the Role of a Consent Manager Under the DPDP Act?

blog-banner
On this page

Table of Contents

    Every time you tap “Accept All” on a cookie banner or a sign-up screen, you hand over a small piece of control over your personal data — usually without knowing exactly what you agreed to, and often with no easy way to take it back later.

    India’s Digital Personal Data Protection Act, 2023 (DPDP Act) was written to close exactly this gap. And one of its most distinctive ideas — something most global privacy laws, including the GDPR, don’t have an equivalent for — is the Consent Manager.

    This guide breaks down, in plain language, what a Consent Manager actually is, why the law created this role, how it functions in practice, who needs to register as one, and what it means for both individuals (Data Principals) and businesses (Data Fiduciaries) as the framework rolls out through 2026 and 2027.

    Quick Summary

    • A Consent Manager is a registered intermediary — approved by the Data Protection Board of India (DPB) — that gives individuals a single place to give, review, manage, and withdraw consent for how their personal data is used.
    • It is defined under Section 2(g) of the DPDP Act and made operational through Section 6(7)–(9).
    • Consent Managers must be companies incorporated in India, with a minimum net worth of ₹2 crore, registered under Rule 4 of the DPDP Rules, 2025.
    • The Consent Manager registration framework becomes operative on 13–14 November 2026, one year after the DPDP Rules were notified.
    • The concept borrows heavily from the Account Aggregator model used in India’s financial sector and from NITI Aayog’s Data Empowerment and Protection Architecture (DEPA).

    What Exactly Is a Consent Manager?

    Under Section 2(g) of the DPDP Act, a Consent Manager is a person — in practice, a registered company — that acts as a single point of contact enabling a Data Principal (the individual whose data is being collected) to give, manage, review, or withdraw consent through a platform that is:

    • Accessible — easy for an ordinary person to use
    • Transparent — clearly showing what has been agreed to and why
    • Interoperable — able to work across multiple apps, websites, and organizations, rather than being locked to one platform

    In simple terms, instead of managing consent separately with your bank, your hospital, your food delivery app, and every e-commerce site you use, a Consent Manager gives you one dashboard where all of those permissions live — and where you can switch any of them off just as easily as you switched them on.

    Importantly, a Consent Manager does not work for the business collecting your data. Under Section 6(8), it is legally accountable to the Data Principal and must act on their behalf. That distinction — acting for the individual, not the company — is what separates a Consent Manager from an ordinary in-house cookie banner or preference center.

    Why the DPDP Act Created This Role

    To understand why Consent Managers exist, it helps to look at how consent was typically handled before the DPDP Act.

    The problem before DPDP

    • Every website and app ran its own, disconnected consent system
    • Consent notices were often long, vague, or bundled together, so people clicked “Agree” without understanding the real scope of what they’d allowed
    • There was no unified way to see everything you had consented to across the apps and services you used
    • Withdrawing consent was, in most cases, either impossible or buried several menus deep

    The result was consent in name only — a formality rather than a real choice.

    What the DPDP Act requires instead

    The Act raises the bar for what counts as valid consent. Under the law, consent must be:

    • Free and not bundled with unrelated permissions
    • Specific to the stated purpose
    • Informed, with a clear notice explaining what data is collected and why
    • Unconditional, and
    • As easy to withdraw as it was to give

    That last requirement — symmetry between giving and withdrawing consent — is the hardest one for most organizations to deliver on their own, especially at scale and across multiple platforms. The Consent Manager framework exists to make that requirement practically achievable, by giving individuals a neutral, standardized layer through which to exercise it.

    Role of a Consent Manager Under the DPDP Act

    The Legal Backbone: Key Provisions to Know

    The Consent Manager framework rests on a small number of provisions that work together:

    Provision What it establishes
    Section 2(g) Defines what a Consent Manager is
    Section 6(7) Gives Data Principals the right to route consent through a Consent Manager
    Section 6(8) Makes the Consent Manager accountable to the Data Principal, not the business
    Section 6(9) Requires every Consent Manager to be registered with the Data Protection Board, on prescribed technical, operational, and financial conditions
    Section 13 Places a grievance redressal obligation on both Data Fiduciaries and Consent Managers
    Rule 4 & First Schedule, Part A (DPDP Rules, 2025) Sets out the detailed registration criteria and ongoing obligations

    Operating as a Consent Manager without registration, once the framework takes effect, is a breach of Section 6(9) and exposes the entity to penalties under the Act’s schedule.

    How a Consent Manager Works, Step by Step

    1. You interact with an app or website — signing up, logging in, or using a feature that needs your data.
    2. You receive a clear consent request, stating what data is needed and for what purpose.
    3. You approve or decline through the Consent Manager’s interface, rather than through the business’s own bespoke pop-up.
    4. The Consent Manager records the decision as a timestamped, auditable entry — along with the privacy notice that accompanied it.
    5. You can revisit your dashboard anytime to review every consent you’ve given, and withdraw any of them individually.

    Behind this simple flow sits a fair amount of technical machinery. The DPDP Rules require Consent Managers to run an interoperable platform that:

    • Relays consent requests from Data Fiduciaries to Data Principals and back
    • Maintains records of consents and the notices that preceded them
    • Supports data portability, letting a Data Principal move their data from one Data Fiduciary to another based on their own consent
    • Uses a “data-blind” transport layer — meaning the Consent Manager routes the data package without being able to read its contents, so it never becomes a silent custodian of your personal information

    That last point matters a lot. A Consent Manager is meant to be a traffic controller for permissions, not a data warehouse.

    Who Can Become a Consent Manager? Registration Requirements

    Registration is deliberately demanding, because a Consent Manager sits in a position of trust across an entire ecosystem of Data Fiduciaries. Under Rule 4 and Part A of the First Schedule of the DPDP Rules, 2025, an applicant must:

    • Be a company incorporated in India
    • Maintain a minimum net worth of ₹2 crore, adjusted periodically for inflation
    • Demonstrate adequate technical, operational, and financial capacity to run the platform reliably
    • Show a sound financial track record and a management team with a reputation for fairness and integrity
    • Build board-level governance and conflict-of-interest safeguards into its constitutional documents
    • Commit to ongoing transparency obligations — publicly disclosing information about its promoters, directors, key managerial personnel, and any shareholders holding more than 2% of the company

    Applications are submitted to the Data Protection Board of India, which can inquire into whether the applicant genuinely meets these conditions before granting registration. Registration isn’t a one-time formality — Consent Managers remain subject to ongoing obligations, including maintaining independent certification of their platform against prescribed technical standards and providing accessible grievance redressal to Data Principals.

    The November 2026 milestone

    The DPDP Rules were notified on 13 November 2025, and they roll out in phases. The Consent Manager registration framework becomes operative around 13–14 November 2026 — a year after notification. From that date, any entity operating as a Consent Manager without registration will be in violation of Section 6(9).

    A few practical points worth flagging for businesses tracking this timeline:

    • The Data Protection Board itself has been operational on paper since November 2025, though its full leadership appointments were still being finalized through much of 2026 — a gap that some legal commentators have flagged as a real-world friction point for the registration process.
    • Full enforcement of the Act’s substantive obligations — consent, notice, security safeguards, and Data Principal rights — is scheduled for 13 May 2027.
    • Because this is a live, phased rollout, businesses evaluating Consent Manager integration should check the Ministry of Electronics and Information Technology (MeitY) and Data Protection Board websites for the latest notifications rather than relying on any single date as fixed indefinitely.

    Do Businesses Actually Need a Consent Manager?

    Not every organization needs to become — or even integrate with — a Consent Manager. The Act doesn’t make routing consent through one mandatory for every transaction. But it becomes genuinely useful, and increasingly expected, when a business:

    • Collects and processes personal data at scale, across many users and touchpoints
    • Needs audit-proof records proving that valid consent was obtained, for regulatory or contractual reasons
    • Operates across multiple systems, apps, or third-party vendors, where consent can otherwise fragment and become impossible to track consistently

    For a small business collecting minimal data through a single channel, manual consent management may remain workable for now. For anyone operating in healthcare, BFSI, e-commerce, or any data-intensive sector, integrating with a registered Consent Manager is quickly becoming a practical necessity rather than a nice-to-have — particularly as enterprise customers begin running DPDP-readiness checks into their vendor due diligence.

    Consent Manager vs. a Regular Consent Management Platform (CMP)

    It’s easy to confuse a legally-recognized Consent Manager with an ordinary cookie-consent tool or CMP that businesses install on their own websites. They are not the same thing.

    Feature Consent Manager Basic CMP / Cookie Banner
    Legal status Registered with the Data Protection Board under the DPDP Act No statutory recognition
    Who it acts for The Data Principal (individual) The business that installed it
    Scope Cross-platform — one dashboard across multiple apps and organizations Limited to a single website or app
    Withdrawal Centralized and standardized Often inconsistent, buried in settings
    Data access “Data-blind” — routes consent and data without reading contents Typically integrated into the host’s own systems

    A CMP is a tool a business owns to manage its own consent workflows. A Consent Manager is a regulated intermediary that exists independently of any single business, on behalf of the individual.

    Why This Matters — For Individuals and for Businesses

    For Data Principals (individuals):

    • One dashboard to see everything you’ve agreed to, instead of hunting through dozens of app settings
    • A genuinely easy way to withdraw consent, matching the ease with which it was given
    • Greater transparency about what data is being shared, with whom, and why

    For Data Fiduciaries (businesses):

    • A structured, defensible way to demonstrate that consent was validly obtained
    • Reduced compliance risk as enforcement of the DPDP Act ramps up through 2026–27
    • A cleaner audit trail across vendors and systems, instead of scattered, inconsistent consent logs

    Consider a simple example: someone uses a banking app, a shopping app, and a health app. Without a Consent Manager, they manage three separate sets of permissions in three separate places. With one in place, they see all three in a single dashboard, understand exactly what each app can access, and can revoke any of them in a few clicks — without ever leaving that one interface.

    Open Questions as the Framework Rolls Out

    No framework this new arrives without friction. A few things worth watching as 2026 progresses:

    • Regulator readiness — the Data Protection Board’s full leadership needs to be in place for registration to run smoothly at the scale the Act anticipates.
    • Overlap with existing systems — India’s RBI-regulated Account Aggregator framework already performs a similar consent-brokering function for financial data, and how the two regimes will interact hasn’t been fully settled.
    • Vendor readiness — Data Fiduciaries will need to make their own systems interoperable with whichever registered Consent Managers their customers choose to use, which is a real integration project, not a checkbox.

    None of this changes the underlying direction: consent in India is moving from a one-off checkbox to something that has to be tracked, proven, and kept easy to reverse on an ongoing basis.

    Conclusion

    The Consent Manager is one of the DPDP Act’s most practical ideas: it turns consent from a one-time, easily forgotten checkbox into something individuals can actually see, track, and control over time. For businesses, it offers a path to demonstrable, audit-ready compliance instead of scattered consent logs across a dozen systems and vendors.

    As the registration framework comes into effect through late 2026 and full enforcement approaches in May 2027, both individuals and organizations in India have good reason to understand exactly how this piece of the DPDP Act works — because it’s likely to become one of the most visible parts of the law in everyday digital life.

    This article is for general informational purposes and reflects the DPDP Act, 2023 and DPDP Rules, 2025 as understood as of August 2026. For specific compliance decisions, consult the official text of the Act and Rules published by the Ministry of Electronics and Information Technology, or a qualified legal professional.

    Frequently Asked Questions

    Is a Consent Manager the same as a Data Fiduciary?

    No. A Data Fiduciary is the organization that determines the purpose and means of processing personal data — essentially, the business collecting your data. A Consent Manager is a separate, independent intermediary that acts on the individual’s behalf, not the business’s.

    Do individuals have to pay to use a Consent Manager?

    The Act itself doesn’t set a fee structure for Data Principals; commercial models for Consent Managers are still developing as the ecosystem matures.

    Can a business build its own Consent Manager?

    Yes, in principle — but it would need to register separately with the Data Protection Board and meet the same incorporation, net-worth, and governance conditions as any other applicant, and it would need to act independently on behalf of Data Principals rather than only serving its own consent needs.

    What happens if a business ignores the Consent Manager framework entirely?

    Using a Consent Manager isn’t universally mandatory for every Data Fiduciary. But businesses still need valid, auditable consent under the Act’s general provisions regardless of whether that consent is routed through a Consent Manager — and as enforcement ramps up toward May 2027, having a structured, defensible consent record becomes increasingly important either way.

    Read More Guides

    blog-img rounded
    Data Privacy & Compliance
    DPDP Consent Management Integration Across Websites, Apps, CRM and ERP

    DPDP Consent Management Integration Across Websites, Apps, CRM and ERP For enterprises, implementing DPDP compliance rarely means...

    Sumeshwar 25 August 2026

    blog-img rounded
    Data Privacy & Compliance
    DPDP Compliance Implementation Cost and Timeline

    India’s Digital Personal Data Protection (DPDP) Act has moved data privacy from a legal consideration to a...

    Sumeshwar 25 August 2026

    blog-img rounded
    Data Privacy & Compliance
    How to Make Existing Web and Enterprise Applications DPDP-Ready: A Practical Implementation Roadmap for 2026

    Many organisations are approaching the Digital Personal Data Protection (DPDP) Act as a legal or documentation exercise....

    Ashwini Kumar 24 August 2026