The DPDP framework does not require every organisation to appoint a Consent Manager (“CM”). A CM is an independently certified person registered with the Data Protection Board of India (“Board”) who acts as a single point of contact through an interoperable platform, that a Data Principal may optionally use to give, manage, review and withdraw consent across Data Fiduciaries. Organisations (Data Fiduciaries) get onboarded onto a CM’s platform if they wish to offer this channel. CM registration is only open to companies meeting eligibility criteria under Rule 4 and the First Schedule.
WHAT IS A CONSENT MANAGER
A person registered with the Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw consent through an accessible, transparent, interoperable platform. The CM acts in a fiduciary capacity toward the Data Principal and is accountable to her, not to the Data Fiduciary.
WHO MAY REGISTER AS A CONSENT MANAGER
- Must be a company incorporated in India, with net worth of at least ₹2 crore.
- Sound financial condition and management; adequate capital structure and earning prospects.
- Directors, KMPs and senior management of general reputation for fairness and integrity.
- MoA/AoA must lock in fiduciary/independence obligations, amendable only with Board approval.
- Independent certification that its consent platform meets Board-published data protection and interoperability standards. (First Schedule, Part A)
CORE OBLIGATIONS OF A REGISTERED CONSENT MANAGER
- Enable consent directly, or routed through another onboarded Data Fiduciary holding the data.
- Platform must not render shared personal data readable/accessible to the CM itself.
- Maintain records of consents given/denied/withdrawn, notices, and data-sharing events; retain for at least 7 years and provide the Data Principal machine-readable access on request.
- No sub-contracting of CM obligations; periodic audits reported to the Board.
- Avoid conflicts of interest with onboarded Data Fiduciaries (ownership, directorship, pecuniary ties); publish ownership/promoter disclosures, including details of shareholders holding more than 2%.
- Change of control requires prior Board approval.
IMPLICATIONS FOR DATA FIDUCIARIES (ORGANISATIONS)
- No CM appointment is mandated to process personal data — CM is an additional, optional consent-management rail, alongside the organisation’s own notice-and-consent flow.
- Getting onboarded onto a CM platform can streamline notice/consent capture, withdrawal handling and audit trails, and is useful for sectors with high consent-transaction volumes (BFSI, health, e-commerce, telecom).
- Organisations should map consent workflows so they can interoperate with CM platforms (API/data schema readiness) once the ecosystem operationalises.
- Organisations should not themselves undertake CM-type consent-aggregation functions without Board registration.
COMPLIANCE TIMELINE
- CM registration and obligations are scheduled to come into force on 13th November 2026. The Board will operationalize the registration and related standards/framework requirements.
RECOMMENDED ACTION POINTS
- Assess whether the organisation’s consent-capture systems can interoperate with CM platforms (structured notices, consent IDs, withdrawal APIs).
- Entities considering registering as a CM should begin readiness now: incorporate/capitalise to the ₹2 crore net-worth threshold, and commission the independent platform certification.
- Do not represent any current consent-aggregation offering as a “DPDP Consent Manager” until formally registered with the Board.