Consent Managers – What Organisations Need to Know

The DPDP framework does not require every organisation to appoint a Consent Manager (“CM”). A CM is an independently certified person registered with the Data Protection Board of India (“Board”) who acts as a single point of contact through an interoperable platform, that a Data Principal may optionally use to give, manage, review and withdraw consent across Data Fiduciaries. Organisations (Data Fiduciaries) get onboarded onto a CM’s platform if they wish to offer this channel. CM registration is only open to companies meeting eligibility criteria under Rule 4 and the First Schedule.

WHAT IS A CONSENT MANAGER

A person registered with the Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw consent through an accessible, transparent, interoperable platform. The CM acts in a fiduciary capacity toward the Data Principal and is accountable to her, not to the Data Fiduciary.

WHO MAY REGISTER AS A CONSENT MANAGER

  • Must be a company incorporated in India, with net worth of at least ₹2 crore.
  • Sound financial condition and management; adequate capital structure and earning prospects.
  • Directors, KMPs and senior management of general reputation for fairness and integrity.
  • MoA/AoA must lock in fiduciary/independence obligations, amendable only with Board approval.
  • Independent certification that its consent platform meets Board-published data protection and interoperability standards. (First Schedule, Part A)

CORE OBLIGATIONS OF A REGISTERED CONSENT MANAGER

  • Enable consent directly, or routed through another onboarded Data Fiduciary holding the data.
  • Platform must not render shared personal data readable/accessible to the CM itself.
  • Maintain records of consents given/denied/withdrawn, notices, and data-sharing events; retain for at least 7 years and provide the Data Principal machine-readable access on request.
  • No sub-contracting of CM obligations; periodic audits reported to the Board.
  • Avoid conflicts of interest with onboarded Data Fiduciaries (ownership, directorship, pecuniary ties); publish ownership/promoter disclosures, including details of shareholders holding more than 2%.
  • Change of control requires prior Board approval.

IMPLICATIONS FOR DATA FIDUCIARIES (ORGANISATIONS)

  • No CM appointment is mandated to process personal data — CM is an additional, optional consent-management rail, alongside the organisation’s own notice-and-consent flow.
  • Getting onboarded onto a CM platform can streamline notice/consent capture, withdrawal handling and audit trails, and is useful for sectors with high consent-transaction volumes (BFSI, health, e-commerce, telecom).
  • Organisations should map consent workflows so they can interoperate with CM platforms (API/data schema readiness) once the ecosystem operationalises.
  • Organisations should not themselves undertake CM-type consent-aggregation functions without Board registration.

COMPLIANCE TIMELINE

  • CM registration and obligations are scheduled to come into force on 13th November 2026. The Board will operationalize the registration and related standards/framework requirements.

RECOMMENDED ACTION POINTS

  • Assess whether the organisation’s consent-capture systems can interoperate with CM platforms (structured notices, consent IDs, withdrawal APIs).
  • Entities considering registering as a CM should begin readiness now: incorporate/capitalise to the ₹2 crore net-worth threshold, and commission the independent platform certification.
  • Do not represent any current consent-aggregation offering as a “DPDP Consent Manager” until formally registered with the Board.

Reach Us

Disclaimer

As per the rules of the Bar Council of India, we are not permitted to solicit work or advertise for our services. The user acknowledges the following:

  • there has been no advertisement, personal communication, solicitation, invitation or inducement of any kind whatsoever from us or any of our members to solicit any work through this website;
  • the user wishes to gain more information about us for his/her own information and use;
  • the information about us is provided to the user only on his/her specific request and any information obtained or material downloaded from this website is completely at the user’s volition and any transmission, receipt or use of this site would not create any lawyer-client relationship.
I AGREE