miniOrange Logo

Products

Services

Plugins

Pricing

Resources

Company

Consent Managers Under India's DPDP Act 2023

miniOrangeAuthor
11th August, 20269 Min Read

For years, consent has lived inside the systems of individual organizations. Banks maintain their own records, healthcare providers manage their own permissions, and online platforms operate their own preference centers. The DPDP Act introduces a different model: Consent Managers.

Built as independent, registered entities, Consent Managers are intended to give individuals greater control over how consent is granted, reviewed, and withdrawn across multiple organizations. However, the role comes with strict legal and operational requirements around registration, grievance redressal, interoperability, and record retention.

This guide explains how Consent Managers work, how they differ from traditional consent tools, the requirements introduced under the DPDP Rules 2025, and what businesses need to know.

Why Consent Matters Under the DPDP Act, 2023

Under the Digital Personal Data Protection (DPDP) Act, consent is one of the primary grounds on which a Data Fiduciary can process an individual's personal data. Before collecting or using personal information, organizations must clearly explain why the data is needed and how it will be used. More importantly, consent must be specific, informed, unconditional, and capable of being withdrawn.

The Limits of Existing Consent Models

As users repeatedly provide permissions across websites, apps, and services, managing consent often becomes overwhelming. This can lead to consent fatigue, where individuals accept requests without fully understanding how their personal data will be used or which organizations continue to have access to it.

As a result, consent information is scattered across websites, emails, account settings, and mobile apps. Most people struggle to answer questions such as:

  • Where did I share my data?
  • What exactly did I agree to?
  • Can I still withdraw my consent?
  • Which organizations continue to have access to my information?

The challenge is not that consent mechanisms do not exist. The real issue is that every organization manages consent differently, leaving individuals without:

  • a single place to review their permissions;
  • a common process for withdrawing consent;
  • visibility into how their data is being used across organizations.

This lack of standardization is one of the key reasons why the DPDP Act introduced the concept of Consent Managers.

Why the DPDP Act Introduced Consent Managers

The DPDP Act introduces Consent Managers to address this gap. The idea is to create a standardized mechanism through which individuals can manage their consent across multiple Data Fiduciaries instead of navigating separate systems for every service they use.

The concept draws inspiration from earlier initiatives such as the Justice Srikrishna Committee's recommendations, the Account Aggregator framework, and DEPA's consent-based approach to data sharing. Together, these efforts reflect a broader goal: giving individuals greater visibility and control over how their personal data is used.

Why India Needed Consent Managers

The Legal Definition

A Consent Manager is a registered entity recognized under the DPDP Act that enables individuals to give, manage, review, and withdraw consent across multiple organizations. Unlike traditional consent tools that operate within a single company's ecosystem, Consent Managers are designed to function across different Data Fiduciaries through an interoperable framework.

The DPDP Rules 2025 further define the conditions under which an organization can operate as a Consent Manager, including requirements related to registration, governance, technical capability, and independence.

What Services Does a Consent Manager Provide?

A Consent Manager acts as a common access point through which individuals can manage their consent preferences. Through a website or mobile application, users can:

  • grant consent for a specific purpose;
  • review existing consents;
  • update their preferences;
  • withdraw consent;
  • track consent activity across multiple organizations.

Instead of visiting different platforms to manage privacy choices, individuals can access a single service to understand where and why their data is being processed.

The Principles Behind the Model

Two principles define the role of a Consent Manager.

First, a Consent Manager operates in the interest of the individual. It is expected to remain neutral and avoid conflicts of interest while facilitating consent management between Data Principals and Data Fiduciaries.

Second, a Consent Manager functions as a data-blind intermediary. Its role is to facilitate consent and communicate instructions without accessing or using the personal data for its own purposes.

Why People Confuse the Two

Cookie banners, preference centers, and consent management tools have become a standard part of digital experiences. As a result, many businesses assume that the consent solutions they already use qualify as Consent Managers under the DPDP Act.

The confusion is understandable. Both Consent Management Platforms (CMPs) and Consent Managers deal with user consent, privacy preferences, and permission management. However, the overlap largely ends there.

Under Section 2(g) of the DPDP Act, a Consent Manager is a person registered with the Data Protection Board of India who acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw consent. In contrast, cookie banners and preference centers are simply tools that organizations use to manage consent within their own systems.

What Is a Consent Management Platform (CMP)?

A Consent Management Platform (CMP) is typically a tool owned and operated by a business. It helps organizations manage cookie preferences, marketing permissions, and internal consent records within their own websites or applications.

A CMP is designed to support a single organization's compliance requirements and does not require registration under the DPDP framework.

Build a DPDP-Ready Consent Management Framework

Understand consent requirements, strengthen privacy workflows, and prepare your organization for evolving DPDP compliance obligations.

What Makes a Consent Manager Different?

A Consent Manager operates under an entirely different framework. Under Section 2(g) of the DPDP Act and Rule 4 of the DPDP Rules 2025, Consent Managers must register with the Data Protection Board and satisfy the conditions prescribed in Part A of the First Schedule.

Consent Management Platform Consent Manager
Used by one business Works across multiple businesses
Manages cookies and preferences Manages consent across organizations
No registration required Registration required
Controlled by the business Independent entity
Internal tool Cross-platform service

Key takeaway: Using a CMP does not automatically make an organization a Consent Manager.

Consent Managers are designed to provide individuals with a single interface to manage consent across different organizations. Here's how the process works in practice.

Step 1: An Individual Signs Up

The individual creates an account through the Consent Manager's website or mobile application, which becomes the primary point for managing consent preferences.

Step 2: A Business Requests Consent

When a Data Fiduciary needs permission to process personal data for a specific purpose, the request is communicated through the Consent Manager.

Step 3: The Individual Makes a Choice

The user can grant, reject, review, or update consent. Each decision is linked to a specific purpose and recorded accordingly.

Step 4: Consent Instructions Are Shared

Once a decision is made, consent artefacts are generated and securely communicated between the relevant parties.

Step 5: Consent Can Be Withdrawn

Individuals can review existing permissions and withdraw consent through the same platform.

What Happens Behind the Scenes?

Behind the interface, Consent Managers rely on machine-readable records, interoperability standards, audit trails, and secure communication mechanisms to ensure that consent instructions are accurately recorded and shared across participating organizations.

Registration Under Rule 4

Section 2(g) of the DPDP Act defines a Consent Manager as a person registered with the Data Protection Board of India. Rule 4 of the DPDP Rules 2025, together with Part A of the First Schedule, sets out the conditions that organizations must satisfy before they can operate as Consent Managers.

Registration is not automatic. Organizations must demonstrate that they have the financial, technical, and operational capacity to manage consent across multiple Data Fiduciaries.

Financial and Technical Requirements

To qualify, an applicant must be a company incorporated in India and maintain a minimum net worth of ₹2 crore. The organization must also prove that it has the technology, infrastructure, and operational systems required to run an interoperable consent platform.

In addition, the platform must be independently certified to ensure that it complies with the technical standards prescribed by the Data Protection Board.

Governance and Independence Requirements

The rules place significant emphasis on governance. Applicants must have sound financial controls, conflict-of-interest policies, and a management team that satisfies the fit-and-proper criteria.

A Consent Manager is also expected to act in a fiduciary capacity, which means that it must prioritize the interests of individuals and maintain independence from the organizations whose consent it manages.

Managing Consent Across Organizations

Registration is only the starting point. Part B of the First Schedule requires Consent Managers to provide individuals with a platform where they can give, manage, review, and withdraw consent across participating Data Fiduciaries.

The website or mobile application operated by the Consent Manager must act as the primary interface through which users access and manage their consent preferences.

Record-Keeping and Transparency

Consent Managers are required to maintain records relating to consents, notices, and data-sharing activities for at least seven years. These records help establish accountability and provide evidence of how consent was granted or withdrawn.

The rules also require Consent Managers to publish information about their promoters, directors, senior management, and major shareholders.

Security, Audits, and Interoperability

Part B requires Consent Managers to implement reasonable security safeguards and maintain interoperable systems that can securely communicate consent instructions across organizations.

They must also conduct regular audits of their controls and report the outcomes to the Data Protection Board of India.

Acting in the Interest of Individuals

One of the most important obligations is the requirement to act in a fiduciary capacity. Consent Managers must avoid conflicts of interest and cannot compromise their independence for commercial reasons.

The rules also make it clear that core responsibilities cannot be delegated to another organization, ensuring that accountability remains with the Consent Manager itself.

Prepare Your Organization for DPDP Compliance

Assess your consent practices, strengthen privacy governance, and build a roadmap for DPDP compliance with guidance from miniOrange experts.

13 November 2025: DPDP Rules Are Notified

The DPDP Rules 2025 formally introduced the framework governing Consent Managers, including Rule 4 and the obligations listed in the First Schedule.

This marked the beginning of the legal framework, although some provisions were scheduled to take effect later.

13 November 2026: Consent Manager Requirements Come Into Force

Rule 4 and the provisions governing Consent Managers are scheduled to come into effect on 13 November 2026.

From this date, organizations seeking to operate as Consent Managers will be expected to comply with the registration, governance, and operational requirements laid down in the rules.

13 May 2027: Broader Compliance Deadlines

The broader DPDP framework, including requirements related to consent, user rights, security safeguards, and breach reporting, is expected to become enforceable in phases.

Organizations should use this transition period to review their internal processes and strengthen their consent management practices.

Is a Consent Manager Mandatory?

No. The DPDP Rules 2025 do not currently require every Data Fiduciary to use a registered Consent Manager. Organizations can continue collecting consent directly as long as they comply with the notice and consent requirements of the DPDP Act.

Registration is only required for entities that want to operate as independent Consent Managers across multiple organizations.

Should Your Organization Become a Consent Manager?

For most organizations, the immediate priority is compliance rather than registration. Becoming a Consent Manager involves significant responsibilities related to governance, technology, security, and record management.

Organizations considering this path should begin evaluating whether they can satisfy the requirements laid down in Rule 4 and Part A of the First Schedule.

Preparing for the Consent Management Framework

The first registered Consent Managers are likely to influence how consent is managed across industries. Understanding the framework today will help businesses make informed decisions about their role in India's evolving privacy ecosystem.

Consent Managers represent a new approach to consent management under India's data protection framework. While organizations are not currently required to operate through a Consent Manager, understanding how the model works is essential as the regulatory landscape continues to evolve.

For most businesses, the immediate priority is not becoming a Consent Manager. Instead, the focus should be on strengthening consent practices, maintaining reliable records, simplifying consent withdrawal, and preparing systems for future interoperability requirements.

Organizations that begin preparing early will be better positioned to adapt as the consent management ecosystem takes shape.

Frequently Asked Questions

What is a Consent Manager under the DPDP Act?

A Consent Manager is an independent entity registered under the DPDP framework that enables individuals to give, manage, review, and withdraw consent across multiple organizations through a single platform.

Is a Consent Manager the same as a cookie banner or consent management platform?

No. A consent management platform is typically used by a single organization to manage cookies and user preferences within its own systems. A Consent Manager operates independently and helps individuals manage consent across multiple organizations.

Does every company need to register as a Consent Manager?

No. The DPDP Rules 2025 do not require every Data Fiduciary to register as a Consent Manager. Organizations can continue collecting consent directly as long as they comply with the Act's notice and consent requirements.

What are the requirements for becoming a Consent Manager?

To register as a Consent Manager, an organization must satisfy the conditions laid out in Rule 4 and the First Schedule of the DPDP Rules 2025, including requirements related to incorporation, net worth, technical capability, governance, and conflict management.

How long must Consent Managers retain consent records?

Consent Managers are required to maintain records of consents, notices, and data-sharing activities for at least seven years in accordance with the DPDP Rules 2025.

When do the Consent Manager requirements come into effect?

The DPDP Rules 2025 were notified on 13 November 2025, while the provisions governing Consent Managers under Rule 4 are scheduled to come into effect on 13 November 2026.

Leave a Comment