Quick answer: A Consent Manager is a specific, separately regulated entity under the Digital Personal Data Protection Act, 2023 – a company registered with the Data Protection Board of India that gives individuals a single interoperable interface to give, manage, review and withdraw consent across multiple organisations at once. It is not a compliance step every business must complete, and it is not the same thing as having a compliant consent management process.
Registration as a Consent Manager applies to a narrow class of infrastructure providers meeting strict eligibility conditions – an India-incorporated company with a minimum net worth of ₹2 crore, among other requirements – and the registration framework itself (Rule 4 of the DPDP Rules, 2025) only comes into force on 13 November 2026. The overwhelming majority of Indian businesses are Data Fiduciaries, not Consent Managers, and what they need is their own DPDP-compliant consent management capability – not registration.
That distinction is where most confusion about this topic comes from, and it’s the reason this guide exists: to separate the statutory Consent Manager role from the everyday obligation every business already has to manage consent properly.
What Is a Consent Manager Under the DPDP Act?
Section 2(g) of the DPDP Act defines a Consent Manager as a person registered with the Data Protection Board who acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw their consent through an accessible, transparent, and interoperable platform. Conceptually, it borrows from a model India has already tested elsewhere – the Account Aggregator framework in financial services, built on NITI Aayog’s Data Empowerment and Protection Architecture (DEPA).
The idea addresses a real, specific problem: today, an individual’s consent is scattered across dozens of separate apps, websites, and services, each with its own settings page, its own withdrawal process, and no shared view of what they’ve agreed to where. A registered Consent Manager is meant to be a neutral, interoperable layer sitting between individuals and the organisations processing their data, so a Data Principal can see and control their consents in one place rather than hunting through twenty different privacy dashboards.
It is important to be precise about what this is: a Consent Manager is infrastructure that Data Principals may optionally choose to use. It is not a mandatory intermediary that every business must integrate with, and it is not simply another term for “having a consent management process.”
The Legal Basis: Sections 6(7)–6(9) and Rule 4
The Consent Manager concept originates in Section 6 of the DPDP Act, which governs consent as a ground for processing personal data. Section 6(9) specifically provides that a Data Principal may give, manage, review or withdraw consent through a Consent Manager. Sections 6(7) and 6(8) set out the Consent Manager’s accountability to the Data Principal and its registration requirement with the Board.
The operational detail – eligibility conditions, application process, and ongoing obligations – comes from Rule 4 of the DPDP Rules, 2025, read with the First Schedule to the Rules. The Rules were notified in the Gazette on 13–14 November 2025, but not every provision took effect immediately. Rule 4, specifically, is scheduled to come into force on 13 November 2026 – a twelve-month runway from notification, giving prospective Consent Managers time to meet the eligibility bar and giving the Data Protection Board time to build out its registration and supervisory processes. As of this writing, the Consent Manager registration framework is approaching that commencement date but is not yet operational.
What a Consent Manager Actually Does
Once the framework is live, a registered Consent Manager’s core functions are:
- Providing a single interface through which a Data Principal can give consent to multiple Data Fiduciaries.
- Letting individuals review what consents they’ve given, to whom, and for what purpose, in one place.
- Enabling instant withdrawal of any consent, with the same ease with which it was given.
- Maintaining records of consent status on behalf of the Data Principal – the Consent Manager keeps the individual’s consent trail, distinct from the Data Fiduciary’s own compliance records.
- Operating on an interoperable basis, meaning it must work across Data Fiduciaries rather than locking individuals into a single organisation’s ecosystem.
A Consent Manager is explicitly barred from acting as a Data Fiduciary or Data Processor for the same Data Principal whose consent it is managing – a structural conflict-of-interest safeguard that keeps the intermediary neutral rather than incentivised to steer consent toward its own commercial interests.
Consent Manager vs Data Fiduciary vs Data Processor

This is the single most misunderstood distinction in this entire area, and it’s worth being explicit about it in a straightforward comparison:
| Consent Manager | Data Fiduciary | Data Processor | |
|---|---|---|---|
| What it is | A registered, neutral intermediary that lets individuals manage consent across multiple organisations | Any organisation that decides why and how personal data is processed | An entity processing data on a Data Fiduciary’s behalf, under contract |
| Who this applies to | A narrow class of specialised infrastructure providers | Virtually every business processing personal data connected to India | Vendors, cloud providers, and service providers acting under instruction |
| Registration required? | Yes – with the Data Protection Board, once Rule 4 is in force | No separate registration for the baseline role | No separate registration for the baseline role |
| Eligibility bar | India-incorporated company, ₹2 crore minimum net worth, governance and technical infrastructure requirements | None – applies regardless of size | None – applies regardless of size |
| What it needs to do about consent | Operate the interoperable consent platform itself | Collect valid consent through its own notice and consent process (or rely on a specific legitimate use) | Process data only as instructed by the Data Fiduciary |
If your organisation collects consent from its own users, for its own products or services, you are a Data Fiduciary. That’s true whether you’re a two-person startup or a listed enterprise. Registering as a Consent Manager is not something you need to do to be compliant – it’s a separate, optional business model that a narrow set of specialised entities may choose to pursue.
Do You Need to Register as a Consent Manager?

For nearly every reader of this guide, the answer is no. Registration is relevant only if your organisation specifically intends to operate as a cross-platform consent intermediary serving multiple, unrelated Data Fiduciaries – not if you simply want to manage consent for your own website, app, or customer base.
If you are evaluating whether registration applies to you, the eligibility conditions under the First Schedule to the DPDP Rules include:
- Incorporation in India as a company under the Companies Act, 2013 – this excludes sole proprietorships, and excludes foreign entities from registering directly (a global consent-platform provider would need an independently qualifying Indian subsidiary).
- Minimum net worth of ₹2 crore, evidenced by audited financials.
- Demonstrated technical, operational and financial capacity to run consent infrastructure securely and reliably – including expectations around secure infrastructure, encryption, and audit-ready logging.
- A governance framework – a Board of Directors with clear conflict-of-interest policies.
- No dual role – the entity cannot simultaneously act as a Data Fiduciary or Data Processor for the same Data Principal whose consent it manages.
Even organisations that clear this bar should think carefully before pursuing registration: it’s a regulated business line with ongoing supervisory obligations to the Data Protection Board, not a side feature to bolt onto an existing product.
What Ordinary Businesses Actually Need Instead
If registration doesn’t apply to you – and for most readers, it doesn’t – your actual obligation is simpler to state and, frankly, more urgent: build a compliant consent management process, not a registered consent management entity. That means, at minimum:
- A standalone, itemised privacy notice under Rule 3 – not a notice buried in general terms and conditions – describing exactly what personal data is collected and for what specific purpose, available in English or any of the 22 languages listed in the Eighth Schedule to the Constitution.
- Free, specific, informed, and unambiguous consent – no pre-ticked boxes, no bundled permissions, no consent inferred from inaction.
- Consent that’s as easy to withdraw as it was to give, with a functioning mechanism to act on that withdrawal.
- A retrievable, timestamped consent record for every individual and purpose – because the burden of proving valid consent was obtained sits with your organisation, not with the individual.
- A way for individuals to exercise their rights – access, correction, erasure – and to lodge a complaint, without needing a registered Consent Manager as an intermediary.
This is, in practice, exactly what “consent management” means for the vast majority of businesses: your own compliant system for your own users, not participation in the separate Consent Manager ecosystem.
Registration Process and Timeline
For the small number of organisations that do intend to pursue registration once Rule 4 is in force, the process follows four stages under the Rules:
- Eligibility – confirming the applicant meets the First Schedule conditions (incorporation, net worth, governance, technical capacity).
- Application – furnishing the particulars, information, and documents the Data Protection Board requires.
- Board inquiry – the Board conducts such inquiry as it considers fit; this is a substantive review, not a formality.
- Registration decision – on being satisfied, the Board registers the applicant and publishes its particulars; if not satisfied, it rejects the application with reasons.
Registration is followed by ongoing supervision – the Board’s information-gathering powers extend beyond the initial registration decision into continuous oversight of registered Consent Managers.
Ongoing Obligations Once Registered
Registration is not a one-time formality. A registered Consent Manager operates under continuous supervision, expected to maintain the technical, financial, and governance standards it registered under, keep its platform genuinely interoperable across Data Fiduciaries, avoid any dual role that would create a conflict of interest, and remain answerable to the Data Protection Board’s ongoing information requests. This is closer in character to a regulated financial or infrastructure business than a simple software feature.
What This Means for Different Roles in Your Organisation
CEO / Founder – The practical takeaway is reassurance, not a new project: you almost certainly don’t need to register as a Consent Manager. What you do need is confidence that your existing consent collection is defensible.
Chief Compliance Officer / Head of Compliance / Compliance Manager – This is the function that should own the distinction described in this guide, and make sure it doesn’t get lost when a vendor pitches “Consent Manager integration” as a compliance requirement it isn’t.
Company Secretary / Admin & Legal Manager – If a third-party vendor claims to be a registered Consent Manager, verify that claim against the Data Protection Board’s published register once the framework is live – a claim of registration is not the same as actual registration, and contracts referencing “Consent Manager” services should be reviewed for what they’re actually providing.
CFO / Chartered Accountants – Registering as a Consent Manager carries real capital and governance costs (₹2 crore minimum net worth, dedicated governance structure) that only make sense as a deliberate business decision, not a compliance reflex.
CHRO / Plant HR Head – Employee consent, where required, is managed the same way customer consent is – through your organisation’s own compliant process, not through a registered Consent Manager, which has no particular relevance to internal HR data flows.
Common Mistakes and Misconceptions
“We need to integrate with a Consent Manager to be DPDP-compliant.” No. Compliant consent collection through your own notice-and-consent process satisfies your obligations as a Data Fiduciary. Consent Managers are an optional channel Data Principals may choose to route consent through once the framework is operational – not a mandatory integration point for every business.
“Any vendor offering a ‘Consent Manager’ product is a registered Consent Manager.” Be careful with terminology here. Many software vendors – including consent management platforms built for Data Fiduciaries – use “consent manager” as a descriptive product name. That is a different thing entirely from being a statutory Consent Manager registered with the Data Protection Board. Ask directly whether a vendor is registered under Rule 4, or whether their product is a consent management tool for your own use as a Data Fiduciary.
“The Consent Manager framework is already fully operational.” Rule 4 comes into force on 13 November 2026. Until then, there is no live registration process to complete, and no registered Consent Managers operating under the Act.
“Small businesses are exempt from consent obligations because they’re not Consent Managers.” These are two entirely separate questions. Every Data Fiduciary – regardless of size – has its own consent and notice obligations under Sections 5 and 6 of the Act, independent of whether the Consent Manager ecosystem exists or applies to them at all.
Building Compliant Consent Management Into Your Program
For the Data Fiduciary majority reading this, the practical build-out looks like this:
- Inventory every point where you collect consent – signup forms, checkout flows, marketing opt-ins, cookie banners, HR onboarding.
- Rewrite notices to be standalone and itemised, matching Rule 3’s requirements rather than a general privacy policy.
- Implement a retrievable consent log tied to the individual, the purpose, and the specific notice version they saw.
- Build a functioning withdrawal mechanism that’s as easy to use as the original consent flow, and that actually stops the relevant processing once triggered.
- Keep the whole system current as you launch new products or data uses – a consent architecture built for one product doesn’t automatically cover the next one.
This is precisely the kind of ongoing, detail-heavy operational work that degrades quickly when tracked manually across spreadsheets, form tools, and CRM exports that don’t talk to each other. RuleExpert’s Consent Management capability handles this as a structured lifecycle – consent collection, purpose management, records management, withdrawal, consent history, and audit trail – built for Data Fiduciaries who need to prove compliant consent on demand, not for organisations pursuing statutory Consent Manager registration.
[Book a demo with RuleExpert →]
Best Practices
- Separate the two conversations explicitly in any internal or vendor discussion: “consent management” (something every Data Fiduciary needs) and “Consent Manager registration” (a narrow, optional path for specialised infrastructure providers).
- Verify vendor claims. If a vendor markets itself as a Consent Manager, confirm whether they mean the statutory registered role or a software product using the term descriptively.
- Don’t wait for the Consent Manager ecosystem to build your own consent process. Your Section 5 and 6 obligations as a Data Fiduciary exist today, independent of Rule 4’s commencement date.
- Revisit your consent architecture at every product launch, not once a year – new data collection points need their own notice and consent flow, not retrofit consent under an old blanket agreement.
- Keep consent records retrievable, not just collected. The ability to produce a specific record on demand is what actually satisfies the burden of proof under the Act.
Frequently Asked Questions
1. What is a Consent Manager under the DPDP Act? A Consent Manager is a company registered with the Data Protection Board of India that provides Data Principals with a single, interoperable interface to give, manage, review, and withdraw consent across multiple Data Fiduciaries.
2. Is a Consent Manager mandatory for businesses under DPDP? No. Registering as a Consent Manager applies only to organisations that want to operate as cross-platform consent intermediaries. Ordinary businesses (Data Fiduciaries) need their own compliant consent management process, not registration as a Consent Manager.
3. What is the difference between a Consent Manager and a consent management platform? A Consent Manager is a statutory, registered entity under Rule 4 of the DPDP Rules. A consent management platform is software that helps a Data Fiduciary manage its own consent lifecycle – collection, tracking, withdrawal – for its own users. Many vendors use “consent manager” as a product name for the latter, which can cause confusion with the former.
4. When does the Consent Manager registration framework come into force? Rule 4 of the DPDP Rules, 2025 is scheduled to come into force on 13 November 2026, twelve months after the Rules were notified in November 2025.
5. What are the eligibility requirements to register as a Consent Manager? Under the First Schedule to the DPDP Rules, an applicant must be a company incorporated in India with a minimum net worth of ₹2 crore, demonstrated technical and operational capacity, a governance framework with conflict-of-interest policies, and no dual role as a Data Fiduciary or Data Processor for the same Data Principal.
6. Can a foreign company register as a Consent Manager in India? Not directly. The eligibility criteria require incorporation in India, so a foreign consent-platform provider would need an Indian subsidiary that independently satisfies the net worth and technical capability requirements.
7. Do I need consent from a Consent Manager to collect data from my customers? No. As a Data Fiduciary, you collect consent directly from your Data Principals through your own compliant notice and consent process. A Consent Manager is an optional channel individuals may choose to route their consent through – it is not a required approval step for your own data collection.
8. What happens if a vendor falsely claims to be a registered Consent Manager? Registration status can be verified against the Data Protection Board’s published register once the framework is operational. Contracting with a vendor based on an unverified registration claim is a due-diligence gap worth closing before signing.
9. How is a Consent Manager different from a Data Protection Officer? A Data Protection Officer is an internal role a Significant Data Fiduciary appoints to oversee its own compliance. A Consent Manager is an external, registered third-party entity operating independently of any single Data Fiduciary. The two serve entirely different functions and neither substitutes for the other.
10. What should my business actually do about consent management right now? Build and maintain a compliant, in-house consent management process – standalone notices, specific and informed consent, easy withdrawal, and retrievable records – regardless of whether the Consent Manager ecosystem is relevant to you. That obligation applies today; Consent Manager registration is a separate question most businesses will never need to answer.
Conclusion
The Consent Manager is one of the more genuinely novel ideas in the DPDP Act, but it’s also one of the most frequently misrepresented – including in content that conflates “you need a Consent Manager” with “you need to manage consent properly.” They are not the same requirement. Registration as a Consent Manager is a narrow, capital-intensive, optional business line that most organisations will never pursue and don’t need to. Building a compliant consent management process for your own Data Fiduciary obligations is something every organisation processing personal data needs today, regardless of what happens with the Consent Manager ecosystem.
Getting this distinction right saves both wasted effort chasing a registration you don’t need, and the far more common risk – assuming a vendor’s “Consent Manager” integration covers a compliance obligation it doesn’t actually touch. For the full picture of how consent, notice, and the rest of DPDP’s obligations fit together, see our complete guide to DPDP in India.
[Book a Demo with RuleExpert →]
Nitin Ray is a Compliance Manager at RuleExpert with expertise in DPDP compliance, data privacy, consent management, and governance. He helps organizations implement practical compliance frameworks and automation strategies to meet the requirements of India’s Digital Personal Data Protection Act, 2023.
