A Role No Other Privacy Law Has. Registration Opens in 2026.
The Consent Manager is the most original idea in the DPDP Act: a licensed intermediary that an individual can use to give, review and withdraw consent across every organisation at once, and which the statute makes accountable to her rather than to whoever pays its bills.
Four provisions create the role
Read them in place: section 6 on consent and section 2 on definitions.
Section 6(8) is a short sentence with a lot of weight in it. The Consent Manager is accountable to the Data Principal and acts on her behalf. But the commercial relationship, in every model anyone has proposed, runs the other way: Data Fiduciaries are the ones with a reason to pay for consent infrastructure.
The Rules answer that tension with structure rather than prohibition: conflict-of-interest duties written into the constitutional documents of the company, a bar on acting for both sides, transparency obligations and audit. Whether that holds in practice is the open question of the whole framework, and it will not be answered until the first registrations are live.
- A company incorporated in India, with sufficient technical, operational and financial capacity.
- Net worth of not less than two crore rupees.
- Directors and senior management with a general reputation and record of fairness and integrity.
- A memorandum and articles of association that bind the company to conflict-of-interest requirements.
- Independent certification that the platform meets data protection standards, and an interoperable design.
- Enable a Data Principal to give, manage, review and withdraw consent for any Data Fiduciary, through a website or app.
- Ensure personal data routed through the platform stays unreadable to the Consent Manager itself. They carry consent, not content.
- Maintain records of consents, withdrawals and notices, and retain them for at least seven years.
- Avoid conflicts of interest with Data Fiduciaries, and act in a fiduciary capacity towards the individual.
- Publish transparency information and run effective audit mechanisms over the platform.
The Board may suspend or cancel a registration after giving the Consent Manager an opportunity to be heard.
What this means if you are not becoming one
Most organisations reading this will never register. The obligation that reaches them is quieter: section 6(7) gives the individual the right to route consent through a Consent Manager, which means a Data Fiduciary has to be able to receive a consent signal it did not collect itself, honour a withdrawal that arrives the same way, and reconcile both against its own purpose records.
If your consent store keys on a session or a form submission rather than on a durable purpose identifier tied to the individual, that is the piece to fix now. It is the same work the consent notice guide describes, with an external caller added.
Section 6(9) and Rule 4 fall in the one-year tranche of the commencement notification, which lands in mid-November 2026. Registration is with the Data Protection Board, and MeitY invited applications for the Board's Chairperson and Members in May 2026. Public reporting since then differs on whether those appointments have been completed, so treat the Board's readiness to receive registrations as an open question rather than a settled fact.
The Part A and Part B conditions above are summarised from the First Schedule to the DPDP Rules, 2025 as reported consistently across sources. Anyone actually applying should work from the Gazette text rather than from this summary.
Consent Managers, answered
What is a Consent Manager, in one sentence?
A Board-registered intermediary that gives an individual one place to grant, review and withdraw consent across many organisations, instead of chasing each company's own preference centre.
Does my company need to become one?
Almost certainly not. The role is a licensed business, not a compliance obligation. What Data Fiduciaries need is the ability to accept and honour consent that arrives through a Consent Manager, because section 6(7) makes that the individual's choice.
When does registration open?
Section 6(9) and Rule 4 sit in the one-year tranche of the commencement notification, which falls in mid-November 2026, one year after the Rules were published on 13 November 2025.
Can a Consent Manager read the data it routes?
No. The First Schedule requires that personal data shared through the platform remains unreadable to the Consent Manager. The design intent is that they hold the consent record and the routing, not the payload.
Is there anything like this in GDPR?
No. GDPR has no statutory consent-intermediary role. This is one of the genuinely original pieces of the Indian framework, closer in spirit to account aggregators in Indian financial regulation than to anything in European data protection law.