DPDPAcademyKnow the law. Prove it.
Home/Consent Managers
§ 2(g) · § 6(7)–(9) · Rule 4 · First Schedule

A Role No Other Privacy Law Has. Registration Opens in 2026.

The Consent Manager is the most original idea in the DPDP Act: a licensed intermediary that an individual can use to give, review and withdraw consent across every organisation at once, and which the statute makes accountable to her rather than to whoever pays its bills.

Unique to IndiaCurrent as of 13 August 2026
In the Act

Four provisions create the role

§ 2(g)The definitionA person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform.
§ 6(7)The routing rightThe Data Principal may give, manage, review or withdraw her consent to the Data Fiduciary through a Consent Manager. It is her choice to route consent this way, not the Data Fiduciary's.
§ 6(8)Whose side they are onThe Consent Manager shall be accountable to the Data Principal and shall act on her behalf. This is the provision that makes the role unusual, and it is the one most likely to be misread.
§ 6(9)Registration is mandatoryEvery Consent Manager shall be registered with the Board, subject to such technical, operational, financial and other conditions as may be prescribed. Those conditions arrived with the Rules.

Read them in place: section 6 on consent and section 2 on definitions.

Accountable to her, paid by someone else

Section 6(8) is a short sentence with a lot of weight in it. The Consent Manager is accountable to the Data Principal and acts on her behalf. But the commercial relationship, in every model anyone has proposed, runs the other way: Data Fiduciaries are the ones with a reason to pay for consent infrastructure.

The Rules answer that tension with structure rather than prohibition: conflict-of-interest duties written into the constitutional documents of the company, a bar on acting for both sides, transparency obligations and audit. Whether that holds in practice is the open question of the whole framework, and it will not be answered until the first registrations are live.

Getting registeredFirst Schedule, Part A
  • A company incorporated in India, with sufficient technical, operational and financial capacity.
  • Net worth of not less than two crore rupees.
  • Directors and senior management with a general reputation and record of fairness and integrity.
  • A memorandum and articles of association that bind the company to conflict-of-interest requirements.
  • Independent certification that the platform meets data protection standards, and an interoperable design.
Staying registeredFirst Schedule, Part B
  • Enable a Data Principal to give, manage, review and withdraw consent for any Data Fiduciary, through a website or app.
  • Ensure personal data routed through the platform stays unreadable to the Consent Manager itself. They carry consent, not content.
  • Maintain records of consents, withdrawals and notices, and retain them for at least seven years.
  • Avoid conflicts of interest with Data Fiduciaries, and act in a fiduciary capacity towards the individual.
  • Publish transparency information and run effective audit mechanisms over the platform.

The Board may suspend or cancel a registration after giving the Consent Manager an opportunity to be heard.

What this means if you are not becoming one

Most organisations reading this will never register. The obligation that reaches them is quieter: section 6(7) gives the individual the right to route consent through a Consent Manager, which means a Data Fiduciary has to be able to receive a consent signal it did not collect itself, honour a withdrawal that arrives the same way, and reconcile both against its own purpose records.

If your consent store keys on a session or a form submission rather than on a durable purpose identifier tied to the individual, that is the piece to fix now. It is the same work the consent notice guide describes, with an external caller added.

Timing, and what is not yet settled

Section 6(9) and Rule 4 fall in the one-year tranche of the commencement notification, which lands in mid-November 2026. Registration is with the Data Protection Board, and MeitY invited applications for the Board's Chairperson and Members in May 2026. Public reporting since then differs on whether those appointments have been completed, so treat the Board's readiness to receive registrations as an open question rather than a settled fact.

The Part A and Part B conditions above are summarised from the First Schedule to the DPDP Rules, 2025 as reported consistently across sources. Anyone actually applying should work from the Gazette text rather than from this summary.

FAQ

Consent Managers, answered

What is a Consent Manager, in one sentence?

A Board-registered intermediary that gives an individual one place to grant, review and withdraw consent across many organisations, instead of chasing each company's own preference centre.

Does my company need to become one?

Almost certainly not. The role is a licensed business, not a compliance obligation. What Data Fiduciaries need is the ability to accept and honour consent that arrives through a Consent Manager, because section 6(7) makes that the individual's choice.

When does registration open?

Section 6(9) and Rule 4 sit in the one-year tranche of the commencement notification, which falls in mid-November 2026, one year after the Rules were published on 13 November 2025.

Can a Consent Manager read the data it routes?

No. The First Schedule requires that personal data shared through the platform remains unreadable to the Consent Manager. The design intent is that they hold the consent record and the routing, not the payload.

Is there anything like this in GDPR?

No. GDPR has no statutory consent-intermediary role. This is one of the genuinely original pieces of the Indian framework, closer in spirit to account aggregators in Indian financial regulation than to anything in European data protection law.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against the DPDP Act, 2023 and notified DPDP Rules, 2025. Educational information, not legal advice.

Review standards and attribution →