What is a Consent Manager under the DPDP Act?
Section 2(g) of the Digital Personal Data Protection Act 2023 defines a Consent Manager as:
"…a person registered with the Board who acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw her consent through an accessible, transparent, and interoperable platform."
In plain terms: a Consent Manager is a registered intermediary that sits between a Data Principal (the individual) and one or more Data Fiduciaries (businesses). Instead of managing separate consent flows with every app or service they use, a Data Principal can manage all their consents through a single platform operated by the Consent Manager.
Think of it as a consent dashboard — one place where an individual can see who has their data, what they consented to, and revoke access with a single click. The Consent Manager doesn't process the personal data itself; it manages the records of consent.
A Consent Manager serves the Data Principal — not the Data Fiduciary. It is accountable to the individual, not to the business whose consent it facilitates. This is what separates it from a Data Processor, which serves the Data Fiduciary.
How does the Consent Manager model work?
Under Section 6(6) of the DPDP Act, a Data Principal can give, manage, and withdraw consent through a Consent Manager. The flow works like this:
- The Data Principal registers with a Consent Manager — a Board-registered platform that manages their consent portfolio.
- When a Data Fiduciary requests consent, the request can be routed through the Data Principal's Consent Manager rather than requiring direct engagement with the Fiduciary's own consent interface.
- The Consent Manager presents the consent notice in a standardised, comprehensible format and records the Data Principal's decision.
- The Data Fiduciary is informed of the consent decision and can proceed accordingly. The consent record is held by the Consent Manager.
- If the Data Principal withdraws consent, they do so through their Consent Manager. The withdrawal is communicated to the Data Fiduciary, who must stop processing within the prescribed timeframe.
Crucially, using a Consent Manager does not transfer a Data Fiduciary's liability. The Data Fiduciary remains fully accountable for ensuring that consent was validly obtained and that processing stops when consent is withdrawn.
Who must register as a Consent Manager?
Any company that wants to operate a consent management platform — to offer a service through which Data Principals can manage their consents — must register with the Data Protection Board of India.
The DPDP Rules 2025 set out the registration requirements:
- Indian incorporation: The Consent Manager must be a company incorporated in India under the Companies Act, 2013.
- Minimum net worth of ₹2 crore at the time of application, certified by a chartered accountant.
- Interoperable, open standards: The platform must operate on open, non-proprietary, interoperable standards — it cannot be a closed, proprietary system that locks Data Principals in.
- Accountability to Data Principals: The Consent Manager must be demonstrably accountable to Data Principals, with clear grievance redress mechanisms.
- Registration fee of ₹10,000 payable to the Data Protection Board.
- Board approval: Registration is subject to the Board's satisfaction. Applicants must demonstrate the technical and organisational capacity to fulfil the role.
Companies planning to operate as Consent Managers need to begin the registration process well in advance of the November 13, 2026 enforcement deadline. Board processing timelines mean that applications submitted close to the deadline risk not receiving approval in time.
The November 13, 2026 deadline — what is actually changing?
The DPDP Act has been enforced in phases since the Rules were published in 2025. The November 13, 2026 milestone marks the enforcement of the consent management provisions — including the Consent Manager framework under Section 6(6).
What do Data Fiduciaries need to do?
Most businesses will not operate as Consent Managers themselves. But every Data Fiduciary needs to understand how the Consent Manager framework affects their compliance posture:
If you plan to use a Consent Manager for your consent flows
- The Consent Manager you engage must be registered with the Data Protection Board. Verify their registration before integrating.
- Your consent notice — even when delivered through a Consent Manager — must meet the DPDP Act's requirements: specific, plain-language, granular by purpose, and revocable.
- You must honour withdrawals processed through the Consent Manager on the same timeline as direct withdrawals (typically within a reasonable period, not exceeding that specified in Rules).
- You remain the Data Fiduciary. You cannot outsource liability to the Consent Manager. If consent was invalid, the responsibility is yours.
If you manage consent directly (not through a Consent Manager)
Nothing changes in your obligations — but your own consent infrastructure must be robust:
- Consent flows must allow Data Principals to withdraw consent as easily as they gave it.
- You must maintain consent records — what was consented to, when, in what version of your notice.
- Your consent records must be accessible to Data Principals on request.
- You must be able to demonstrate valid consent if the Board investigates a complaint.
Can your current system prove, for any individual, exactly what they consented to, when, and in which version of your notice — and demonstrate that consent was freely given without bundling? If not, your consent infrastructure needs work before November 2026.
Consent Manager vs Data Processor — what is the difference?
Consent readiness checklist for November 2026
Whether or not you plan to use a Consent Manager, your organisation should be able to check every item below before November 13:
- Valid consent obtained before processing begins — free, informed, specific, unconditional
- Consent notice is available in English and regional languages as applicable
- Purpose of processing is clearly stated — no blanket consents
- Withdrawal mechanism is as easy to use as the original consent interface
- Consent records maintained with timestamp, notice version, and purpose
- Processing stops within the prescribed period after withdrawal
- If using a Consent Manager: verified they are registered with the Data Protection Board
- If using a Consent Manager: integration tested for withdrawal workflows
- Consent audit log accessible for Data Principal and Board queries
- Staff trained on consent management obligations
Frequently asked questions
Is appointing a Consent Manager mandatory?
No. The DPDP Act does not require Data Fiduciaries to use a Consent Manager. A business can manage consent directly through its own interfaces and systems. The Consent Manager is an option — a way for individuals to centralise consent management across many services. If your business uses a consent intermediary, that intermediary must be a registered Consent Manager.
Can a company be both a Data Fiduciary and a Consent Manager?
The Act does not prohibit this, but operating as a Consent Manager for your own customers would raise serious conflict-of-interest concerns — a Consent Manager must be accountable to the Data Principal, not to the business whose consent it manages. In practice, Consent Managers are expected to be independent entities.
What happens if a Consent Manager's registration is revoked?
The Data Protection Board can suspend or revoke a Consent Manager's registration if they fail to comply with the Act or Rules. Data Fiduciaries relying on a deregistered Consent Manager must transition to an alternative consent mechanism promptly. This is another reason to maintain a direct consent fallback even if you primarily use a Consent Manager.
Do startups and SMEs need to worry about Consent Managers?
Startups and SMEs do not need to register as Consent Managers unless they intend to offer consent management as a service. But they do need to ensure their own consent flows comply with the Act before November 2026 — the basic consent obligations apply to every Data Fiduciary, regardless of size.
What should your business do right now?
With 68 days to the November 13 deadline, there are three actions every Indian business should take:
- Audit your current consent flows. Map every touchpoint where you collect personal data. Check whether the consent obtained meets the DPDP Act's validity requirements. Identify gaps.
- Decide on your consent infrastructure strategy. Will you manage consent directly, or use a registered Consent Manager? If the latter, identify and vet your provider now — Board registration takes time.
- Build your consent records system. Ensure you can retrieve, for any individual, a complete record of their consent — what they agreed to, when, in what notice version, and for what purpose. This is what the Board will ask for in an investigation.
NxgSecure's DPDP compliance team works with Indian businesses on consent architecture, data mapping, and Board-ready documentation. Start with a free assessment to understand your current gap.