· 8 min read
By Correct Editorial — Compliance Research Desk
Consent Manager: Key Requirements Explained
Published on: July 29, 2026
The Consent Manager is the most structurally novel idea in India's data protection framework. No comparable licensed intermediary exists in the GDPR. It is also the piece of the Digital Personal Data Protection Rules, 2025 with the earliest hard deadline: Rule 4 and the First Schedule commence on 13 November 2026, twelve months after notification and six months before the rest of the regime becomes enforceable on 13 May 2027.
This article covers what a Consent Manager is, who can become one, the thirteen continuing obligations that attach to registration, and — the question most compliance teams actually have — what an ordinary Data Fiduciary needs to build regardless of whether it ever onboards to one. For the wider statutory picture, start with DPDP Act 2023: An Overview for Businesses.
What Is a Consent Manager?
Section 2(g) of the Digital Personal Data Protection Act, 2023 defines a Consent Manager as a person registered with the Data Protection Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform.
Read that definition carefully, because each phrase is load-bearing:
- Registered with the Board — this is a licensed activity, not a product category. An unregistered vendor selling a consent widget is a software supplier, not a Consent Manager.
- Single point of contact — the individual sees one dashboard across many businesses, rather than hunting through dozens of privacy settings pages.
- Interoperable — the platform must speak a common technical language with participating Data Fiduciaries, against standards the Board publishes.
Section 6(9) completes the picture: where a Data Principal gives consent through a Consent Manager, she may also withdraw it through that Consent Manager, and the Consent Manager is accountable to her. The relationship is fiduciary in the true sense — the Consent Manager works for the individual, not for the businesses that pay to connect.
When Does the Regime Start, and What Exists Today?
The commencement sequence is unusually precise.
| Date | What happens |
|---|---|
| 3 January 2025 | Draft Rules published for consultation (G.S.R. 02(E)) |
| 13 November 2025 | Final Rules notified as G.S.R. 846(E); Board provisions of the Act commence |
| 14 November 2025 | Rules published in the Gazette of India |
| 13 November 2026 | Rule 4 and the First Schedule commence; Section 6(9) and Section 27(1)(d) commence — the Board can register Consent Managers and act on non-adherence |
| 13 May 2027 | Rules 3, 5 to 16, 22 and 23 commence; the general compliance regime becomes enforceable |
As of mid-2026, no entity has been registered as a Consent Manager, and the Board has not yet published the data protection standards and assurance framework that certification must test against. This is therefore a get-ready topic for aspiring intermediaries and an architecture topic for everyone else — not yet a procurement decision.
Who Can Register? Part A Conditions
Rule 4(1) allows a person who satisfies Part A of the First Schedule to apply to the Board, furnishing the particulars the Board publishes on its website. The conditions, read with MeitY's explanatory note, require the applicant to be:
- A company incorporated in India — not a foreign entity, LLP, or partnership
- Possessed of a net worth of not less than ₹2 crore, where net worth means total assets less liabilities as appearing in its books of account
- Of sound financial and operational capacity, with technical capability to run the platform at scale
- Managed by persons with a reputation for fairness and integrity
- Operating a platform that is independently certified as consistent with the data protection standards and assurance framework the Board publishes, with appropriate technical and organisational measures to sustain that adherence
The ₹2 crore figure is a floor, not an indexed threshold, and it deliberately screens out thinly capitalised entrants from a role that will hold the consent records of millions of individuals.
Rule 4(2) gives the Board discretion to inquire as it deems fit before registering an applicant and publishing its particulars, or rejecting the application with reasons communicated to the applicant.
What Must a Registered Consent Manager Do? Part B Obligations
Rule 4(3) binds registered entities to the obligations in Part B of the First Schedule. They fall into five clusters.
Record-keeping. The platform must maintain a record of consents given, denied or withdrawn; the notices that preceded or accompanied each consent request; and every instance of sharing personal data with a transferee Data Fiduciary. The individual must have access to that record, and on request must receive it in machine-readable form. Records must be retained for at least seven years, or longer if agreed with the individual or required by law.
Neutrality and non-readability. A Consent Manager routes consent, not content. It must ensure it cannot read the personal data flowing between Data Fiduciaries through its platform, and it may not subcontract or assign its obligations to any other person.
Conflict of interest. Strict rules prevent directors, key managerial personnel and senior management of the Consent Manager from having interests that compromise independence from participating Data Fiduciaries. Control of the company cannot be transferred by sale, merger or otherwise without the Board's prior approval.
Transparency. The Consent Manager must publish, in an easily accessible manner, its promoters, directors, key managerial personnel and senior management; every person holding more than two per cent of its shareholding; every body corporate in which those individuals hold more than two per cent as on the first day of the preceding calendar month; and anything else the Board directs in the interests of transparency.
Audit and supervision. It must operate effective audit mechanisms covering technical and organisational controls, continued fulfilment of registration conditions, and adherence to the Act and Rules, and report outcomes to the Board periodically and whenever directed.
What Happens If a Consent Manager Fails?
Rule 4(4) allows the Board, after giving an opportunity of being heard, to inform the Consent Manager of non-adherence and direct corrective measures. Rule 4(5) goes further: in the interests of Data Principals, and for reasons recorded in writing, the Board may suspend or cancel registration and issue any directions it considers fit. Rule 4(6) lets the Board call for information at any time.
Layered on top, a Consent Manager remains a person bound by the Act. Breach of an obligation with no specific entry in the Schedule falls under the residuary head — up to ₹50 crore — and any failure of security safeguards over the consent artefacts it holds is exposed to the ₹250 crore head. The commercial model has to be underwritten accordingly.
If Consent Managers Are Optional, What Must My Business Build?
This is the question that matters for the overwhelming majority of readers. Using a Consent Manager is not mandatory. A Data Fiduciary may continue to obtain consent directly. What is mandatory, from 13 May 2027, is that your consent architecture meets the standard of the Act and Rules — and the fastest way to get there is to build as though a Consent Manager will eventually plug into it.
Six capabilities are non-negotiable:
- Rule 3 notice. A standalone, plain-language notice with an itemised list of the personal data collected and a specific description of the purpose, goods, services or uses enabled. Generic phrases such as "to improve our services" will not survive scrutiny.
- Affirmative, unbundled consent. Section 6(1) requires consent to be free, specific, informed, unconditional and unambiguous, signified by a clear affirmative action, and limited to the data necessary for the specified purpose. Pre-ticked boxes and consent bundled into terms of service fail.
- Withdrawal parity. Section 6(4) to 6(6) require withdrawal to be as easy as giving consent, with the fiduciary and its processors ceasing processing within a reasonable time.
- A durable consent ledger. Store what was consented to, the exact notice version shown, the timestamp, the channel, and the subsequent lifecycle events. If you cannot reproduce the notice a user saw eighteen months ago, you cannot evidence valid consent.
- Machine-readable export. Build the export path now; the First Schedule already sets that expectation for Consent Managers, and interoperability will be judged against it.
- Rights and grievance plumbing. Rule 14 requires you to publish how rights requests are made and the identifiers you need, and to respond to grievances within 90 days.
Two adjacent obligations are frequently missed. Rule 10 requires verifiable parental consent before processing a child's data, using reliable identity and age details already available with the fiduciary or a virtual token mapped to them; Rule 11 applies the same logic to persons with disability who have a lawful guardian. And where your processors touch consented data, your contracts must carry the flow-down security terms discussed in Data Fiduciary vs Data Processor: Key Differences.
A Practical Readiness Sequence
| Quarter | Focus | Output |
|---|---|---|
| Q3 2026 | Inventory every consent capture point across web, app, offline digitisation, and HR | Consent map with purposes and data fields |
| Q4 2026 | Rewrite notices to Rule 3, unbundle consent, ship withdrawal parity | Versioned notice library and consent ledger |
| Q1 2027 | Wire rights requests, grievance SLA, parental consent flows | Rights console and 90-day tracking |
| Q2 2027 | Dry-run an interoperability test and an audit of consent evidence | Evidence pack before 13 May 2027 |
Businesses that treat consent as a data structure rather than a checkbox will find Consent Manager integration a configuration exercise. Those that treat it as a banner will be rebuilding under a deadline. More Indian regulatory explainers are available at Correct Learn, and the end-to-end programme view sits in our DPDP compliance roadmap.
References
- Gazette of India — The Digital Personal Data Protection Act, 2023 — Sections 2(g), 6 and 27 governing Consent Managers.
- MeitY — Explanatory Note to the DPDP Rules, 2025 — Official explanation of Rule 4 registration and obligations.
- Digital Personal Data Protection Rules, 2025 — notified text — Rule 4 and the First Schedule, Parts A and B.
- Ministry of Electronics and Information Technology — Consultation record and policy materials for the consent framework.
- Gazette of India portal — G.S.R. 846(E) dated 13 November 2025 and the draft G.S.R. 02(E) dated 3 January 2025.
- Press Information Bureau — Government communications on the phased commencement of the Rules.
- India Code — Consolidated bare Act text with commencement annotations.
Frequently asked questions
- What is a Consent Manager under the DPDP Act?
- Section 2(g) defines a Consent Manager as a person registered with the Data Protection Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.
- When does the Consent Manager framework come into force?
- Rule 4 and the First Schedule of the DPDP Rules, 2025 commence on 13 November 2026, exactly one year after notification. Section 6(9) and Section 27(1)(d) of the Act commence on the same date, giving the Board jurisdiction over registered Consent Managers.
- Is it mandatory for businesses to use a Consent Manager?
- No. A Data Fiduciary may continue to collect consent directly. Using a registered Consent Manager is an option the individual may choose, so businesses should build consent systems that can interoperate with one rather than assuming they must onboard to one.
- What is the net worth requirement to register as a Consent Manager?
- Part A of the First Schedule requires the applicant to be a company incorporated in India with a net worth of not less than ₹2 crore, sound financial and operational capacity, a reputation for fairness and integrity, and an independently certified interoperable platform.