Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

The DPDP consent manager explained

Consent Manager: A Clear Guide to DPDP Rule 4 in 2026

A consent manager is India’s answer to a problem no other privacy regime has tried to solve institutionally: giving a person one place to grant, review and withdraw consent across every organisation holding their data. Rule 4 of the DPDP Rules 2025 creates it as a registered, regulated intermediary — and it is the first hard deadline in the whole DPDP framework.

This guide covers what a consent manager does, the registration bar, the obligations that come with it, and what the rest of us have to do about it.

Consent manager under the DPDP Rules: where it sits between principal and fiduciary
An intermediary that routes consent without being able to read what passes through it.

The DPDP Act gives a data principal the right to give, manage, review and withdraw consent through a consent manager — a person registered with the Data Protection Board, accountable to the data principal, and operating through an accessible, transparent and interoperable platform.

The design intent is a single dashboard: one interface where an individual can see which organisations hold consent, for what purpose, and revoke any of it without visiting each company’s website. It does not hold the data. It routes and records the consent, and it must do so in a way that keeps the personal data flowing through it unreadable to itself.

The obligations that define the role

Obligation What it means in practice
Fiduciary duty to the principal The individual is the client, not the business paying for the integration
No conflicting role Cannot act as data fiduciary or processor for the same data principals it serves
Data unreadable to itself Routed personal data must not be readable by the consent manager
Consent records retained Records of consents, notices and shares kept for at least seven years
Registration conditions Indian incorporation, minimum net worth of ₹2 crore, demonstrated technical and financial capacity
Governance constraints Fit-and-proper directors and management; conflict provisions in the constitutional documents

Breach of these can lead to suspension or cancellation of the registration, which for such a business is everything.

The DPDP Rules 2025 were notified as G.S.R. 846(E) dated 13 November 2025, and they do not all commence together. Rule 4 — registration and obligations of consent managers — takes effect one year after publication, on 13 November 2026, while most substantive obligations on data fiduciaries wait a further six months until 13 May 2027.

That ordering is deliberate. The consent infrastructure has to exist before the consent obligations bite. Our guide to the two DPDP Rules 2025 deadlines sets out the full commencement table, and the DPDP Act timeline covers what lands in 2027.

If you are not becoming one

Most organizations will never register as a consent manager, and still have work to do:

  • Be able to accept consent from one. A data principal may route consent through a consent manager, and your systems have to recognise a consent granted or withdrawn that way as valid.
  • Make withdrawal as easy as granting. That is a statutory requirement independent of the intermediary, and most consent flows fail it today.
  • Record consent properly now. Purpose, notice version, timestamp, and the route it arrived by. Retrofitting that after May 2027 is expensive.
  • Decide whether to integrate. Consumer-facing businesses will likely be asked; internal and B2B systems mostly will not.

Where the model is untested

This is a genuinely new institution, and honesty about the open questions is worth more than confidence. The Board’s registration process and the technical interoperability standards are the mechanics everyone is waiting on, and until registrations happen there is no established practice for how a fiduciary verifies that a consent presented by an intermediary is genuine. Build your consent records so the route is captured, and the answer will fit whatever the mechanics turn out to be.

Frequently asked questions

What is a consent manager under the DPDP Act?
A person registered with the Data Protection Board who gives data principals a single platform to give, manage, review and withdraw consent, acting on the individual’s behalf.

When does the requirement start?
Rule 4 commences one year after the Rules were published — 13 November 2026. Most other obligations follow eighteen months from publication, on 13 May 2027.

What does registration require?
Incorporation in India, a minimum net worth of ₹2 crore, demonstrated technical, operational and financial capacity, and governance arrangements that prevent conflicts of interest.

Can we act as our own consent manager?
No. A consent manager cannot be a data fiduciary or processor for the same data principals it serves — the conflict rule exists precisely to stop that.

Is this the same as a GDPR consent management platform?
No. A CMP is a product a controller buys to run its own consent. This is a registered intermediary that owes duties to the individual, not to the business.

Where this leaves you

If you are building one, the registration bar is capital plus governance plus a platform that cannot read what it routes, and the clock runs to 13 November 2026. If you are not — which is nearly everyone — treat the consent manager as an interface you will have to honour: record consent with its purpose, notice version, timestamp and route, make withdrawal genuinely as easy as granting, and get that in place well before the 13 May 2027 obligations arrive.

References

More on privacy compliance

Consent notices, records and the fiduciary document set are in the DPDP Act Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.