A consent manager is India’s answer to a problem no other privacy regime has tried to solve institutionally: giving a person one place to grant, review and withdraw consent across every organisation holding their data. Rule 4 of the DPDP Rules 2025 creates it as a registered, regulated intermediary — and it is the first hard deadline in the whole DPDP framework.
This guide covers what a consent manager does, the registration bar, the obligations that come with it, and what the rest of us have to do about it.

What a consent manager is, and what it is not
The DPDP Act gives a data principal the right to give, manage, review and withdraw consent through a consent manager — a person registered with the Data Protection Board, accountable to the data principal, and operating through an accessible, transparent and interoperable platform.
The design intent is a single dashboard: one interface where an individual can see which organisations hold consent, for what purpose, and revoke any of it without visiting each company’s website. It does not hold the data. It routes and records the consent, and it must do so in a way that keeps the personal data flowing through it unreadable to itself.
The obligations that define the role
| Obligation | What it means in practice |
|---|---|
| Fiduciary duty to the principal | The individual is the client, not the business paying for the integration |
| No conflicting role | Cannot act as data fiduciary or processor for the same data principals it serves |
| Data unreadable to itself | Routed personal data must not be readable by the consent manager |
| Consent records retained | Records of consents, notices and shares kept for at least seven years |
| Registration conditions | Indian incorporation, minimum net worth of ₹2 crore, demonstrated technical and financial capacity |
| Governance constraints | Fit-and-proper directors and management; conflict provisions in the constitutional documents |
Breach of these can lead to suspension or cancellation of the registration, which for such a business is everything.
The consent manager deadline comes first
The DPDP Rules 2025 were notified as G.S.R. 846(E) dated 13 November 2025, and they do not all commence together. Rule 4 — registration and obligations of consent managers — takes effect one year after publication, on 13 November 2026, while most substantive obligations on data fiduciaries wait a further six months until 13 May 2027.
That ordering is deliberate. The consent infrastructure has to exist before the consent obligations bite. Our guide to the two DPDP Rules 2025 deadlines sets out the full commencement table, and the DPDP Act timeline covers what lands in 2027.
If you are not becoming one
Most organizations will never register as a consent manager, and still have work to do:
- Be able to accept consent from one. A data principal may route consent through a consent manager, and your systems have to recognise a consent granted or withdrawn that way as valid.
- Make withdrawal as easy as granting. That is a statutory requirement independent of the intermediary, and most consent flows fail it today.
- Record consent properly now. Purpose, notice version, timestamp, and the route it arrived by. Retrofitting that after May 2027 is expensive.
- Decide whether to integrate. Consumer-facing businesses will likely be asked; internal and B2B systems mostly will not.
Where the model is untested
This is a genuinely new institution, and honesty about the open questions is worth more than confidence. The Board’s registration process and the technical interoperability standards are the mechanics everyone is waiting on, and until registrations happen there is no established practice for how a fiduciary verifies that a consent presented by an intermediary is genuine. Build your consent records so the route is captured, and the answer will fit whatever the mechanics turn out to be.
Frequently asked questions
What is a consent manager under the DPDP Act?
A person registered with the Data Protection Board who gives data principals a single platform to give, manage, review and withdraw consent, acting on the individual’s behalf.
When does the requirement start?
Rule 4 commences one year after the Rules were published — 13 November 2026. Most other obligations follow eighteen months from publication, on 13 May 2027.
What does registration require?
Incorporation in India, a minimum net worth of ₹2 crore, demonstrated technical, operational and financial capacity, and governance arrangements that prevent conflicts of interest.
Can we act as our own consent manager?
No. A consent manager cannot be a data fiduciary or processor for the same data principals it serves — the conflict rule exists precisely to stop that.
Is this the same as a GDPR consent management platform?
No. A CMP is a product a controller buys to run its own consent. This is a registered intermediary that owes duties to the individual, not to the business.
Where this leaves you
If you are building one, the registration bar is capital plus governance plus a platform that cannot read what it routes, and the clock runs to 13 November 2026. If you are not — which is nearly everyone — treat the consent manager as an interface you will have to honour: record consent with its purpose, notice version, timestamp and route, make withdrawal genuinely as easy as granting, and get that in place well before the 13 May 2027 obligations arrive.
References
- MeitY — data protection framework — the DPDP Act and the Rules as notified.
- Digital Personal Data Protection Act, 2023 (PDF) — the Act as published by MeitY, including the consent manager provisions.
More on privacy compliance
- The consent manager — you are here
- The DPDP Act timeline
- The DPDP Rules 2025 deadlines
- Handling data subject requests
Consent notices, records and the fiduciary document set are in the DPDP Act Toolkit, or start with the free ISO templates.