Consent manager companies in India:
none registered yet, and why.
People searching for consent manager companies in India usually want one of three things: a registered DPDP Consent Manager, an account aggregator, or consent software for their own website. They are different things. This guide sorts them out, says where registration stands on 6 October 2026, and shows how to check a Consent Manager once they exist. Not legal advice.
Last updated Published by TryTrustableNot legal advice
As of 6 October 2026 there are no registered consent manager companies in India under the DPDP Act. Registration under Rule 4 of the DPDP Rules 2025 only opens on 13 November 2026, so no company can yet be a Consent Manager registered with the Data Protection Board, and anyone claiming to be one today is not. Once registration opens, only a company incorporated in India with a net worth of at least Rs 2 crore and an independently certified interoperable platform can qualify, and the Board publishes the particulars of each one it registers on its website.
Are there any registered consent manager companies in India?
No, not yet. Section 6(9) of the Digital Personal Data Protection Act, 2023 says every Consent Manager must be registered with the Data Protection Board, and Rule 4 of the DPDP Rules 2025, which sets up that registration, comes into force on 13 November 2026, one year after the Rules were published. Until then there is no route to register, so no company in India is a registered Consent Manager under the Act.
Two further things have to happen before the first registration. Rule 4(1) says applicants file the particulars and documents the Board publishes on its website for the purpose, and as of our last check on 28 September 2026 the Board had not published them. The Board also had no Chairperson or Members appointed at that date (MeitY invited applications in May 2026). So the first registrations may come some time after 13 November 2026. We track both on the DPDP regulatory tracker.
If a company says it is a registered Consent Manager today, it is not. It may be preparing to apply, it may be an RBI-licensed account aggregator, or it may sell consent software. Any of those can be legitimate. None is a Board-registered Consent Manager before Rule 4 is in force and the Board has registered it.
Who can register as a consent manager in India?
Only a company incorporated in India, as MeitY's announcement of the Rules also stressed. Part A of the First Schedule adds eight more conditions, among them a net worth of at least Rs 2 crore (total assets less liabilities, as in its books), sufficient technical, operational and financial capacity, fit and proper management, articles of association that bind it to avoid conflicts with Data Fiduciaries, operations in the interests of individuals, and independent certification of its interoperable platform. The Board may inquire before it registers or rejects an applicant, and can later direct, suspend or cancel a registration. Every condition and every obligation is set out item by item in our DPDP Consent Manager guide.
How to evaluate a consent manager once they are registered
If your users may start arriving through Consent Managers, or a vendor pitches one to you, these are the checks that matter. Each comes from the Rules, so a real Consent Manager should be able to answer every one with a document or a link.
| Check | What to look for | Where it comes from |
|---|---|---|
| Is it on the Board's register? | Its particulars published on the Data Protection Board's website. A press release, a certificate on its own site or a sales deck is not the register | Rule 4(2)(a) |
| Is it an Indian company? | Incorporated in India under the Companies Act. A foreign parent can own it only if the Indian company still meets every other condition | First Schedule, Part A item 1 |
| Is it independent of the businesses it serves? | No conflicts with Data Fiduciaries, their promoters or key managerial personnel, and that duty written into its articles of association | Part A item 7; Part B items 9 and 10 |
| Does it publish who owns and runs it? | Promoters, directors, key managerial personnel and senior management, and every shareholder above 2%, on its website or app | Part B item 11 |
| Can it read your users' data? | It must not. Data made available or shared through it must not be readable by it | Part B item 2 |
| Is the platform certified? | Independent certification that the interoperable platform meets the Board's data protection standards and assurance framework | Part A item 9 |
| What record does it keep? | Consents given, denied and withdrawn, the notices behind them, and each data sharing, kept for at least seven years and available to the individual in machine-readable form | Part B items 3 and 4 |
| Who actually does the work? | It may not sub-contract or assign its obligations | Part B item 6 |
| Is it audited? | Audit mechanisms over its controls and compliance, with the outcome reported to the Board | Part B item 12 |
| How does it handle complaints? | A published grievance response period of no more than ninety days | Rule 14(3) |
Paraphrased from Rule 4, Rule 14 and the First Schedule to the DPDP Rules 2025. The full list of conditions and obligations is on our Consent Manager guide.
Then check the integration on your side. Consent given through a Consent Manager is still consent you must be able to prove under section 6(10), so it has to land in your own consent record with the purpose and notice version, and a withdrawal made there has to reach every system and processor that holds the data.
Consent manager platform vs consent management platform (CMP)
A search for consent manager software, tools or platforms usually means one of two things. A DPDP Consent Manager is a regulated intermediary that acts for the individual. A consent management platform is software a business runs on its own site and acts for that business. The difference decides whether you need registration (only the first) and who owes duties to whom.
| Consent Manager (DPDP) | Consent management platform | |
|---|---|---|
| Acts for | The individual (Data Principal) | The business that deploys it (Data Fiduciary) |
| Registration | With the Data Protection Board, from 13 November 2026 | None |
| Who can be one | Only an Indian company meeting the First Schedule | Any software vendor |
| Covers | Many businesses on one platform the individual uses | One business's own notices, purposes and trackers |
| Typical job | Let a person see and change her consents to several businesses, and route consent and sharing instructions | Show the notice, block trackers until a choice, record each choice against the notice version, handle withdrawal |
| Do you need one? | Only if your users choose to come through one | Yes, if you collect consent on a website or app |
Most companies need a CMP. A few will also need to accept consent that arrives through a Consent Manager.
TryTrustable is a CMP, not a Consent Manager
TryTrustable is a consent management platform. It is not a Consent Manager under the DPDP Act, it is not registered with the Data Protection Board, and it does not act for individuals across businesses. Consent by TryTrustable is software a Data Fiduciary runs on its own website or app: a banner that blocks trackers until consent, DPDP rules for visitors in India and GDPR-style opt-in for the EU and UK, Google Consent Mode v2, versioned notices, a tamper-evident consent ledger, withdrawals relayed to your processors with each delivery logged, and a privacy-request link that feeds a rights queue with deadlines. It helps you meet your own notice and consent duties; it does not make you compliant on its own. Scan your site free to see what fires before anyone chooses.
The things people ask us
Which companies are registered consent managers in India?
None, as of 6 October 2026. Registration under Rule 4 of the DPDP Rules 2025 opens on 13 November 2026, and the Board publishes the particulars of each Consent Manager it registers on its website. Check that register, not a company's own claim.
When does consent manager registration open in India?
On 13 November 2026, when Rule 4 comes into force, one year after the Rules were published on 13 November 2025. Applicants file the particulars and documents the Data Protection Board publishes on its website.
Is an account aggregator a consent manager under the DPDP Act?
Not automatically. Account aggregators are NBFCs licensed by the RBI to share financial information with the customer's consent. A DPDP Consent Manager is registered by the Data Protection Board under Rule 4. One company could be both, but only by registering with the Board as well.
Can a foreign company be a consent manager in India?
No. The first condition in Part A of the First Schedule is that the applicant is a company incorporated in India. A foreign group would need an Indian company that meets every other condition, including independence from the Data Fiduciaries it serves.
What net worth does a consent manager need?
At least Rs 2 crore, measured as total assets less liabilities in the company's books. Capacity, sound finances, independence and a certified platform are required as well.
Do I need a consent manager to comply with the DPDP Act?
No. Using a Consent Manager is the individual's option under section 6(7). You need a way to give notice, collect and prove consent, and honour withdrawal on your own site and app, which is what a consent management platform does.
Is TryTrustable a registered consent manager?
No. TryTrustable is a consent management platform that a business runs on its own website or app. It is not registered with the Data Protection Board and does not act for individuals across businesses.
Consent on your own site does not wait for Rule 4.
Thirty minutes on your notice, banner and consent record for India, the EU and the US, with your own site scanned live.