DPDP Consent Manager
and registration under the DPDP Rules 2025.
What the Act means by a Consent Manager, the conditions a company has to meet to register under Rule 4 from 13 November 2026, what it must do once registered, and why it is a different thing from the consent management platform on your own site.
Last updated Published by TryTrustableNot legal advice
What is a Consent Manager under the DPDP Act?
A Consent Manager under the DPDP Act is a company registered with the Data Protection Board of India that gives individuals a single, interoperable platform to give, manage, review and withdraw their consent across many Data Fiduciaries. It is accountable to the individual and acts on her behalf, not on behalf of the businesses that ask for consent.
The definition is in section 2(g) of the Digital Personal Data Protection Act, 2023: a person registered with the Board who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform. Section 6 then gives it three properties:
- Section 6(7). A Data Principal may give, manage, review or withdraw her consent to a Data Fiduciary through a Consent Manager
- Section 6(8). The Consent Manager is accountable to the Data Principal and acts on her behalf, subject to the obligations the Rules prescribe
- Section 6(9). Every Consent Manager must be registered with the Board, on the technical, operational, financial and other conditions the Rules prescribe
The Rules make the model concrete with an illustration. An individual registered on a Consent Manager's platform receives a request from one bank for her account statement. She can give that consent directly, or route it through a second bank that holds the statement and instruct that bank to send it across. The Consent Manager carries the consent and the instruction. It must not be able to read the data itself: Part B requires that personal data made available or shared through it is not readable by it.
Who can register as a Consent Manager?
Only a company incorporated in India that meets all nine conditions in Part A of the First Schedule to the DPDP Rules 2025, including a net worth of at least ₹2 crore and an independently certified interoperable platform. The Board decides whether the conditions are met, and can inquire before it does.
| # | Condition in Part A of the First Schedule | What it means in practice |
|---|---|---|
| 1 | The applicant is a company incorporated in India. | A foreign entity cannot apply. An LLP or partnership is not a company for this purpose. |
| 2 | Sufficient capacity, including technical, operational and financial capacity, to fulfil its obligations. | The Board will look at the platform, the team running it and the money behind it. |
| 3 | Sound financial condition and general character of management. | A judgement call, which is why it sits alongside the hard numbers. |
| 4 | Net worth of not less than ₹2 crore. | Total assets less liabilities as shown in the books. A floor, not a qualification on its own. |
| 5 | Adequate volume of likely business, capital structure and earning prospects. | Viability is tested because the records have to be kept for at least seven years. |
| 6 | Directors, key managerial personnel and senior management with a reputation and record of fairness and integrity. | Fit-and-proper, applied to the people, not only the company. |
| 7 | Memorandum and articles require adherence to the conflict-of-interest obligations (Part B items 9 and 10), with policies to ensure it, amendable only with the Board's prior approval. | Independence is written into the constitutional documents, not only a policy. |
| 8 | The proposed operations are in the interests of Data Principals. | The fiduciary duty runs to the individual. A business model built on the Data Fiduciaries' side fails here. |
| 9 | Independent certification that the interoperable platform meets the data protection standards and assurance framework the Board publishes, and that technical and organisational measures are in place. | Interoperability is certified against the Board's framework, not self-declared. |
Conditions paraphrased from Part A of the First Schedule to the DPDP Rules 2025. Read the notified text before relying on the wording.
Two of these do most of the filtering. Condition 1 removes every foreign company. Conditions 7 and 8, read with the Part B conflict rules, remove most companies that are themselves Data Fiduciaries, or are owned by one, because the Consent Manager has to be structurally on the individual's side.
How does Consent Manager registration work under the DPDP Rules 2025?
A company that meets the Part A conditions applies to the Data Protection Board under Rule 4, which comes into force on 13 November 2026. The Board may inquire, then either registers the applicant and publishes its particulars on the Board's website, or rejects the application with reasons.
Rule 4 is short, and each sub-rule carries weight:
| Rule | What it provides |
|---|---|
| 4(1) | An applicant meeting Part A applies with the particulars, information and documents the Board publishes on its website for this purpose. |
| 4(2) | The Board may make any inquiry it thinks fit. If satisfied, it registers the applicant and publishes its particulars; if not, it rejects the application and gives reasons. |
| 4(3) | A registered Consent Manager carries the obligations in Part B of the First Schedule. |
| 4(4) | If the Board thinks a Consent Manager is not adhering to the conditions or obligations, it may, after a hearing, direct it to take measures to comply. |
| 4(5) | In the interests of Data Principals, and after a hearing, the Board may suspend or cancel registration and give directions to protect the individuals affected. |
| 4(6) | The Board may require a Consent Manager to furnish any information it calls for. |
On timing: the Rules were published as Gazette notification G.S.R. 846(E), dated 13 November 2025 and announced by MeitY on 14 November 2025. Rule 1(3) brings Rule 4 into force one year after publication, which gives 13 November 2026. The substantive duties on Data Fiduciaries follow on 13 May 2027, so Consent Managers can be registered and operating before the notice and consent rules they serve are in force. The DPDP Act and Rules 2025 guide sets out the full timetable.
Rule 4 does not itself fix a fee, a form or a decision period. Those depend on what the Board publishes on its website, so check there before you plan around them.
What must a registered Consent Manager do?
A registered Consent Manager must act in a fiduciary capacity towards the Data Principal, avoid conflicts with Data Fiduciaries, keep a record of every consent and notice for at least seven years, never be able to read the data it helps share, never sub-contract its obligations, and report audits of its own controls to the Board.
Part B of the First Schedule lists thirteen obligations. Grouped by what they protect:
| Area | Obligation (Part B item) |
|---|---|
| The service | Let a Data Principal give consent to an onboarded Data Fiduciary, directly or through another onboarded Data Fiduciary that holds the data (1). Run a website or app as the primary way people use the service (5). |
| Blindness to content | Make data available or shared in a way that its contents are not readable by the Consent Manager (2). |
| The record | Keep a record of consents given, denied or withdrawn, the notices that preceded or accompanied each request, and each sharing with a transferee Data Fiduciary (3). Give the individual access to it, in machine-readable form on request, and keep it for at least seven years (4). |
| Accountability | No sub-contracting or assigning its obligations (6). Reasonable security safeguards against breach (7). Act in a fiduciary capacity towards the Data Principal (8). |
| Independence | Avoid conflicts of interest with Data Fiduciaries, their promoters and key managerial personnel (9), with measures covering directorships, financial interests, employment, beneficial ownership and material pecuniary relationships (10). |
| Transparency | Publish its promoters, directors, key managerial personnel and senior management, every shareholder above 2%, and every body corporate in which its insiders hold more than 2% (11). |
| Oversight | Audit its controls, its continued fulfilment of the registration conditions and its compliance, and report the outcome to the Board (12). No transfer of control by sale or merger without the Board's prior approval (13). |
The Act adds two things around this. A Data Principal can complain to the Board about a Consent Manager's breach of its obligations, and a breach of a registration condition is itself a matter the Board can inquire into and penalise under section 27.
Should your company become a Consent Manager?
Almost certainly not, unless your business is the consent layer itself. A Consent Manager earns nothing from the data, cannot read it, must be independent of the businesses that use it, and carries a fiduciary duty to individuals. That fits a neutral utility. It does not fit a company that mainly processes personal data for its own purposes.
Worth considering if you are building shared consent infrastructure for a sector (the Rules' own illustration is banking), you can hold the independence the Schedule demands, and your revenue model does not depend on the data flowing one way rather than another.
Not worth it if you are a Data Fiduciary wanting better consent on your own site, a group whose other companies are Data Fiduciaries, a software vendor whose customers are Data Fiduciaries and pay you, or a foreign company without an Indian incorporated vehicle. For all of those, the conflict rules alone are decisive before net worth comes into it.
Consent Manager vs consent management platform: what is the difference?
A Consent Manager is a Board-registered intermediary that acts for the individual across many businesses. A consent management platform is software one business runs on its own website or app to collect, enforce and prove the consents it asks for. The first needs registration under Rule 4; the second needs none.
| Consent Manager (DPDP) | Consent management platform (CMP) | |
|---|---|---|
| Legal footing | Defined in section 2(g); registered under section 6(9) and Rule 4 | No statutory status. A tool a Data Fiduciary uses to meet sections 5 and 6 |
| Who uses it | The Data Principal, through the Consent Manager's own website or app | The Data Fiduciary, embedded in its own website, app or forms |
| Who it acts for | The Data Principal, in a fiduciary capacity | The Data Fiduciary that deploys it |
| Registration | Required, with the Data Protection Board, from 13 November 2026 | None |
| Scope across fiduciaries | Many Data Fiduciaries onboarded onto one platform | One Data Fiduciary's own notices and purposes |
| Entry conditions | Company incorporated in India, net worth at least ₹2 crore, certified interoperable platform, independence from Data Fiduciaries | None beyond ordinary procurement |
| Can it read the data? | Must not be able to read personal data shared through it | Handles the consent record, not the underlying data |
| What it does | Lets one person see and change her consents to several businesses in one place, and routes consent and data-sharing instructions between them | Shows the notice, blocks non-essential trackers until a choice, records each choice against the notice version and language, and handles withdrawal on that site |
TryTrustable is a consent management platform (CMP), not a Consent Manager: it is software a Data Fiduciary runs on its own website or app to collect, enforce and evidence consent, and it is not registered with the Data Protection Board of India as a Consent Manager. The consent product is Consent by TryTrustable, a standalone consent management platform for DPDP and GDPR, and how its proof of consent works is set out separately.
What should a Data Fiduciary do if users arrive through a Consent Manager?
Treat consent given through a registered Consent Manager as consent under the Act, map it to your own purposes and notice version, stop processing promptly when it is withdrawn there, and keep your own record, because the burden of proving notice and consent under section 6(10) stays with you, not the Consent Manager.
In practice that is five things:
1. Onboard deliberately. Consent Managers serve Data Fiduciaries onboarded onto their platform. Decide which ones your users are likely to use, and treat each as an integration with an owner, not a checkbox.
2. Keep your notice as the source. Your section 5 notice, and its version, is what the person is consenting against. The Consent Manager records the notice that accompanied the request, so make sure the one it carries is the current one. The DPDP consent notice template covers what it must contain.
3. Record it on your side. A consent that arrived through a Consent Manager still needs a line in your own consent record: who, which purposes, which notice version, when, and that it came through that channel. Whatever CMP you use has to accept consent that did not originate in its own banner.
4. Honour withdrawal end to end. Under section 6(4) to (6), withdrawal must be as easy as giving consent, and once it is withdrawn you and your Data Processors must stop processing within a reasonable time. A withdrawal that arrives through a Consent Manager is no different: it has to reach every system and processor that holds the data.
5. Answer grievances for your own side. Section 13 gives a Data Principal a right to grievance redressal from a Data Fiduciary and from a Consent Manager, each for its own acts. Under Rule 14(3) both must publish the period in which they respond, and it cannot exceed ninety days. A complaint about how you handled a consent that came through a Consent Manager is still yours to answer.
Whether or not a Consent Manager is involved, the first failure most sites have is trackers loading before anyone has chosen. Run the free scan on your own domain to see what fires before consent, and check what a failure can cost in the DPDP penalty calculator.
The things people ask us
Is TryTrustable a Consent Manager registered with the Data Protection Board?
No. Under section 6(9) of the DPDP Act and Rule 4 of the DPDP Rules 2025, a Consent Manager is a registered intermediary that acts for Data Principals across many organisations. It must be a company incorporated in India with a net worth of at least two crore rupees, registered with the Board. TryTrustable is a consent management platform: software a Data Fiduciary runs on its own site. That needs no registration.
Do I need to register as a Consent Manager to collect consent on my own website?
No. Collecting consent for your own processing, through your own banner, forms or app, is what every Data Fiduciary does, and the Act puts no registration requirement on it. Registration under Rule 4 is only for a company that wants to operate a platform through which individuals manage consent given to many other Data Fiduciaries.
When can a company apply to become a Consent Manager?
From 13 November 2026, when Rule 4 of the DPDP Rules 2025 comes into force, one year after the Rules were published in the Gazette. The application goes to the Data Protection Board with the particulars and documents the Board publishes on its website, and the Board may inquire before it registers or rejects the applicant.
What net worth does a Consent Manager need?
Not less than two crore rupees, under item 4 of Part A of the First Schedule. Net worth is defined as total assets less liabilities as they appear in the company's books. The Schedule also requires sufficient technical, operational and financial capacity and a sound financial condition, so meeting the figure alone does not qualify an applicant.
Can a foreign company register as a Consent Manager?
Not directly. The first condition in the First Schedule is that the applicant is a company incorporated in India. Whether a particular Indian company qualifies then turns on the other conditions, including its independence from the Data Fiduciaries it would serve and the disclosure of significant shareholders, so a group with Data Fiduciary businesses should take advice early.
Is every Data Fiduciary required to work with a Consent Manager?
No. Section 6(7) says a Data Principal may give, manage, review or withdraw consent through a Consent Manager. It is an option for the individual, not a mandate on every business. If your users do arrive through one, consent given that way is consent under the Act, and you must honour it and any withdrawal that follows.
How long must a Consent Manager keep consent records?
At least seven years, or longer if the Data Principal agrees or the law requires it, under item 4 of Part B of the First Schedule. The record covers consents given, denied or withdrawn, the notices that accompanied each request, and every sharing of personal data with a transferee Data Fiduciary.
Most companies need a CMP, not a Consent Manager.
See what your site does before anyone consents, then look at the platform that holds those tags back and keeps the record: every choice against the notice version and language that produced it.