DPDP Consent Manager

DPDP Consent Manager
and registration under the DPDP Rules 2025.

What the Act means by a Consent Manager, the conditions a company has to meet to register under Rule 4 from 13 November 2026, what it must do once registered, and why it is a different thing from the consent management platform on your own site.

Section 2(g)Section 6(7)–(9)Rule 4First Schedule

Last updated Published by TryTrustableNot legal advice

07

What should a Data Fiduciary do if users arrive through a Consent Manager?

Treat consent given through a registered Consent Manager as consent under the Act, map it to your own purposes and notice version, stop processing promptly when it is withdrawn there, and keep your own record, because the burden of proving notice and consent under section 6(10) stays with you, not the Consent Manager.

In practice that is five things:

1. Onboard deliberately. Consent Managers serve Data Fiduciaries onboarded onto their platform. Decide which ones your users are likely to use, and treat each as an integration with an owner, not a checkbox.

2. Keep your notice as the source. Your section 5 notice, and its version, is what the person is consenting against. The Consent Manager records the notice that accompanied the request, so make sure the one it carries is the current one. The DPDP consent notice template covers what it must contain.

3. Record it on your side. A consent that arrived through a Consent Manager still needs a line in your own consent record: who, which purposes, which notice version, when, and that it came through that channel. Whatever CMP you use has to accept consent that did not originate in its own banner.

4. Honour withdrawal end to end. Under section 6(4) to (6), withdrawal must be as easy as giving consent, and once it is withdrawn you and your Data Processors must stop processing within a reasonable time. A withdrawal that arrives through a Consent Manager is no different: it has to reach every system and processor that holds the data.

5. Answer grievances for your own side. Section 13 gives a Data Principal a right to grievance redressal from a Data Fiduciary and from a Consent Manager, each for its own acts. Under Rule 14(3) both must publish the period in which they respond, and it cannot exceed ninety days. A complaint about how you handled a consent that came through a Consent Manager is still yours to answer.

Whether or not a Consent Manager is involved, the first failure most sites have is trackers loading before anyone has chosen. Run the free scan on your own domain to see what fires before consent, and check what a failure can cost in the DPDP penalty calculator.

Questions

The things people ask us

Is TryTrustable a Consent Manager registered with the Data Protection Board?

No. Under section 6(9) of the DPDP Act and Rule 4 of the DPDP Rules 2025, a Consent Manager is a registered intermediary that acts for Data Principals across many organisations. It must be a company incorporated in India with a net worth of at least two crore rupees, registered with the Board. TryTrustable is a consent management platform: software a Data Fiduciary runs on its own site. That needs no registration.

Do I need to register as a Consent Manager to collect consent on my own website?

No. Collecting consent for your own processing, through your own banner, forms or app, is what every Data Fiduciary does, and the Act puts no registration requirement on it. Registration under Rule 4 is only for a company that wants to operate a platform through which individuals manage consent given to many other Data Fiduciaries.

When can a company apply to become a Consent Manager?

From 13 November 2026, when Rule 4 of the DPDP Rules 2025 comes into force, one year after the Rules were published in the Gazette. The application goes to the Data Protection Board with the particulars and documents the Board publishes on its website, and the Board may inquire before it registers or rejects the applicant.

What net worth does a Consent Manager need?

Not less than two crore rupees, under item 4 of Part A of the First Schedule. Net worth is defined as total assets less liabilities as they appear in the company's books. The Schedule also requires sufficient technical, operational and financial capacity and a sound financial condition, so meeting the figure alone does not qualify an applicant.

Can a foreign company register as a Consent Manager?

Not directly. The first condition in the First Schedule is that the applicant is a company incorporated in India. Whether a particular Indian company qualifies then turns on the other conditions, including its independence from the Data Fiduciaries it would serve and the disclosure of significant shareholders, so a group with Data Fiduciary businesses should take advice early.

Is every Data Fiduciary required to work with a Consent Manager?

No. Section 6(7) says a Data Principal may give, manage, review or withdraw consent through a Consent Manager. It is an option for the individual, not a mandate on every business. If your users do arrive through one, consent given that way is consent under the Act, and you must honour it and any withdrawal that follows.

How long must a Consent Manager keep consent records?

At least seven years, or longer if the Data Principal agrees or the law requires it, under item 4 of Part B of the First Schedule. The record covers consents given, denied or withdrawn, the notices that accompanied each request, and every sharing of personal data with a transferee Data Fiduciary.

Consent on your own site

Most companies need a CMP, not a Consent Manager.

See what your site does before anyone consents, then look at the platform that holds those tags back and keeps the record: every choice against the notice version and language that produced it.