Consent Manager framework And obligations Under The DPDP Rules, 2025

Consent Manager framework And obligations Under The DPDP Rules, 2025

A Consent Manager is a company registered with the Data Protection Board that gives an individual a single, interoperable platform to give, review, manage and withdraw consent. The consent manager framework and obligations under the DPDP Rules, 2025 sit in Rule 4 and the First Schedule, notified on 13 November 2025 and commencing on 13 November 2026. Using a Consent Manager is not mandatory: a business can still collect consent directly. To register, a company must be incorporated in India, hold a net worth of at least ₹2 crore, and meet thirteen continuing obligations, from keeping consent records for seven years to never reading the data it routes.

This article sets out the consent manager framework and obligations under the DPDP Rules, 2025: who can register, how registration works, the thirteen Part B duties, how a registration is suspended or cancelled, the correct penalty scale, and how the role differs from a Data Fiduciary, a Data Processor and an off-the-shelf CMP.

The sequence is worth fixing in your mind. The draft Rules appeared on 3 January 2025, the final Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, and Rule 4 with the First Schedule switch on exactly one year later, on 13 November 2026. As of mid-2026, no entity is yet registered as a Consent Manager, so this is a get-ready topic rather than a pick-your-vendor one.

One feature sets this role apart from everything that came before it in India. A Consent Manager answers to the individual whose data is being routed, not to the businesses that onboard it. That single line of accountability is why the Rules load it with net worth, governance and audit conditions that ordinary software vendors never face.



Consent Managers under the DPDP Rules, 2025

A Consent Manager under the DPDP Rules, 2025 is a Board-registered company that runs the consent layer for individuals, and the first thing to settle is that no business is forced to use one.

A Consent Manager under the DPDP Rules, 2025 is a company registered with the Data Protection Board that gives an individual one interoperable platform to give, review, manage and withdraw consent. It is accountable to the individual, not to the businesses that use it, and using one is not mandatory.

That description tracks Section 2(g) of the Digital Personal Data Protection Act, 2023, which defines a Consent Manager as a person registered with the Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. Two terms matter here. The Data Principal is the individual the data is about. The Data Fiduciary is the business that decides why and how that data gets processed.

The four core facts:

  • Who can register: a company incorporated in India.
  • Minimum net worth: at least ₹2 crore.
  • When the regime goes live: 13 November 2026.
  • Mandatory to use one? No.

Why build a separate institution for something a business could arrange itself? Because consent in India has been scattered across dozens of privacy notices that never talked to each other. The Consent Manager is meant to be the one dashboard where a person sees every consent they have given and pulls any of them back.

How did India arrive at the consent-manager model?

India arrived at this model through a decade of constitutional and legislative build-up. The starting point is Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, the 2017 nine-judge Supreme Court ruling that held privacy to be a fundamental right under Article 21 and protected an individual’s control over their own information. The Aadhaar judgment that followed, Justice K.S. Puttaswamy (Retd.) v. Union of India, (2019) 1 SCC 1, added the proportionality and purpose-limitation standards that a consent architecture is meant to put into practice.

From there the legislative arc runs through successive Personal Data Protection Bills between 2018 and 2022 (the 2019 Bill first floated a consent-manager style intermediary), the Digital Personal Data Protection Act, 2023 that defined the role in Section 2(g), the draft Rules of 3 January 2025, and the final Rules notified on 13 November 2025. For lawyers tracking India’s evolving data-protection and privacy obligations, the Consent Manager is the first genuinely new institution the DPDP framework creates.

How India built the Consent Manager: 2017 to 2027
The DPDP consent-manager framework, from a fundamental right to a live registration regime
2017
Puttaswamy (privacy)
Supreme Court nine-judge bench holds privacy a fundamental right under Article 21
2018–2022
PDP Bill drafts
Successive Personal Data Protection Bills; the 2019 Bill first floats a consent-manager style intermediary
Aug 2023
DPDP Act 2023 enacted
Section 2(g) defines the Consent Manager
3 Jan 2025
Draft Rules published
Draft DPDP Rules released for consultation
13 Nov 2025
Final DPDP Rules notified
Digital Personal Data Protection Rules, 2025 notified; now operative law
13 Nov 2026
Consent Manager regime live
Rule 4 and the First Schedule commence; registration window opens
13 May 2027
Data Fiduciary obligations enforceable
Broader Data Fiduciary obligations become enforceable
As of mid-2026, no entity is yet registered as a Consent Manager.
LawSikho

Is it mandatory to use a Consent Manager under the DPDP Act?

No. Using a Consent Manager is not mandatory under the DPDP Act, and this is the single most common misunderstanding on the subject. A Data Fiduciary may keep collecting consent directly, provided it meets the Act’s notice and consent standards. The Consent Manager is an optional, regulated channel, not a compulsory gateway.

Here’s the thing many businesses get backwards: onboarding a Consent Manager does not move your compliance obligations onto it. The Data Fiduciary still owes the Data Principal the primary duties, which include lawful notice, purpose limitation, security safeguards and breach notification. The Consent Manager runs the consent plumbing. It does not absorb your accountability for how you process the data afterwards.

So if a Consent Manager is optional, why would any business use one? Because a clean, auditable, withdrawable consent trail is genuinely hard to build well, and a registered intermediary that specialises in exactly that can lower a company’s own compliance risk. Just don’t mistake it for a way to offload your own accountability.

Who can register as a Consent Manager in India?

A Consent Manager must be a company incorporated in India that meets nine conditions in Part A of the First Schedule to the DPDP Rules, 2025. The conditions read less like a software checklist and more like the licensing gate for a regulated financial intermediary.

The nine Part A conditions are:

  1. The applicant is a company incorporated in India.
  2. It has sufficient technical, operational and financial capacity to meet its obligations.
  3. Its financial condition is sound and its management is of good character.
  4. Its net worth is not less than ₹2 crore (₹2,00,00,000).
  5. It has an adequate volume of business, capital structure and earning prospects.
  6. Its directors and key or senior management have a general reputation for fairness and integrity.
  7. Its articles of association bind it to its obligations, and any amendment needs Board approval.
  8. Its operations are conducted in the interest of Data Principals.
  9. It holds an independent certification that its platform meets the data-protection and interoperability standards set by the Board.

Two of these carry most of the weight. The ₹2 crore net worth is measured in the ordinary company-law sense (assets minus liabilities on audited accounts), and the Rule fixes it as a floor rather than an indexed figure, so it sets a minimum, not a moving target. The articles-of-association condition is the unusual one: it turns the company’s own constitution into a compliance instrument, and locks amendments behind the Board.

Does an overseas entity have a route in? Not directly. Incorporation in India is the threshold condition, so a foreign company would have to work through an Indian subsidiary that itself satisfies every Part A test.

Does the company-form requirement rule out a society or trust?

The primary Rule text says “a company incorporated in India,” and that is the position to write down. Some secondary commentary loosely describes the eligible entity as a “company, society or trust,” but the notified First Schedule Part A language is “company.” Where the two diverge, the notified text governs, and a cautious adviser treats the “society or trust” framing as unconfirmed until the Board clarifies it.

How does a company register as a Consent Manager with the Data Protection Board?

A company registers by petitioning the Data Protection Board with documentation showing it meets the Part A conditions, after which the Board investigates and either registers it, with public notice on its website, or rejects the application with reasons. The mechanic sits in Rule 4 of the Digital Personal Data Protection Rules, 2025, which frames registration as an investigated application rather than a self-declaration.

The certification requirement is the part that trips people up. An applicant must hold an independent certification that its platform meets the Board’s data-protection and technical standards, including interoperability. “Interoperable” here means the platform must speak to other systems in the consent ecosystem rather than lock a person’s consent records inside one vendor, so a Data Principal can carry their consent picture across services. That is an engineering and standards commitment, not a paperwork line.

What experienced advisers know is that the real gate is this certification bar, not the petition itself. Filing documents is straightforward; building a platform that a Board-recognised certifier will sign off on, before a single client is live, is where the time and money go. Because no entity is registered yet, there is no worked precedent to copy, only the notified text to build against.

What does it cost to become a Consent Manager?

The Rules do not fix an application fee, so the honest answer is that the real cost is not a filing charge at all. It is the ₹2 crore net worth you must hold, the independent certification of the platform, and the governance build (articles of association, conflict controls, audit capability) that Part A and Part B demand. Anyone quoting you a neat “registration fee” is inventing it: the notified text sets none.

What obligations must a registered Consent Manager meet under the DPDP Rules?

A registered Consent Manager must meet thirteen continuing obligations set out in Part B of the First Schedule to the DPDP Rules, 2025, and they run for the life of the registration, not just at entry. This is the section most competitor pages thin out. To keep thirteen duties readable, they group into three clusters.

Consent and record duties

Four of the thirteen obligations govern consent and records. The Consent Manager must enable a Data Principal to give consent through its platform, directly or via onboarded Data Fiduciaries. It must also make its website or app the primary means of access.

On the records side, it must maintain a log of every consent given, denied or withdrawn, along with the accompanying notices and any sharing with transferee fiduciaries, and retain that log for at least seven years. And it must provide those records to the Data Principal in machine-readable form on request.

The seven-year retention duty is longer than many startups plan for, and it is not optional. A Consent Manager that deletes consent logs after a year to save storage has breached Part B.

Data-handling and security duties

Four further obligations govern how data moves and how it is secured. The manner in which the Consent Manager makes personal data available or shares it must keep the contents unreadable by the Consent Manager itself. It may not sub-contract or assign any of its obligations.

It must also maintain reasonable security safeguards to prevent a personal data breach. And it must act in a fiduciary capacity toward the Data Principal at all times.

Can a Consent Manager read the personal data it routes? No. The non-readability duty means the operator carries the data without being able to see its contents, which is the sharpest line in the whole schedule and the one that quietly rules out most existing consent tools.

Governance, conflict and transparency duties

The last five obligations are governance ones, and they are unusually heavy for a technology company. The Consent Manager must avoid conflicts of interest with Data Fiduciaries and their key personnel, maintain internal controls and director disclosures to prevent such conflicts, and publicly disclose its promoters, directors, any shareholding above 2%, and any information the Board directs. It must undergo periodic audits of its technical and organisational controls and its continued eligibility, reported to the Board. And any transfer of control, whether by sale, merger or otherwise, needs prior Board approval.

This is also where a common question gets its answer: can a Consent Manager also be a Data Fiduciary or Data Processor? No, because the conflict-of-interest and independence duties are designed precisely to stop the neutral consent intermediary from also being a party with a commercial stake in the data. iPleaders has a useful companion piece on operational DPDP compliance for Indian businesses that sits alongside this obligations map.

How can a Consent Manager’s registration be suspended or cancelled?

The Data Protection Board can suspend or cancel a Consent Manager’s registration after giving it an opportunity of being heard, and the power runs throughout the registration’s life. Most competitor pages stop at how you get in. The Rules are just as concerned with how you lose it.

The lifecycle is layered. A registered Consent Manager must fulfil every Part B obligation, and on non-adherence the Board notifies it and directs corrective action after giving it a chance to respond. If that does not resolve matters, the Board may suspend or cancel the registration, again only after an opportunity of being heard, where doing so serves the interest of Data Principals.

The Board can also issue protective directions in the meantime, and it may demand any information from the Consent Manager it needs for oversight.

What happens to the consent records if a Consent Manager shuts down or loses its registration? The Rules do not leave that dangling. The seven-year retention duty still bites, and the Board’s power to issue protective directions in the Data Principals’ interest is the tool meant to stop consent history from evaporating when an operator exits.

Consent Manager, Data Fiduciary, Data Processor and CMP compared

A Consent Manager, a Data Fiduciary, a Data Processor and a CMP occupy four different positions in the DPDP scheme, and only the first is registered with the Board and accountable to the individual. Readers conflate these four constantly, so here is the clean split.

Attribute Consent Manager Data Fiduciary Data Processor CMP (software)
Registered with the Board? Yes No (but may be a Significant Data Fiduciary) No No
Accountable to whom? The Data Principal The Data Principal The Data Fiduciary The Data Fiduciary that buys it
Decides purpose of processing? No Yes No (acts on instructions) No
Minimum net worth ₹2 crore Not applicable Not applicable Not applicable
Can read the personal data? No (non-readability duty) Yes Per contract Depends on the product
Mandatory to use? No Not applicable Not applicable No

The Data Fiduciary decides why and how personal data is processed and owes the primary duties to the individual. The Data Processor processes data on the fiduciary’s instructions and answers to the fiduciary, not to the individual. The CMP, or Consent Management Platform, is off-the-shelf software a business buys to manage cookies and preferences on its own behalf, so it serves the fiduciary and is not registered with anyone. The Consent Manager is the only one of the four that is Board-registered, carries a net worth floor, and answers to the Data Principal.

Does appointing a Consent Manager remove the need for a Data Protection Officer? No. Those are different roles, and it helps to separate the Consent Manager (an external, registered intermediary) from the Data Protection Officer, who is accountable inside a company. One runs the consent layer for individuals; the other sits within a Significant Data Fiduciary and answers to its board and to regulators.

There is a live academic debate worth flagging: will Consent Managers act as genuine gatekeepers of individual autonomy, or drift into instruments of the larger fiduciaries that fund them? The Rules answer that structurally, through the conflict-of-interest rules and the 2% shareholding disclosure, but the concern is real enough that a serious adviser keeps it in view.

Consent Manager vs Data Fiduciary vs Data Processor vs CMP
Four different positions under the DPDP scheme — only one is Board-registered and accountable to you
Roles under the Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025
Attribute Consent Manager Data Fiduciary Data Processor CMP (software)
Registered with the Board? Yes No (but may be a Significant Data Fiduciary) No No
Accountable to whom? The Data Principal The Data Principal The Data Fiduciary The Data Fiduciary that buys it
Decides purpose of processing? No Yes No (acts on instructions) No
Minimum net worth ₹2 crore Not applicable Not applicable Not applicable
Can read the personal data? No (non-readability duty) Yes Per contract Depends on the product
Mandatory to use? No Not applicable Not applicable No
Source: Digital Personal Data Protection Act, 2023; Digital Personal Data Protection Rules, 2025 (First Schedule).
LawSikho

What penalties apply if a Consent Manager breaches its duties?

The DPDP Act’s Schedule sets civil financial penalties adjudicated by the Data Protection Board, with no imprisonment attached to any of them. This is where accuracy matters most, because ranking content on this topic gets it wrong.

The scale, set in the Schedule to the Digital Personal Data Protection Act, 2023, runs to three headline figures. Failure to take reasonable security safeguards attracts a penalty of up to ₹250 crore, the top of the scale. Failure to notify a personal data breach to the Board or to affected Data Principals attracts up to ₹200 crore, and several consent and general-duty breaches attract up to ₹50 crore.

The practical reality is that these are ceilings, not tariffs. Penalties are assessed per instance and can be cumulative across distinct violations, and the Board weighs mitigating and aggravating factors rather than auto-applying the maximum.

One correction is worth making explicitly, because ranking pages get it wrong. There is no criminal imprisonment anywhere in the DPDP Act. And the “₹500 crore” civil figure circulating in some vendor content is wrong: the civil maximum is ₹250 crore. A page that mentions a jail term or a ₹500 crore cap has the law wrong, and repeating either figure is the pitfall to avoid.

Should your startup become a Consent Manager, or simply use one?

For most startups the realistic answer is to use a Consent Manager, not to become one, because the ₹2 crore net worth and the conflict-of-interest and control-transfer rules make it closer to a regulated intermediary than to ordinary SaaS. Becoming one is a capital-and-governance decision, not a product decision, and it only makes sense if consent infrastructure is your business, not a feature of it.

So how would a Consent Manager even make money if it cannot monetise the data? It charges the businesses that onboard for the service itself: the consent plumbing, the audit trail, the interoperability and the records access. It does not, and structurally cannot, monetise the personal data, which it is not even permitted to read.

The second-order effects are where this gets interesting for the profession. A new legal-advisory niche is forming around structuring these entities: the articles-of-association clauses, the ₹2 crore capitalisation, the conflict-of-interest governance and the audit frameworks are billable work that did not exist two years ago.

And because a Data Fiduciary cannot outsource its own accountability, the larger growth may sit in hybrid compliance advisory (notice design plus optional Consent-Manager integration) rather than in pure Consent-Manager adoption. If your team is drafting the surrounding agreements, the data-protection clauses in your technology contracts are where this decision actually lands on paper. For those weighing the field as a whole, it also opens a career in international data protection and privacy law.

What comes next for Consent Managers in India?

The near-term outlook points to a new compliance-tech sub-market forming around registered Consent Managers, with first registrations expected only after the regime goes live on 13 November 2026. Early signals suggest India’s “consent layer” is likely to converge over time with the Account Aggregator framework in finance and with health-data systems such as ABDM, as the Board’s interoperability standards settle. Practitioners expect the Board’s registration, audit and suspension machinery to become operational through 2026 and 2027, and those early enforcement postures will set market expectations.

Frequently asked questions

1. What is a Consent Manager under the DPDP Act? A Consent Manager is a company registered with the Data Protection Board that gives an individual a single, interoperable platform to give, manage, review and withdraw consent. It acts as a single point of contact for the Data Principal and is accountable to that individual, not to the businesses that onboard it.

2. What does an “interoperable” consent platform mean? Interoperable means the platform can exchange consent information with other systems in the ecosystem rather than trapping a person’s records inside one vendor. In practice, it lets a Data Principal carry a single, portable picture of their consents across different services and fiduciaries.

3. When were the DPDP Rules, 2025 notified? The final Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025. The draft version had been published earlier, on 3 January 2025, for consultation.

4. What is the ₹2 crore net worth requirement for a Consent Manager? Part A of the First Schedule requires an applicant company to have a net worth of not less than ₹2 crore (₹2,00,00,000). It is a floor rather than an indexed figure, measured in the ordinary company-law sense of assets minus liabilities on audited accounts.

5. Does a foreign company qualify as a Consent Manager? No. The applicant must be a company incorporated in India. A foreign group would need an Indian subsidiary that itself satisfies every Part A condition, including the ₹2 crore net worth and the governance requirements.

6. Are there any Consent Managers registered in India yet? No entity is registered as a Consent Manager as of mid-2026. Registration cannot open before the regime commences on 13 November 2026, so this remains a get-ready, first-mover space.

7. When do the Consent Manager rules come into force? Rule 4 and the First Schedule, which contain the entire registration and obligations regime, commence on 13 November 2026, one year after the Rules were notified. Broader Data Fiduciary obligations become enforceable on 13 May 2027.

8. How long must a Consent Manager keep consent records? At least seven years. The retention covers consents given, denied and withdrawn, the accompanying notices, and any sharing with transferee fiduciaries.

9. Can a Consent Manager read the personal data it routes? No. Part B requires that the manner of sharing keep the data’s contents unreadable by the Consent Manager itself, so it moves data without being able to see it. This non-readability duty is the single hardest constraint in the schedule.

10. How does a Consent Manager make money without monetising data? It charges the businesses that onboard for the consent service, the audit trail, the interoperability and records access. It cannot monetise the personal data, which it is not permitted to read, so its revenue comes from the infrastructure, not the data.

11. Is a Consent Management Platform (CMP) the same as a Consent Manager? No. A CMP is off-the-shelf software a business buys to manage cookies and preferences on its own behalf, serving the business. A registered Consent Manager is a Board-registered institution that serves the individual and carries a net worth floor and statutory duties.

12. Does appointing a Consent Manager remove our need for a DPO? No. A Data Protection Officer is an individual accountable inside a Significant Data Fiduciary, while a Consent Manager is an external registered intermediary. They are separate roles that do not substitute for each other.

13. How is a Consent Manager different from an RBI Account Aggregator? Both run an interoperable, consent-based data-sharing layer, and the Account Aggregator model (live in finance since 2021) is the closest existing analogue. The difference is domain and regulator: Account Aggregators operate in the RBI’s financial-data space, while Consent Managers operate across personal data under the Data Protection Board.

14. Can a Consent Manager also be a Data Fiduciary or Data Processor? No. The Part B conflict-of-interest and independence duties are designed to keep the neutral consent intermediary from also being a party with a commercial stake in the data it routes. Combining the roles would breach those duties.

References

Case Law

  1. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1. Supreme Court of India, nine-judge Constitution Bench, 24 August 2017; privacy held to be a fundamental right under Article 21.
  2. Justice K.S. Puttaswamy (Retd.) v. Union of India (Aadhaar), (2019) 1 SCC 1. Supreme Court of India, five-judge Constitution Bench, 26 September 2018; developed proportionality and purpose-limitation standards for data collection.

Statutes

  1. Digital Personal Data Protection Act, 2023. Sections cited: 2(g) (definition of Consent Manager) and the Schedule (financial penalties).
  2. Digital Personal Data Protection Rules, 2025, Rule 4 (registration and obligations of a Consent Manager); First Schedule, Part A (conditions for registration) and Part B (thirteen continuing obligations).

This article is for informational purposes only and does not constitute legal advice. For specific legal guidance, consult a qualified legal professional.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *