top of page

How to Register and Operate as a Consent Manager Under India's DPDP Act 2023 and DPDP Rules 2025

  • Writer: Kaustav Chowdhury
    Kaustav Chowdhury
  • 8 minutes ago
  • 6 min read

The Digital Personal Data Protection Rules, 2025, notified by the Ministry of Electronics and Information Technology (MeitY) on 13 November 2025, introduce the Consent Manager framework through Rule 4, which is scheduled to come into force on 13 November 2026. A Consent Manager is a registered intermediary that provides Data Principals (individuals whose personal data is processed) with an accessible, transparent, and interoperable platform to give, manage, review, and withdraw consent for the processing of their personal data. This guide walks through the eligibility requirements, registration process, technical obligations, and ongoing compliance duties for entities seeking to operate as Consent Managers under Indian law.

In practice, the Consent Manager framework creates a new category of regulated intermediary in India's data protection ecosystem, analogous to Account Aggregators in the financial sector. Entities planning to enter this space should begin preparations well before the November 2026 effective date.

Step 1: Understand the Legal Framework

The Consent Manager concept originates in Section 6(9) of the Digital Personal Data Protection Act, 2023 (DPDP Act), which provides that a Data Principal may give, manage, review, or withdraw consent through a Consent Manager. The operational details are prescribed in Rule 4 of the DPDP Rules, 2025, read with the First Schedule to the Rules.

Key statutory provisions to review before proceeding:

  • Section 6 of the DPDP Act 2023: Governs consent as a ground for processing personal data. Section 6(9) specifically provides for the Consent Manager mechanism.

  • Rule 4 of the DPDP Rules 2025: Establishes the registration framework, eligibility criteria, and operational requirements for Consent Managers.

  • First Schedule to the DPDP Rules: Prescribes specific eligibility and other requirements for registration, including corporate form and net worth requirements.

  • Section 18 of the DPDP Act: Establishes the Data Protection Board of India (DPBI) as the registering and supervisory authority for Consent Managers.

Step 2: Confirm Eligibility Requirements

The First Schedule to the DPDP Rules prescribes the following eligibility criteria for registration as a Consent Manager:

Corporate Incorporation

The applicant must be a company incorporated in India under the Companies Act, 2013. This means sole proprietorships, partnerships, LLPs, trusts, and foreign-incorporated entities are not eligible to register as Consent Managers. The company must have its registered office in India.

Minimum Net Worth

The applicant must have a minimum net worth of Rs 2 crore (approximately USD 240,000). Net worth is calculated as per the definition under the Companies Act, 2013, which means paid-up share capital plus free reserves minus accumulated losses, deferred expenditure, and miscellaneous expenditure not written off. This requirement ensures that Consent Managers have adequate financial standing to support the technological infrastructure and compliance obligations involved.

In practice, startups and early-stage entities planning to enter this space should ensure they meet the net worth threshold before filing their application. This may require a fresh capital infusion or restructuring of the balance sheet.

No Conflict of Interest

The Consent Manager must not act as a Data Fiduciary in respect of personal data processed through its platform. This means the entity cannot simultaneously collect and process personal data for its own purposes while serving as a consent intermediary for Data Principals. The separation ensures that the Consent Manager's interests are aligned with those of the Data Principal, not with the interests of the entities seeking consent.

Step 3: Prepare and File the Registration Application

Registration applications must be filed with the Data Protection Board of India (DPBI). While the DPBI has been legally established under Section 18 of the DPDP Act, as of September 2026, MeitY has initiated the process of appointing the Chairperson and Members of the Board. Applicants should monitor the DPBI's official communications for the opening of the registration window.

The application should include:

  • Certificate of incorporation and memorandum of association demonstrating the company's objects include consent management services.

  • Audited financial statements demonstrating the minimum net worth of Rs 2 crore.

  • Details of the proposed technology platform, including architecture documents, data flow diagrams, and security certifications.

  • A declaration confirming that the applicant does not and will not act as a Data Fiduciary in respect of personal data processed through its Consent Manager platform.

  • Details of the directors, key managerial personnel, and the designated compliance officer.

Step 4: Build the Technology Platform

The DPDP Act and Rules require that the Consent Manager platform be accessible, transparent, and interoperable. This imposes specific technical obligations:

Accessibility

The platform must be accessible to all Data Principals, which implies compliance with accessibility standards (such as WCAG 2.1 guidelines) and availability across multiple channels, including web and mobile interfaces. The consent dashboard should allow Data Principals to view all active consents, the identity of Data Fiduciaries to whom consent has been given, and the purposes for which consent was granted.

Transparency

The platform must present consent requests in clear and plain language, consistent with the notice requirements under Section 5 of the DPDP Act. Each consent request should clearly identify the Data Fiduciary, the categories of personal data being collected, the purpose of processing, and the Data Principal's right to withdraw consent at any time.

Interoperability

The platform must be interoperable with the systems of Data Fiduciaries and, potentially, with other Consent Managers. This is the most technically demanding requirement, as it implies the need for standardised APIs, data exchange protocols, and consent artefact formats.

In practice, entities should study the Account Aggregator framework under RBI's regulatory sandbox as a precedent. The Account Aggregator ecosystem uses a consent artefact standard (defined by the ReBIT specifications) that enables interoperable consent flows between financial information providers and financial information users. A similar standard is likely to emerge for Consent Managers under the DPDP framework.

Step 5: Implement Data Protection Safeguards

Although the Consent Manager does not process personal data for its own purposes, it handles consent artefacts and metadata that may include identifiers, timestamps, and purpose descriptions. The following safeguards are essential:

  • Encryption: All consent artefacts and related metadata must be encrypted in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).

  • Access controls: Role-based access controls must restrict who within the organisation can access consent logs and Data Principal records.

  • Audit trails: Immutable audit logs must record every consent grant, modification, and withdrawal, with timestamps and identifiers sufficient to reconstruct the consent history for any Data Principal.

  • Data minimisation: The Consent Manager should not retain personal data beyond what is strictly necessary for its consent management function. Consent artefacts should be designed to minimise the inclusion of substantive personal data.

  • Breach notification: Under the DPDP Rules, personal data breaches must be notified to the DPBI and affected Data Principals within the prescribed timelines. Consent Managers must have incident response protocols in place.

Step 6: Establish Ongoing Compliance Processes

Once registered, a Consent Manager must maintain ongoing compliance with the DPDP Act and Rules:

  • Periodic reporting: The Consent Manager may be required to submit periodic reports to the DPBI on the volume of consent transactions processed, complaints received, and security incidents.

  • Grievance redressal: A dedicated grievance redressal mechanism must be established for Data Principals who have complaints about the consent management process.

  • Annual compliance audit: The Rules may require annual audits of the Consent Manager's technical infrastructure, data protection practices, and compliance with registration conditions.

  • Renewal of registration: Registration as a Consent Manager is subject to renewal, and the DPBI may impose conditions or revoke registration for non-compliance.

Timeline and Key Deadlines

  • 13 November 2025: DPDP Rules notified; DPBI establishment provisions come into force.

  • May 2026: MeitY invites applications for DPBI Chairperson and Members.

  • 13 November 2026: Rule 4 (Consent Manager framework) scheduled to come into force.

  • 13 May 2027: Substantive compliance provisions of the DPDP Act and remaining Rules come into force.

Cited Cases and Regulatory References

  • Digital Personal Data Protection Act, 2023 -- Sections 5, 6, 6(9), 18.

  • Digital Personal Data Protection Rules, 2025 -- Rule 4, First Schedule.

  • K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1 -- Supreme Court decision recognising the fundamental right to privacy under Article 21, which forms the constitutional basis for India's data protection regime.

  • Companies Act, 2013, Section 2(57) -- Definition of 'net worth' relevant to the Rs 2 crore eligibility threshold.

  • RBI Account Aggregator Framework -- Regulatory precedent for consent-based data intermediaries in the financial sector.

Sources and References

Disclaimer: This article is for informational purposes only and does not constitute legal advice. The DPDP framework is still being implemented, and specific registration procedures may be updated as the DPBI becomes fully operational. Readers should consult qualified legal professionals for advice on data protection compliance matters.

Comments


bottom of page