Section 1 — What Is a Consent Manager?
Q1. What exactly is a Consent Manager under DPDP?
A Consent Manager is a registered intermediary defined under Section 2(g) of the DPDP Act 2023 and governed by Rule 4 and the First Schedule of DPDP Rules 2025. It is a licensed platform that sits between users (Data Principals) and the organisations that process their data (Data Fiduciaries), enabling users to give, review, manage, and withdraw consent from a single centralised, interoperable dashboard. Think of it as a consent broker — not a tool your organisation builds internally, but an authorised third party you may optionally integrate with.
Q2. Is a Consent Manager the same as a cookie consent banner?
Q3. Who actually becomes a Consent Manager?
Specialised technology companies or fintech-grade intermediaries that build and operate centralised consent infrastructure as their primary business model. Registration requirements include: incorporation in India, minimum net worth of ₹2 crore (adjusted annually for inflation), Board-level governance with documented conflict-of-interest policies, AES-256 encrypted infrastructure certified by an independent body to DPBI standards, and a prohibition on simultaneously acting as a Data Fiduciary or processor for the same users whose consent is being managed.
Section 2 — Does My Organisation Need to Become a Consent Manager?
Q4. We are a small school / clinic / cooperative / NGO. Do we need to register as a Consent Manager?
Almost certainly not. Your organisation is a Data Fiduciary — the entity that collects and processes personal data. You are the potential customer of a Consent Manager platform, not a peer in that regulatory category. The registration pathway exists for specialised intermediary platforms whose core business is managing consent infrastructure on behalf of multiple Data Fiduciaries.
Q5. We are a startup exploring this as a business opportunity. Can we register?
Yes, but it is a serious regulated undertaking. The Consent Manager registration framework opens with the DPBI on November 13, 2026. Beyond the ₹2 crore net worth, applicants must demonstrate: a certified interoperable platform meeting DPBI technical standards, sound Board governance with independence checks, documented conflict-avoidance mechanisms covering directors and KMPs, and evidence that proposed operations genuinely serve the interests of Data Principals. The DPBI may suspend or cancel registrations for non-adherence.
Section 3 — What Does This Mean for Us as a Data Fiduciary?
Q6. What is our actual consent obligation under DPDP?
Under DPDP Act §6, you must obtain free, informed, specific, and unconditional consent before processing personal data — except where processing falls under legitimate use grounds in §7 (such as legal obligations, medical emergencies, or employment purposes). You must provide a clear notice covering: what data is collected, for what purpose, for how long, and with whom it may be shared. You must offer a functional consent withdrawal mechanism and honour withdrawal without penalising the user or making services conditional on consent that is not necessary.
Q7. Is using a registered Consent Manager mandatory for Data Fiduciaries?
No. DPDP Rules 2025 do not mandate that Data Fiduciaries route consent through a registered Consent Manager. You may build and operate your own internal consent mechanism, provided it meets the Act's requirements.
“Every organisation that collects personal data digitally is a Data Fiduciary under DPDP — a school, a cooperative, a clinic, an NGO. There is no sector exemption for small or unregulated entities. The question is not whether DPDP applies to you; it is whether your consent process will pass scrutiny by May 2027.”
— CREATIVECYBER DPO ADVISORYQ8. Then why would a small organisation use one?
Three practical reasons: (1) Audit-ready consent records — a registered Consent Manager provides timestamped, tamper-proof consent logs without you building the logging infrastructure yourself. (2) Pre-built withdrawal workflows — consent withdrawal is a legal obligation; a Consent Manager handles the UX and record-keeping. (3) Data portability — Consent Managers are required to provide consent records in machine-readable format to users on request; this is a capability you would otherwise need to build yourself. For organisations without dedicated technical teams, the integration cost may be lower than the build cost.
Section 4 — Timelines
| Obligation | Consent Manager | Data Fiduciary (you) |
|---|---|---|
| Register with DPBI | ✓ Required | ✗ Not required |
| ₹2 Cr minimum net worth | ✓ Required | ✗ Not applicable |
| Certified interoperable platform | ✓ Required | ✗ Not required |
| AES-256 encrypted infrastructure | ✓ Required | ⚠ Proportionate security safeguards |
| Issue consent notice to users | ✗ Not their role | ✓ Required |
| Enable consent withdrawal | ✓ Must facilitate | ✓ Must honour |
| Consent record retention (7 years) | ✓ Required | ✓ Required (own records) |
| Conflict-of-interest governance | ✓ Required | ⚠ General fiduciary obligations apply |
| Grievance redressal mechanism | ✓ Required | ✓ Required |
| Periodic audits reported to DPBI | ✓ Required | ✗ Not required (unless notified as SDF) |
Q9. When do these obligations become enforceable?
DPDP Rules were notified on November 13, 2025, with a phased implementation schedule:
Phase 1 (November 13, 2025 — already in effect): Data Protection Board of India established; administrative provisions in force. The DPBI can already receive complaints and issue directions.
Phase 2 (November 13, 2026): Consent Manager registration framework opens. Organisations meeting eligibility criteria may register with the DPBI as Consent Managers from this date.
Phase 3 (May 13, 2027): All substantive compliance obligations become enforceable — consent mechanisms, privacy notices, breach notification (72-hour to DPBI), data principal rights (access, correction, erasure, grievance), and security safeguard requirements.
Q10. We are not regulated by RBI, SEBI, or IRDAI. Does DPDP still apply to us?
Yes. The DPDP Act applies to every entity processing digital personal data within India, regardless of sector or regulatory status. A school holding student records digitally, a gym capturing member health data, a small e-commerce business storing customer addresses, an NGO managing beneficiary details — all are Data Fiduciaries under the Act. There is no blanket sector-based exemption for small or unregulated organisations. Limited exemptions exist for personal or domestic use and certain research or archival purposes, but these are narrow and do not apply to typical business processing.
Section 5 — Practical Steps for 2026
Q11. What should our organisation do right now?
Three actions for 2026 that any organisation can begin immediately:
1. Map your data. Document what personal data you collect, from whom, for what specific purpose, on what legal basis, and for how long it is retained. This is the foundation of your Record of Processing Activities (ROPA) and is a prerequisite for understanding which processing activities require consent versus those covered by legitimate use grounds.
2. Audit your current consent mechanism. A checkbox buried in terms and conditions, or a pre-ticked box, does not constitute valid consent under DPDP §6. Consent must be specific to a purpose, freely given, informed, and withdrawable. If users currently cannot withdraw consent independently — without contacting your team — that is a compliance gap that needs to be addressed before May 2027.
3. Decide your implementation approach. Either build a compliant internal consent management flow with proper audit logging, or plan to integrate with a registered Consent Manager once the framework opens in November 2026. Both paths are valid; the decision should be made based on your technical capacity, budget, and the volume of data subjects you interact with.
Q12. What consent records must we keep, and for how long?
Consent records must be retained for at least 7 years from the date of consent or from the date of its withdrawal, whichever is later. For each consent record, you must be able to demonstrate: what consent was obtained, the specific purpose for which it was given, when it was given, and whether it was subsequently withdrawn. These records must be available to the DPBI on request, and to individual users in response to a Data Subject Access Request. If your current CRM or database does not log consent with timestamps and purpose codes, that is an infrastructure gap to address during 2026.
Talk to a specialist →