Section 1 — What Is a Consent Manager?

Q1. What exactly is a Consent Manager under DPDP?

A Consent Manager is a registered intermediary defined under Section 2(g) of the DPDP Act 2023 and governed by Rule 4 and the First Schedule of DPDP Rules 2025. It is a licensed platform that sits between users (Data Principals) and the organisations that process their data (Data Fiduciaries), enabling users to give, review, manage, and withdraw consent from a single centralised, interoperable dashboard. Think of it as a consent broker — not a tool your organisation builds internally, but an authorised third party you may optionally integrate with.

THREE-PARTY RELATIONSHIP — WHO IS WHO UNDER DPDP CONSENT FRAMEWORK
DATA PRINCIPAL Your user Gives & withdraws consent Holds rights under DPDP CONSENT MANAGER Licensed intermediary DPBI registered & audited ₹2 Cr min net worth Conflict-of-interest governed NOT a role most orgs play Centralised consent dashboard DATA FIDUCIARY Your organisation Collects & processes data This is where you fit
Your organisation is the Data Fiduciary — you use a Consent Manager, you do not become one. The amber border marks the role most organisations never need to occupy.

Q2. Is a Consent Manager the same as a cookie consent banner?

Do not confuse a cookie banner with a Consent Manager A cookie consent banner is a UI element on your website. A Consent Manager under DPDP Rules 2025 is a formally registered, government-overseen intermediary subject to DPBI registration, minimum net worth requirements, certified infrastructure, and periodic audit obligations. They operate at an entirely different level of legal weight. Your cookie banner is implementation; a registered Consent Manager is a regulated entity.

Q3. Who actually becomes a Consent Manager?

Specialised technology companies or fintech-grade intermediaries that build and operate centralised consent infrastructure as their primary business model. Registration requirements include: incorporation in India, minimum net worth of ₹2 crore (adjusted annually for inflation), Board-level governance with documented conflict-of-interest policies, AES-256 encrypted infrastructure certified by an independent body to DPBI standards, and a prohibition on simultaneously acting as a Data Fiduciary or processor for the same users whose consent is being managed.

₹2 Cr
Minimum net worth to register as a Consent Manager
7 Years
Minimum consent record retention period under DPDP
May 2027
Full DPDP enforcement deadline — all obligations live
Nov 2026
Consent Manager registration framework opens with DPBI

Section 2 — Does My Organisation Need to Become a Consent Manager?

Q4. We are a small school / clinic / cooperative / NGO. Do we need to register as a Consent Manager?

Almost certainly not. Your organisation is a Data Fiduciary — the entity that collects and processes personal data. You are the potential customer of a Consent Manager platform, not a peer in that regulatory category. The registration pathway exists for specialised intermediary platforms whose core business is managing consent infrastructure on behalf of multiple Data Fiduciaries.

Q5. We are a startup exploring this as a business opportunity. Can we register?

Yes, but it is a serious regulated undertaking. The Consent Manager registration framework opens with the DPBI on November 13, 2026. Beyond the ₹2 crore net worth, applicants must demonstrate: a certified interoperable platform meeting DPBI technical standards, sound Board governance with independence checks, documented conflict-avoidance mechanisms covering directors and KMPs, and evidence that proposed operations genuinely serve the interests of Data Principals. The DPBI may suspend or cancel registrations for non-adherence.

Section 3 — What Does This Mean for Us as a Data Fiduciary?

Q6. What is our actual consent obligation under DPDP?

Under DPDP Act §6, you must obtain free, informed, specific, and unconditional consent before processing personal data — except where processing falls under legitimate use grounds in §7 (such as legal obligations, medical emergencies, or employment purposes). You must provide a clear notice covering: what data is collected, for what purpose, for how long, and with whom it may be shared. You must offer a functional consent withdrawal mechanism and honour withdrawal without penalising the user or making services conditional on consent that is not necessary.

Using a registered Consent Manager is optional for most organisations The DPDP Rules 2025 do not mandate that Data Fiduciaries route consent through a registered Consent Manager. You may manage consent through your own systems, provided your process meets the Act's requirements: clear notice, documented consent record, a functional withdrawal mechanism, and grievance redressal. A registered Consent Manager is one implementation path — not the only one.

Q7. Is using a registered Consent Manager mandatory for Data Fiduciaries?

No. DPDP Rules 2025 do not mandate that Data Fiduciaries route consent through a registered Consent Manager. You may build and operate your own internal consent mechanism, provided it meets the Act's requirements.

“Every organisation that collects personal data digitally is a Data Fiduciary under DPDP — a school, a cooperative, a clinic, an NGO. There is no sector exemption for small or unregulated entities. The question is not whether DPDP applies to you; it is whether your consent process will pass scrutiny by May 2027.”

— CREATIVECYBER DPO ADVISORY

Q8. Then why would a small organisation use one?

Three practical reasons: (1) Audit-ready consent records — a registered Consent Manager provides timestamped, tamper-proof consent logs without you building the logging infrastructure yourself. (2) Pre-built withdrawal workflows — consent withdrawal is a legal obligation; a Consent Manager handles the UX and record-keeping. (3) Data portability — Consent Managers are required to provide consent records in machine-readable format to users on request; this is a capability you would otherwise need to build yourself. For organisations without dedicated technical teams, the integration cost may be lower than the build cost.

Section 4 — Timelines

DPDP IMPLEMENTATION TIMELINE — THREE PHASES TO FULL ENFORCEMENT
1 Phase 1 Nov 13, 2025 DPBI Established Rules notified COMPLETE 2 Phase 2 Nov 13, 2026 CM Registration Opens with DPBI UPCOMING 3 Phase 3 May 13, 2027 Full Enforcement ALL obligations TARGET DATE 2025 — rules in force 2026 — your build year
Phase 1 is done — the DPBI exists and can receive complaints now. Phase 2 opens the Consent Manager pathway. Phase 3 is the enforcement deadline every organisation must plan toward.
Obligation Consent Manager Data Fiduciary (you)
Register with DPBI ✓ Required ✗ Not required
₹2 Cr minimum net worth ✓ Required ✗ Not applicable
Certified interoperable platform ✓ Required ✗ Not required
AES-256 encrypted infrastructure ✓ Required ⚠ Proportionate security safeguards
Issue consent notice to users ✗ Not their role ✓ Required
Enable consent withdrawal ✓ Must facilitate ✓ Must honour
Consent record retention (7 years) ✓ Required ✓ Required (own records)
Conflict-of-interest governance ✓ Required ⚠ General fiduciary obligations apply
Grievance redressal mechanism ✓ Required ✓ Required
Periodic audits reported to DPBI ✓ Required ✗ Not required (unless notified as SDF)
2026 is your build year — May 2027 is the enforcement deadline Full compliance obligations become enforceable on May 13, 2027. Use 2026 to map your data, audit your consent mechanism, and decide your implementation approach. Waiting for the enforcement date to start is not a viable strategy.

Q9. When do these obligations become enforceable?

DPDP Rules were notified on November 13, 2025, with a phased implementation schedule:

Phase 1 (November 13, 2025 — already in effect): Data Protection Board of India established; administrative provisions in force. The DPBI can already receive complaints and issue directions.

Phase 2 (November 13, 2026): Consent Manager registration framework opens. Organisations meeting eligibility criteria may register with the DPBI as Consent Managers from this date.

Phase 3 (May 13, 2027): All substantive compliance obligations become enforceable — consent mechanisms, privacy notices, breach notification (72-hour to DPBI), data principal rights (access, correction, erasure, grievance), and security safeguard requirements.

Q10. We are not regulated by RBI, SEBI, or IRDAI. Does DPDP still apply to us?

Yes. The DPDP Act applies to every entity processing digital personal data within India, regardless of sector or regulatory status. A school holding student records digitally, a gym capturing member health data, a small e-commerce business storing customer addresses, an NGO managing beneficiary details — all are Data Fiduciaries under the Act. There is no blanket sector-based exemption for small or unregulated organisations. Limited exemptions exist for personal or domestic use and certain research or archival purposes, but these are narrow and do not apply to typical business processing.

Section 5 — Practical Steps for 2026

Q11. What should our organisation do right now?

Three actions for 2026 that any organisation can begin immediately:

1. Map your data. Document what personal data you collect, from whom, for what specific purpose, on what legal basis, and for how long it is retained. This is the foundation of your Record of Processing Activities (ROPA) and is a prerequisite for understanding which processing activities require consent versus those covered by legitimate use grounds.

2. Audit your current consent mechanism. A checkbox buried in terms and conditions, or a pre-ticked box, does not constitute valid consent under DPDP §6. Consent must be specific to a purpose, freely given, informed, and withdrawable. If users currently cannot withdraw consent independently — without contacting your team — that is a compliance gap that needs to be addressed before May 2027.

3. Decide your implementation approach. Either build a compliant internal consent management flow with proper audit logging, or plan to integrate with a registered Consent Manager once the framework opens in November 2026. Both paths are valid; the decision should be made based on your technical capacity, budget, and the volume of data subjects you interact with.

Q12. What consent records must we keep, and for how long?

Consent records must be retained for at least 7 years from the date of consent or from the date of its withdrawal, whichever is later. For each consent record, you must be able to demonstrate: what consent was obtained, the specific purpose for which it was given, when it was given, and whether it was subsequently withdrawn. These records must be available to the DPBI on request, and to individual users in response to a Data Subject Access Request. If your current CRM or database does not log consent with timestamps and purpose codes, that is an infrastructure gap to address during 2026.

DPDP Assurance Platform CreativeCyber’s DPDP Assurance Platform helps organisations map their data, build their ROPA, implement compliant consent notices, and set up withdrawal workflows — without requiring in-house legal or technical expertise to start. The platform's Consent Management module generates purpose-specific consent notices, maintains 7-year records, and provides a grievance redressal workflow that meets the Act's requirements.

Talk to a specialist →