If you have started reading about the Digital Personal Data Protection (DPDP) Act 2023 and its rules, you have almost certainly run into the term “Consent Manager,” usually without a clear explanation of what it actually is. Is it a piece of software? A company? A regulator-approved middleman? The confusion is fair, because the consent manager is genuinely new to Indian data law, and a lot of what is written about it online blurs the legal role with the compliance tools that support it.
This guide clears that up. It explains what a consent manager is under the DPDP Act, exactly how one gets registered with the Data Protection Board, the obligations it must meet once registered, and the question most businesses actually care about: whether you need to become one or simply work with one.
Everything below is grounded in the letter of the DPDP Rules, 2025, specifically Rule 4 and the First Schedule. Where it matters, the relevant clause is named so you can verify it yourself.
What is a consent manager under DPDP Act?
A Consent Manager is a company registered with the Data Protection Board of India that gives people a single, interoperable platform to give, manage, review, and withdraw their consent for how their personal data is processed. It sits between the individual (the Data Principal) and the businesses that use their data (the Data Fiduciaries), and it is legally bound to act in the individual’s interest, not the businesses’, through a fiduciary duty defined in the DPDP Rules.
Two features make it unusual. First, it is a regulated entity: not just anyone can call themselves a consent manager. It must be an Indian company with a net worth of at least ₹2 crore and must be registered with the Board. Second, it is deliberately built to be “blind.” The rules require that consent and data pass through its platform in a form the Consent Manager itself cannot read.
That is the whole concept in a paragraph. The rest of this article unpacks each part.

Consent Manager vs. Consent Management System: an important distinction
Before going further, it is worth killing a common mix-up, because it trips up even experienced privacy teams.
- A Consent Manager (capital C, capital M) is the legal role created by the DPDP Act: a board-registered company acting as a neutral, interoperable consent intermediary.
- A consent management system, or consent management platform (CMP), is the software a business uses to capture, store, and honor consent for its own data processing.
Every data fiduciary needs some form of consent management capability to comply with the Act. Very few businesses will ever become a registered consent manager. Buying or building a consent management platform does not make you a consent manager, and you do not need to register with the board simply to manage consent for your own users. Keep this distinction in mind, because the rest of this guide uses “Consent Manager” strictly in its legal sense.
Where the Consent Manager fits in the DPDP ecosystem
The DPDP Act works with a small cast of defined players:
- Data Principal: the individual whose personal data is being processed (you and me).
- Data Fiduciary: the entity that decides why and how personal data is processed (a bank, a hospital, an e-commerce app).
- Data Processor: an entity that processes data on a fiduciary’s behalf.
- Consent Manager: the registered intermediary that lets the Data Principal control consent across many Fiduciaries from one place.
Think of the Consent Manager as a single dashboard for your consents. Instead of every app maintaining its own opaque consent settings buried three menus deep, a Data Principal can go to one trusted platform, see every business that holds a consent from them, and grant or withdraw it there. When consent is withdrawn, the instruction flows back to the relevant fiduciary.
If that architecture sounds familiar to anyone in Indian fintech, it should. It is conceptually close to the Account Aggregator model, where a regulated, consent-driven intermediary moves information between institutions without reading or retaining it. The consent manager generalizes that idea across the whole economy, not just financial data.
How a Consent Manager actually works: a real-world example
The easiest way to get this is to walk through a situation you have probably lived through.
Say you are applying for a personal loan. The lender needs to see your bank statement to check your income. Normally that means digging out a PDF, or worse, handing over your net-banking login to some aggregator you have never heard of. With a consent manager in the picture, it looks different.
You are already a user on a Consent Manager’s app; call it your consent dashboard. The lender is onboarded there too. When they need your statement, a request lands in your dashboard: “[Lender] wants to access your account statement for loan assessment.” You see exactly who is asking, for what, and for how long. You tap approve, and your bank sends the statement straight to the lender. The consent and the instruction to share both flow through the Consent Manager’s platform.
Here is the part that matters: the consent manager never sees your statement. The rules are explicit that data has to pass through in a form the consent manager cannot read. It is carrying a sealed envelope from your bank to the lender. It routes it and logs that it happened but never opens it.
And because every one of these approvals is recorded in one place, you can open your dashboard six months later, see that the lender still has standing access, and revoke it in a couple of taps. No hunting through email, no calling a helpline. That is the whole promise: your consents, visible and reversible, from a single screen.
Who can become a consent manager? Registration conditions under the DPDP Rules
This is where a lot of businesses realise the consent manager role is not for them, and that is by design. Part A of the First Schedule to the DPDP Rules, 2025, sets a deliberately high bar. To be eligible, an applicant must satisfy conditions including:
- It is a company incorporated in India. Not an LLP, not a foreign entity, not an individual.
- It has sufficient technical, operational, and financial capacity to meet its obligations.
- Its financial condition and the general character of its management are sound.
- Its net worth is not less than ₹2 crore.
- Its capital structure and earning prospects are adequate for the volume of business expected.
- Its directors, key managerial personnel, and senior management have a reputation and record of fairness and integrity.
- Its constitutional documents (MoA and AoA) lock in the key fiduciary and conflict-of-interest obligations, changeable only with the Board’s prior approval.
- Its proposed operations are in the interest of data principals.
- It is independently certified that its interoperable consent platform meets the data-protection standards and assurance framework the Board publishes and that appropriate technical and organisational measures are in place.
Read together, these conditions signal the Board’s intent: a Consent Manager should look less like a startup shipping an MVP and more like a small, well-capitalised, independently audited financial-market infrastructure. That is a feature, not a bug. The whole model depends on data principals being able to trust these intermediaries completely.

How the registration process works: Rule 4 step by step
Rule 4 of the DPDP Rules governs the mechanics. The flow is straightforward:
- Application (Rule 4(1)). An eligible company applies to the Data Protection Board, furnishing the particulars, information, and documents the Board specifies on its website.
- Inquiry and decision (Rule 4(2)). The Board may make any inquiry it sees fit to confirm the applicant meets Part A. If satisfied, it registers the company, informs it, and publishes the Consent Manager’s particulars on its website. If not satisfied, it rejects the application and communicates the reasons.
- Ongoing obligations (Rule 4(3)). Once registered, the Consent Manager must meet the obligations in Part B of the First Schedule (covered below).
- Direction to remediate (Rule 4(4)). If the Board believes a Consent Manager is not adhering to its conditions or obligations, it must give the company an opportunity of being heard, then inform it of the non-adherence and direct it to fix the issue.
- Suspension or cancellation (Rule 4(5)). If the Board considers it necessary in the interest of data principles, it may, again after a hearing and for reasons recorded in writing, suspend or cancel the registration and issue whatever directions it deems fit to protect data principles.
- Power to call for information (Rule 4(6)). The Board can require a consent manager to furnish any information it calls for.
Notice the pattern: the Board leans toward remediation before punishment, and every adverse action carries a hearing and a written-reasons requirement. That procedural fairness is baked in.
The obligations of a registered Consent Manager
Registration is the start, not the finish. Part B of the First Schedule lays out the standing duties. The most consequential ones:
Enable full consent lifecycle control. The platform must let a data principal give, manage, review, and withdraw consent, whether directly to a fiduciary or routed through another onboarded fiduciary.
Stay blind to the data. As covered above, the manner of sharing must ensure the contents are not readable by the consent manager.
Keep a complete, portable record. The consent manager must record every consent given, denied, or withdrawn; the notices that accompanied each consent request; and every instance of data sharing with a transferee fiduciary. It must give the Data Principal access to this record, provide it in machine-readable form on request, and retain it for at least seven years (or longer, if law or agreement requires).
Run a real website or app. The rules require a website or app (or both) as the primary way data principals reach the service. The Consent Manager cannot be a back-office API with no front door for individuals.
No subcontracting. A consent manager cannot subcontract or assign its obligations under the Act and Rules. The buck stops with the registered entity.
Act as a fiduciary. It must act in a fiduciary capacity toward the Data Principal, a legal standard of loyalty, meaning the individual’s interest comes first.
Avoid conflicts of interest. It must actively avoid conflicts with data fiduciaries, including through its promoters and key personnel, and put measures in place so that directorships, financial interests, employment, or beneficial ownership in fiduciaries do not compromise its neutrality.
Be transparent about ownership. It must publish, accessibly, details of its promoters, directors, KMP, and senior management; anyone holding more than 2% of its shares; related body-corporate shareholdings; and anything else the Board directs in the interest of transparency.
Submit to audit. It must maintain effective audit mechanisms and report outcomes to the Board, covering its technical and organizational controls, its continued fulfillment of registration conditions, and its adherence to the Act and Rules.
Get board approval to change control. Control of the company cannot be transferred by sale, merger, or otherwise without the Board’s prior approval.
Taken together, these obligations are what turn a “consent app” into a trusted piece of public infrastructure.
Do you need to become a Consent Manager, or just work with one?
For the vast majority of businesses reading this, the honest answer is, “You don’t need to become one.”
If you are a bank, an insurer, a hospital, an e-commerce platform, a lender, or any other business that collects personal data to serve your own customers, you are a data fiduciary. Your obligation under the DPDP Act is to obtain valid consent, honor withdrawals, secure the data, and meet the notice and rights requirements. You can do all of that with a consent management platform of your own. You do not need to register with the Board as a Consent Manager to run your own consent flows.
Becoming a registered consent manager only makes sense if your actual business is to be the neutral, interoperable consent intermediary for others, a distinct commercial model with the ₹2 crore net-worth floor, independent certification, no-sub-contracting rule, and audit obligations that come with it.
So the practical question for most teams is not “How do we register as a consent manager?” It is “how do we make our own consent management DPDP-ready?” capturing granular, purpose-specific consent, storing an auditable record, and making withdrawal as easy as granting. That is a software and process problem, and it is solvable today.
Conclusion
The Consent Manager is one of the more forward-looking ideas in the DPDP framework: a regulated, blind, fiduciary intermediary that hands control of consent back to individuals and makes it portable across the businesses they deal with. It is a high-bar role, Indian incorporation, ₹2 crore net worth, independent certification, seven-year records, audits, and board oversight, and it is not something most companies will, or should, become.
What every data fiduciary does needs is consent management; it can stand behind when the board comes asking: granular, purpose-bound, fully logged, and easy to withdraw. Getting that right is the real DPDP consent task in front of most Indian businesses today.
FAQs
Ques: Is a consent manager the same as a consent management platform (CMP)?
Ans: No. A consent manager is a board-registered company performing a defined legal role under the DPDP Act. A consent management platform is software a business uses to manage consent for its own processing. You can run a CMP without ever being a consent manager.
Ques: What is the minimum net worth to register as a consent manager?
Ans: Under Part A of the First Schedule to the DPDP Rules, 2025, the applicant’s net worth must be not less than ₹2 crore, along with other technical, operational, financial, and integrity conditions.
Ques: How long must a consent manager keep consent records?
Ans: At least seven years, or longer if the Data Principal and Consent Manager agree or if another law requires it. The record must also be available to the data principal in machine-readable form on request.
Ques: Can a consent manager read the personal data flowing through it?
Ans: No. The rules require that data be shared in a manner that is not readable by the consent manager. It facilitates the movement of data and consent without accessing the contents.
Ques: Who registers and regulates consent managers?
Ans: The Data Protection Board of India. It grants registration under Rule 4, can direct a consent manager to remediate non-compliance, and can suspend or cancel registration, always after a hearing and with written reasons.
Ques: Does every business need to appoint or use a consent manager?
Ans: No. Data principals may choose to use a consent manager, but the Act does not force every data fiduciary to route consent through one. Businesses still carry their own consent obligations regardless.
(This article is for general informational purposes and reflects the DPDP Act, 2023, and the DPDP Rules, 2025, as published. It is not legal advice; for how these obligations apply to your specific business, consult a qualified data-protection professional.)
