Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Back To Home
Consent Manager

Introduction
India’s Digital Personal Data Protection Act, 2023 introduces the concept of a Consent Manager, as a person registered with the Board who acts as a single point of contact to enable individuals to give, review, and withdraw consent across multiple organisations through a single interoperable platform.
It is important to note that the DPDP Rules do not require data fiduciaries to use a Consent Manager. Data fiduciaries may continue to obtain consent directly from individuals, without engaging a Consent Manager, provided they can independently comply with the notice, consent, withdrawal, and record-keeping requirements under the DPDP Act.
However, in practice, sectors that depend on the exchange of data across multiple entities, such as financial services, healthcare, public benefit systems, and credit underwriting, may increasingly prefer Consent Managers because they offer a common framework that supports data portability, auditability, and user control.
For organisations considering this role, registration is not merely a procedural exercise. This article explains the Consent Manager framework, identifies who is eligible to apply, and provides a practical checklist of the legal and technical readiness that aspiring Consent Managers should develop.
Conditions for Registration of a Consent Manager
The DPDP Rules, 2025 lay down specific conditions that an applicant must satisfy to be registered as a Consent Manager. It has been provided under First Schedule Part A of the rules and is as follows:
Incorporation in India: The applicant must be a company incorporated in India.
Technical, Operational, and Financial Capacity: The applicant must have sufficient technical, operational, and financial capacity to fulfil its obligations as a Consent Manager.
Sound Financial Condition and Management: The financial condition of the applicant and the overall character of its management must be sound.
Minimum Net Worth: The applicant must have a net worth of not less than two crore rupees.
Adequate Business Prospects: The expected volume of business available to the applicant, along with its capital structure and earning prospects, must be adequate.
Fairness and Integrity of Management: The directors, key managerial personnel, and senior management of the applicant company must have a general reputation and record of fairness and integrity.
Operations in the Interest of Data Principals: The operations proposed by the applicant must be in the interests of Data Principals.
Independent Certification: It must be independently certified that: the applicant’s interoperable platform, which enables a Data Principal to give, manage, review, and withdraw consent, is consistent with the data protection standards and assurance framework published by the Board on its website from time to time; and appropriate technical and organisational measures are in place to ensure compliance with these standards and framework.
Obligations of a Consent Manager
The DPDP Rules set out specific obligations that a Consent Manager must fulfil when providing consent management services to Data Principals. These are defined under First Schedule, Part B of the Rules and are as follows:
Enabling Consent: The Consent Manager shall enable a Data Principal using its platform to give consent for the processing of her personal data by a Data Fiduciary onboarded onto the platform, either directly to such Data Fiduciary or through another onboarded Data Fiduciary that maintains such personal data with the consent of that Data Principal.
Ensuring Data Confidentiality: The Consent Manager shall ensure that the manner in which personal data is made available or shared is such that its contents are not readable by the Consent Manager.
Maintaining Records: The Consent Manager shall maintain on its platform a record of:
consents given, denied, or withdrawn by the Data Principal;
notices preceding or accompanying requests for consent; and
sharing of the Data Principal’s personal data with a transferee Data Fiduciary.
Providing Access to Records: The Consent Manager:
shall give the Data Principal access to such record;
shall, upon request and in accordance with its terms of service, make the information contained in the record available to the Data Principal in machine-readable form; and
shall maintain the record for at least seven years, or for a longer period as agreed between the Data Principal and the Consent Manager or as required by law.
Website or App: The Consent Manager shall develop and maintain a website or app, or both, as the primary means through which a Data Principal may access its services.
Restriction on Sub-contracting: The Consent Manager shall not sub-contract or assign the performance of any of its obligations under the Act and these rules.
Security Safeguards: The Consent Manager shall take reasonable security safeguards to prevent personal data breaches.
Fiduciary Capacity: The Consent Manager shall act in a fiduciary capacity in relation to the Data Principal.
Avoiding Conflict of Interest: The Consent Manager shall avoid conflicts of interest with Data Fiduciaries, including with respect to their promoters and key managerial personnel.
Measures to Prevent Conflicts: The Consent Manager shall have measures in place to ensure that no conflict of interest arises due to its directors, key managerial personnel, or senior management holding a directorship, financial interest, employment, beneficial ownership in Data Fiduciaries, or having a material pecuniary relationship with them.
Publication of Information: The Consent Manager shall publish, in an easily accessible manner on its website or app, or both, information regarding:
the promoters, directors, key managerial personnel, and senior management of the company registered as a Consent Manager; and
every person holding shares in excess of two per cent of the shareholding of the company registered as a Consent Manager.
Features of a Good Consent Management Platform (CMP)
A Consent Management Platform (CMP) of a Consent Manager enables it to request, obtain, and record user consent for data collection and tracking technologies such as cookies and pixels. It displays consent banners, stores users’ consent preferences, and integrates with other systems to ensure that personal data is processed lawfully.
By managing consent through a centralised system, they reduce compliance risks and strengthen user trust. A CMP enables businesses to automate compliance with these requirements while providing a consistent user experience across different regions and devices. Moreover, it also assists marketing and analytics teams in maintaining data accuracy and accountability by ensuring that only data for which valid consent has been obtained is used for personalisation and reporting.
Implementation of Technical and Organisational Security Measures
Consent Manager registration is scheduled to commence on 13 November 2026. Although this marks the opening of the registration window, businesses should not view it as the point at which preparation should begin. Entities intending to operate as Consent Managers should begin aligning their financial, technical, and compliance frameworks well in advance of the registration date so that potential bottlenecks can be avoided when the application process opens.
Considering the minimum net worth requirement of ₹2 crore, there exists a need for technical certifications such as ISO 27001 or SOC 2, and the expected governance and documentation obligations. Organisations that postpone preparation may encounter difficulties in satisfying the eligibility requirements within the required timeframe.
ISO (International Organisation for Standardisation) certifications are globally recognised standards that ensure quality, safety, and efficiency in products, services, and systems. It has many benefits, including:
Reduced Defects: By identifying and addressing quality issues early in the process, ISO certification can minimise defects and waste.
Risk Management: ISO certification helps identify and mitigate risks, reducing the likelihood of costly errors or disruptions, including regulatory fines.
Continuous Improvement: The ISO framework encourages a culture of continuous improvement, leading to ongoing optimisation and cost savings.
Consequences of non-compliance
A registered Consent Manager is accountable to the Data Principal and is subject to inquiry by the Board for its own breaches. The DPDP Act provides for a monetary penalty of up to INR 50 crores for non-compliance by Consent Managers. In addition to monetary penalties, the Board may also direct the Consent Manager to remedy the non-compliance, suspend or cancel its registration, and issue protective directions in the interests of Data Principals.
Conclusion
The opening of Consent Manager registration represents an important step in implementing India’s data protection framework. For organisations considering this role, readiness involves more than meeting the minimum financial requirement. It requires strong corporate governance, comprehensive legal documentation, and a secure and interoperable technology platform designed on data-blind principles.
Organisations that begin preparing early, from both legal and technical perspectives, will be better positioned to complete the registration process efficiently and operate as reliable intermediaries once the framework becomes fully operational.
Want to stay ahead?
Reach out to the experts at tsaaro.com today.
Talk to a Privacy Expert
Get a free 1:1 session on AI compliance, DPDPA readiness, or incident response planning.
Related articles












