The only role in the Act that works for her, not for you
7 October 2026
Sec. 2(g) makes a Consent Manager a person registered with the Board acting for the Data Principal. Why it is not a consent management platform.
The Consent Manager is the one role in the Digital Personal Data Protection Act, 2023 that is licensed rather than merely defined, and the one this market mislabels most often. Software sold to a business to collect that business's own consent is not a Consent Manager. The difference is whose side the role is on.
The definition, in the Act's words
"Consent Manager" means a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform.
That is Sec. 2(g), and three phrases in it are load-bearing: registered with the Board, single point of contact and interoperable. A platform serving one business is not a single point of contact for anything.
Sec. 6 adds the mechanics. Sec. 6(7) lets a Data Principal give, manage, review or withdraw her consent to the Data Fiduciary through a Consent Manager; Sec. 6(8) makes the Consent Manager accountable to her and requires it to act on her behalf; Sec. 6(9) requires registration with the Board on prescribed conditions.
Rule 4 of the DPDP Rules, 2025 is where those conditions landed. Rule 4(1) lets a person meeting Part A of the First Schedule apply; Rule 4(2) lets the Board inquire and then either register and publish its particulars or reject with reasons; Rule 4(3) binds a registrant to the thirteen obligations in Part B; Rule 4(5) lets the Board suspend or cancel after a hearing.
The same thing, in one sentence
A Consent Manager is a company registered with the Data Protection Board that gives a person one place to give and withdraw consent across many businesses, and that works for her rather than for them.
A worked example
The First Schedule supplies its own. A platform P is maintained by a Consent Manager and X is a registered user of it. Bank B1 sends a request on P for consent to process the personal data in her bank account statement.
In the Schedule's first case she uses P to give that consent directly to B1 and gives B1 access to the statement in her digital locker. In the second her account is with bank B2, so she routes her consent through B2 to B1 and instructs B2 to send the statement.
One screen, two banks, her decision, and a record of it that is hers. A woman in Lucknow banking with two banks today manages those permissions in two apps.
What a Consent Manager is not
It is not a consent management platform. This is the confusion that matters commercially, and Part B of the First Schedule settles it in three items a vendor-side product cannot satisfy by design. Item 8 requires the Consent Manager to act in a fiduciary capacity in relation to the Data Principal. Items 9 and 10 require it to avoid conflict of interest with Data Fiduciaries, down to its own directors and senior management holding employment or beneficial ownership in one. Item 2 requires that personal data be made available or shared in a manner whose contents are not readable by it.
A platform a Data Fiduciary buys to run its own notice and consent is accountable to its customer, is in a commercial relationship with a Data Fiduciary by definition, and reads the data it handles. Each is a disqualifier. Consent Manager registration under Rule 4 works through the conditions in detail.
It is not a role a Data Fiduciary needs to enter to be compliant: if you collect consent for your own processing you are a Data Fiduciary, and Sec. 5, Sec. 6 and Sec. 8 are your provisions. Nor is it a Data Processor, which acts on behalf of a Data Fiduciary under Sec. 2(k) — item 6 of Part B bars a Consent Manager from sub-contracting any of its obligations at all.
And it is not something anyone is today. Rule 1(3) brings Rule 4 into force one year after the Rules were published — they carry G.S.R. 846(E) and the date 13 November 2025, so Rule 4 commences on 13 November 2026. Until the register exists nobody is on it, this company included.
What follows from being one
Part A of the First Schedule sets nine conditions for entry, and they are capital and governance conditions rather than feature requirements: incorporation in India, a net worth of not less than two crore rupees, a sound general character of management, and independent certification that the interoperable platform matches the framework the Board publishes, among them.
Part B's thirteen obligations then run for as long as the registration does, and the record-keeping ones are heaviest. Item 3 requires a record of consents given, denied and withdrawn, of the notices preceding or accompanying each request, and of every sharing with a transferee Data Fiduciary. Item 4 requires that record to be accessible to her, available machine-readable on request, and kept for at least seven years. Item 13 bars a transfer of control without the Board's previous approval.
One duty reaches it from elsewhere: Sec. 13(1) gives the Data Principal a right of grievance redressal against a Consent Manager as well as a Data Fiduciary, and Rule 14(1) requires it to publish the means of making such a request.
Where to go next
The Act, from the beginning places Sec. 6(7) to Sec. 6(9) among the consent provisions, and what commences when covers the 13 November 2026 date. Our own consent management module is built for the Data Fiduciary side of Sec. 5 and Sec. 6, which is a different job — and we say so rather than borrow the name.