Rule 4

Consent Manager registration opens13 Nov 2026

myconsent+
Learn

Registering as a Consent Manager

Last updated

Published

Follow this on Google — add MyConsent+ to your preferred sources

Consent Manager registration under the DPDP Rules 2025 opens on 13 November 2026. What the role is, what registration involves, and how to prepare for it.

The Consent Manager is the most distinctive thing in the DPDP framework, and the most widely misread. It is not a label for any product that collects consent. It is a registered role, and Rule 4 of the DPDP Rules, 2025 governs entry to it.

What the role actually is

A Consent Manager gives a Data Principal a single place to give, review, manage and withdraw consent — across Data Fiduciaries, not within one. The Act frames it as acting on behalf of the Data Principal. That framing carries the whole weight of the obligation: the Consent Manager's duty runs to the person whose data it is, not to the businesses that want to process it.

Who needs to register

If you collect consent for your own processing, you are a Data Fiduciary and Rule 4 is not your provision. Sec. 5, Sec. 6 and the rest still are. Registration matters only when you intend to stand between Data Principals and multiple Fiduciaries.

When

Registration opens on 13 November 2026. The preparation is not the application form; it is having a consent record that another organisation can act on, an interface a Data Principal can actually use to withdraw, and governance that survives the Board looking at it.

The part that takes the longest

Interoperability. A consent record that only makes sense inside your own database is not one a second Data Fiduciary can honour. Getting to a portable, verifiable record — one where a withdrawal recorded in your system provably reaches the Fiduciary that has to act on it — is the engineering work, and it is measured in quarters rather than weeks.

The five steps, in order

Five steps, and only the fourth is an application. The other four are the reason an application succeeds.

1. Establish whether you need to register

Registration applies to entities that let Data Principals manage consent across multiple Data Fiduciaries. Collecting consent for your own processing does not require it.

Sec. 6(7) lets the Data Principal give, manage, review and withdraw consent through a Consent Manager, and Sec. 6(9) requires every Consent Manager to be registered with the Board, subject to prescribed technical, operational, financial and other conditions.

A Consent Manager has to give and withdraw consent on behalf of a Data Principal across Fiduciaries, which requires a consent record that is portable and machine-readable rather than internal to one product.

Part A item 9 makes the platform itself the subject of an independent certification, against such data protection standards and assurance framework as the Board may publish on its website.

3. Meet the obligations of the role before applying

A Consent Manager acts on behalf of the Data Principal and is accountable to them. The technical and governance conditions are conditions of registration, not commitments to fulfil afterwards.

That comes from Sec. 6(8), and item 8 of Part B restates it as a duty to act in a fiduciary capacity toward her.

4. Apply to the Data Protection Board from 13 November 2026

Registration opens on that date. Applications are made to the Board, which maintains the register of Consent Managers.

Under Rule 4, a person who fulfils the conditions in Part A may apply, furnishing such particulars, information and documents as the Board may publish in this behalf on its website.

5. Operate under continuing obligations

Registration is not a one-time gate. The Board can review it, and the duties attach for as long as the entity holds the role.

Rule 4(6) lets the Board call for information, and Rule 4(4) and Rule 4(5) set out what follows non-adherence.

Part A — the nine conditions for registration

Part A of the First Schedule is the entry test: company-law conditions, financial ones and a technical certification. An applicant has to satisfy all nine.

The nine conditions for registration as a Consent Manager under Part A of the First Schedule
ItemThe conditionWhat it asks of an applicant
1A company incorporated in India.An entity incorporated elsewhere does not qualify by operating here.
2Sufficient technical, operational and financial capacity to fulfil its obligations as a Consent Manager.Capacity measured against Part B, which lists the obligations in question.
3Sound financial condition, and a sound general character of management.A judgment on the company, separate from the net worth figure in item 4.
4Net worth of not less than two crore rupees.The Schedule defines net worth as the aggregate value of total assets reduced by liabilities, as appearing in the books of accounts.
5Adequate likely volume of business, capital structure and earning prospects.Forward-looking, where item 4 is a snapshot.
6Directors, key managerial personnel and senior management of general reputation and record of fairness and integrity.A test on named individuals, which makes who is appointed before applying part of the application.
7A memorandum and articles of association containing provisions requiring adherence to items 9 and 10 of Part B, and policies and procedures to ensure it, amendable only with the previous approval of the Board.Items 9 and 10 are the conflict-of-interest obligations, written into the constitution and locked there.
8Proposed operations that are in the interests of Data Principals.The business model is assessed, not only the platform.
9Independent certification that the interoperable platform through which a Data Principal gives, manages, reviews and withdraws consent is consistent with such data protection standards and assurance framework as the Board may publish on its website from time to time, and that appropriate technical and organisational measures are in place to ensure adherence to them and effective observance of item 11 of Part B.The certification depends on a framework the Board publishes, not on the Rules alone.

Part A of the First Schedule to the DPDP Rules, 2025. Company, control, director, key managerial personnel, promoter and senior management carry their Companies Act, 2013 meanings.

Part B — the thirteen obligations that follow

Rule 4(3) attaches Part B to a registered Consent Manager. Thirteen obligations, in four groups.

Items 1 to 5 — the platform and the record

  1. Enable a Data Principal to give consent to processing by a Data Fiduciary onboarded with the Consent Manager, either directly or through another onboarded Data Fiduciary that holds that personal data with her consent.
  2. Ensure that personal data is made available or shared in a manner whose contents are not readable by the Consent Manager.
  3. Maintain a record of consents given, denied or withdrawn; of the notices preceding or accompanying each request for consent; and of the sharing of personal data with any transferee Data Fiduciary.
  4. Give her access to that record, make it available in machine-readable form on request in accordance with its terms of service, and maintain it for at least seven years, or longer if agreed or required by law.
  5. Maintain a website or app as the primary means of access.

Items 6 to 8 — how it has to behave

  1. Not sub-contract or assign the performance of any of its obligations.
  2. Take reasonable security safeguards to prevent a personal data breach.
  3. Act in a fiduciary capacity in relation to the Data Principal.

Items 9 to 11 — conflict of interest, and who has to be visible

  1. Avoid conflict of interest with Data Fiduciaries, including their promoters and key managerial personnel.
  2. Take measures so that no conflict arises from its directors, key managerial personnel or senior management holding directorships, financial interests, employment or beneficial ownership in a Data Fiduciary, or having a material pecuniary relationship with one.
  3. Publish, in an accessible form, its promoters, directors, key managerial personnel and senior management; every person holding more than 2% of its shares; every body corporate in which any of those persons holds more than 2% of the shares as on the first day of the preceding calendar month; and anything else the Board directs in the interests of transparency.

Items 12 and 13 — audit, and change of control

  1. Have effective audit mechanisms to review, monitor and evaluate, reporting the outcomes to the Board periodically and as directed — covering technical and organisational controls, continued fulfilment of the registration conditions, and adherence to these obligations.
  2. Not transfer control of the company by sale, merger or otherwise except with the previous approval of the Board, on the conditions it specifies.

Item 11 is the one most likely to be underestimated. It is a standing disclosure of shareholdings above 2%, measured as on the first day of the preceding calendar month, that reaches through the individuals to the other companies they hold stakes in.

Applying under Rule 4, and what the Board can do afterwards

The application is followed by an inquiry rather than a filing receipt. The Board may make such inquiry as it considers appropriate. If satisfied that the applicant fulfils the Part A conditions, it registers the applicant and publishes its particulars on its website; if not, it rejects the application and communicates the reasons.

After registration the relationship stays open. Rule 4(6) lets the Board call for information. Rule 4(4) covers non-adherence to Part B: the Board gives an opportunity of being heard, and can then direct the Consent Manager to take measures. Rule 4(5) is the serious end — in the interests of Data Principals, after a hearing, by written order stating its reasons, the Board may suspend or cancel the registration and give directions.

A hearing precedes both. What an organisation brings to it is whatever it can produce at short notice about its own adherence, which makes the item 12 audit record a working document.

The two conditions that shape the build

Two of the obligations determine the architecture, and both are in Part B.

Item 2 requires personal data to be made available or shared in a manner whose contents are not readable by the Consent Manager. The Consent Manager brokers the decision; it does not get to read what the decision releases.

Read plainly, that rules out personal data passing through the platform in the clear. What remains is a platform that carries consent state, notices and the record, with the data itself moving in a form it cannot read — a decision that fixes the data model and the key management, and so cannot be deferred.

A record kept for at least seven years, machine-readable on request

Item 4 sets a minimum of seven years for the record described in item 3 — consents given, denied and withdrawn, the notices that preceded or accompanied each request, and sharing with a transferee Data Fiduciary — and requires it to be accessible to the Data Principal and available to her in machine-readable form on request.

The notices are inside the seven years, not only the decisions. A notice superseded in year two is still part of the record in year six, because a consent given in year two rested on it. Anything that overwrites a notice in place, or treats a withdrawal as deleting the consent it withdrew, cannot satisfy this.

What the Board has not published yet

Two parts of the process point at documents the Board issues rather than at text in the Rules. Part A item 9 requires certification against such data protection standards and assurance framework as the Board may publish on its website from time to time. Rule 4 makes the application consist of such particulars, information and documents as the Board may publish in this behalf on its website.

Check the Board's website for the current position on both. Neither is reproduced in the Rules, so an application cannot be assembled from the Rules alone.

One note on dates. The compression MeitY proposed in January 2026 concerned the eighteen-month window in Rule 1(4), and the reporting frames it around Significant Data Fiduciary duties rather than around Rule 4; Rule 4 takes its date from Rule 1(3) either way. As of this update it stands as a proposal: Business Standard reported it in January 2026. Check the Gazette before planning to any date other than the two in the Rules.

Questions people ask

Who has to register as a Consent Manager?
An entity that gives Data Principals a single place to give, manage, review and withdraw consent across multiple Data Fiduciaries. Sec. 6(9) requires every Consent Manager to be registered with the Board, and Rule 4 with the First Schedule sets the conditions. Collecting consent for your own processing makes you a Data Fiduciary, not a Consent Manager.
What does the two crore rupee net worth condition mean?
Part A of the First Schedule requires an applicant to have a net worth of not less than two crore rupees. The Schedule defines net worth as the aggregate value of total assets reduced by liabilities, as appearing in the company's books of accounts.
Does a Data Fiduciary that collects its own consent need to register?
No. Rule 4 governs entry to the Consent Manager role. A Data Fiduciary collecting consent for its own processing is bound by Sec. 5, Sec. 6 and the rest of the Act, and registration is not one of its duties.
When does Consent Manager registration open?
13 November 2026. Rule 1(3) of the DPDP Rules, 2025 brings Rule 4 into force one year after the Rules were published on 13 November 2025. The particulars an applicant has to furnish are published by the Board on its website, so check there before assembling an application.
Can a Consent Manager sub-contract its obligations?
No. Item 6 of Part B of the First Schedule says a Consent Manager shall not sub-contract or assign the performance of any of its obligations. Item 13 separately bars a transfer of control of the company by sale, merger or otherwise without the previous approval of the Board.