DPDP · Consent Manager

Consent Manager Under DPDP

A Consent Manager is a statutory role under the DPDP Act: a person registered with the Data Protection Board who enables Data Principals to give, manage, review and withdraw consent through an interoperable platform.

What a Consent Manager is under the Act

Section 2(g) defines a Consent Manager as a person registered with the Board who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. The definition is institutional: registration with the Board is part of what the term means under the Act.

Section 6(7)–(9) situates Consent Managers in the consent framework. A Data Principal may give, manage, review or withdraw consent to a Data Fiduciary through a Consent Manager. The Consent Manager is accountable to the Data Principal and must act in a manner that enables transparent management of consent. Registration with the Board under Section 6(9) is subject to conditions prescribed in the Rules.

Rule 4 of the DPDP Rules, 2025 addresses registration and obligations of Consent Managers, including conditions for registration, ongoing obligations, and the Board’s role in relation to those conditions. These provisions have their own commencement timeline under the Rules — organizations and vendors should not assume the registration ecosystem is already fully live solely because the Rules were notified.

Important: This page explains the statutory concept for education and implementation planning. ConsentifyAI is not described here as a Consent Manager registered with the Data Protection Board. Product marketing language that uses the words “consent manager” is not the same as Section 2(g) / Section 6(9) status.

What it means in practice

For Data Principals, a registered Consent Manager is intended as a single, interoperable place to manage consent relationships with multiple Data Fiduciaries — give, review, manage and withdraw — rather than hunting through each organization’s separate interfaces alone.

For Data Fiduciaries, Consent Managers (once the registration regime is operative and entities are registered) are a channel through which consent may be obtained or managed, subject to the Act and Rules. Fiduciaries still carry their own obligations for purpose, notice, processing limits, security and rights. Using a Consent Manager does not erase Fiduciary accountability.

For vendors and platforms, the practical distinction is critical. Software that helps a Data Fiduciary capture and store consent for its own processing is consent management tooling. A statutory Consent Manager is a Board-registered person enabling Data Principals across an accessible, transparent and interoperable platform under the Act’s conditions. Teams evaluating products should ask which role is actually offered — and verify registration claims against Board processes when those processes apply — rather than equating brand labels with statute.

Timing matters. Section 6(9) and Rule 4 follow the phased commencement schedule published with the November 2025 notifications. Planning for Consent Manager interactions is sensible; treating every vendor as already a registered Consent Manager is not.

Separately, organizations still need their ownconsentandnoticedesigns where they rely on consent directly. A Consent Manager ecosystem complements Fiduciary processes; it does not replace understanding Sections 5 and 6.

Common mistakes

  • Calling any consent software a “Consent Manager” without Board registration under Section 6(9) and Rule 4.
  • Assuming ConsentifyAI or similar products are statutory Consent Managers based on marketing wording alone.
  • Believing use of a Consent Manager removes the Data Fiduciary’s own notice, purpose and security obligations.
  • Ignoring commencement dates and treating Consent Manager registration rules as already fully operational for all purposes.

For consent capture and audit tooling used by organizations (not as a statutory Consent Manager claim), see theConsent Management Platform— CMP tooling is not the same as a registered Consent Manager under the Act.

Official source

ConsentifyAI’s explanation is educational. Authoritative text is published by the Government of India / MeitY.

Information on this page is provided for general educational and implementation-planning purposes. It is not legal advice. Organizations should assess their specific obligations with qualified legal or privacy professionals.