Consent Manager
A 'Consent Manager' is a new kind of regulated middleman for consent — and despite the November 2026 deadline you keep hearing about, almost no business needs to become one. Here's what it actually is, and what it means for you.
Do you need to register as one? — Almost certainly not
A Data Fiduciary is the organisation that decides why and how personal data gets used. That's nearly every business. But being a Data Fiduciary does not make you a Consent Manager. This is a separate, optional, specialised role. You register only if you want to run a consent-management platform as a business. Large, cross-sector intermediaries are the likely registrants — think major IT-services and telecom players who are already eyeing it. Ordinary product companies are not the target. To register at all, you must be a company incorporated in India, and you must show the technical, operational and financial capacity set out in the First Schedule.
What a Consent Manager is
A Consent Manager is a service that lets a person manage consents in one place. It gives an individual one dashboard to give, review, manage, and withdraw consent across many different companies at once. It registers with the Data Protection Board. By design, the personal data passing through it stays unreadable to the Consent Manager itself. Think of it as a neutral consent dashboard for the individual, not another data collector.
The two anchors in the law
- DPDP Act — Section 6(3), read with Sections 6(7)–6(9) — introduces the Consent Manager as a party a Data Principal can give, manage, review and withdraw consent through, and requires it to be registered with the Board.
- DPDP Rules 2025 — Rule 4 and the First Schedule — set out how a Consent Manager is registered, what it must be capable of, and how it must operate.
Eligibility and ongoing duties
Part A of the First Schedule sets out who may register: an India-incorporated company with sound finances and demonstrated technical, operational and financial capacity to run the platform. Part B sets out what a registered Consent Manager must keep doing:
- Give people easy tools to grant and withdraw consent.
- Keep the data unreadable to itself.
- Maintain consent records.
- Act in the individual's interest.
- Stay interoperable with other systems.
The Board can suspend or cancel a registration after a fair hearing. If you operate as an unregistered Consent Manager after the deadline, you fall in the Act's residual penalty tier — up to ₹50 crore.
What to do now
Most Data Fiduciaries — the organisations that decide why and how personal data gets used — don't need to register. The real takeaway is interoperability. Build your own consent systems so they can exchange "granted / reviewed / withdrawn" signals with registered Consent Managers once the framework goes live. Concretely:
- Track the framework as it operationalises, rather than waiting for a single switch-on date.
- Build awareness of the November 2026 timeline inside your product and compliance teams, not just legal.
- Don't over-invest in a bespoke consent hub that conflicts with the framework — you'd have to unwind it later.
In plain English: assume Consent Managers will exist, design your consent flow so it can plug into one later, and don't build a competing system of your own in the meantime.
The date — and the catch
ScheduledRule 4 comes into force on 13 November 2026. That's a Phase II milestone, ahead of full enforcement on 13 May 2027. But here's the catch — the kind this site exists to flag. That registration deadline points at the Data Protection Board. The Board is established in law (DPDP Act s.18; G.S.R. 843(E)). As notified, it has a Chairperson and four Members, to be appointed through a Search-cum-Selection Committee (Government reply, Lok Sabha Unstarred Question 3960, 12 August 2026). The posts were advertised in Employment News on 6 June 2026. The reply does not report any appointment. We have found no appointment order since. Last checked 6 October 2026. The same reply does not say whether any Consent Manager has been registered. It's the body meant to receive registrations and set the technical and assurance standards Consent Managers must meet. So you have a hard date on paper, aimed at a regulator that can't yet act on it. Treat this as a gap worth watching, not a settled obligation.
Track the Board and this deadline in what's still pending →
For binding registration, interface and assurance obligations, consult qualified counsel and the primary sources below.
Sources
DPDP Act, 2023 — Sections 6(3) & 6(7)–6(9)
Notified — checked 2026-10-06. Opened the DPDP Act, 2023 (Gazette PDF). Partly in force: most duties start 13 May 2027 (G.S.R. 843(E)).
DPDP Rules, 2025 — Rule 4 & First Schedule
Notified — checked 2026-10-06. Opened the DPDP Rules, 2025 (Gazette PDF).
Am I a Data Fiduciary?
Reading about DPDP obligations? Run the 2-minute self-check to see exactly what applies to your product.
Run it nowThe Rules are dated 13 November 2025 and were published in the Gazette on 14 November 2025. Some sources therefore give 14 May 2027. We use 13 May 2027; see Methodology.
Last updated: 17 August 2026 · Reviewed by Sandesh Kokate, Editor
Educational only. Re-verify against the Gazette of India before relying on anything here.
How does this apply to you?
Take the 2-minute self-check to find out whether you're a Data Fiduciary, Data Processor, or both — with your personalised action checklist.
Take the DPDP Applicability CheckYour answers stay in your browser. If you choose "Email me this report", we send your email address and result type to our report service.