Summary

  • A Consent Manager is an entity registered with the Data Protection Board that lets an individual give, manage, review, and withdraw consent from one place. 
  • There is no Consent Manager registered in India yet. The registration window opens on 13 November 2026.
  • A Consent Manager only manages consent. Everything else the DPDP Act requires - retention, deletion, breach notifications, third-party risk - is your responsibility.
Close Button

What is a Consent Manager

Pushkal Dubey

Head - Consent Infra
July 9, 2026

Summary

  • A Consent Manager is an entity registered with the Data Protection Board that lets an individual give, manage, review, and withdraw consent from one place. 
  • There is no Consent Manager registered in India yet. The registration window opens on 13 November 2026.
  • A Consent Manager only manages consent. Everything else the DPDP Act requires - retention, deletion, breach notifications, third-party risk - is your responsibility.

Summary

  • A Consent Manager is an entity registered with the Data Protection Board that lets an individual give, manage, review, and withdraw consent from one place. 
  • There is no Consent Manager registered in India yet. The registration window opens on 13 November 2026.
  • A Consent Manager only manages consent. Everything else the DPDP Act requires - retention, deletion, breach notifications, third-party risk - is your responsibility.

What is a Consent Manager?

A Consent Manager is an entity registered with the Data Protection Board under the Digital Personal Data Protection (DPDP) Act. It lets an individual give, manage, review, and withdraw consent from one single platform - across the different businesses that hold their data. 

It acts as a single dashboard for consent - an individual can see and control all of it through one interface, instead of tracking all the privacy consents and permissions that they've agreed to with each company separately.

Are there any Consent Managers right now?

No, as of today there are no registered Consent Managers in India. The registration window opens on 13 November 2026. Until then, no entity can call itself a registered Consent Manager.

What does a Consent Manager do?

A Consent Manager sits between an individual and the businesses they share data with, and its job is narrow and specific. In practice, it:

  • Relays consent requests from a business to the individual, along with the notice that explains what data is being collected and why.
  • Routes consent between businesses through a "data-blind" layer, meaning it passes the information but cannot read it.
  • Consolidates consent from all platforms i.e. websites, mobile apps, WhatsApp etc on a single dashboard.
  • Provides individuals control through one dashboard to see, change, or withdraw any consent, at whatever level of detail they choose.
  • Maintains records of the consent given and the notice shown, as a verifiable log.

Therefore it enables giving, managing, reviewing, and withdrawing consent through one platform.

What are the obligations of a Consent Managers?

A registered Consent Manager acts in a fiduciary capacity - it must act in the individual's interest, not the business's. Its core obligations include:

  • Data-blind operation: it cannot read the personal data that passes through it.
  • Record-keeping: it maintains records of consents given and notices shown. 
  • Transparency: it gives the individual an accessible record of their consent history.
  • Grievance redressal: it provides a clear channel for complaints and must respond within 90 days as per the DPDP Rules
  • Security and governance: the DPDP Rules require entities to ensure encryption, regular audits, and conflict-of-interest rules.

How to become a Consent Manager?

This section is for entities that want to operate as a Consent Manager. If you are a business trying to comply with the DPDP Act, skip to "Do you need a Consent Manager?" below.

A Consent Manager must register with the Data Protection Board, and the window opens on 13 November 2026.

Eligibility Criteria

  • Incorporated in India: the entity must be a company incorporated in India.
  • Net worth: A minimum net worth of ₹2 crore is required as per the Rules
  • Technical capability: it should be able to meet the DPB's standards for technical soundness, including a data-blind transport layer and audit-ready logging.
  • Sound governance: it should not have conflict of interest with any Data Fiduciaries.

How to register as a consent manager? 

  1. Apply to the DPB with the required documents.
  2. The Board reviews technical capability, financial standing, and governance.
  3. If satisfied, the Board registers the entity and lists it. If not, it issues a reasoned rejection.

How consent is managed across sectors in India today?

While the DPDP Act has specified a universal framework, several sector-specific models already exist:

Model Sector Function
Account Aggregator (AA) Finance Let's individuals share financial data like bank statements and transaction history between financial institutions, with consent.
ABDM Healthcare Let's patients share health records with doctors and hospitals.
TRAI DCA Telecom Manages consent and preferences for commercial communication.
Consent Artifacts IT/General A standardised, machine-readable record of a single consent: what was agreed, by whom, and for what.

Do I need a Consent Manager?

You may need one, but not as your DPDP compliance solution.

A registered Consent Manager acts for the individual i.e. the Data Principal. So as a business you will not select one, the way you choose a vendor. 

The framework is expected to be interoperable, like UPI or the Account Aggregator system, so a business supports the standard and the individual decides which Consent Manager to use.

Even once registered, a Consent Manager alone won't make you compliant - you need a DPDP Compliance Platform

Consent Managers, once they are registered, will only allow management of consent: letting an individual give, review, and withdraw consent. All businesses will have a lot more obligations than just consent management under the DPDP Act. Businesses have to:

  • collect consent correctly, with a clear notice of what is collected and why;
  • honour withdrawals, and delete the associated data when consent is withdrawn;
  • retain and delete data on time, once its purpose is met;
    • map and discover personal data across your systems to keep it accurate;
  • manage third-party and vendor risk, including deletion across that chain;
  • send breach notifications;
  • issue look-back notices for consent collected before the Act;
  • collect cookie consent on your websites and apps; and
  • be able to prove all of it.

A registered Consent Manager helps with the first item on that list. To manage the rest, you need a DPDP Compliance Platform – a system that manages all DPDP obligations including collection, storage, withdrawal, retention, deletion, and third-party risk, across every system that holds your data. 

You can build this in-house or buy it. 

A registered Consent Manager is something you will support later, not a substitute for a compliance platform. Think of it the way you think about payments. A Consent Manager is like UPI for consent; a compliance platform is like the payments infrastructure behind it. UPI lets a customer pay, but a business still needs a full payment stack to run.

Why choose Consent Management by Consentin?

YConsentin is a consent and DPDP compliance platform built by legal and compliance experts. It runs the full lifecycle — consent collection and storage, withdrawal, retention and deletion, data principal rights, and third-party risk — and integrates with your existing systems, whether that's your CRM, ERP, or marketing tools. We help large enterprises understand and navigate the DPDP Act.

Frequently Asked Questions

Qustion - Does my business need to register as a Consent Manager?

Answer - No. Registration is for entities that want to operate a Consent Manager for individuals. A business that processes personal data is a Data Fiduciary, with a different set of obligations.

Question - How do I onboard a Consent Manager?

Answer - You don't onboard one the way you onboard software. Consent Managers act for the individual on an interoperable protocol, so you support the standard rather than pick a provider. To actually manage consent and your other DPDP obligations, you need to onboard a DPDP compliance platform.

Question - Should I wait for a registered Consent Manager before I start DPDP compliance?

Answer - No. The Act already applies, and a Consent Manager would only ever cover part of your obligations. Waiting leaves the rest unmet.

Question - Did MeitY and NeGD recently designate any entity as a Consent Manager?

Answer -You may see vendors point to a win or ranking in MeitY-NeGD's "Code for Consent" challenge. That challenge is a competition to build open-source consent code, not registration under the DPDP Act. Registered Consent Managers are licensed by the Data Protection Board, and that window only opens on 13 November 2026. → More on the NeGD confusion here.

Don’t wait for the 2026 deadline. Schedule a Demo Call today

Book a Demo Call

Compliance Deadline:

0 weeks away