Home Blog DPDP Act Updates DPDP Act Consent Manager: What Businesses Need to Know in 20...
DPDP Act Consent Manager: What Businesses Need to Know in 2026

DPDP Act Consent Manager: What Businesses Need to Know in 2026

DPDP Act Updates · By Admin User · April 22, 2026 · 0 views

The Digital Personal Data Protection Rules, 2025 introduced a concept many Indian businesses had not seen defined in law before: the Consent Manager. It is one of the more operationally significant pieces of the DPDP framework, because it changes how consent for processing personal data can be collected, tracked, and withdrawn, not just what a privacy policy needs to say.

What a Consent Manager Actually Does

A Consent Manager is a registered, independent intermediary that sits between individuals (Data Principals) and the businesses that want to process their data (Data Fiduciaries). Rather than every business building and maintaining its own consent collection and withdrawal system, a Consent Manager provides a standardised, interoperable platform where an individual can see, grant, and revoke consents across multiple businesses in one place. It is a similar concept to the Account Aggregator framework in financial services, applied to personal data generally.

Who Can Become One

Under the DPDP Rules, only companies incorporated in India are eligible to apply for Consent Manager registration. The eligibility bar is deliberately high: an applicant must demonstrate adequate technical, operational, and financial capacity, including a minimum net worth of Rs 2 crore, which is inflation-adjusted annually. This is not a role most businesses will take on themselves; it is a specialised, regulated intermediary function.

The Timeline That Matters

Rule 4, which establishes the registration and oversight framework for Consent Managers, is set to come into force on 13 November 2026. Until that provision takes effect, there is no formal registration process live, but the framework itself, and the obligations Consent Managers will need to meet once registered, are already defined in the Rules. Businesses that expect to rely on Consent Manager infrastructure, or that are considering applying to become one, should treat this date as the point from which formal compliance becomes assessable, not the point from which preparation should start.

What This Means for Ordinary Data Fiduciaries

Most businesses processing personal data will not become Consent Managers themselves. What matters for them is different:

  • Consent architecture needs to be interoperable-ready: Consent records, purpose limitation, and withdrawal mechanisms built now should be structured so they can eventually plug into a Consent Manager platform, rather than being built as closed, proprietary systems.
  • Withdrawal has to be as easy as granting: This principle, already present in the DPDP Act itself, is central to how the Rules expect Consent Managers, and by extension all data fiduciaries, to operate.
  • Ongoing obligations don't go away: Whether or not a Consent Manager is involved, a Data Fiduciary's core obligations, purpose limitation, data minimisation, breach notification, remain unchanged. See our guide on Data Fiduciary obligations under the DPDP Act for the full list.

Why This Is Worth Tracking Now

Businesses that build their consent infrastructure around rigid, closed systems now may face rework later once Consent Manager interoperability becomes an expectation, whether by regulation or market pressure once major platforms register. It is considerably cheaper to design consent flows with this in mind from the start than to retrofit them. This is also relevant for businesses assessing their exposure ahead of enforcement; our guide on DPDP Act penalties covers what non-compliance can actually cost.

Practical Next Steps

If your business handles personal data at any meaningful scale, whether as an e-commerce platform, a SaaS product, or a services firm collecting customer information, the practical steps worth taking now are: audit your current consent collection mechanism against DPDP principles, confirm your privacy policy language matches actual data practices rather than being generic boilerplate, and build a data processing register that could support Consent Manager integration if and when it becomes necessary.

Clawrity advises businesses on DPDP Act compliance, including consent architecture reviews and readiness assessments ahead of the Consent Manager framework taking effect. See our DPDP Act Compliance Audit service or get in touch to discuss your current setup.

The information in this article is for general informational purposes only and does not constitute legal advice. Laws and regulations may change; consult a qualified lawyer before making any property-related decisions. Read full disclaimer

Share this article

Follow Clawrity

C

Clawrity Expert

Legal expert at Clawrity specialising in property law and real estate due diligence in Bangalore.

Need Expert Legal Advice?

Our property lawyers are ready to help , book your consultation today.

Book a Consultation WhatsApp Us

More Articles You May Like

More from DPDP Act Updates

Data Fiduciary vs Data Processor Under DPDP Act: Key Differences DPDP Act Updates

Data Fiduciary and Data Processor carry very different legal exposure under India's DPDP Act. Here is how to tell which ...

Jun 08, 2026 Read More →
What is the DPDP Act 2023? A Plain-Language Guide for Indian Businesses DPDP Act Updates

India's Digital Personal Data Protection Act 2023 is now law. Here is what every business that handles personal data of ...

Mar 30, 2026 Read More →
DPDP Act: What Are Your Obligations as a Data Fiduciary? DPDP Act Updates

If your business processes personal data of Indian citizens, you are a Data Fiduciary under the DPDP Act. Here are your ...

Mar 30, 2026 Read More →
View All Articles