If your business collects customers’ personal data, you may have heard about a DPDP Consent Manager. A Consent Manager under DPDP Act is a special entity defined under the DPDP Rules. It helps people manage their consent for sharing personal data. In this guide, you’ll learn what a Consent Manager is, what it does, who can register as one, and how your business should prepare.

Key Takeaways

  • A DPDP Consent Manager helps people give, review, and withdraw consent for their personal data.
  • Registration begins on 13 November 2026. Before that, no company is an official DPDP Consent Manager.
  • Only Indian companies with at least ₹2 crore net worth can apply to become a Consent Manager.
  • A Consent Manager does not store or use personal data. It only manages consent.
  • Businesses still have to follow the DPDP Act, even if a customer uses a Consent Manager.
  • From 13 May 2027, DPDP compliance becomes mandatory, and violations can lead to penalties of up to ₹250 crore.

Consent Manager under DPDP Act is a company registered with the Data Protection Board of India. It allows people to give, review, and withdraw consent for sharing their personal data through an interoperable platform.

 

Under the DPDP Rules 2025, registration for Consent Managers starts on 13 November 2026. Until then, no company in India is a registered DPDP Consent Manager.

 

Under the DPDP Act, the individual whose personal data is being processed is called the Data Principal. A Consent Manager works on behalf of the Data Principal to help them manage their consent. 

It acts as a bridge between individuals and businesses. Its job is to help people control how their personal data is used.

 

It mainly performs these tasks:

  • Sends consent requests from businesses to users.
  • Shows users why their data is being collected.
  • Records every consent given or withdrawn.
  • Lets users review or withdraw their consent anytime.
  • Keeps consent records for at least seven years in machine-readable records.
  • Provides a way for users to raise complaints if needed.

A Consent Manager remains data blind. It manages consent requests without accessing, reading, storing, or using an individual’s personal data.

Simplify Your Compliance & Stay Audit-Ready

Help your team manage controls, risks, and audits with ease

Book a Demo Now

Not every company can become a Consent Manager. The DPDP Rules set strict eligibility conditions.

 

“The eligibility and registration process are governed under Rule 4 of the DPDP Rules, 2025.”

 

A company must:

  • Be incorporated in India.
  • Have a minimum net worth of ₹2 crore.
  • Have strong technical and financial capabilities.
  • Be managed by people with a good reputation and integrity.
  • Avoid conflicts of interest. It cannot act as both a Consent Manager and a Data Fiduciary or Data Processor for the same users.

A registered Consent Manager must also operate independently and remain transparent and accountable while managing consent on behalf of individuals.

 

How does dpdp consent manager work?

Here’s a simple example.

 

Suppose Megha signs up for an online shopping app and allows it to use her email address for promotional offers. A few months later, she no longer wants to receive marketing messages.

 

Instead of contacting the company directly, she can use her registered Consent Manager to withdraw her consent. The Consent Manager sends the withdrawal request to the business and records the action. The business must then stop using her data for that purpose.

When Do the Rules Apply?

The DPDP Rules are being introduced in phases.

PhaseDateWhat Starts
Phase 113 November 2025DPDP Rules notified
Phase 213 November 2026Consent Manager registration begins
Phase 313 May 2027Full DPDP compliance becomes mandatory

 

Businesses that fail to follow the rules may face penalties of up to ₹250 crore, depending on the violation.

 

consent manager vs business

Not directly, a Consent Manager is chosen by the individual, not by the business. If a customer wants to manage their consent through a registered Consent Manager, your business should be able to support that process.

 

However, using a Consent Manager does not remove your compliance responsibilities.

 

You are still responsible for:

  • Collecting valid consent.
  • Giving clear privacy notices.
  • Allowing users to withdraw consent easily.
  • Deleting data when required.
  • Reporting data breaches.
  • Keeping proper consent records.

In short, a Consent Manager only helps manage consent. Your business remains responsible for DPDP compliance.

Consent Manager and a Data Protection Officer (DPO) have different responsibilities.

 

Data Protection OfficerDPDP Consent Manager
Works for one companyIndependent registered company
Helps the company follow DPDP rulesHelps individuals manage consent
Handles compliance activitiesHandles consent requests and withdrawals
Represents the businessActs in the interest of the individual

 

Even if your business appoints a DPO, you must still support requests that come through a registered Consent Manager.

How Can Your Business Prepare?

You do not need to wait until 2026 to start preparing and complete DPDP compliance checklist.

 

Here are a few important steps:

  • Identify where personal data is collected and stored.
  • Update your consent notices using simple language.
  • Make it easy for users to withdraw consent.
  • Create processes for deleting data when it is no longer needed.
  • Keep complete and time-stamped consent records.
  • Prepare a process for reporting data breaches.

Conclusion

A DPDP Consent Manager helps individuals control how their personal data is shared. Businesses are still responsible for collecting valid consent, keeping proper records, handling withdrawals, and protecting personal data. 

 

Instead of waiting for the registration process to begin, start improving your online consent management & monitoring system now.

FAQs

Ans: It is a company registered with the Data Protection Board of India that lets individuals give, manage, review, and withdraw consent for their personal data through one interoperable platform. It acts in a fiduciary capacity toward the individual.

 

Ans: Only a company incorporated in India with a net worth of at least Rs 2 crore is eligible to register as a consent manager under DPDP Act. It must also prove technical capacity, sound management, and neutrality. Registration opens 13 November 2026.

 

Ans: A DPO is an individual a Significant Data Fiduciary appoints to manage its own DPDP compliance. A consent manager is an independent Board-registered company that helps individuals control consent across many businesses. One serves the company, the other the public.

 

Ans: The role of a consent manager is to let individuals give, manage, review, and withdraw consent from one dashboard while staying data blind. It relays consent requests, keeps machine-readable records for seven years, and handles grievances for data principals.

 

Ans: A consent management platform is solution a business use to collect, record, and honour user consent across its own websites and apps. Unlike a DPDP consent manager, which serves individuals, a CMP keeps the data fiduciary itself compliant and audit ready.

 

Ans: Rs 2 crore, as per Part A of the First Schedule of the DPDP Rules 2025 

 

Ans: Registration opens on 13 November 2026, one year after the DPDP Rules 2025 were notified on 13 November 2025. This is Phase 2 of the rollout. Full compliance obligations for businesses, including notices, breach reporting, and data principal rights, take effect on 13 May 2027. 

 

Ans: No, it does not access or use personal data. Its role is limited to managing consent requests, recording consent and withdrawals, and sharing those instructions between individuals and businesses.

Simplify Your Compliance & Stay Audit-Ready

Help your team manage controls, risks, and audits with ease

Book a Demo Now

Share On
Author Image

Vijay Kandari

administrator

Vijay Kandari is part of the marketing team, driving brand growth and digital campaigns. He is passionate about automation, digital transformation, and the evolving trends shaping the future of customer onboarding and verification.