If your business collects customers’ personal data, you may have heard about a DPDP Consent Manager. A Consent Manager under DPDP Act is a special entity defined under the DPDP Rules. It helps people manage their consent for sharing personal data. In this guide, you’ll learn what a Consent Manager is, what it does, who can register as one, and how your business should prepare.
Key Takeaways
- A DPDP Consent Manager helps people give, review, and withdraw consent for their personal data.
- Registration begins on 13 November 2026. Before that, no company is an official DPDP Consent Manager.
- Only Indian companies with at least ₹2 crore net worth can apply to become a Consent Manager.
- A Consent Manager does not store or use personal data. It only manages consent.
- Businesses still have to follow the DPDP Act, even if a customer uses a Consent Manager.
- From 13 May 2027, DPDP compliance becomes mandatory, and violations can lead to penalties of up to ₹250 crore.
What Is a DPDP Consent Manager?
Consent Manager under DPDP Act is a company registered with the Data Protection Board of India. It allows people to give, review, and withdraw consent for sharing their personal data through an interoperable platform.
Under the DPDP Rules 2025, registration for Consent Managers starts on 13 November 2026. Until then, no company in India is a registered DPDP Consent Manager.
Under the DPDP Act, the individual whose personal data is being processed is called the Data Principal. A Consent Manager works on behalf of the Data Principal to help them manage their consent.
What Does a DPDP Consent Manager Do?
It acts as a bridge between individuals and businesses. Its job is to help people control how their personal data is used.
It mainly performs these tasks:
- Sends consent requests from businesses to users.
- Shows users why their data is being collected.
- Records every consent given or withdrawn.
- Lets users review or withdraw their consent anytime.
- Keeps consent records for at least seven years in machine-readable records.
- Provides a way for users to raise complaints if needed.
A Consent Manager remains data blind. It manages consent requests without accessing, reading, storing, or using an individual’s personal data.
Simplify Your Compliance & Stay Audit-Ready
Help your team manage controls, risks, and audits with ease
Who Can Become a DPDP Consent Manager?
Not every company can become a Consent Manager. The DPDP Rules set strict eligibility conditions.
“The eligibility and registration process are governed under Rule 4 of the DPDP Rules, 2025.”
A company must:
- Be incorporated in India.
- Have a minimum net worth of ₹2 crore.
- Have strong technical and financial capabilities.
- Be managed by people with a good reputation and integrity.
- Avoid conflicts of interest. It cannot act as both a Consent Manager and a Data Fiduciary or Data Processor for the same users.
A registered Consent Manager must also operate independently and remain transparent and accountable while managing consent on behalf of individuals.

How Does a DPDP Consent Manager Work?
Here’s a simple example.
Suppose Megha signs up for an online shopping app and allows it to use her email address for promotional offers. A few months later, she no longer wants to receive marketing messages.
Instead of contacting the company directly, she can use her registered Consent Manager to withdraw her consent. The Consent Manager sends the withdrawal request to the business and records the action. The business must then stop using her data for that purpose.
When Do the Rules Apply?
The DPDP Rules are being introduced in phases.
| Phase | Date | What Starts |
| Phase 1 | 13 November 2025 | DPDP Rules notified |
| Phase 2 | 13 November 2026 | Consent Manager registration begins |
| Phase 3 | 13 May 2027 | Full DPDP compliance becomes mandatory |
Businesses that fail to follow the rules may face penalties of up to ₹250 crore, depending on the violation.

Does Your Business Need a DPDP Consent Manager?
Not directly, a Consent Manager is chosen by the individual, not by the business. If a customer wants to manage their consent through a registered Consent Manager, your business should be able to support that process.
However, using a Consent Manager does not remove your compliance responsibilities.
You are still responsible for:
- Collecting valid consent.
- Giving clear privacy notices.
- Allowing users to withdraw consent easily.
- Deleting data when required.
- Reporting data breaches.
- Keeping proper consent records.
In short, a Consent Manager only helps manage consent. Your business remains responsible for DPDP compliance.
DPDP Consent Manager vs Data Protection Officer (DPO)
Consent Manager and a Data Protection Officer (DPO) have different responsibilities.
| Data Protection Officer | DPDP Consent Manager |
| Works for one company | Independent registered company |
| Helps the company follow DPDP rules | Helps individuals manage consent |
| Handles compliance activities | Handles consent requests and withdrawals |
| Represents the business | Acts in the interest of the individual |
Even if your business appoints a DPO, you must still support requests that come through a registered Consent Manager.
How Can Your Business Prepare?
You do not need to wait until 2026 to start preparing and complete DPDP compliance checklist.
Here are a few important steps:
- Identify where personal data is collected and stored.
- Update your consent notices using simple language.
- Make it easy for users to withdraw consent.
- Create processes for deleting data when it is no longer needed.
- Keep complete and time-stamped consent records.
- Prepare a process for reporting data breaches.
Conclusion
A DPDP Consent Manager helps individuals control how their personal data is shared. Businesses are still responsible for collecting valid consent, keeping proper records, handling withdrawals, and protecting personal data.
Instead of waiting for the registration process to begin, start improving your online consent management & monitoring system now.
FAQs
Ques: What Is a DPDP Consent Manager?
Ans: It is a company registered with the Data Protection Board of India that lets individuals give, manage, review, and withdraw consent for their personal data through one interoperable platform. It acts in a fiduciary capacity toward the individual.
Ques: Who Is Eligible for DPDP Consent Manager Registration?
Ans: Only a company incorporated in India with a net worth of at least Rs 2 crore is eligible to register as a consent manager under DPDP Act. It must also prove technical capacity, sound management, and neutrality. Registration opens 13 November 2026.
Ques: What Is the Difference Between a DPO and a Consent Manager?
Ans: A DPO is an individual a Significant Data Fiduciary appoints to manage its own DPDP compliance. A consent manager is an independent Board-registered company that helps individuals control consent across many businesses. One serves the company, the other the public.
Ques: What Is the Role of a Consent Manager?
Ans: The role of a consent manager is to let individuals give, manage, review, and withdraw consent from one dashboard while staying data blind. It relays consent requests, keeps machine-readable records for seven years, and handles grievances for data principals.
Ques: What Is a Consent Management Platform?
Ans: A consent management platform is solution a business use to collect, record, and honour user consent across its own websites and apps. Unlike a DPDP consent manager, which serves individuals, a CMP keeps the data fiduciary itself compliant and audit ready.
Ques: What is the minimum net worth to register as a consent manager?
Ans: Rs 2 crore, as per Part A of the First Schedule of the DPDP Rules 2025
Ques: When Does DPDP Consent Manager Registration Open?
Ans: Registration opens on 13 November 2026, one year after the DPDP Rules 2025 were notified on 13 November 2025. This is Phase 2 of the rollout. Full compliance obligations for businesses, including notices, breach reporting, and data principal rights, take effect on 13 May 2027.
Ques: Does a DPDP Consent Manager Store Personal Data?
Ans: No, it does not access or use personal data. Its role is limited to managing consent requests, recording consent and withdrawals, and sharing those instructions between individuals and businesses.