Consentrio

What is a Consent Manager under the DPDP Act?

3 min read · Updated 30 September 2026

"Consent manager" sounds like a generic product category. Under India's Digital Personal Data Protection Act, 2023, it is a defined, regulated role. Mixing the two up leads to confusion when choosing tools and when describing your own compliance.

The legal definition

Section 2(g) of the Act defines a Consent Manager as:

a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform.

Three things follow from that definition:

  • A Consent Manager must be registered with the Data Protection Board of India.
  • It works for the Data Principal, the individual, not for the company collecting the data.
  • Its platform must be interoperable, so one person can manage consents given to many different Data Fiduciaries in one place.

What the Act says about Consent Managers

  • Section 6(7): a Data Principal may give, manage, review or withdraw consent to a Data Fiduciary through a Consent Manager.
  • Section 6(8): the Consent Manager is accountable to the Data Principal and acts on their behalf.
  • Section 6(9): every Consent Manager must be registered with the Board, subject to technical, operational, financial and other conditions set by the Rules.
  • When consent was given through a Consent Manager, the Data Principal can also withdraw it through the Consent Manager (Section 6(4)).

What the DPDP Rules, 2025 add

Rule 4 and the First Schedule of the DPDP Rules, 2025 set the registration conditions and obligations. Among other things, a Consent Manager must be a company incorporated in India with sufficient technical, operational and financial capacity, including a minimum net worth of ₹2 crore, and must avoid conflicts of interest with the Data Fiduciaries it connects to. It has to keep records of consents given, reviewed and withdrawn, and share personal data in a way that keeps its contents unreadable to the Consent Manager itself.

The provisions on Consent Managers take effect one year after the Rules were notified, which puts them in November 2026. See the DPDP Rules 2025 timeline.

Consent Manager vs consent management platform

Consent Manager (DPDP) Consent management platform (CMP)
Who it serves The Data Principal The Data Fiduciary
Registration Required with the Data Protection Board Not required
Legal basis Section 2(g), 6(7)–6(9) and Rule 4 A tool you use to meet your own obligations
Typical job One place for a person to manage consents across many companies Notices, consent capture, withdrawal, records and proof for one organisation

Most organisations need a consent management platform regardless of whether their users ever use a registered Consent Manager. The Act makes you responsible for notices, valid consent, easy withdrawal and proof (Section 6(10)), whichever channel the consent arrived through. If a user comes through a Consent Manager, your systems still have to receive, record and honour that consent.

Where Consentrio fits

Consentrio is a consent management platform for Data Fiduciaries. It is not a registered Consent Manager. It gives your team:

  • versioned consent notices built from a single purpose library;
  • consent capture through web, mobile and server SDKs and a validation API;
  • a preference centre where your users see, renew, update and withdraw their consents;
  • rights requests and grievances with SLA tracking;
  • signed notifications to your processors when consent changes;
  • a tamper-evident audit trail that serves as proof of consent.

If you are evaluating tools, ask vendors which of the two roles they play. Anyone who describes their product as a "Consent Manager" under the DPDP Act should be able to show their registration with the Board.

This guide is general information, not legal advice. Check the Act and the Rules, or ask your counsel, for decisions about your organisation.