Consent Managers Under the DPDP Act: What Rule 4 Will Require Before 13 November 2026
Rule 4 of the DPDP Rules, 2025 sets the registration route for consent managers under India’s DPDP Act. It is not in force as at 10 September 2026; its commencement computes to 13 November 2026, one year after the 13 November 2025 gazette, with Candour Legal computing 14 November.

A consent manager is a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform, under Section 2 of the Digital Personal Data Protection Act, 2023. The registration route runs through Rule 4 of the DPDP Rules, 2025, read with the First Schedule, and Rule 1(3) brings Rule 4 into force one year after the date of publication of the gazette, which computes to 13 November 2026 from the 13 November 2025 gazette instrument; Candour Legal computes the same commencement as 14 November 2026. As at 10 September 2026 neither Rule 4 nor the First Schedule is in force, so nothing below describes an obligation that binds anyone today.
This piece covers what Rule 4 and the First Schedule will require of an applicant once they commence, which parts of the statutory framework switch on at the one-year mark and which wait longer, and what the Act and the Rules say about the data fiduciary’s side of a consent-manager relationship.
Consent Manager and Consent Management Platform Are Different Things
Regulatory classification versus internally-operated compliance software
TrustArc draws the distinction directly. A DPDPA Consent Manager, in its description, is a registered third-party intermediary that must be registered with the Data Protection Board of India, acts on behalf of the Data Principal rather than the business, and does not access or store personal data. A Consent Management Platform, again per TrustArc, is not a regulated entity, requires no regulatory registration, operates for the business’s own compliance needs, and may process consent and preference data as a data processor. TrustArc calls the two complementary but not interchangeable.
The statutory material behind the first half of that description sits in three places. “Registered with the Board” is in the Section 2 definition. “The Consent Manager shall act in a fiduciary capacity in relation to the Data Principal” is item 8 of Part B of the First Schedule. And the requirement that it ensure “that the manner of making available the personal data or its sharing is such that the contents thereof are not readable by it” is item 2 of the same Part. Reading those provisions against TrustArc’s framing, the registration and fiduciary-capacity requirements are what mark out the regulated category; software a data fiduciary runs internally to capture its own customers’ consent is the other thing TrustArc describes, and AZB & Partners records that data fiduciaries may continue to obtain consent directlyif they meet the Act’s own standards.
For the wider vocabulary, KYCKART’s companion pieces cover the DPDP Act itself, the data fiduciary role, the data processor role and the Data Protection Board of India.
What the Act Says About Consent Managers
Statutory provisions across Sections 2, 6, 27, and the Schedule
The Act’s consent-manager provisions sit in four places, with the Board’s powers over Consent Managers in a fifth.
Section 2 supplies the definition quoted above. Section 6(7) provides that “The Data Principal may give, manage, review or withdraw her consent to the Data Fiduciary through a Consent Manager.” The verb is permissive. Section 6(8) provides that “Every Consent Manager shall be accountable to the Data Principal and shall act on her behalf in such manner and subject to such obligations as may be prescribed.” Section 6(9)provides that “Every Consent Manager shall be registered with the Board in such manner and subject to such technical, operational, financial and other conditions as may be prescribed.”
The Board’s supervisory hooks sit in two separate clauses of Section 27(1). Clause (c) gives it the power, “on a complaint made by a Data Principal in respect of a breach in observance by a Consent Manager of its obligations in relation to her personal data, to inquire into such breach and impose penalty”. Clause (d) gives it the power, on receiving intimation of a Consent Manager’s breach of its registration conditions, to inquire into that breach and impose penalty. Neither Section 6(7) to (9) nor either clause of Section 27(1) is in force as at 10 September 2026, and the two clauses commence on different dates, which the timeline section below sets out.
On penalties, the Schedule to the DPDP Act contains seven entries, keyed to Section 8(5) at ₹250 crore, Section 8(6) at ₹200 crore, Section 9 at ₹200 crore, Section 10 at ₹150 crore, Section 15 at ₹10,000, Section 32 to the extent applicable to the underlying breach, and a residuary entry for “breach of any other provision of this Act or the rules made thereunder” at up to ₹50 crore. No entry in the Schedule names a Consent Manager. AZB & Partners states the consequence directly: “The DPDP Act prescribes a monetary penalty of up to INR 50 crores in case of non-compliances by Consent Managers.”
Rule 4, Sub-Rule by Sub-Rule
Registration procedure, obligations link, rectification, and supervisory powers
Rule 4 of the DPDP Rules, 2025 is titled “Registration and obligations of Consent Manager” and has six sub-rules. None of it is in force as at 10 September 2026:
- Rule 4(1), eligibility and application. “A person who fulfils the conditions for registration of Consent Managers set out in Part A of First Schedule may apply to the Board for registration as a Consent Manager”, with the particulars and documents specified.
- Rule 4(2), the Board’s inquiry. The Board may inquire into whether the applicant fulfils the conditions and either register the applicant, with public notice of the registration, or reject the application and communicate the reasons to the applicant.
- Rule 4(3), the obligations cross-reference. “The Consent Manager shall have obligations as specified in Part B of First Schedule.”
- Rule 4(4), rectification. Where the Board finds non-adherence, it notifies the Consent Manager, gives it an opportunity of being heard, and directs corrective measures.
- Rule 4(5), suspension, cancellation and protective directions. The Board may “suspend or cancel the registration of such Consent Manager” and “give such directions as it may deem fit to that Consent Manager, to protect the interests of the Data Principals”, in each case for written reasons and after an opportunity of being heard.
- Rule 4(6), power to call for information. “The Board may, for the purposes of this rule, require the Consent Manager to furnish such information as the Board may call for.”
The two cross-references in Rule 4(1) and Rule 4(3) both point at the First Schedule: Part A for the conditions of registration, Part B for the obligations.
First Schedule, Part A: The Nine Registration Conditions
Eligibility, ₹2 crore net worth, integrity checks, and independent technical certification
The nine conditions below are quoted from Part A of the First Schedule, as reproduced by dpdpa.in. They will apply to an applicant once Rule 4 commences:
- “The applicant is a company incorporated in India.”
- “The applicant has sufficient capacity, including technical, operational and financial capacity, to fulfil its obligations as a Consent Manager.”
- “The financial condition and the general character of management of the applicant are sound.”
- “The net worth of the applicant is not less than two crore rupees.”
- “The volume of business, capital structure and earning prospects of the applicant are adequate.”
- “The directors, key managerial personnel and senior management of the applicant company are individuals with a general reputation and record of fairness and integrity.”
- The constitutional-documents condition, quoted in full: “The memorandum of association and articles of association of the applicant company contain provisions requiring that the obligations under items 9 and 10 of Part B are adhered to, that policies and procedures are in place to ensure such adherence, and that such provisions may be amended only with the previous approval of the Board.” Items 9 and 10 of Part B are the conflict-of-interest obligations described below.
- “The operations proposed to be undertaken by the applicant are in the interests of Data Principals.”
- Independent certification. Item 9 opens “It is independently certified that” and then sets two limbs. Limb (a): “the interoperable platform of the applicant to enable the Data Principal to give, manage, review and withdraw her consent is consistent with such data protection standards and assurance framework as may be published by the Board on its website from time to time”. Limb (b): “appropriate technical and organisational measures are in place to ensure adherence to such standards and framework and effective observance of the obligations under item 11 of Part B”.
Absence of Published Assurance Standards
Item 9(a) makes registration conditional on certification against a data protection standards and assurance framework that the Board publishes on its website, and no published version of such a framework was located. MeitY’s Business Requirement Document, described further below, is expressly non-binding and not a part of the DPDP Act and is a different instrument.
First Schedule, Part B: The Thirteen Obligations
Data-blindness, 7-year log retention, fiduciary duties, and conflict-of-interest controls
Part B sets thirteen obligations on a registered Consent Manager. The text below is quoted from Part B of the First Schedule, as reproduced by dpdpa.in. Like Part A, it takes effect only on Rule 4’s commencement.
Operating Model (Items 1 & 2)
Item 2 (Data-blindness bar): “The Consent Manager shall ensure that the manner of making available the personal data or its sharing is such that the contents thereof are not readable by it.”
Records, Conduct and Corporate Structure (Items 3 to 13):
- A record maintained on the platform of “(a) Consents given, denied or withdrawn by her; (b) Notices preceding or accompanying requests for consent; and (c) Sharing of her personal data with a transferee Data Fiduciary”.
- Access for the Data Principal to those records, provision of the information in machine-readable form on request in accordance with its terms of service, and retention of the record “for at least seven years, or for such longer period as the Data Principal and Consent Manager may agree upon or as may be required by law”.
- Development and maintenance of “a website or app, or both, as the primary means through which a Data Principal may access the services”.
- It “shall not sub-contract or assign the performance of any of its obligations under the Act and these rules”.
- Reasonable security safeguards to prevent personal data breach.
- It “shall act in a fiduciary capacity in relation to the Data Principal”.
- Avoidance of conflict of interest with Data Fiduciaries, “including in respect of their promoters and key managerial personnel”.
- Measures ensuring no conflict of interest arises from its directors, key managerial personnel and senior management holding a directorship, financial interest, employment or beneficial ownership in Data Fiduciaries, or a material pecuniary relationship with them.
- Public disclosure of its promoters, directors, key managerial personnel and senior management; every person holding shares in excess of 2% of the Consent Manager; every body corporate in which any of those persons holds shares in excess of 2% as on the first day of the preceding calendar month; and such other information as the Board directs “in the interests of transparency”.
- Effective audit mechanisms to review, monitor, evaluate and report audit outcomes to the Board, periodically and as the Board directs, covering technical and organisational controls, continued fulfilment of the registration conditions, and adherence to the obligations.
- “The control of the company registered as the Consent Manager shall not be transferred by way of sale, merger or otherwise, except with the previous approval of the Board.”
Commencement: What Switches On, and When
The 1-year versus 18-month split between registration and consumer usage
Rule 1 of the DPDP Rules, 2025 phases the Rules in three stages: “(2) Rules 1, 2 and 17 to 21 shall come into force on the date of their publication in the Official Gazette. (3) Rule 4 shall come into force one year after the date of publication of this Gazette. (4) Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication of this Gazette.” The Rules were notified as G.S.R. 846(E), New Delhi, dated the 13th November 2025.
Only one of the three anchor dates is stated on an instrument: 13 November 2025. 13 November 2026 and 13 May 2027 are computed from the commencement periods, since both Rule 1 and the Act’s commencement notification express the later tranches as periods rather than dates. Tsaaro reports the three-date mapping as 13 November 2025, 13 November 2026 and 13 May 2027, while Candour Legal computes the consent-manager commencement as 14 November 2026. This piece uses 13 November 2026 throughout, matching the gazette instrument date, and that alternative computation should be read alongside every occurrence of it.
The Act itself is phased separately, by G.S.R. 843(E), dated 13 November 2025. Its three tranches, reproduced section by section, run as follows:
| Tranche | Act provisions | Computed date |
|---|---|---|
| On publication | Section 1(2), Section 2, Sections 18 to 26, Sections 35, 38, 39, 40, 41, 42, 43, and Section 44(1) and (3) | 13 November 2025, stated on the instrument |
| One year from publication | Section 6(9) and Section 27(1)(d), and nothing else | Computed 13 November 2026, with 14 November 2026 computed by Candour Legal |
| Eighteen months from publication | Sections 3 to 5, Section 6(1) to (8) and (10), Sections 7 to 10, Sections 11 to 17, Section 27 except clause (d) of sub-section (1), Sections 28 to 34, Sections 36, 37 and Section 44(2) | Computed 13 May 2027 |
Placing the Rules’ own tranches against that: Rule 4 and the First Schedule sit at one year, alongside Section 6(9) and Section 27(1)(d). Rule 3, Rules 5 to 16, Rule 22 and Rule 23 sit at eighteen months, alongside the rest of Section 6 and the rest of Section 27(1). As at 10 September 2026, neither of the later tranches has arrived, so Rule 4, the First Schedule, Section 6(9) and Section 27(1)(d) are all outside force. What is operative on this subject today is the Section 2 definition and Sections 18 to 26 constituting the Board.
Reading the notification’s lists against the section texts
Setting the one-year list beside the section textsproduces a reading that no source cited here states as such, and it is offered as this piece’s own interpretation rather than as settled law:
The one-year tranche contains Section 6(9), the registration requirement, and Section 27(1)(d), the Board’s power over a breach of registration conditions. It does not contain Section 6(7), the provision under which a Data Principal may route consent through a Consent Manager; Section 6(8), the Consent Manager’s accountability to the Data Principal; or Section 27(1)(c), the Board’s power on a Data Principal’s complaint about a Consent Manager’s obligations. Those three sit in the eighteen-month tranche.
Read that way, the framework arrives in two pieces. At the computed 13 November 2026 date (14 November on Candour Legal’s computation), an entity can be registered and can be policed for breaching its registration conditions. The statutory provision giving a Data Principal the ability to route her consent through a Consent Manager, and the Board’s complaint jurisdiction over one, follow at the computed 13 May 2027 date.
The Board that Rule 4 registers through
As of the most recent reporting located, dated 1 August 2026, no Chairperson and no Members of the Data Protection Board had been appointed, and MeitY’s Search-cum-Selection Committees had solicited nominations by communications dated 6 May 2026 and 6 June 2026. Under Rule 17 of the DPDP Rules, 2025, the Chairperson’s Search-cum-Selection Committee is headed by the Cabinet Secretary and includes the Secretary, Department of Legal Affairs, the Secretary, MeitY, and two domain experts, with a separate committee chaired by the Secretary, MeitY selecting the other Members.
Candour Legal’s commentarystates the resulting position: “Six months out from the November 2026 deadline, the practical risk is that the compliance runway for applicants compresses into whatever window is left once the Board is actually staffed and its standards are published.”
The Data Fiduciary’s Side of the Relationship
Optional integration, the statutory drafting silence, and the surviving burden of proof
Using a consent manager will be optional for a data fiduciary once Section 6(7) commences. AZB & Partners states: “Notably, the DPDP Rules do not mandate that data fiduciaries use a consent manager. Data fiduciaries may continue to obtain consent directly … if they can meet the DPDP Act’s notice, consent, withdrawal, and record-keeping standards independently.” Clyde & Co states the same: “the DPDP Rules do not presently make it mandatory for Data Fiduciaries to work with Consent Managers. In theory, a company can continue to seek consent directly from users, as long as it complies with the Act’s stringent notice and consent requirements.” TrustArc frames integration as optional and says it is not mandatory for every business to use one.
The only textual hook for the fiduciary side inside the consent-manager provisions is one phrase. Part B item 1 refers to “a Data Fiduciary onboarded onto such platform”. Checked against Rule 4, Part A, Part B, Rule 3 and Rule 14, those provisions prescribe no onboarding procedure, no technical interface a fiduciary must expose, no contents for a consent artefact originating from a Consent Manager, no validation step, and no timeline or evidencing format for acting on a withdrawal routed through one.
What will bind the fiduciary when those provisions commence comes from the Act and from the notice and rights rules, independent of any consent manager:
- Section 6(4)gives the Data Principal the right to withdraw her consent at any time, “with the ease of doing so being comparable to the ease with which such consent was given”. Section 6(5) places the consequences of withdrawal on the Data Principal and preserves the legality of processing carried out before it.
- Section 6(6)is the downstream-propagation duty: on withdrawal, “the Data Fiduciary shall, within a reasonable time, cease and cause its Data Processors to cease processing the personal data of such Data Principal unless such processing without her consent is required or authorised under the provisions of this Act or the rules made thereunder or any other law for the time being in force in India.”
- Section 6(10)places the evidential burden on the same party: where consent is the basis of processing and a question arises in a proceeding, “the Data Fiduciary shall be obliged to prove that a notice was given by her to the Data Principal and consent was given by such Data Principal to the Data Fiduciary in accordance with the provisions of this Act and the rules made thereunder.” On this piece’s reading of the sub-section, the text carries no qualifier about the channel through which consent arrived, so the burden reads the same whether consent came directly or through a Consent Manager.
- Section 8sets the baseline: responsibility for compliance “irrespective of any agreement to the contrary” under 8(1), valid processor contracts under 8(2), data accuracy under 8(3), security safeguards under 8(5), and breach intimation under 8(6).
- Rule 3 is the notice rule and comes closest to a fiduciary-side withdrawal interface, requiring itemised descriptions and withdrawal links. Rule 3 says nothing about Consent Managers and sits in the eighteen-month tranche.
- Rule 14(1) and 14(3) put both entities under a shared duty to prominently publish rights-request routes and a grievance redressal timeline not exceeding 90 days.
MeitY’s Business Requirement Document is design guidance, not Rule 4
MeitY released a Business Requirement Document on Consent Management Systems on 6 June 2025, through the National e-Governance Division. AZB & Partners places it within MeitY’s “Code for Consent: The DPDP Innovation Challenge” and describes it: “The BRD (while non-binding and not a part of the DPDP Act) is intended to act as a guideline for the development and implementation of a CMS.”
Its content covers consent lifecycle management across collection, validation, update, renewal and withdrawal, cookie consent controls, a user dashboard, notifications, grievance redressal, and tamper-proof logging around a “Consent Artifact” recording timestamp, user ID, purpose ID, session ID and consent method. It addresses a consent management system a fiduciary runs itself, which is a different subject from Board registration under Rule 4.
Account Aggregators: A Second Consent Regime, Under a Different Regulator
DEPA lineage, overlapping ₹2 crore capital requirements, and the parallel-track paradox
The Account Aggregator framework predates the DPDP Rules and sits with RBI. The Master Direction : Non-Banking Financial Company : Account Aggregator (Reserve Bank) Directions, 2016 was issued on 2 September 2016 and updated 6 September 2024, defining an Account Aggregator as a non-banking financial company undertaking “the business of an account aggregator, for a fee or otherwise”, by “retrieving or collecting … financial information pertaining to its customer … and consolidating, organizing and presenting such information”.
The architectural ancestry is documented. NITI Aayog released the draft Data Empowerment and Protection Architecture framework in August 2020, proposing a “Consent Manager” institution, with RBI’s Account Aggregator framework described there as the financial-sector instance of that concept, built on open APIs supporting interoperability and switching between operators. DEPA is a NITI Aayog draft framework rather than law.
Three provisions of the Master Direction are comparable in substance to Part B items quoted above:
- The Master Direction requires a standardised consent artefact containing the customer’s identity and contact details, the nature of the financial information requested, the purpose of collecting it, the identity of the recipients, a notification URL, creation and expiry dates, and the AA’s signature.
- It provides that an “Account Aggregator shall not support transactions by customers” and that “No financial information of the customer accessed by the Account Aggregator … shall reside with the Account Aggregator”.
- And it sets a minimum net owned fund of “not less than rupees two crore” plus RBI registration before commencing operations. That capital figure matches the ₹2 crore net worth in Part A item 4 numerically, under a different regulator and a different instrument.
How the two regimes relate is unresolved on the record. Writing in SCC Times on 26 June 2026, Sambhav Mukherjee notes that Account Aggregators “operate exclusively on ‘financial information’” while Consent Managers’ scope covers personal data generally including financial information, that “the absence of a coordinated standard between RBI and the DPB means that these frameworks are developing in parallel without any compatibility”, and that “it is therefore unclear whether additional approval from the DPB is necessary, leaving room for ambiguity and potentially leading to significant overlaps in oversight”, raising “potential parallel enforcement, duplicative penalties, and uncertainty”. Candour Legal separately records the question as formally unresolved.
One industry position has been published on the question, as advocacy rather than as an outcome. Sahamati, the Account Aggregator ecosystem’s industry body, argued on 18 March 2025 that “ensuring that the DPB deems and/or registers all operating AAs as Consent Managers under the DPDP Act is important”, proposed registration of sector-specific consent managers rather than an exemption, and argued that “interoperability can be guaranteed under both regimes, as long as all AAs/CMs operate on common underlying technical specifications such as those laid down by ReBIT”. That is what one industry body has asked for.
Consent Manager, Account Aggregator, Consent Management Platform
Three distinct architectures for consent handling across Indian BFSI
A structural comparison across registration requirements, governing instruments, data scope, and live operational status:
Our Take: What the Commencement Split and the Drafting Silence Mean Together
Practical interpretations for regulated lenders and technology providers
Everything in this section is interpretation built from the provisions and commentary cited above, not a new claim.
Read together, the one-year list and the eighteen-month list suggest a framework that becomes registrable before it becomes usable. Section 6(9) and Section 27(1)(d) arrive at the computed 13 November 2026 date, with Candour Legal computing 14 November; Section 6(7), Section 6(8) and Section 27(1)(c) follow at the computed 13 May 2027 date. The practical implication is that the six-month gap between the two computed dates belongs to applicants and to the Board rather than to institutions choosing whether to route consent through anyone, since the provision enabling that routing sits in the later tranche.
Two further cited facts point at the same six-month window. Part A item 9(a) conditions registration on independent certification against a framework the Board publishes, and no published version of that framework was located. As of 1 August 2026 reporting, the Board had no Chairperson and no Members. That is the sequencing Candour Legal’s commentary describes when it says the applicant runway compresses into whatever window remains once the Board is staffed and its standards published.
On the fiduciary side, the drafting silence and the optionality point the same way. AZB & Partners and Clyde & Co both record that using a consent manager is not mandatory, and Rule 4, the First Schedule, Rule 3 and Rule 14 prescribe no integration mechanics on that side. Our reading is that the obligations a BFSI institution will carry when the eighteen-month tranche commences come from the same provisions whether or not a Consent Manager is in the picture: Section 6(6)’s duty to cease and cause processors to cease within a reasonable time, Section 6(10)’s burden of proving notice and consent, and Section 8’s baseline. Since Section 6(10)’s text carries no channel qualifier, the evidential burden on those future facts appears to sit with the fiduciary in either arrangement.
The Account Aggregator question remains open on the published record, and this piece does not resolve it. SCC Times records the absence of a coordinated standard between RBI and the Board and the resulting ambiguity about whether additional Board approval is needed, Candour Legal calls the question formally unresolved, and Sahamati has argued for deeming or registering operating AAs as Consent Managers as an industry position. Read together, those three suggest that any planning assumption about how an existing NBFC-AA relationship will be treated under the DPDP framework is currently an assumption rather than a settled position.
Frequently Asked Questions
Key statutory determinations on Consent Managers under the DPDP Act and Rules
This piece is KYCKART’s informational interpretation of publicly available regulatory sources on the DPDP Act, 2023, the DPDP Rules, 2025, the commencement notifications G.S.R. 843(E) and G.S.R. 846(E), and RBI’s NBFC-Account Aggregator Master Directions, 2016. Regulatory positions stated here are as at 10 September 2026, when Rule 4, the First Schedule, Section 6(9) and Section 27(1)(d) are not in force. Statutory text cited here is drawn from secondary reproductions of the Act, the Rules and the commencement notifications rather than from an official government domain, and should be verified against the primary gazette text. This is not legal, tax or compliance advice. Organisations should consult qualified counsel before acting on any interpretation here, including on whether and when to apply for registration or to integrate with a consent manager.
DPDP Consent Architecture
Navigating the Consent Manager & DPDP Compliance Roadmap for Your Financial Institution?
Connect with our compliance and technical engineering specialists to understand how KYCKART ensures tamper-proof consent logging, notice management, and verifiable audit trails across banking and lending systems.
Speak with Our Compliance Teamarrow_forward