Checklist · Consent Manager

DPDPA Checklist for Consent Managers

Two different roles share this title. The registered Consent Manager under the Act is a narrow, Board-licensed category. Everyone else running consent notices and withdrawal inside a company is a consent-operations owner. The dates differ too — 13 November 2026 for registration, 13 May 2027 for the rest. Know which you are.

Last reviewed: 30 July 2026

What must a consent manager or consent-operations owner do for DPDPA compliance?

Items 1–7 apply to anyone owning consent operations. Items 8–9 apply only if you intend to register as a Consent Manager with the Board. Item 10 applies to both.

  1. Establish which role you actually hold — and write it down. A registered Consent Manager is a defined entity: a person registered with the Data Protection Board, enabling Data Principals to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform, and — critically — acting in a fiduciary capacity in relation to the Data Principal (First Schedule, Part B, item 8). It is a licensed intermediary business, not a job title. Most organisations will never register, and you do not need to be or to use a Consent Manager to be DPDPA compliant — Section 6(7) makes the Consent Manager route an option available to the Data Principal, not an obligation on Data Fiduciaries. If you run consent inside a company, you are a consent-operations owner and items 2–7 and 10 are your remit. Say which one you are in your programme charter, because the two produce very different budgets.
  2. Diarise the split commencement — the registration gateway opens first. This is the timing point almost nobody has noticed:
    ProvisionCommencesWhat it covers
    Rule 4, Act s.6(9), s.27(1)(d)13 November 2026Registration and obligations of Consent Managers; the Board's function in respect of them
    Act s.6(1)–(8) and (10), ss.3–5, 7–17, 27, 28–34, 36, 37; Rules 3, 5–16, 22, 2313 May 2027Notice, consent, legitimate uses, duties of Data Fiduciaries, rights, breach reporting
    The gazette was published 13 November 2025; Rule 1(3) sets Rule 4 at one year and Rule 1(4) sets the main tranche at eighteen months. So the registration regime is live roughly six months before the substantive consent obligations bite. If you are pursuing registration, your window opens in November 2026 — work backwards from there, not from May 2027.
  3. Itemise purposes at the notice layer, not the UI layer. Rule 3 requires the notice to be presented and understandable independently of any other information you make available, to give in clear plain language an itemised description of the personal data and the specified purpose or purposes with a specific description of the goods, services or uses enabled, and to give the particular communication link and any other means by which the Data Principal may withdraw consent (with ease comparable to that with which it was given), exercise rights, and make a complaint to the Board. That last element is the most commonly omitted. Operationally: one purpose, one affirmative action; no pre-ticked boxes; no bundling; and consent cannot be made a condition of a service for purposes the service does not need. Version your notices and keep every version retrievable — you will need to prove which text was served, not just that consent exists.
  4. Make the consent record evidentiary rather than merely present. The question in an inquiry is not "do you have consent" but "prove the state of consent on a given date." Capture per event: notice version served, purposes granted, purposes refused, timestamp, channel, and the identity-verification method where a child or guardian was involved. Store it tamper-evidently and time-ordered so you can reconstruct any point in the timeline. Note the registered-Consent-Manager standard here, which is a useful benchmark even if it does not bind you: Part B item 3 requires a record of consents given, denied or withdrawn, the notices preceding or accompanying each consent request, and each sharing of personal data with a transferee Data Fiduciary.
  5. Test that withdrawal actually propagates — end to end, on a live journey. Withdrawal must be as easy as giving. The harder half is downstream: run a real test and confirm the withdrawal reaches your primary database, CRM, CDP, email and messaging gateways, any uploaded ad audience, and every processor and partner holding that record. Most organisations can stop the first system and none of the rest. Document the boundaries honestly in your SOP: withdrawal does not reach data retained under a legal obligation, and processing done before withdrawal remains lawful — which is precisely why the timestamped record in item 4 matters.
  6. Build the child and guardian paths as separate flows, not conditional branches. Where a Data Principal is a child (anyone under 18), Rule 10 requires appropriate technical and organisational measures to obtain verifiable parental consent, with due diligence that the individual identifying as the parent is an adult who is identifiable — by reference to reliable identity and age details you already hold, details voluntarily provided, or a virtual token mapped to such details issued by an authorised entity, which includes a Digital Locker service provider. Record which route was used. Rule 11 is a different test entirely for a person with disability who has a lawful guardian: verify appointment by a court, by a designated authority under s.15 of the Rights of Persons with Disabilities Act 2016, or by a local level committee under s.13 of the National Trust Act 1999. Build an eighteenth-birthday trigger that moves consent from guardian to individual. Check separately whether Rule 12 and the Fourth Schedule carve-outs apply to you — they are class- and purpose-bound (healthcare, education, crèche, school transport, and specified purposes), and they are not general relief.
  7. Publish the rights and grievance machinery — Rule 14 names Consent Managers expressly. Rule 14(1) requires the Data Fiduciary and, where applicable, the Consent Manager to prominently publish the means by which a Data Principal makes a rights request and any identifier required to locate her. Rule 14(3) requires every Data Fiduciary and Consent Manager to publish its grievance redressal system and respond within a reasonable period not exceeding ninety days, with technical and organisational measures to make that effective. Rule 14(4) requires supporting nomination of one or more individuals. Rule 9 requires publishing the business contact information of the DPO if applicable, or a person able to answer questions about processing — and repeating it in every response to a rights communication. Instrument the queue with SLA timers and report volumes monthly; an unmeasured queue is the easiest thing for a regulator to find wanting.
  8. If registering: work the First Schedule Part A conditions now, not in November 2026. Registration is by application to the Board, furnishing such particulars, information and documents as the Board may publish on its website (Rule 4(1)) — so monitor that page rather than assuming a form exists. The conditions are cumulative and several have long lead times:
    • Incorporated as a company in India
    • Sufficient technical, operational and financial capacity; sound financial condition and general character of management
    • Net worth not less than ₹2 crore
    • Adequate volume of likely business, capital structure and earning prospects
    • Directors, key managerial personnel and senior management of general reputation and record of fairness and integrity
    • MoA and AoA containing provisions requiring adherence to Part B items 9 and 10, with policies and procedures in place, amendable only with the Board's prior approval
    • Operations proposed are in the interests of Data Principals
    • Independent certification that your interoperable give/manage/review/withdraw platform is consistent with the data protection standards and assurance framework the Board may publish on its website, and that appropriate measures exist for Part B item 11
    The MoA/AoA amendment and the independent certification are the two that will set your critical path. Note the Board may reject an application and must communicate its reasons (Rule 4(2)(b)).
  9. If registering: design to the Part B operating model before you write code. Several obligations are architectural and cannot be retrofitted:
    • Content blindness. The manner of making available or sharing personal data must be such that the contents are not readable by you (item 2). If your design reads payloads, it is the wrong design.
    • No sub-contracting. You shall not sub-contract or assign performance of any obligation under the Act and these Rules (item 6). This constrains a great deal of ordinary SaaS architecture.
    • Records for at least seven years, or longer as agreed with the Data Principal or required by law; accessible to her, and available in machine-readable form on request per your terms of service (items 3–4).
    • Website or app as primary access channel (item 5).
    • Fiduciary capacity toward the Data Principal (item 8) — a higher standard than a commercial service relationship.
    • Conflict of interest avoidance with Data Fiduciaries, including in respect of promoters and KMP, plus measures covering directorships, financial interests, employment, beneficial ownership and material pecuniary relationships (items 9–10).
    • Public disclosure of promoters, directors, KMP and senior management; every person holding more than two per cent of shareholding; and every body corporate in which any of those individuals holds more than two per cent as on the first day of the preceding calendar month (item 11).
    • Effective audit mechanisms to review, monitor, evaluate and report outcomes to the Board periodically and as directed, covering technical and organisational controls, continued fulfilment of registration conditions, and adherence to obligations (item 12).
    • Control cannot be transferred by sale, merger or otherwise except with the Board's prior approval and on conditions it specifies (item 13). Flag this to your investors early — it materially affects exit optionality.
  10. Secure the consent store and rehearse the breach — a consent ledger is a high-value target. Map your controls to Rule 6(1): encryption, obfuscation, masking or virtual tokens (a); access control over computer resources (b); logs, monitoring and review giving visibility on access (c); backups and continuity (d); retention of logs and personal data for one year unless another law requires otherwise (e); security provisions in processor contracts (f); and technical and organisational measures ensuring effective observance (g). Registered Consent Managers owe reasonable security safeguards under Part B item 7 independently. Then pre-build the notification runbook to four cumulative lanes: CERT-In within 6 hours of noticing where the incident is covered; Rule 7(1) intimation to each affected Data Principal without delay; Rule 7(2)(a) initial intimation to the Board without delay; Rule 7(2)(b) detailed report to the Board within 72 hours. The Board receives two filings, not one — most runbooks have only the 72-hour report. Note also that a consent-platform compromise is a breach even with no exfiltration if it caused loss of access, and that the 72-hour report must include a report on the intimations given to affected Data Principals, so your dispatch logs are a filing input.

Frequently asked questions

Does our company need to appoint a Consent Manager, or register as one?

Almost certainly neither. A Consent Manager under the DPDPA is a separate business that offers Data Principals a platform to give, manage, review and withdraw consent across multiple onboarded Data Fiduciaries. Section 6(7) gives the Data Principal the option to route consent through one; it imposes no obligation on you to appoint one, and using a Consent Manager is not a compliance requirement for a Data Fiduciary. Registration under Section 6(9) and Rule 4 applies only if you intend to offer that service — and it is a licensed activity with a ₹2 crore net-worth floor, a mandated MoA/AoA structure, independent platform certification, and Board approval required for any transfer of control.

What you almost certainly do need is an internal owner for consent operations: notices meeting Rule 3, itemised purposes, an evidentiary consent record, working withdrawal propagation, and the Rule 14 rights and grievance machinery. That role has no statutory title, is not a DPO (a designated DPO under Section 10(2) is a Significant Data Fiduciary obligation, conferred by Central Government notification), and is not a Consent Manager. Naming it clearly prevents the common failure of a team building toward registration requirements it never needed to meet. One further clarification worth making internally: an RBI-registered Account Aggregator is not automatically a DPDPA Consent Manager, and vice versa. They are separate regimes with separate regulators, registration conditions and obligations, and an AA consent artefact does not discharge your DPDPA notice and consent duties.

We do intend to register. What is the realistic sequence and timeline?

Work backwards from 13 November 2026, when Rule 4 and Section 6(9) commence. Four things sit on the critical path and none is quick.

First, corporate structure: you must be a company incorporated in India, and your memorandum and articles must contain provisions requiring adherence to Part B items 9 and 10 on conflict of interest — with the constraint that once registered, those provisions may be amended only with the Board's prior approval. Draft them deliberately; you are locking them in.

Second, conflict-of-interest cleanup: Part B items 9 and 10 require you to avoid conflicts with Data Fiduciaries, including in respect of promoters and KMP, and to have measures ensuring no director, KMP or senior management figure holds a directorship, financial interest, employment, beneficial ownership or material pecuniary relationship with a Data Fiduciary. If your cap table or board includes prospective client entities, that is a structural problem to solve before applying, not during.

Third, independent certification that your interoperable platform is consistent with the data protection standards and assurance framework the Board may publish on its website from time to time, plus measures for the Part B item 11 disclosures. Since that framework is published by the Board rather than fixed in the Rules, monitor the Board's site and build to a defensible baseline in the meantime.

Fourth, financial thresholds and disclosure readiness: net worth of not less than ₹2 crore, demonstrable technical, operational and financial capacity, and a standing ability to publish promoter, director, KMP and senior-management details plus every above-two-per-cent shareholder and the connected bodies corporate, refreshed against the first day of the preceding calendar month.

Application is made to the Board furnishing such particulars, information and documents as it publishes on its website (Rule 4(1)); the Board may make such inquiry as it deems fit, and must communicate reasons if it rejects (Rule 4(2)).

Once registered, what are the ongoing obligations — and what happens if we fall short?

Ongoing, the sharp edges are the ones that constrain product and corporate decisions rather than paperwork. You must keep the platform blind to content: the manner of making data available or sharing it must be such that the contents are not readable by you. You cannot sub-contract or assign performance of any obligation under the Act or the Rules. You must maintain the consent, notice and sharing records for at least seven years and make them available to the Data Principal, in machine-readable form on request. You act in a fiduciary capacity toward the Data Principal — a materially higher duty than a commercial service relationship, and the frame a Board inquiry will use. You must maintain effective audit mechanisms and report outcomes to the Board periodically and whenever it directs, covering your controls, your continued fulfilment of registration conditions, and your adherence to obligations. And control of the company cannot be transferred by sale, merger or otherwise without the Board's prior approval, on such conditions as it specifies — a term worth surfacing to investors before a term sheet, not after. Rule 14(3) also binds you directly to the ninety-day grievance ceiling.

On consequences, the Rules give the Board a graduated path specific to Consent Managers. Under Rule 4(4), if the Board is of the opinion that you are not adhering to the conditions and obligations, it may — after giving you an opportunity of being heard — inform you of the non-adherence and direct you to take remedial measures. Under Rule 4(5), if satisfied it is necessary in the interests of Data Principals, and again after an opportunity of being heard, it may by written reasoned order suspend or cancel your registration and give such directions as it thinks fit. Under Rule 4(6) it may require you to furnish information at any time. For a licensed intermediary, suspension is the commercially decisive sanction, and it arrives through a process you can engage with — which is an argument for documenting your remediation contemporaneously rather than reactively.

Separately, the Act's Schedule sets the monetary penalty heads, and these apply to your own processing where you are a Data Fiduciary in your own right — up to ₹250 crore for failure to take reasonable security safeguards to prevent a personal data breach under Section 8(5), and up to ₹200 crore for failure to give the required breach intimation under Section 8(6), assessed separately so one incident can attract both. These are statutory ceilings, not expected fines; the Board determines quantum on the facts, weighing the nature, gravity and duration of the breach, the type of personal data affected, whether the conduct was repetitive, and the mitigation undertaken and how promptly.

Official sources

Consent operations or registration — know which path you are on

A 30-minute call: we sort whether you need internal consent-ops hygiene or a Rule 4 registration track, then walk notices, evidentiary records, withdrawal propagation and — if you are registering — Part A conditions and Part B architecture constraints. You leave with a written gap list.

Book a demo call Free Gap Analysis

Bring your current consent notice and one withdrawal journey. No deck.

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For organisation-specific obligations, work with qualified Indian legal counsel.