Consent Manager registration under the Digital Personal Data Protection (DPDP) Rules, 2025 applies to entities that intend to operate as registered Consent Managers in India. Rule 4 establishes the registration framework, while Part A of the First Schedule sets nine conditions covering corporate structure, financial standing, management, governance, and the technology platform.
The framework makes one thing clear: a Consent Manager is not simply a consent collection software or tool. Registration brings the organization, its operating model, and its interoperable platform under a defined regulatory framework. Understanding what the Rules require therefore means looking at both the eligibility criteria and the infrastructure needed to fulfil the role.
What Is A Consent Manager?
A Consent Manager is an entity that provides a platform through which a Data Principal can give, manage, review, and withdraw consent for the processing of personal data.
The role sits between Data Principals and Data Fiduciaries. Instead of consent remaining fragmented across individual applications and services, the Consent Manager provides an interoperable layer through which the Data Principal can manage consent with participating Data Fiduciaries.
The DPDP Rules make interoperability central to this role. The platform is expected to facilitate consent across the participating ecosystem, rather than simply record a preference within one company's environment. Part B further requires the Consent Manager to maintain records of consents given, denied, or withdrawn, the notices accompanying consent requests, and specified instances of personal data sharing.
That distinction separates a registered Consent Manager from a conventional cookie banner, preference center, or consent management interface. Those tools may capture a choice. A Consent Manager operates as a regulated intermediary with defined responsibilities toward the Data Principal.
Want to know more about Consent Manager under the DPDP Act? Read here.
DPDP Consent Manager Registration Under Rule 4
Rule 4 establishes the registration mechanism.
A person that fulfils the conditions in Part A of the First Schedule may apply to the Data Protection Board by furnishing the particulars, information, and documents that the Board publishes on its website.
The Board may conduct an inquiry to determine whether the applicant satisfies the prescribed conditions. Where it is satisfied, the applicant is registered as a Consent Manager and its particulars are published on the Board's website. Where the application is rejected, the Board must communicate the reasons for rejection.
The framework therefore follows a straightforward regulatory sequence:
- Meet the conditions in Part A
- Submit the prescribed information and documents
- Undergo the Board's inquiry
- Receive registration or reasons for rejection
- Operate in accordance with Part B after registration
The final step is important. Registration does not create a permanent exemption from scrutiny. Rule 4 allows the Board to seek information, identify non-adherence, direct remedial measures, and, where necessary in the interests of Data Principals, suspend or cancel registration after providing an opportunity to be heard.
Consent Manager registration is therefore better understood as the beginning of a regulated operating relationship rather than the completion of an application.
Conditions to Know for Consent Manager Registration
Part A of the First Schedule establishes nine conditions for registration. They span four broad dimensions: legal eligibility, institutional strength, governance, and technical capability.
The first eight conditions largely examine whether the applicant is structurally capable and appropriately governed to take on the role. The ninth moves directly into the technology layer, requiring independent certification of the interoperable platform and the technical and organizational measures supporting it.
Company Incorporated In India
The applicant must be a company incorporated in India.
This is a foundational eligibility requirement. The registration framework attaches the regulated role to the legal entity itself, not simply to a product or service offered within India.
That distinction matters for businesses with global operations or multinational technology stacks. The entity seeking Consent Manager status must satisfy the incorporation requirement in its own right.
Technical, Operational, And Financial Capacity
The Rules require sufficient capacity, including technical, operational, and financial capacity, to fulfil the obligations of a Consent Manager.
The three dimensions are closely connected. Technical capacity concerns the infrastructure supporting an interoperable consent service. Operational capacity encompasses the processes, people, controls, and oversight needed to run that service consistently. Financial capacity speaks to the resources available to sustain the operation.
For a Consent Manager, capacity cannot be measured simply by whether a platform can display a consent request. The service has to support an entire lifecycle: consent initiation, decision capture, review, withdrawal, record maintenance, interaction with Data Fiduciaries, security, and audit.
Sound Financial Condition And Management
The applicant's financial condition and the general character of its management must be sound. This requirement extends the assessment beyond a single financial threshold. The Rules are concerned with whether the entity has a stable foundation and whether its management is suitable for a role involving the consent decisions of Data Principals.
The result is a broader trust assessment. Financial strength, management quality, and the integrity of the operating entity all become relevant to registration.
Minimum Net Worth Of ₹2 Crore
The applicant must have a net worth of not less than ₹2 crore. The Rules define net worth as the aggregate value of total assets reduced by liabilities as reflected in the Consent Manager's books of accounts.
The ₹2 crore threshold establishes a clear financial entry condition. It also sits alongside the broader requirement for adequate capital structure and earning prospects, meaning the minimum net worth should not be viewed as the entirety of the financial assessment.
Adequate Business And Financial Prospects
The Rules require the volume of business likely to be available to the applicant, its capital structure, and its earning prospects to be adequate.
The question is not simply whether an applicant has sufficient capital today. The proposed Consent Manager operation must also have a credible economic foundation capable of supporting the role it intends to undertake.
Directors And Management With Fairness And Integrity
The directors, key managerial personnel, and senior management must have a general reputation and record of fairness and integrity.
The requirement reflects the nature of the role. A Consent Manager is entrusted with maintaining records and facilitating consent decisions on behalf of Data Principals. The Rules therefore examine the people responsible for directing and managing the entity, not only the systems they operate.
Required Governance Provisions
The memorandum and articles of association must contain provisions requiring adherence to specified obligations under Part B. The applicant must also have policies and procedures to support those obligations, and the specified provisions can be amended only with prior approval of the Board.
This brings corporate governance directly into the registration architecture.
It also creates an important distinction between ordinary internal policy and obligations embedded into the company's constitutional documents. Certain Consent Manager responsibilities are not intended to remain informal operational commitments. They become part of the organization's formal governance framework.
Operations In The Interests Of Data Principals
The proposed operations must be in the interests of Data Principals. This gives the Consent Manager framework a clear orientation. The platform is not merely a mechanism for helping businesses obtain consent. Its operation must account for the interests of the individual whose consent is being managed.
That principle becomes especially relevant when the platform handles consent withdrawal, maintains consent histories, interacts with multiple Data Fiduciaries, and manages the information surrounding those interactions.
Independent Certification Of The Interoperable Platform
The ninth condition is the most technology-intensive requirement in Part A.
The applicant must have independent certification that its interoperable platform enables the Data Principal to give, manage, review, and withdraw consent and is consistent with the data protection standards and assurance framework published by the Board. It must also demonstrate appropriate technical and organizational measures for adherence to those standards and effective observance of the relevant Part B obligations.
Interoperability changes the nature of the architecture. A Consent Manager cannot treat consent as an isolated record inside one application. Its platform sits between Data Principals and participating Data Fiduciaries, creating a requirement for consent to remain understandable, accessible, and actionable across those relationships.
That makes the underlying architecture important. Identity, consent records, notices, withdrawal events, integrations, security controls, and audit mechanisms all become part of the consent lifecycle.
The requirement also changes how certification should be viewed. It is not simply a check on whether a consent interface works. The platform and its supporting controls need to demonstrate that the Consent Manager can perform its regulated role reliably.
In other words, consent management becomes consent infrastructure.
What Does A Consent Manager Need To Do After Registration?
The First Schedule does not stop at eligibility. Part B establishes a continuing set of obligations for registered Consent Managers.
The platform must enable Data Principals to give consent to processing by onboarded Data Fiduciaries. It must also maintain records covering:
- Consents given, denied, or withdrawn
- Notices preceding or accompanying requests for consent
- Sharing of personal data with a transferee Data Fiduciary
Data Principals must be able to access these records, and the Consent Manager must make the information available in machine-readable form when requested under its terms of service. The records must generally be retained for at least seven years, subject to the longer periods specified in the Rules.
The operating requirements extend further. A registered Consent Manager must maintain a website or app as the primary access point, take reasonable security safeguards against personal data breaches, act in a fiduciary capacity toward Data Principals, and avoid conflicts of interest with Data Fiduciaries.
The Rules also prohibit subcontracting or assigning the performance of the Consent Manager's obligations. Effective audit mechanisms must cover technical and organizational controls, continued fulfilment of registration conditions, and adherence to the Act and Rules.
Consent Manager Vs. Data Fiduciary: Differences to Understand
The two roles occupy different positions within the DPDP ecosystem. A Data Fiduciary determines the purpose and means of processing personal data, while a Consent Manager provides the regulated infrastructure through which Data Principals can manage consent.
| Aspect | Consent Manager | Data Fiduciary |
|---|---|---|
| Primary Role | Provides an interoperable platform for Data Principals to give, manage, review, and withdraw consent. | Determines the purpose and means of processing personal data. |
| Regulatory Position | Operates under the Consent Manager registration and obligation framework in Rule 4 and the First Schedule. | Operates under the obligations applicable to Data Fiduciaries under the DPDP framework. |
| Registration | Requires registration with the Data Protection Board to operate as a Consent Manager. | Does not become a Consent Manager merely by processing personal data. |
| Consent Relationship | Facilitates consent between the Data Principal and onboarded Data Fiduciaries. | Seeks and relies on consent where consent is the applicable ground for processing. |
| Technology Role | Maintains the interoperable platform and the mechanisms required to manage consent records and related interactions. | Maintains the systems through which its own processing activities are carried out and governed. |
| Records | Maintains specified records of consent decisions, notices, and certain data-sharing events. | Maintains the records and evidence relevant to its processing obligations. |
| Data Principal Relationship | Acts in a fiduciary capacity toward the Data Principal. | Has obligations toward Data Principals in relation to the personal data it processes. |
| Conflict Of Interest | Must avoid conflicts of interest with Data Fiduciaries and maintain measures addressing specified management relationships. | Must manage its processing activities in accordance with the obligations applicable to it. |
| Ongoing Oversight | Subject to registration conditions, audits, information requests, remedial directions, and potential suspension or cancellation. | Subject to the applicable compliance, security, and accountability requirements under the DPDP framework. |
The distinction is fundamental. A Consent Manager is a regulated role, not simply another name for a consent management product. A Data Fiduciary can implement sophisticated consent infrastructure without becoming a Consent Manager.
When Does Consent Manager Registration Begin?
Rule 1 establishes different commencement periods for the DPDP Rules.
Rule 4 comes into force one year after the date of publication of the Rules in the Official Gazette. The notification is dated 13 November 2025, and the Rules' commencement schedule identifies 13 November 2026 for Rule 4.
This gives the registration framework a defined commencement point. It does not, however, mean every detail of the application experience can be inferred in advance. Rule 4 specifically states that applicants must furnish the particulars, information, and documents that the Board publishes for this purpose.
That distinction is useful when planning around the timeline. The commencement date is established by the Rules; the operational mechanics of applying depend on the information and framework published by the Board.
Preparing For Consent Manager Registration
The nine conditions point to a readiness model that spans the legal entity, its governance, its financial position, and its technology.
Establish The Corporate Foundation
The legal structure needs to satisfy the India-incorporated company requirement, while the memorandum and articles of association need to accommodate the relevant Part B obligations.
Establish Financial Readiness
The ₹2 crore net worth threshold is only one part of the financial assessment. Capital structure, expected business volume, earning prospects, and overall financial condition also appear within Part A.
Build Governance Into The Operating Model
The governance requirements extend to directors, key managerial personnel, senior management, policies, procedures, and constitutional documents.
For a Consent Manager, governance cannot sit separately from technology. Conflict-of-interest controls, accountability, audit mechanisms, and transparency requirements directly affect how the platform is operated.
Design For The Complete Consent Lifecycle
The critical question is not simply whether a user can click “accept.”
A mature consent architecture needs to preserve the context around that decision and support what follows: review, withdrawal, record access, data sharing, and audit. That calls for a connected view of identity, consent, applications, and processing relationships.
Treat Interoperability As An Architectural Principle
A Consent Manager exists precisely because consent may span multiple Data Fiduciaries.
Interoperability therefore needs to be designed into the platform rather than added as an integration layer at the end. The consent record, associated notice, status, and withdrawal event need to remain usable across the ecosystem in which the Consent Manager operates.
Build For Evidence, Not Just Execution
A system can perform an action without being able to prove how or why it happened.
Consent infrastructure needs a stronger evidence model. The ability to reconstruct the relevant consent event, associated notice, status changes, and downstream activity becomes important for auditability and accountability.
From Consent Collection To Consent Infrastructure
The DPDP framework changes the significance of consent.
Consent is no longer simply a moment at which an individual selects an option. It becomes a record that has to remain meaningful throughout its lifecycle: from the notice presented before the decision, through the consent itself, to subsequent review, withdrawal, and related data-sharing activity.
That lifecycle requires more than a front-end consent experience. It requires connections between identity, consent, applications, data flows, security controls, and audit mechanisms.
This is where miniOrange's broader identity and privacy expertise becomes relevant. miniOrange's Consent Management Platform provides a foundation for managing consent as an enterprise process, connecting consent management with the systems and identity infrastructure that already govern digital interactions.
The architectural value lies in treating consent as a governed data object rather than an isolated checkbox. A consent decision can be captured, managed, reviewed, and acted upon within a broader framework of identity and privacy controls.
That perspective becomes particularly important under a regulatory model where interoperability, independent certification, consent records, security safeguards, and ongoing audits are all part of the Consent Manager framework.
The question, therefore, is not simply:
“Can the platform collect consent?”
It is:
“Can the platform establish a consent lifecycle that remains reliable, traceable, interoperable, and governable?”
That is the level at which Consent Manager readiness needs to be considered.
What Consent Manager Registration Means For The DPDP Ecosystem
The nine conditions make the scope clear. Registration is not determined by a product feature set alone. It encompasses the legal identity of the applicant, its financial foundation, the integrity of its management, its governance structure, its orientation toward Data Principals, and the technology underpinning its interoperable platform.
A registered Consent Manager under DPDP compliance must preserve consent records, support Data Principal access, maintain security safeguards, manage conflicts of interest, enable auditing, and remain accountable to the Data Protection Board.
The strongest consent architecture will not be defined by how effectively it captures a user's initial decision. It will be defined by how reliably that decision can be understood, managed, withdrawn, evidenced, and respected across the systems connected to it.
Frequently Asked Questions
Can An LLP Register As A Consent Manager?
Part A of the First Schedule specifies that the applicant must be a company incorporated in India. The Rules do not specify an LLP as an eligible applicant.
Is Independent Certification Required For Consent Manager Registration?
Yes. Part A requires independent certification of the interoperable platform against the data protection standards and assurance framework published by the Board, together with appropriate technical and organizational measures to support adherence.
Can A Consent Manager Read The Personal Data Being Shared?
The Rules require the manner of making personal data available or sharing it to be such that the contents are not readable by the Consent Manager.
Can A Consent Manager Subcontract Its Obligations?
No. Part B states that a Consent Manager shall not subcontract or assign the performance of its obligations under the DPDP Act and Rules.
Can Consent Manager Registration Be Suspended Or Cancelled?
Yes. The Data Protection Board may suspend or cancel registration if it is satisfied that doing so is necessary in the interests of Data Principals. The Consent Manager must first receive an opportunity to be heard, and the Board must record its reasons in writing.
Does A Consent Manager Have To Disclose Its Ownership And Management Details?
Yes. Part B requires specified information about promoters, directors, key managerial personnel, senior management, shareholders holding more than 2% of the company's shareholding, and certain corporate relationships to be published in an easily accessible manner.
Are Consent Managers Subject To Audits?
Yes. The Rules require effective audit mechanisms covering technical and organizational controls, systems, procedures and safeguards, continued fulfilment of registration conditions, and adherence to obligations under the Act and Rules.
Can Control Of A Registered Consent Manager Be Transferred?
Not without prior approval from the Data Protection Board. Part B states that control cannot be transferred through sale, merger, or otherwise unless the Board approves it and applicable conditions are fulfilled.




Leave a Comment