On this page
Only a small part of the DPDP framework starts on 13 November 2026, and it is about Consent Managers. The Rules that set out how a Consent Manager registers and what it must do begin that day. The Act’s rule that every Consent Manager must be registered begins the same day. The rest of the Act that is not yet in force, including the duties of Data Fiduciaries, begins six months later, on 13 May 2027.
What a Consent Manager is
The Act defines a Consent Manager as a person registered with the Board who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform. The Act says a Data Principal may give, manage, review or withdraw consent to a Data Fiduciary through a Consent Manager, and that the Consent Manager is accountable to the Data Principal and acts on her behalf, subject to the obligations the Rules set.
The Rules give an example. People manage their consent through a platform kept by a Consent Manager, and two banks are signed up to it. A person can give her consent directly to one bank, or route it through the bank where she holds her account, which sends her statement to the other bank on her digital instruction.
The dates, exactly
The government’s notification and the Rules both set these dates as periods counted from the date of publication, 13 November 2025. Neither prints the later calendar dates. Counted from 13 November 2025:
| Date | What starts |
|---|---|
| 13 November 2026 (one year) | The Rules on registering as a Consent Manager and on a Consent Manager’s obligations. The Act’s requirement that every Consent Manager be registered with the Board. The Board’s power to inquire into a breach of a registration condition. |
| 13 May 2027 (eighteen months) | The Act’s sections on using a Consent Manager and on its accountability to the Data Principal, the Board’s power to act on a complaint about a Consent Manager, grievance redressal, the duty of a Data Fiduciary (and, where applicable, a Consent Manager) to publish the means for rights requests, and the duty of every Data Fiduciary and Consent Manager to publish a grievance period. |
In short, registration opens first, and the broader framework follows on 13 May 2027. The Act’s duties for businesses belong to the later group: see the timeline article.
How registration works

- A person who meets the conditions in Part A of the First Schedule may apply to the Board, giving the particulars, information and documents the Board publishes on its website.
- The Board may inquire as it sees fit. If it is satisfied, it registers the applicant, tells the applicant, and publishes the Consent Manager’s particulars on its website. If not, it rejects the application and gives its reasons.
- If the Board thinks a Consent Manager is not following the conditions and obligations, it may, after giving an opportunity of being heard, tell it so and direct it to put matters right. The Board may also suspend or cancel a registration, by an order with reasons recorded in writing, after giving the Consent Manager an opportunity of being heard, if that is necessary in the interests of Data Principals, and may require information.
The conditions to register
Part A of the First Schedule lists nine conditions. In plain words, the applicant must:
- be a company incorporated in India;
- have sufficient technical, operational and financial capacity;
- be in sound financial condition, with management of sound general character;
- have a net worth of not less than two crore rupees;
- show adequate likely volume of business, capital structure and earning prospects;
- have directors, key managerial personnel and senior management with a general reputation and record of fairness and integrity;
- have charter documents that require the Part B obligations on conflicts of interest to be followed, with policies to ensure it, and that can be amended only with the Board’s prior approval;
- propose operations that are in the interests of Data Principals; and
- have its interoperable platform independently certified as consistent with the data protection standards and assurance framework the Board publishes, and that it has measures in place to follow them.
What a registered Consent Manager must do
Part B of the First Schedule lists the obligations. Among them, a Consent Manager must:
- let a person give consent to a Data Fiduciary on its platform, directly or through another Data Fiduciary on the platform that holds the data;
- make sure the contents of the data it passes on are not readable by the Consent Manager;
- keep a record of consents given, denied or withdrawn, of the notices that came with consent requests, and of sharing with another Data Fiduciary, give the person access to it and, on request, a machine-readable copy, and keep it for at least seven years, or longer if the person agrees or the law requires;
- run a website or app as the main route to its services, and not sub-contract or assign its obligations under the Act and Rules;
- take reasonable security safeguards against personal data breach;
- act in a fiduciary capacity towards the Data Principal; and
- avoid conflicts of interest with Data Fiduciaries, and publish information on its promoters, directors, key managerial personnel and senior management, shareholders holding more than two per cent, and related bodies corporate.
Do you need a Consent Manager?
If you are an ordinary business, read the Act’s wording closely. It says a Data Principal may manage her consent through a Consent Manager. It gives the choice to the person. The Act’s sections on notice and consent still apply to you from 13 May 2027, and where you rely on consent and it is questioned in a proceeding, you, as the Data Fiduciary, must prove that a notice was given and consent was given in line with the Act and the Rules. A Consent Manager keeps its own record of consents and notices, but the Act’s sentence on proof names the Data Fiduciary.
Two practical points follow. First, the Rules require a Data Fiduciary and, where applicable, a Consent Manager to publish how requests are made, and every Data Fiduciary and Consent Manager to publish the period within which it will respond to grievances, a reasonable period of not more than 90 days. Those duties start on 13 May 2027. Second, before then you can use the time to build your own notice and consent records. See what a consent notice must contain.
If you are thinking of becoming one
The conditions above are demanding: a company incorporated in India, net worth of at least two crore rupees, an independently certified platform, and a standing duty to avoid conflicts of interest with the Data Fiduciaries on its platform. Check the Board’s website for the application particulars the Rules refer to, and take advice before you apply. To see which duties apply to your own business, use the processing map.
Common questions
When does Consent Manager registration start?
On 13 November 2026, one year after the notifications published on 13 November 2025. The Board’s power to inquire into a breach of a registration condition starts the same day.
What is a Consent Manager?
A person registered with the Board who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform.
Who can register as a Consent Manager?
A company incorporated in India that meets the conditions in the First Schedule, including a net worth of not less than two crore rupees and an independently certified interoperable platform.
Do I need to use a Consent Manager?
The Act says a Data Principal may give, manage, review or withdraw her consent to a Data Fiduciary through a Consent Manager. Under the Act, using a Consent Manager is the person’s option. Where consent is the basis for processing and it is questioned in a proceeding, the Data Fiduciary must prove that a notice was given and consent was given in line with the Act and the Rules.
What starts on 13 May 2027 for Consent Managers?
The Act’s sections on using a Consent Manager and on its accountability to the Data Principal, the Board’s power to act on a complaint about a Consent Manager, the duty of a Data Fiduciary (and, where applicable, a Consent Manager) to publish how requests are made, and the duty of every Data Fiduciary and Consent Manager to publish a grievance period of no more than ninety days.
Next steps
- Check whether the DPDP Act applies to your business, free, in a few clicks
- How-to 05: Ask properly, in the toolkit
- How-to 02: Plan the work, in the toolkit
- The free duties list, every duty in plain words
In the news
- DPDP Rules: Consent Managers Must Be India-Incorporated Firms
Plain explainer of the Consent Manager rule that our article walks through step by step.
- One Function, Two Rulebooks: Consent Manager-Account Aggregator Overlap Under DPDP Rules, 2025.
Looks at how Consent Managers sit alongside Account Aggregators; useful context for the registration question.
- TCS is all set to seek ‘consent manager’ permit under DPDP
Reports one large IT firm’s plan to apply for Consent Manager registration.
Sources
Every section, rule and date above was checked against the official text on 6 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)
- Section 2(g)Consent Manager
- Section 6(7)A Data Principal may give, manage, review or withdraw consent through a Consent Manager
- Section 6(8)Accountable to the Data Principal; acts on her behalf under the prescribed obligations
- Section 6(9)Every Consent Manager registered with the Board; in force one year from 13 November 2025
- Section 6(10)Where consent is the basis of processing and is questioned in a proceeding, the Data Fiduciary must prove notice and consent
- Section 13Grievance redressal by a Data Fiduciary or Consent Manager
- Section 27(1)(c)Board inquiry on a complaint about a Consent Manager
- Section 27(1)(d)Board inquiry on breach of a registration condition; in force one year from 13 November 2025
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
- Rule 1(3)Rule 4 in force one year after publication
- Rule 1(4)Rule 14 in force eighteen months from publication
- Rule 4Registration and obligations of a Consent Manager
- Rule 14Publish how to make requests (Data Fiduciary and, where applicable, Consent Manager) and a grievance period of not more than ninety days (every Data Fiduciary and Consent Manager)
- First Schedule, Part ANine conditions for registration, including incorporation in India and net worth of at least two crore rupees
- First Schedule, Part BThirteen obligations, including records kept for at least seven years
Notifications
Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)
- G.S.R. 843(E), clauses (b) and (c)Section 6(9) and Section 27(1)(d) one year from publication; Sections 6(1) to 6(8), 6(10), 13 and 27 (except 27(1)(d)) eighteen months
A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.



