Digital Personal Data Protection Rules, 2025 (hereinafter ‘the DPDP Rules’), which was notified and published in the e-Gazette on 13th November, 2025, gave operational shape to one of the more distinctive features of the Digital Personal Data Protection Act, 2023 (hereinafter ‘the DPDPA): a registered, neutral intermediary, the Consent Manager, through whom a Data Principal may give, manage, review or withdraw consent across multiple Data Fiduciaries on a single interoperable platform. Rule 4 will come into force on 13th November, 2026, giving prospective Consent Managers a measured twelve-month runway to reach the floor.
1. The Statutory Anchor
The architecture sits on three short pillars of the DPDPA rather than on the Rules alone. Section 2(g) of the Act defines a Consent Manager as “a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review or withdraw her consent through an accessible, transparent and interoperable platform”. Section 6(7) to (9) marks that definition operational by empowering the Data Principal “to give, manage, review or withdraw her consent to the Data Fiduciary through a Consent Manager,” requiring the Consent Manager to be registered with the Board. Section 13 of the Act places an accompanying obligation on Data Fiduciaries and Consent Managers to provide grievance redressal.
Three features of this formulation merits emphasis. First, registration is mandatory and structural, not optional. Second, the function operates as a single point of contact across multiple Data Fiduciaries rather than as a parallel mechanism built into each. Third, the platform must be interoperable, an instruction that anticipates a market in which a Data Principal may migrate between providers and a Data Fiduciary need not integrate unilaterally with each one. The Act leaves the technical specification to the Rules and in turn, to the Board’s assurance framework. The regulatory triangle whose center of gravity rests on Rule 4 read with the First Schedule is, in Bagehot’s phrase, “constitution and not catastrophe”.
2. The Procedural Aspect of Rule 4 of the DPDP Rules
Rule 4 of the DPDP Rules contemplates a four-stage process: eligibility, application, the Board’s inquiry and the registration decision, followed by ongoing supervision regime. Sub-rules (1) and (2) permit any person who fulfills the Part A of the First Schedule conditions to apply, by furnishing such particulars, information and documents as the Board may publish and direct the Board to make such inquiry “as it deems fit” and, on satisfaction, either register and publish particulars on its website or reject with reasons. The deem fit standard confers broad fact-finding latitude ad confirms that registration is a substantive review, not a stamp. Sub-rule (6) extends the Board’s information-gathering power both at registration and during ongoing supervision and thereby supplies the evidentiary backbone of the regime.
Sub-rules (3) to (5) translate registration into continuous supervisory relationship. Sub-rule (3) makes the Part B of First Schedule obligations binding on every registered Consent Manager. Sub-rule (4) supplies the working instrument for ordinary non-adherence: a hearing, a written communication and a direction to remediate. Sub-rule (5) states that Where the Board is satisfied that it is necessary in the interests of Data Principals, it may, after hearing the Consent Manager and for reasons recorded in writing, by order suspend or cancel the registration and give such directions as it deems fit to protect Data Principals. The threshold for escalation is the interests of Data Principals, not the gravity of the underlying default; even relatively minor failures may justify cancellation where the use popular is materially affected.
3. Eligibility: A Capital-Adequacy and Governance Test
Part A of the First Schedule of the Act states the registration procedure conditions which will be levied on the Consent Managers. Whether read sequentially or in aggregate, the scheduled lays down:
Item (2): sufficient technical operational and financial capacity, carries the heaviest weight in any compliance review, because the Board may refuse registration if any of the three limbs is inadequate;
Item (4) sets a quantitative net-worth floor at Rs. 2 crores, a figure materially below comparable regulated intermediaries such as payment banks, digital lenders and signaling the rule- maker’s willingness to admit relatively young participants;
Items (3), (5), (6) and (8) collectively reserve substantial qualitative discretion: sound financial condition and management character, going-concern indicators, the reputation and integrity of directors and key managerial personnel and operations in the interests of Data Principals;
Item (7) effects a constitutional lock-in by requiring the Memorandum and Articles of Association to adherence to the Part B obligations and to require prior Board approval for any amendment, ensuring that a registered Consent Manager cannot unilaterally dilute its obligations;
Item (9), the closing condition, requires independent certification of the interoperable platform against the assurance framework the Board will publish from time to time, a dynamic and continuing condition that ties the registration to a still-evolving technical standard.
Two implications follow: First, the Schedule operates as a floor and not a ceiling; the qualitative items prevent applicants from gaming the test by leaning on a single strong limb. Second, item (9) creates a hard dependency: until the Board publishes its assurance framework, no applicant can finalize platform certification. The framework, not the Rules, alone, will set the gate.
4. Substantive Obligations: Three Clusters
Part A of the First Schedule of the Act states the obligations of the Consent Manager which can be explained and divided into three parts.
The first part, which includes items from 1 to 4, governs the mechanics of consent. The platform must enable the Data Principal to give consent. The contents of personal data flowing through the platform must, at the same time, not be readable by the Consent Manager. This blind-operator principle is the nuts and bolts of the architecture and pushes the platform toward hashed identifiers, tokenized artefacts or end-to-end encryption, with the Consent Manager retaining only routing metadata. Records of consent, notices and data sharing must be tamper-proof and auditable, made available to Data Principals in, machine-readable form and retained for seven years from creation; a retention period materially exceeding the three-year-civil-limitation baseline under the Limitation Act, 1963.
The second part, from items 5 to 7, demands directness. Item (5) confines the principal service channel to a website or application, item (6) prohibits the sub-contracting or assignment of any obligations (“the Consent Manager shall not sub-contract or assign any of its obligations”) and item (7) requires prescribed security safeguards. The non-delegation clause is, in practical terms, a ban on the outscoring playbook ordinally available to regulated intermediaries.
The third part, includes items from 8 to 13, sets the posture. The Consent Manager shall act “in a fiduciary capacity in relation to the Data Principal”, avoid conflict of interest with onboarded Data Fiduciaries to director level, disclose its promoters and any person holding more than two percent of its share capital or voting rights, submit to Board-prescribed audits and obtain Board approval for any change of control (“Change of control of the Consent Manager shall not be effected without the prior approval of the Board”). Read together, this part is what makes the Consent Manager genuinely fiduciary rather than merely transactional; a sister entity of a Data Fiduciary it serves cannot, in any meaningful sense, be the entry.
5. Business and Interoperability Architecture
The Rules are silent on the revenue question, leaving undecide whether a Consent Manager may charge Data Principals directly or must rely on Data Fiduciary-borne fees or substitute transaction-based pricing. The First Schedule and Rule 4 contemplate Board-published particulars under Rule 4 (1), but fee structure is not specified. The Account Aggregate ecosystem resolved a parallel question through a freemium model; free at user end, paid by the recipient FIP; and a comparable equilibrium modelled on DigiLocker or Adhaar-authenticated flows is plausible for the Consent Manager ecosystems.
6. Supervisory Reach
The Board’s supervisory toolkit rests on three sub-rules operating in tandem. Rule 4 (4) supplies the working instrument for ordinary non-adherence; Rule 4(5) escalates to suspension or cancellation where necessary in the interests of Data Principals, on a reasoned written order and Rule 4(6), read with Rule 19 (9), supplies both the information-gathering lever and the framework of inquiry timing, a complaint under Section 27 of the Act must ordinarily be resolved within six months, extendable by three months on recorded grounds. The combined posture is what in analogous sectors call continuous supervision: ask, warn, compel, suspend, cancel.
7. Practical Implications and What Remains Open
Three operative dates frame the next eighteen months. Immediate (13 November 2025 gazette publication): Rule 1, 2, and 17 to 21 are in force. One-year horizon (13 November 2026): Rule 4 becomes operative. Eighteen-month horizon (mid-2027): Rule 3 (notice by Data Fiduciary before seeking consent) takes effect. Until the Board publishes the assurance framework contemplated in Part A item 9, no applicant can finalize platform certification; however the prospective Consent Manager should treat that publication, rather than the rule’s commencement, as the binding milestone.
For prospective Consent Manager, the practical checklist is, by large, determinable: reach the Rs. 2 crore net-worth floor; constitutes a board whose record of fairness and integrity can withstand qualitative review; draft MOA and AOA provisions that operationalize the Part B constitutional lock-in, build a platform to the blind-operator and tamper-proof record standard; commission independent certification against the forthcoming assurance framework; institute conflict of interest policies for the company and its directors; construct a seven year record retention infrastructure with machine-readable export; and prepare an audit function sized to Board prescribed scope.
Further, the Data Fiduciaries should make timely preparation for upcoming compliance phases in the following manner:
- Comprehensive mapping of all personal data flows, including legacy datasets;
- Redesigning consent workflows and revising notice templates;
- Reviewing vendor contracts and inter-company processing arrangements;
- Strengthening governance structures (including appointing a DPO or authorized representative, where applicable);
- Updating retention and deletion protocols;
- Enhancing breach-response mechanisms and system logging practices;
- Preparing for Consent Manager Integrations.
8. Conclusion
The DPDP Rules do not resolve every question surrounding the role and functioning of the Consent Managers, they rather establish the regulatory framework within which the said same can be answered. The Rules lay down the registration, eligibility, functions, obligations and accountability of Consent Managers, making them an important component of India’s evolving data governance regulations. However, their significance will not only depend on the wording of the Rules, but on the way in which these obligations are interpreted and operationalized in practice.
The immediate challenge is to turn the regulatory framework into a functional and interoperable consent ecosystem. The Data Protection Board will play a key role in the implementation of compliance obligations and the development of regulatory expectations. In turn, Registered Consent Managers will be required to build systems that are technologically interoperable, transparent to Data Principals, secure against misuse and able to facilitate consent without an unnecessarily complex process. Likewise, Data Principals will evaluate the trustworthiness of the model based on their willingness to trust Consent Managers as trusted third parties to exercise and control their data-related decisions.
They construct the platform on which the questions will be resolved, whether by Board direction, by industry consolidation, or by litigation. Whether India’s Consent Manager becomes a niche regulated utility; the way the Account Aggregator ecosystem was for its first three years; or whether, as the Rules evidently intend, it becomes the de facto consent infrastructure of the country’s digital economy will turn less on the texts of the Rules and more how the Board, the registered Consent Managers and Data Principals themselves negotiate the interoperable plane the legislature has built.
Author : Ketan Joshi, Associate Partner
Co-Author : Khyati, Intern




