DPDP Consent Manager Explained (Rule 4, 2026)
India's DPDP consent manager framework opens for registration on 13 November 2026. Here's what a consent manager does and what your business must decide.

What it is: under India's Digital Personal Data Protection (DPDP) Rules 2025, Rule 4 sets up a registration framework for a new type of platform called a Consent Manager. Why it matters: a DPDP consent manager lets an individual give, review, and withdraw consent for how their personal data is used across many different companies, all from one place, instead of managing separate consent settings on every app and website. When it applies: registration for Consent Managers opens on 13 November 2026, which is a key date on the road to full DPDP compliance, due by 13 May 2027.
Two roles you need to know
The DPDP law uses two plain-English roles. A Data Fiduciary is any organisation that decides why and how personal data is collected and used - in most cases, that is your business. A Data Principal is the individual the data is about - your customer, employee, or user. A Consent Manager sits between the two: it is a registered platform that helps a Data Principal manage their consent decisions across multiple Data Fiduciaries.
What it takes to register as a consent manager
Not every company can become a Consent Manager. Rule 4 sets specific eligibility conditions: the entity must be a company incorporated in India under the Companies Act, 2013 - a limited liability partnership, a partnership firm, a sole proprietorship, or a foreign entity does not qualify. It must also hold a minimum net worth of Rs 2 crore. Beyond eligibility, a registered Consent Manager has ongoing obligations: it must be data-blind, meaning personal data that passes through its platform must stay unreadable to the Consent Manager itself, so it cannot see or use the data it is only managing consent for. It must keep detailed, auditable records of every consent decision, avoid conflicts of interest that could bias how it presents choices, and run strong technical security controls to protect the consent records it holds.
Why this matters even if you never become one
Most businesses reading this will never register as a Consent Manager themselves - that is a specialised role for a small number of platforms. What matters to you as a Data Fiduciary is how you interact with the framework. Once Consent Managers are operational, individuals may increasingly manage their consent for your product through one of these platforms rather than directly inside your app. That means your consent flows need to be built in a way that can eventually interoperate with a registered Consent Manager's records, and your notices need to be clear enough to work in that model.
Build your own consent flow, or wait for consent managers?
You do not need to wait for Consent Managers to become common before fixing your own consent practices. The DPDP Act already requires every Data Fiduciary to obtain clear, specific, and informed consent before processing personal data, give an easy way to withdraw that consent, and keep records of what consent was given for what purpose. Building a compliant consent flow now - clear notices, granular consent choices, and an easy withdrawal mechanism - is not wasted work even after Consent Managers launch, because a well-built consent system is exactly what will interoperate with them later. Treat the Consent Manager rollout as a future integration point, not a reason to delay compliance work you should be doing anyway.
Key dates to track
- 13 November 2025 - DPDP Rules formally notified.
- 13 November 2026 - Consent Manager registration opens under Rule 4.
- 13 May 2027 - full DPDP compliance deadline for all Data Fiduciaries, with penalties of up to Rs 250 crore per breach for non-compliance.
If your business handles personal data of individuals in India - which covers almost every consumer-facing company - the practical action item today is not registering as a Consent Manager. It is making sure your own consent notices, consent records, and withdrawal mechanisms are ready well before the May 2027 deadline.