Consent Managers under DPDP: what Rule 4 sets up
By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed
The short answer
A Consent Manager is a person registered with the Data Protection Board who acts as a single point of contact for individuals to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. Rule 4 sets up Board registration against the First Schedule conditions, which include incorporation in India and a net worth of at least two crore rupees, and the obligations include keeping consent records and being unable to read the personal data passing through. Rule 4 comes into force one year after the Rules publication, which computes to 13 November 2026, interpretation until confirmed.
Consent Managers are the framework's most novel institution: consent infrastructure as a regulated business.
What the Act defines
"“Consent Manager” means a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform"
Interoperable is the load bearing word: the platform routes consent between individuals and the Data Fiduciaries onboarded onto it.
What Rule 4 sets up
Rule 4 creates the registration machinery: application to the Board against the conditions in Part A of the First Schedule, Board inquiry, registration or reasoned rejection, and Board powers to direct, suspend or cancel. The Part A conditions include being a company incorporated in India, sufficient technical, operational and financial capacity, a net worth of at least two crore rupees, and independent certification of the platform's data protection standards.
The Part B obligations shape the product. Two stand out. The Consent Manager must make personal data available or route its sharing in a manner where the contents are not readable by it: consent plumbing, blind to the payload. And it must keep records of consents given, denied or withdrawn, the notices, and the sharing, for at least seven years, giving the individual access to that record, and on request the information in it in machine readable form.
The clock
Rule 4 is on its own commencement track: one year after the Rules publication, which computes to 13 November 2026 and is interpretation until officially confirmed. Financial data sharing businesses in particular should read the First Schedule closely before that date.
What to do
If consent flows are core to your product, read Rule 4's official text and factor the registration conditions into your planning. For most organisations the practical step is watching which Consent Managers register and deciding whether to integrate.
Rule 4, official text →The fintech guide →
Sources cited on this page
- [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 2(g), p. 2. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [2]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 4, p. 25. Published 13 November 2025. Official source ↗ · Official requirement · Verified 17 August 2026
- [3]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), First Schedule, p. 32. Published 13 November 2025. Official source ↗ · Official requirement · Verified 17 August 2026Part A registration conditions and Part B obligations; the schedule begins on Gazette page 32.
- [4]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (3), p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 16 August 2026Rule 4 commences one year after publication; the computed date 13 November 2026 is interpretation until officially confirmed.