DPDPA अब भारत में लागू है। अपनी वेबसाइट पर मुफ़्त प्राइवेसी स्कैन चलाएँ। अभी स्कैन करें

India / DPDPA

What is a Consent Manager?

Also known as: DPDPA Consent Manager, Consent Manager India, Consent Management Intermediary

Under India's Digital Personal Data Protection Act, 2023 (DPDPA), a Consent Manager is a person registered with the Board that acts as a single point of contact through which a Data Principal can give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform.

The Consent Manager concept is designed to give individuals greater control over their personal-data consent across different Data Fiduciaries.

A Consent Manager is different from a standard Consent Management Platform (CMP). A CMP typically helps an individual website or application collect and enforce consent, while the DPDPA Consent Manager is a distinct regulatory concept intended to provide an interoperable way for Data Principals to manage consent across services.

What does Consent Manager mean under DPDPA?

The Digital Personal Data Protection Act, 2023 defines a Consent Manager as a person registered with the Board that acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform.

In simple terms, a Consent Manager is intended to act as a central consent control layer for individuals.

Instead of managing consent separately across every service, the DPDPA model envisions an interoperable platform through which a Data Principal can manage applicable consent decisions.

What does a Consent Manager do?

A DPDPA Consent Manager can provide a central mechanism for Data Principals to:

Give consent

Review existing consent

Manage consent preferences

Withdraw consent

Understand which consents are active

Interact with participating Data Fiduciaries

Manage consent through an accessible interface

The objective is to make consent management more transparent and give individuals greater control over their personal-data choices.

Who can be a Consent Manager?

Under the DPDPA, a Consent Manager is not simply any company that provides a cookie banner or consent tool.

The Act defines a Consent Manager as a person registered with the Board and establishes the concept as an interoperable consent-management intermediary.

The detailed operational requirements, registration framework, and technical requirements are governed by the applicable DPDPA framework and Rules.

This distinction is important for businesses because the term “Consent Manager” under the DPDPA should not automatically be treated as another name for a website CMP.

Consent Manager vs Consent Management Platform

A Consent Manager and a Consent Management Platform (CMP) can sound like the same thing, but they serve different roles.

DPDPA Consent ManagerConsent Management Platform
Defined under India's DPDPAGeneral privacy technology category
Registered with the BoardMay be provided by any qualifying technology vendor
Designed to be interoperableUsually configured for a website, app, or organisation
Enables Data Principals to manage consentCollects and enforces consent
Intended to work across Data FiduciariesOften manages consent for a specific property
Includes giving, managing, reviewing and withdrawing consentCan include banners, preference centers, blocking and consent records

A CMP can therefore support the technical consent layer used by a Data Fiduciary, while a statutory Consent Manager represents a distinct DPDPA concept.

How is a Consent Manager different from a cookie consent banner?

A cookie consent banner is a user interface displayed on a website to inform visitors about cookies and collect applicable consent.

A Consent Management Platform can go further by managing preferences, blocking trackers, recording consent, and communicating choices to website technologies.

A DPDPA Consent Manager is different again. It is the specific regulated intermediary described by the DPDPA for enabling Data Principals to give, manage, review, and withdraw consent through an interoperable platform.

In other words:

Cookie Banner

Website consent interface

CMP

Consent collection and enforcement technology

DPDPA Consent Manager

Registered, interoperable consent intermediary

Why is the Consent Manager important?

The Consent Manager concept is important because it aims to give Data Principals greater control over their consent decisions.

Instead of treating consent as a one-time checkbox, the model supports a lifecycle:

  1. Give
  2. Review
  3. Manage
  4. Withdraw

This can make privacy choices more transparent and easier for individuals to control.

For businesses, it also reinforces the importance of maintaining reliable consent records and ensuring that withdrawal decisions are communicated to the systems responsible for processing personal data.

Consent Manager and Data Principal

The Data Principal is the individual to whom personal data relates.

The Consent Manager is designed to provide that individual with a mechanism to manage consent.

For example:

  1. Data Principal
  2. Consent Manager
  3. Data Fiduciary

The Data Principal can use the Consent Manager to interact with consent decisions, while the Data Fiduciary remains responsible for the processing activities it determines.

This creates a separation between the individual managing consent and the organisations processing the individual's personal data.

Consent Manager and Data Fiduciary

A Data Fiduciary determines the purpose and means of processing personal data.

A Consent Manager provides the consent-management interface and interoperability layer contemplated by the DPDPA.

A simplified relationship can look like:

  1. Data Principal
  2. Consent Manager
  3. Data Fiduciary
  4. Data Processor

The Data Fiduciary may use Data Processors to process personal data on its behalf, while the Consent Manager serves a different function in the consent ecosystem.

What is interoperable consent?

Interoperability means that consent information can work across participating systems rather than being locked inside one organisation's technology environment.

For a Data Principal, this can potentially mean using a consistent consent-management mechanism across multiple services.

For businesses, interoperability can require systems that can reliably exchange and interpret consent information while maintaining appropriate security, authenticity, and auditability.

Consent Manager and consent withdrawal

One of the important functions of a DPDPA Consent Manager is enabling Data Principals to withdraw consent.

The DPDPA provides that a Data Principal has the right to withdraw consent at any time, and the ease of withdrawing consent should be comparable to the ease of giving consent.

This makes consent withdrawal an important part of the consent lifecycle rather than an afterthought.

Businesses should therefore ensure that consent withdrawal can be propagated to the systems and processing activities affected by that withdrawal.

Consent Manager and DPDPA compliance

The Consent Manager concept is part of India's broader privacy and consent framework.

A business preparing for DPDPA compliance should consider:

  • What personal data it processes
  • Why the data is processed
  • Whether consent is the applicable basis
  • How consent is collected
  • How consent is recorded
  • How consent can be withdrawn
  • How Data Principal rights are handled
  • Which Data Processors receive personal data
  • How consent information is communicated between systems
  • How evidence of consent is maintained

Using a consent tool does not by itself make an organisation DPDPA compliant. Compliance depends on the organisation's actual processing activities, notices, consent practices, security controls, rights processes, and other applicable obligations.

Consent Manager and DPDP Rules

The DPDP Rules, 2025 provide additional operational requirements supporting the DPDPA framework.

The Rules were notified on 13 November 2025 and introduce requirements covering areas including consent, notices, children's data, security safeguards, personal-data breaches, and the Consent Manager framework.

Businesses should track applicable commencement dates because the Rules contain phased implementation provisions.

Is a Consent Manager the same as a CMP?

No.

This is one of the most important distinctions to understand.

A CMP is a privacy technology platform used by organisations to collect, manage, store, and enforce consent.

A Consent Manager under the DPDPA is a specific statutory concept involving a registered and interoperable platform through which Data Principals can give, manage, review, and withdraw consent.

The two can work together, but they should not be treated as identical concepts.

Do websites need a Consent Manager?

Not every website should assume that installing a conventional CMP makes it a DPDPA Consent Manager.

The DPDPA defines a Consent Manager as a specific registered entity and establishes requirements around its role.

However, websites and applications can still need robust consent management even when they are not themselves Consent Managers.

Businesses should evaluate their processing activities, consent requirements, Data Principal rights, and applicable DPDPA obligations separately.

Consent Manager vs Consent Receipt

A Consent Manager is an entity/platform that enables Data Principals to manage consent.

A Consent Receipt is evidence or a record of a consent decision.

For example:

Consent Manager

Provides the mechanism for managing consent.

Consent Receipt

Records evidence of what consent was given, when it was given, and other relevant information.

These concepts can work together but serve different purposes.

Consent Manager in ConsentX

ConsentX provides consent-management technology that can help businesses build the technical layer around DPDPA consent.

ConsentX can help organisations:

Present purpose-based consent notices

Capture affirmative consent

Manage consent preferences

Support consent withdrawal

Maintain tamper-evident consent records

Block applicable trackers before consent

Manage Data Principal requests

Support DPDPA-specific consent flows

Maintain audit-ready evidence

Apply region-specific privacy rules

ConsentX is a Consent Management Platform, not automatically a statutory DPDPA Consent Manager simply because it provides consent-management functionality.

This distinction allows businesses to use ConsentX as their organisational consent-management layer while keeping the DPDPA's separate Consent Manager concept clear.

Put Consent Management into practice

ConsentX helps businesses collect meaningful consent, enforce privacy choices, manage withdrawals, and maintain audit-ready evidence across websites and digital services. Start free with ConsentX.

Frequently asked questions