Back to Key Provisions

Consent Manager Role

Understanding the Consent Manager under the DPDPA - registration, obligations, interoperability, and the role in facilitating consent management.

8 min read

What is a Consent Manager?

A Consent Manager is a novel concept introduced by the DPDPA (Section 2(g) and Section 6(7)-(10)). It is a person registered with the Data Protection Board who acts as a single point of contact for Data Principals to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform. The Consent Manager concept draws from India's experience with Account Aggregators in the financial sector and represents an infrastructure-level approach to consent management.

Registration Requirements

Consent Managers must be registered with the Data Protection Board of India. The DPDP Rules (R.4-5) prescribe the registration requirements, which include: • Being a company incorporated in India • Meeting prescribed financial and technical eligibility criteria • Demonstrating interoperability capabilities • Having adequate grievance redressal mechanisms • Maintaining prescribed net worth requirements Registration may be suspended or cancelled by the Board for non-compliance with conditions.

Obligations of Consent Managers (R.5)

Registered Consent Managers must: • Act in the interest of the Data Principal • Maintain transparency in their operations • Ensure interoperability with other Consent Managers and Data Fiduciaries • Maintain the confidentiality and security of consent records • Not engage in processing personal data for purposes other than consent management • Provide an accessible platform for Data Principals to view and manage all their consents in one place • Be accountable to the Data Principal for their services The Consent Manager must not act in a manner that compromises the interests of the Data Principal. They are effectively trustees of the consent relationship.

Interoperability Framework

A key feature of the Consent Manager framework is interoperability. Consent Managers must be able to: 1. Interface with multiple Data Fiduciaries across sectors 2. Allow Data Principals to port their consent preferences across platforms 3. Operate on open standards that enable seamless integration This interoperability requirement ensures that consent management is not siloed within individual organisations but operates as a cross-sector infrastructure - similar to how UPI operates across banks in the payments ecosystem. The technical standards for interoperability are expected to be further detailed through Board guidance and industry standards.

Practical Use Cases

Consent Managers will be particularly valuable in scenarios where: • Individuals interact with multiple Data Fiduciaries and need a centralised dashboard for consent management • Organisations need a standardised mechanism for obtaining verifiable consent • Cross-sector data sharing requires trusted intermediaries to manage consent flows • Individuals wish to withdraw consent from multiple Fiduciaries simultaneously The Consent Manager ecosystem is still in its early stages, with registration processes and operational standards being finalised under the Rules.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.