Back to Key Provisions

Consent Manager Role

Understanding the Consent Manager under the DPDPA - registration, obligations, interoperability, and the role in facilitating consent management.

8 min read

What is a Consent Manager?

A Consent Manager is a novel concept introduced by the DPDPA (Section 2(g) and Section 6(7)-(10)). It is a person registered with the Data Protection Board who acts as a single point of contact for Data Principals to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform. The Consent Manager concept draws from India's experience with Account Aggregators in the financial sector and represents an infrastructure-level approach to consent management.

Registration Requirements

Consent Managers must be registered with the Data Protection Board of India. The DPDP Rules (R.4) and the First Schedule prescribe the registration requirements, which include: • Being a company incorporated in India • Meeting prescribed financial and technical eligibility criteria, including a minimum net worth of Rs 2 crore • Demonstrating interoperability capabilities • Having adequate grievance redressal mechanisms Registration may be suspended or cancelled by the Board for non-compliance with conditions.

Obligations of Consent Managers (First Schedule)

Registered Consent Managers must, under the First Schedule, Part B to the Rules: • Act in the interest of the Data Principal • Maintain transparency in their operations • Ensure interoperability with other Consent Managers and Data Fiduciaries • Maintain the confidentiality and security of consent records, and retain consent records for a minimum of seven years • Not sub-contract or assign the performance of any of its obligations under the Act and the Rules • Not engage in processing personal data for purposes other than consent management • Provide an accessible platform for Data Principals to view and manage all their consents in one place • Be accountable to the Data Principal for their services • Avoid conflict of interest with Data Fiduciaries, including their promoters and key managerial personnel • Have measures to ensure no conflict of interest arises from its own directors, key managerial personnel or senior management holding directorship, financial interest, employment or beneficial ownership in Data Fiduciaries, or a material pecuniary relationship with them • Publish, easily accessibly on its website or app, information on its promoters, directors, key managerial personnel and senior management, and on every person holding more than two per cent of its shares • Maintain effective audit mechanisms to review, monitor, evaluate and report audit outcomes to the Board, periodically and as the Board directs, covering its technical and organisational controls, continued fulfilment of registration conditions, and adherence to its obligations • Not undergo any change of control without the prior approval of the Data Protection Board The Consent Manager must not act in a manner that compromises the interests of the Data Principal. They are effectively trustees of the consent relationship.

Interoperability Framework

A key feature of the Consent Manager framework is interoperability. Consent Managers must be able to: 1. Interface with multiple Data Fiduciaries across sectors 2. Allow Data Principals to port their consent preferences across platforms 3. Operate on open standards that enable seamless integration This interoperability requirement ensures that consent management is not siloed within individual organisations but operates as a cross-sector infrastructure - similar to how UPI operates across banks in the payments ecosystem. The technical standards for interoperability are expected to be further detailed through Board guidance and industry standards.

Practical Use Cases

Consent Managers will be particularly valuable in scenarios where: • Individuals interact with multiple Data Fiduciaries and need a centralised dashboard for consent management • Organisations need a standardised mechanism for obtaining verifiable consent • Cross-sector data sharing requires trusted intermediaries to manage consent flows • Individuals wish to withdraw consent from multiple Fiduciaries simultaneously The Consent Manager ecosystem is still in its early stages, with registration processes and operational standards being finalised under the Rules.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.