What Is a Consent Manager Under DPDP? Rule 4 Explained
Rule 4 is the first substantive rule to commence, on 14 November 2026. It creates a new regulated intermediary that most companies will deal with rather than become.
The short answer
A Consent Manager is a registered intermediary that gives a Data Principal one place to give, manage, review and withdraw consent across every Data Fiduciary she deals with, rather than managing consent separately with each one.
Rule 4 governs their registration and obligations. Under Rule 1(3) it commences one year after publication of the Rules, on 14 November 2026, making it the first substantive rule to take effect.
Who can actually become one
Part A of the First Schedule sets the registration conditions. The bar is deliberately high:
- The applicant is a company incorporated in India.
- It has sufficient technical, operational and financial capacity to fulfil its obligations.
- Its financial condition and the general character of its management are sound.
- Its net worth is not less than two crore rupees.
- Its volume of likely business, capital structure and earning prospects are adequate.
- Its directors, key managerial personnel and senior management are individuals of general reputation and record of fairness and integrity.
The obligations that come with it
The Rules place continuing duties on a registered Consent Manager. Among them, it must maintain effective audit mechanisms to review, monitor, evaluate and report audit outcomes to the Board, periodically and whenever the Board directs, covering its technical and organisational controls, its continued fulfilment of the registration conditions, and its adherence to its obligations under the Act and Rules.
Control of a registered Consent Manager company cannot be transferred by sale or otherwise without following the process the Rules prescribe. The intent is that registration attaches to an entity whose ownership and management the Board can keep sight of.
What this means if you are a Data Fiduciary
Nothing in Rule 4 obliges an ordinary Data Fiduciary to route consent through a Consent Manager. What it does is establish a mechanism the Data Principal may choose to use.
The practical implication is architectural. If consent can arrive through, be reviewed in, and be withdrawn via an external interface, then consent cannot be a checkbox recorded once at sign-up and never revisited. It has to be a record your systems can read, update and act on when it changes.
A consent architecture that cannot process a withdrawal arriving from outside your own product is not ready for the framework the Rules are building, whatever your privacy policy says.
Infosek Team
What to do before November 2026
- Establish whether consent in your systems is a stored artefact with a purpose, a timestamp and a state, or merely an implicit consequence of the user having signed up.
- Confirm that withdrawing consent actually stops the processing it authorised, rather than only flipping a flag in a settings table.
- Map which processing activities depend on consent and which rest on another basis, because only the first group is affected by a withdrawal.
- If you are considering registering as a Consent Manager, note the two crore net worth and India incorporation requirements early, since neither is quick to arrange.
Common questions
What is a Consent Manager under the DPDP Act?
A Consent Manager is a registered intermediary through which a Data Principal can give, manage, review and withdraw consent across multiple Data Fiduciaries from a single interface. Registration conditions are set out in Part A of the First Schedule to the DPDP Rules 2025, and Rule 4 commences on 14 November 2026.
What are the requirements to register as a Consent Manager?
Under Part A of the First Schedule, the applicant must be a company incorporated in India with a net worth of not less than two crore rupees, must have sufficient technical, operational and financial capacity, and its directors and senior management must be of sound general reputation and record of fairness and integrity.
Preparing your consent architecture?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment