The DPDP Act Has Changed How Every Indian Organisation Must Collect and Manage Consent. The Build Window Is Narrowing.

The DPDP Act Has Changed How Every Indian Organisation Must Collect and Manage Consent. The Build Window Is Narrowing.

August 21, 2026

Every organisation in India that collects personal data from individuals is sitting on an obligation that did not exist three years ago. The Digital Personal Data Protection Act, 2023 - notified in full operational form through the DPDP Rules 2025 on November 14, 2025 - has introduced a consent framework that is fundamentally different from anything India's regulatory landscape has required before. At the centre of that framework sits a new regulated entity: the Consent Manager.

For most organisations, the Consent Manager framework raises two distinct questions. The first is whether they need to register as a Consent Manager. The second - and far more immediately relevant for the overwhelming majority of Indian businesses - is whether their own systems are technically capable of connecting to registered Consent Managers, managing consent in the way the Act requires, and generating the audit trail that the Data Protection Board of India will expect to see. The answer to that second question, for most organisations, is currently no.

What the DPDP Act Actually Says About Consent

The DPDP Act, 2023 operates primarily on a foundation of explicit, informed, freely given, specific, and unconditional consent. This is not the same as the implied consent, bundled consent, or pre-ticked box consent that most Indian organisations have relied on historically.

Under the Act, before processing any personal data, a Data Fiduciary must provide the Data Principal with a clear, standalone notice — in plain language — specifying exactly what data will be collected and for exactly what purpose. The Data Principal must then affirmatively consent to each specified purpose. And critically:

 

  • Consent must be as easy to withdraw as it was to give: The withdrawal mechanism must be equally accessible and seamless as the original consent collection flow. A consent that is one click to give but requires a written request and three business days to withdraw does not meet the standard.
  • Consent is purpose-specific: Consent given for one purpose cannot be used for a different purpose. If an organisation wants to use data for a new purpose, it must seek fresh consent.
  • Consent records should be retained for a minimum of seven years — not as an explicit DPDP Act mandate, but as a general audit standard and in alignment with sectoral laws such as PMLA, RBI norms, and the Income Tax Act that govern record retention for regulated entities: Every consent artefact — the notice provided, the consent given, any modifications, and any withdrawals — should be retained for audit and compliance purposes. Note: The DPDP Act's Section 8(7) actually mandates storage limitation — data must be erased once consent is withdrawn or the purpose is served. Retention obligations for consent records flow from sectoral laws such as PMLA, RBI Master Directions, and the Income Tax Act, not from the DPDP Act itself.
  • Children's data requires verifiable parental consent: For processing data of individuals below 18 years of age, verifiable consent of a parent or guardian is mandatory before any processing begins.

 

The DPDP Act does not create a higher bar for consent collection. It creates an entirely different architecture for it — one where consent is granular, purpose-specific, revocable in real time, and auditable for seven years. Most existing consent flows do not come close to meeting this standard.

What Is a Consent Manager — And Who Needs to Become One

Section 2(g) of the DPDP Act defines a Consent Manager as "a person registered with the Board who acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw her consent through an accessible, transparent, and interoperable platform." This definition is precise and consequential.

A Consent Manager is not a data processor. It is not a Data Fiduciary. It is a regulated intermediary that sits between the Data Principal and the Data Fiduciaries — enabling the individual to manage their consents across multiple organisations from a single platform, without the Consent Manager itself ever accessing the personal data that flows between them.

The eligibility requirements to register as a Consent Manager under Part A of the First Schedule of the DPDP Rules 2025 are specific:

 

  • Incorporation in India: The entity must be incorporated in India — as a private company, public company, society, or trust.
  • Minimum net worth of Rs 2 crore: Adjusted annually for inflation as specified by the Board.
  • Board of Directors with demonstrated governance framework: Including independent directors and clear accountability structures.
  • Technical, operational, and financial capacity: The entity must demonstrate it can operate the consent platform reliably, securely, and at scale.
  • Platform must be accessible, transparent, and interoperable: The consent interface must work across different Data Fiduciary systems and be accessible to Data Principals through multiple channels.
  • Personal data must not be accessible to the Consent Manager: The Consent Manager routes consent artefacts but must not be able to read or access the personal data flowing between the Data Principal and the Data Fiduciary.

 

The Consent Manager framework under Rule 4 becomes operational on 13 November 2026. Any entity operating as a Consent Manager after this date without Data Protection Board registration will be in violation of Section 6(9) of the Act — with penalties of up to Rs 50 crore per instance.

For the overwhelming majority of Indian organisations — banks, NBFCs, fintechs, e-commerce platforms, healthcare providers, SaaS companies — the correct action is not to pursue Consent Manager registration. It is to build the internal consent management infrastructure that can interoperate with registered Consent Managers and meet the Act's requirements for their own data processing activities. The registration deadline for internal compliance — deploying a compliant consent management platform — is May 13, 2027.

The Three Functional Obligations of a Registered Consent Manager

Under Part B of the First Schedule of the DPDP Rules 2025, Consent Managers operate across three interdependent functional dimensions. Understanding these obligations is important not just for entities considering registration, but for any Data Fiduciary whose systems must integrate with registered Consent Managers.

1. Consent Facilitation — The Core Interface Function: The Consent Manager must provide a platform through which Data Principals can give, review, modify, and withdraw consent across all Data Fiduciaries they have consented to. This interface must be accessible 24 hours a day, seven days a week. Withdrawal mechanisms must be as seamless as the original consent flow. Real-time consent status dashboards must be available to Data Principals at all times. The platform must be interoperable — meaning it must be capable of exchanging consent signals with any Data Fiduciary's systems through standardised APIs.

2. Audit and Reporting Obligations: Consent Managers must conduct periodic independent audits of their consent management systems. The outcomes of these audits must be reported to the Data Protection Board of India periodically and on demand. Every consent artefact — the notice, the consent, any modification, and any withdrawal — must be retained for seven years in a format that is accessible to the Board for investigation or audit. The Consent Manager must also maintain detailed logs of all consent transactions.

3. Grievance Redress: Consent Managers must establish and maintain a grievance redress mechanism for Data Principals who have complaints about consent management — denial of withdrawal, incorrect consent status, data processing after consent withdrawal. The Consent Manager is accountable to the Data Principal, not to the Data Fiduciary, and the Board has direct supervisory authority over its operations.

What Data Fiduciaries Must Do — Regardless of Whether They Register

The Consent Manager registration question is a distraction for most organisations. The more pressing question is what the Act requires of every Data Fiduciary — which is any organisation that determines the purpose and means of processing personal data. That includes virtually every business operating in India today.

 

  • Standalone consent notices in plain language: Every data collection point must be accompanied or preceded by a standalone notice — not embedded in terms and conditions — clearly specifying the data collected and the precise purpose. Existing privacy policies and bundled consent mechanisms do not meet this standard.
  • Purpose-specific consent for every processing activity: Separate consent for separate purposes. Marketing, analytics, third-party sharing, and core service delivery each require their own consent — not a single checkbox that covers all of them.
  • Real-time consent withdrawal infrastructure: The organisation must be technically capable of stopping data processing immediately when a Data Principal withdraws consent. This requires backend systems that can receive a withdrawal signal and act on it in real time.
  • Seven-year consent record retention: Every consent artefact must be stored, timestamped, and retrievable for seven years. This is an infrastructure requirement, not a documentation requirement.
  • Interoperability with registered Consent Managers: Once the Consent Manager ecosystem is live, Data Fiduciaries must be technically capable of exchanging consent signals with any registered Consent Manager their Data Principals choose to use. This requires API-level integration readiness.
  • Children's data — verifiable parental consent: For any service that may be accessed by individuals under 18, a verifiable parental consent mechanism must be in place before any data processing occurs.

 

The indicative compliance deadline for Data Fiduciaries is May 13, 2027 — based on the DPDP Rules 2025 as notified, subject to final confirmation by the Data Protection Board once constituted. But the technical complexity of building consent infrastructure from scratch means that organisations that begin building in early 2027 will not be ready in time. The window to start is now.

 

The Technical Architecture a Consent Management System Requires

MeitY's Business Requirement Document for Consent Management Systems, released in June 2025, provides the most detailed public guidance on what a compliant consent management system must be technically capable of. It is not legally binding, but it provides a clear preview of the technical expectations that will be formally enforced.

 

  • Consent lifecycle management: The system must handle the complete consent lifecycle - notice delivery, consent collection, consent storage, consent modification, consent withdrawal, and post-withdrawal processing cessation — in a single integrated flow.
  • User dashboard accessible 24/7: Data Principals must be able to view all consents they have given, see which Data Fiduciaries are processing their data, and withdraw any consent at any time through a real-time dashboard.
  • Notification infrastructure: Automated notifications to Data Principals when consent is used, when it is about to expire, when a new purpose requires fresh consent, and when a withdrawal has been processed.
  • Grievance redress mechanism: A documented, time-bound grievance process for Data Principals who dispute consent status, withdraw consent that was not acted on, or believe their data is being processed without valid consent.
  • Admin capabilities — data retention policy configuration: System administrators must be able to configure data retention policies at the consent artefact level, manage user roles and access controls, and generate compliance reports on demand.
  • Audit log generation: Every consent transaction — grant, modification, withdrawal, and any processing action taken on the basis of consent — logged with timestamp, purpose, data category, and actor identity. Retrievable for seven years.

 

How Letsfin's Tech and APIs Enable Consent Management Compliance

Letsfin provides the technology infrastructure and APIs that organisations need to build and operate consent management systems compliant with the DPDP Act and DPDP Rules 2025 — whether they are a Data Fiduciary building internal compliance infrastructure, or an entity considering Consent Manager registration.

 

  • Consent Collection APIs: Configurable APIs for delivering standalone consent notices and collecting purpose-specific consent at every data collection point — web, mobile, IVR, agent-assisted, and physical channels. Each consent artefact generated with a unique identifier, timestamp, and cryptographic signature for tamper-evident audit trail creation.
  • Consent Lifecycle Management: Complete consent state management — active, modified, withdrawn, expired — with real-time status accessible to both the Data Principal and the Data Fiduciary. Withdrawal signals processed and acted on in real time, with downstream system notifications triggered automatically.
  • Consent Record Storage — Aligned with Sectoral Retention Requirements: Immutable, timestamped consent artefact storage with retrieval capability for regulatory audits. Retention periods configurable based on applicable sectoral laws — PMLA (5 years), RBI norms, Income Tax Act — rather than a single DPDP-mandated timeline. Encrypted storage with access controls.
  • Data Principal Dashboard APIs: APIs for building the 24/7 accessible consent management interface that Data Principals are entitled to under the Act — showing all active consents, the purposes they cover, the Data Fiduciaries processing data, and the withdrawal controls.
  • Interoperability APIs for Consent Manager Integration: For Data Fiduciaries that need to exchange consent signals with registered Consent Managers, Letsfin's interoperability APIs provide the standardised integration layer — receiving consent grants and withdrawal signals from any registered Consent Manager and propagating them to the relevant internal systems in real time.
  • Children's Consent Verification APIs: Verifiable parental consent collection flows — integrated with identity verification infrastructure — for organisations whose services may be accessed by individuals under 18.
  • Audit and Reporting APIs: Automated generation of consent audit reports — by Data Principal, by purpose, by time period, by consent status — in formats accessible for internal review, independent audit, and Data Protection Board submission.
  • Grievance Management Integration: APIs for routing Data Principal consent grievances into a tracked, time-bound resolution workflow — with automated acknowledgement, status updates, and escalation triggers.

 

The Practical Reality of the November 2026 Deadline

The Consent Manager registration deadline of November 13, 2026 has a complication that every organisation tracking it needs to be aware of. As of mid-2026, the Data Protection Board of India — the body empowered to receive registration applications, prescribe technical standards, and issue registrations — has not yet had its Chairperson and Members formally appointed. The selection committee process was still underway as of the most recent public information available.

This creates an operational uncertainty: the registration deadline exists in the Rules, but the body that processes registrations is not yet fully constituted. The government has shown no public indication of moving the deadline. The practical implication is that the Board, once constituted, will need to process registrations, prescribe technical standards, and operationalise the framework within a compressed window.

For organisations that are not pursuing Consent Manager registration — the majority — this Board constitution delay does not change the underlying compliance obligation. The requirement to have consent infrastructure capable of meeting the Act's standards remains, and the Data Fiduciary compliance deadline of May 2027 is not affected by the Board's constitution timeline.

Operating as a Consent Manager after November 13, 2026 without registration carries penalties of up to Rs 50 crore per instance. Civil penalties for broader consent non-compliance under Section 27 can reach up to Rs 250 crore. Neither is a theoretical risk — the Data Protection Board has explicit enforcement authority and financial penalties as its primary compliance instrument.

The Bottom Line

The DPDP Act has created a consent compliance requirement that is categorically different from what Indian organisations have managed before. The existing approach — a privacy policy on the website, a checkbox in the registration form, a consent bundled into the terms of service — does not meet the standard the Act sets. And the gap between where most organisations are today and where the Act requires them to be is not a documentation gap. It is a technology gap.

Building consent infrastructure that can collect purpose-specific consent, manage the full consent lifecycle, support real-time withdrawal, generate audit-ready consent trail aligned with applicable sectoral retention laws, and interoperate with registered Consent Managers is a meaningful technical build. Organisations that treat it as a documentation exercise will not be compliant by May 2027. Organisations that treat it as an infrastructure build — and start now — will be.

Letsfin's consent management technology and APIs are built for exactly this requirement. Whether you are a fintech, an NBFC, an e-commerce platform, a healthcare organisation, or an entity considering Consent Manager registration, reach out to the Letsfin team to understand what a compliant consent infrastructure looks like for your organisation. The regulatory clock is running.