August 21, 2026
Every organisation in India that collects personal data from individuals is sitting on an obligation that did not exist three years ago. The Digital Personal Data Protection Act, 2023 - notified in full operational form through the DPDP Rules 2025 on November 14, 2025 - has introduced a consent framework that is fundamentally different from anything India's regulatory landscape has required before. At the centre of that framework sits a new regulated entity: the Consent Manager.
For most organisations, the Consent Manager framework raises two distinct questions. The first is whether they need to register as a Consent Manager. The second - and far more immediately relevant for the overwhelming majority of Indian businesses - is whether their own systems are technically capable of connecting to registered Consent Managers, managing consent in the way the Act requires, and generating the audit trail that the Data Protection Board of India will expect to see. The answer to that second question, for most organisations, is currently no.
What the DPDP Act Actually Says About Consent
The DPDP Act, 2023 operates primarily on a foundation of explicit, informed, freely given, specific, and unconditional consent. This is not the same as the implied consent, bundled consent, or pre-ticked box consent that most Indian organisations have relied on historically.
Under the Act, before processing any personal data, a Data Fiduciary must provide the Data Principal with a clear, standalone notice — in plain language — specifying exactly what data will be collected and for exactly what purpose. The Data Principal must then affirmatively consent to each specified purpose. And critically:
The DPDP Act does not create a higher bar for consent collection. It creates an entirely different architecture for it — one where consent is granular, purpose-specific, revocable in real time, and auditable for seven years. Most existing consent flows do not come close to meeting this standard.
What Is a Consent Manager — And Who Needs to Become One
Section 2(g) of the DPDP Act defines a Consent Manager as "a person registered with the Board who acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw her consent through an accessible, transparent, and interoperable platform." This definition is precise and consequential.
A Consent Manager is not a data processor. It is not a Data Fiduciary. It is a regulated intermediary that sits between the Data Principal and the Data Fiduciaries — enabling the individual to manage their consents across multiple organisations from a single platform, without the Consent Manager itself ever accessing the personal data that flows between them.
The eligibility requirements to register as a Consent Manager under Part A of the First Schedule of the DPDP Rules 2025 are specific:
The Consent Manager framework under Rule 4 becomes operational on 13 November 2026. Any entity operating as a Consent Manager after this date without Data Protection Board registration will be in violation of Section 6(9) of the Act — with penalties of up to Rs 50 crore per instance.
For the overwhelming majority of Indian organisations — banks, NBFCs, fintechs, e-commerce platforms, healthcare providers, SaaS companies — the correct action is not to pursue Consent Manager registration. It is to build the internal consent management infrastructure that can interoperate with registered Consent Managers and meet the Act's requirements for their own data processing activities. The registration deadline for internal compliance — deploying a compliant consent management platform — is May 13, 2027.
The Three Functional Obligations of a Registered Consent Manager
Under Part B of the First Schedule of the DPDP Rules 2025, Consent Managers operate across three interdependent functional dimensions. Understanding these obligations is important not just for entities considering registration, but for any Data Fiduciary whose systems must integrate with registered Consent Managers.
1. Consent Facilitation — The Core Interface Function: The Consent Manager must provide a platform through which Data Principals can give, review, modify, and withdraw consent across all Data Fiduciaries they have consented to. This interface must be accessible 24 hours a day, seven days a week. Withdrawal mechanisms must be as seamless as the original consent flow. Real-time consent status dashboards must be available to Data Principals at all times. The platform must be interoperable — meaning it must be capable of exchanging consent signals with any Data Fiduciary's systems through standardised APIs.
2. Audit and Reporting Obligations: Consent Managers must conduct periodic independent audits of their consent management systems. The outcomes of these audits must be reported to the Data Protection Board of India periodically and on demand. Every consent artefact — the notice, the consent, any modification, and any withdrawal — must be retained for seven years in a format that is accessible to the Board for investigation or audit. The Consent Manager must also maintain detailed logs of all consent transactions.
3. Grievance Redress: Consent Managers must establish and maintain a grievance redress mechanism for Data Principals who have complaints about consent management — denial of withdrawal, incorrect consent status, data processing after consent withdrawal. The Consent Manager is accountable to the Data Principal, not to the Data Fiduciary, and the Board has direct supervisory authority over its operations.
What Data Fiduciaries Must Do — Regardless of Whether They Register
The Consent Manager registration question is a distraction for most organisations. The more pressing question is what the Act requires of every Data Fiduciary — which is any organisation that determines the purpose and means of processing personal data. That includes virtually every business operating in India today.
The indicative compliance deadline for Data Fiduciaries is May 13, 2027 — based on the DPDP Rules 2025 as notified, subject to final confirmation by the Data Protection Board once constituted. But the technical complexity of building consent infrastructure from scratch means that organisations that begin building in early 2027 will not be ready in time. The window to start is now.
The Technical Architecture a Consent Management System Requires
MeitY's Business Requirement Document for Consent Management Systems, released in June 2025, provides the most detailed public guidance on what a compliant consent management system must be technically capable of. It is not legally binding, but it provides a clear preview of the technical expectations that will be formally enforced.
How Letsfin's Tech and APIs Enable Consent Management Compliance
Letsfin provides the technology infrastructure and APIs that organisations need to build and operate consent management systems compliant with the DPDP Act and DPDP Rules 2025 — whether they are a Data Fiduciary building internal compliance infrastructure, or an entity considering Consent Manager registration.
The Practical Reality of the November 2026 Deadline
The Consent Manager registration deadline of November 13, 2026 has a complication that every organisation tracking it needs to be aware of. As of mid-2026, the Data Protection Board of India — the body empowered to receive registration applications, prescribe technical standards, and issue registrations — has not yet had its Chairperson and Members formally appointed. The selection committee process was still underway as of the most recent public information available.
This creates an operational uncertainty: the registration deadline exists in the Rules, but the body that processes registrations is not yet fully constituted. The government has shown no public indication of moving the deadline. The practical implication is that the Board, once constituted, will need to process registrations, prescribe technical standards, and operationalise the framework within a compressed window.
For organisations that are not pursuing Consent Manager registration — the majority — this Board constitution delay does not change the underlying compliance obligation. The requirement to have consent infrastructure capable of meeting the Act's standards remains, and the Data Fiduciary compliance deadline of May 2027 is not affected by the Board's constitution timeline.
Operating as a Consent Manager after November 13, 2026 without registration carries penalties of up to Rs 50 crore per instance. Civil penalties for broader consent non-compliance under Section 27 can reach up to Rs 250 crore. Neither is a theoretical risk — the Data Protection Board has explicit enforcement authority and financial penalties as its primary compliance instrument.
The Bottom Line
The DPDP Act has created a consent compliance requirement that is categorically different from what Indian organisations have managed before. The existing approach — a privacy policy on the website, a checkbox in the registration form, a consent bundled into the terms of service — does not meet the standard the Act sets. And the gap between where most organisations are today and where the Act requires them to be is not a documentation gap. It is a technology gap.
Building consent infrastructure that can collect purpose-specific consent, manage the full consent lifecycle, support real-time withdrawal, generate audit-ready consent trail aligned with applicable sectoral retention laws, and interoperate with registered Consent Managers is a meaningful technical build. Organisations that treat it as a documentation exercise will not be compliant by May 2027. Organisations that treat it as an infrastructure build — and start now — will be.
Letsfin's consent management technology and APIs are built for exactly this requirement. Whether you are a fintech, an NBFC, an e-commerce platform, a healthcare organisation, or an entity considering Consent Manager registration, reach out to the Letsfin team to understand what a compliant consent infrastructure looks like for your organisation. The regulatory clock is running.