Skip to main content
Compliance Guides
Consent Manager
DPDPA
Registration
DPBI
Rule 4
India

DPDP Consent Manager Registration: Eligibility, the ₹2 Crore Net Worth Bar, and the Application Checklist

The Consent Manager framework goes live on 13 November 2026. Registration requires incorporation in India, a minimum net worth of ₹2 crore, and demonstrated technical capability to run consent across fiduciaries. Here is who qualifies, what the application needs, and — importantly — why most businesses should not apply.

Consently Team
14 July 2026
9 min read

Short answer: A Consent Manager is a DPBI-registered entity through which Data Principals can give, manage, review, and withdraw consent across multiple Data Fiduciaries from one interface. Registration requires incorporation in India, a minimum net worth of ₹2 crore, demonstrated technical and operational capability, and a fit-and-proper standing. The framework becomes operational on 13 November 2026. Almost no ordinary business needs to register.

First, the Confusion Worth Clearing

"Consent Manager" is a defined statutory role in India. It is not a synonym for consent management software. This distinction costs Indian companies real money in wasted evaluation cycles.

Consent Manager (statutory role)Consent Management Platform (software)
Defined byDPDP Act s.2(g), Rule 4, First ScheduleNothing — it is a product category
Registered with DPBI?RequiredNo registration exists
ServesData Principals, across many fiduciariesA Data Fiduciary, on its own properties
Net worth bar₹2 crore minimumNone
Who needs oneEntities building interoperable consent infrastructureEvery business that collects personal data

Key insight: if you run a website, an app, or a business that collects customer data, you need a consent management platform and you almost certainly do not need to become a registered Consent Manager. Registering is a decision to enter the consent-infrastructure business, not a compliance step for your own processing. We unpack the distinction further in Consent Manager vs CMP.

What a Registered Consent Manager Actually Does

The role is deliberately narrow and deliberately fiduciary. A Consent Manager:

  • gives Data Principals a single interface to give, manage, review, and withdraw consent across multiple Data Fiduciaries,
  • is accountable to the Data Principal, not to the fiduciaries who receive consent through it,
  • acts as an interoperable platform, so a withdrawal made once propagates to every fiduciary that holds consent through the manager,
  • maintains records of consent given, withdrawn, and notices served, and makes them accessible to the Data Principal,
  • must not itself read the personal data flowing between principal and fiduciary — it manages the consent artefact, not the payload.

That last constraint is the architectural heart of the role. A Consent Manager that could read the data it brokers would become a Data Fiduciary many times over. The design intent is a blind conduit for consent state.

Eligibility Criteria

RequirementDetail
IncorporationA company incorporated in India. This excludes foreign entities and foreign CMPs from operating as registered Consent Managers.
Net worthMinimum ₹2 crore. Certified financials required.
Technical capabilityDemonstrated ability to operate the consent lifecycle — capture, storage, review, withdrawal, propagation — at scale, with interoperability.
Fit and properAssessment of the applicant's and its promoters' reputation, standing, and record.
GovernanceObligations of certified independence, published grievance mechanism, and reporting to the Board.
SecurityAppropriate technical and organisational measures, with audit obligations.

The ₹2 crore net worth requirement is the most consequential filter. It is not a large number for a bank or a telco; it is a decisive barrier for a two-person startup that thought "consent manager" was a product label. Combined with the India-incorporation requirement, it also means global CMP vendors cannot register their offshore entities — they would need an Indian subsidiary meeting the net worth test.

The Application Checklist

Applications are made to the Data Protection Board of India. An applicant should expect to assemble:

  1. Certificate of incorporation and constitutional documents evidencing Indian incorporation.
  2. Audited financial statements demonstrating net worth of at least ₹2 crore, with an auditor's certificate.
  3. Technical architecture documentation — how consent is captured, stored, versioned, propagated, and withdrawn; how interoperability with multiple fiduciaries is achieved; how the platform avoids access to the underlying personal data.
  4. Security posture — encryption, access control, logging, retention, incident response, and any independent audit or certification held.
  5. Governance framework — board composition, independence, conflict-of-interest policy, and the accountability line to Data Principals.
  6. Grievance redressal mechanism — the published channel, the response commitment, and escalation to the Board.
  7. Fit-and-proper declarations for the entity and its promoters and directors.
  8. Business continuity and exit plan — what happens to consent records if the Consent Manager ceases operations, which the Board will care about because Data Principals would otherwise lose their consent history.

Obligations That Begin After Registration

Registration is the start of a permanent operating burden, not a certificate to display. A registered Consent Manager carries continuing duties:

  • Maintain the consent record for every Data Principal, covering consents given, withdrawn, and the notices served against each — and make it accessible to the Data Principal on demand.
  • Propagate withdrawal reliably to every Data Fiduciary holding consent through the platform. A withdrawal that reaches four fiduciaries out of five is a failure with a named victim.
  • Operate a grievance mechanism and publish it, with escalation to the Board.
  • Maintain independence — the Consent Manager owes duties to the Data Principal, and structures that make revenue depend on fiduciaries getting more consent create exactly the conflict the framework is designed to prevent.
  • Submit to audit and report to the Board, including on security posture and incidents.
  • Not access the personal data flowing between principals and fiduciaries — an architectural commitment that constrains every future product decision.
  • Maintain continuity, including an orderly plan for consent records if the business winds down.

Registration can also be cancelled. An entity that fails these duties does not merely face penalties; it can lose the status its business model depends on.

India Has Done This Before

The Consent Manager design is not invented from nothing. India already runs a consent-intermediary framework in financial services: the Account Aggregator ecosystem under DEPA, where RBI-licensed NBFC-AAs move financial data between institutions on the customer's instruction, without reading the data they move.

The parallels are close enough to be instructive — a licensed intermediary, a fiduciary duty to the individual, an explicit blindness requirement, and interoperability by design. So are the lessons. Account Aggregator adoption was slow for years, held back by uneven onboarding across institutions, patchy user experience, and weak consumer awareness rather than by the technical framework. Anyone building toward Consent Manager registration should assume the same shape: the licence is achievable, the distribution problem is the real one. We explored this in our analysis of the Account Aggregator blueprint and its privacy lessons.

The Regulator Problem

There is a practical wrinkle worth stating plainly. The registration counterparty is the Data Protection Board of India. MeitY invited applications for the DPBI Chairperson and four Members in May 2026 — meaning that as of mid-2026 the Board was still being staffed, while the framework it must administer switches on in November 2026.

Prospective applicants should plan for a compressed and possibly shifting process: registration mechanics, forms, and timelines may be published close to the operative date. This is an argument for having the documentation assembled in advance rather than starting when the window opens. Our DPBI explainer covers the Board's composition and powers.

Should You Register? A Decision Test

Answer these honestly:

  • Do you intend to serve Data Principals across many unrelated Data Fiduciaries? If you only manage consent for your own properties, no.
  • Is consent infrastructure your product, or a compliance need? If it is a need, buy a platform.
  • Can you accept fiduciary duty to Data Principals over commercial duty to your customers? The role requires it, and it conflicts directly with a vendor-serving business model.
  • Do you meet ₹2 crore net worth and Indian incorporation? Non-negotiable.
  • Can you carry ongoing audit, governance, and grievance obligations? Registration is a permanent operating burden, not a certificate.

For the overwhelming majority of Indian businesses — e-commerce, SaaS, banks, hospitals, manufacturers — the answer is no, and the correct action is to deploy a compliant consent management platform against the 13 May 2027 deadline instead.

Frequently Asked Questions

What is a Consent Manager under India's DPDP Act?

A Consent Manager is an entity registered with the Data Protection Board of India that provides Data Principals a single, interoperable interface to give, manage, review, and withdraw consent across multiple Data Fiduciaries. It is accountable to the Data Principal rather than to the fiduciaries, and it must not access the personal data flowing between them.

When does Consent Manager registration open?

The Consent Manager framework under Rule 4 becomes operational on 13 November 2026, twelve months after the DPDP Rules 2025 were notified on 13 November 2025. Entities intending to operate as registered Consent Managers should have their application material ready before that date.

What is the net worth requirement for a Consent Manager in India?

A minimum net worth of ₹2 crore, evidenced by audited financials. The applicant must also be a company incorporated in India, which excludes foreign entities and offshore CMP vendors from registering directly.

Does every business need to register as a Consent Manager?

No. Registration applies only to entities that intend to operate consent infrastructure serving Data Principals across multiple Data Fiduciaries. A business managing consent for its own websites, apps, and customers is a Data Fiduciary and needs a consent management platform — not registration.

Can a foreign consent management platform register in India?

Not directly. The eligibility criteria require incorporation in India, so a global CMP would need an Indian subsidiary that independently satisfies the ₹2 crore net worth and technical capability requirements.

Can a Data Fiduciary also be a registered Consent Manager?

It sits badly with the framework's design. A Consent Manager owes duties to the Data Principal and must not access the personal data it brokers, while a Data Fiduciary determines the purposes of processing and holds the data. Combining both roles in one entity creates a structural conflict of interest that the independence and fit-and-proper requirements are intended to prevent. At minimum it would require genuine separation of entity, systems, and governance.

What does a Consent Manager cost to operate?

Beyond the ₹2 crore net worth threshold, the recurring costs are the ones that decide viability: independent audit, a governance and grievance function, security and continuity obligations, and engineering to maintain interoperability with each Data Fiduciary that connects. Because the role is infrastructure serving Data Principals rather than a product sold to businesses, revenue models are constrained by the independence requirement — which is precisely why this is a strategic decision rather than a compliance step.

What happens if an unregistered entity operates as a Consent Manager?

Once the framework is operational, holding out as a Consent Manager without registration is not permitted. The role and its accountability to Data Principals are defined by registration; operating without it exposes the entity to enforcement action by the Board.

Where Consently Fits

Consently is a consent management platform for Data Fiduciaries — the thing the great majority of Indian businesses actually need. It handles itemised per-purpose consent, notices in all 22 Scheduled languages, one-click withdrawal, immutable zero-PII consent records with notice versioning, Data Principal rights workflows, and India-resident infrastructure. If you are trying to work out whether your situation calls for a platform or for registration, talk to us — the answer is usually clear in one conversation and usually saves a wasted quarter.

Share this article

Related Articles

Compliance Guides

Employee Data Under the DPDP Act: What Indian HR Teams Must Fix Before 2027

HR holds more sensitive personal data than marketing ever will — Aadhaar, bank details, medical records, background checks, CCTV, and now productivity monitoring. The DPDP Act covers all of it. The good news: much of it does not need consent. The bad news: most HR teams have no idea which parts do.

10 Jul 20269 min
Compliance Guides

Significant Data Fiduciary Under DPDP: Obligations, DPO Requirements, Audits and Cross-Border Rules

Being designated a Significant Data Fiduciary adds four obligations no ordinary Data Fiduciary has: a resident DPO, an independent data auditor, annual Data Protection Impact Assessments, and algorithmic due diligence. MeitY has also signalled cross-border restrictions for SDFs. Here is what the designation means and how to prepare.

6 Jul 202610 min
Compliance Guides

Can You Train AI on Indian Customer Data? What the DPDP Act Says About AI Training Data

India's DPDP Act has no research exemption for commercial AI, no legitimate-interests basis, and no concept of anonymised-enough. If you are fine-tuning a model on customer support transcripts or building a RAG index over user records, here is what the law actually requires — and what breaks.

23 Jun 202610 min