DPDP Consent Manager Registration: Eligibility, the ₹2 Crore Net Worth Bar, and the Application Checklist
The Consent Manager framework goes live on 13 November 2026. Registration requires incorporation in India, a minimum net worth of ₹2 crore, and demonstrated technical capability to run consent across fiduciaries. Here is who qualifies, what the application needs, and — importantly — why most businesses should not apply.
Short answer: A Consent Manager is a DPBI-registered entity through which Data Principals can give, manage, review, and withdraw consent across multiple Data Fiduciaries from one interface. Registration requires incorporation in India, a minimum net worth of ₹2 crore, demonstrated technical and operational capability, and a fit-and-proper standing. The framework becomes operational on 13 November 2026. Almost no ordinary business needs to register.
First, the Confusion Worth Clearing
"Consent Manager" is a defined statutory role in India. It is not a synonym for consent management software. This distinction costs Indian companies real money in wasted evaluation cycles.
| Consent Manager (statutory role) | Consent Management Platform (software) | |
|---|---|---|
| Defined by | DPDP Act s.2(g), Rule 4, First Schedule | Nothing — it is a product category |
| Registered with DPBI? | Required | No registration exists |
| Serves | Data Principals, across many fiduciaries | A Data Fiduciary, on its own properties |
| Net worth bar | ₹2 crore minimum | None |
| Who needs one | Entities building interoperable consent infrastructure | Every business that collects personal data |
Key insight: if you run a website, an app, or a business that collects customer data, you need a consent management platform and you almost certainly do not need to become a registered Consent Manager. Registering is a decision to enter the consent-infrastructure business, not a compliance step for your own processing. We unpack the distinction further in Consent Manager vs CMP.
What a Registered Consent Manager Actually Does
The role is deliberately narrow and deliberately fiduciary. A Consent Manager:
- gives Data Principals a single interface to give, manage, review, and withdraw consent across multiple Data Fiduciaries,
- is accountable to the Data Principal, not to the fiduciaries who receive consent through it,
- acts as an interoperable platform, so a withdrawal made once propagates to every fiduciary that holds consent through the manager,
- maintains records of consent given, withdrawn, and notices served, and makes them accessible to the Data Principal,
- must not itself read the personal data flowing between principal and fiduciary — it manages the consent artefact, not the payload.
That last constraint is the architectural heart of the role. A Consent Manager that could read the data it brokers would become a Data Fiduciary many times over. The design intent is a blind conduit for consent state.
Eligibility Criteria
| Requirement | Detail |
|---|---|
| Incorporation | A company incorporated in India. This excludes foreign entities and foreign CMPs from operating as registered Consent Managers. |
| Net worth | Minimum ₹2 crore. Certified financials required. |
| Technical capability | Demonstrated ability to operate the consent lifecycle — capture, storage, review, withdrawal, propagation — at scale, with interoperability. |
| Fit and proper | Assessment of the applicant's and its promoters' reputation, standing, and record. |
| Governance | Obligations of certified independence, published grievance mechanism, and reporting to the Board. |
| Security | Appropriate technical and organisational measures, with audit obligations. |
The ₹2 crore net worth requirement is the most consequential filter. It is not a large number for a bank or a telco; it is a decisive barrier for a two-person startup that thought "consent manager" was a product label. Combined with the India-incorporation requirement, it also means global CMP vendors cannot register their offshore entities — they would need an Indian subsidiary meeting the net worth test.
The Application Checklist
Applications are made to the Data Protection Board of India. An applicant should expect to assemble:
- Certificate of incorporation and constitutional documents evidencing Indian incorporation.
- Audited financial statements demonstrating net worth of at least ₹2 crore, with an auditor's certificate.
- Technical architecture documentation — how consent is captured, stored, versioned, propagated, and withdrawn; how interoperability with multiple fiduciaries is achieved; how the platform avoids access to the underlying personal data.
- Security posture — encryption, access control, logging, retention, incident response, and any independent audit or certification held.
- Governance framework — board composition, independence, conflict-of-interest policy, and the accountability line to Data Principals.
- Grievance redressal mechanism — the published channel, the response commitment, and escalation to the Board.
- Fit-and-proper declarations for the entity and its promoters and directors.
- Business continuity and exit plan — what happens to consent records if the Consent Manager ceases operations, which the Board will care about because Data Principals would otherwise lose their consent history.
Obligations That Begin After Registration
Registration is the start of a permanent operating burden, not a certificate to display. A registered Consent Manager carries continuing duties:
- Maintain the consent record for every Data Principal, covering consents given, withdrawn, and the notices served against each — and make it accessible to the Data Principal on demand.
- Propagate withdrawal reliably to every Data Fiduciary holding consent through the platform. A withdrawal that reaches four fiduciaries out of five is a failure with a named victim.
- Operate a grievance mechanism and publish it, with escalation to the Board.
- Maintain independence — the Consent Manager owes duties to the Data Principal, and structures that make revenue depend on fiduciaries getting more consent create exactly the conflict the framework is designed to prevent.
- Submit to audit and report to the Board, including on security posture and incidents.
- Not access the personal data flowing between principals and fiduciaries — an architectural commitment that constrains every future product decision.
- Maintain continuity, including an orderly plan for consent records if the business winds down.
Registration can also be cancelled. An entity that fails these duties does not merely face penalties; it can lose the status its business model depends on.
India Has Done This Before
The Consent Manager design is not invented from nothing. India already runs a consent-intermediary framework in financial services: the Account Aggregator ecosystem under DEPA, where RBI-licensed NBFC-AAs move financial data between institutions on the customer's instruction, without reading the data they move.
The parallels are close enough to be instructive — a licensed intermediary, a fiduciary duty to the individual, an explicit blindness requirement, and interoperability by design. So are the lessons. Account Aggregator adoption was slow for years, held back by uneven onboarding across institutions, patchy user experience, and weak consumer awareness rather than by the technical framework. Anyone building toward Consent Manager registration should assume the same shape: the licence is achievable, the distribution problem is the real one. We explored this in our analysis of the Account Aggregator blueprint and its privacy lessons.
The Regulator Problem
There is a practical wrinkle worth stating plainly. The registration counterparty is the Data Protection Board of India. MeitY invited applications for the DPBI Chairperson and four Members in May 2026 — meaning that as of mid-2026 the Board was still being staffed, while the framework it must administer switches on in November 2026.
Prospective applicants should plan for a compressed and possibly shifting process: registration mechanics, forms, and timelines may be published close to the operative date. This is an argument for having the documentation assembled in advance rather than starting when the window opens. Our DPBI explainer covers the Board's composition and powers.
Should You Register? A Decision Test
Answer these honestly:
- Do you intend to serve Data Principals across many unrelated Data Fiduciaries? If you only manage consent for your own properties, no.
- Is consent infrastructure your product, or a compliance need? If it is a need, buy a platform.
- Can you accept fiduciary duty to Data Principals over commercial duty to your customers? The role requires it, and it conflicts directly with a vendor-serving business model.
- Do you meet ₹2 crore net worth and Indian incorporation? Non-negotiable.
- Can you carry ongoing audit, governance, and grievance obligations? Registration is a permanent operating burden, not a certificate.
For the overwhelming majority of Indian businesses — e-commerce, SaaS, banks, hospitals, manufacturers — the answer is no, and the correct action is to deploy a compliant consent management platform against the 13 May 2027 deadline instead.
Frequently Asked Questions
What is a Consent Manager under India's DPDP Act?
A Consent Manager is an entity registered with the Data Protection Board of India that provides Data Principals a single, interoperable interface to give, manage, review, and withdraw consent across multiple Data Fiduciaries. It is accountable to the Data Principal rather than to the fiduciaries, and it must not access the personal data flowing between them.
When does Consent Manager registration open?
The Consent Manager framework under Rule 4 becomes operational on 13 November 2026, twelve months after the DPDP Rules 2025 were notified on 13 November 2025. Entities intending to operate as registered Consent Managers should have their application material ready before that date.
What is the net worth requirement for a Consent Manager in India?
A minimum net worth of ₹2 crore, evidenced by audited financials. The applicant must also be a company incorporated in India, which excludes foreign entities and offshore CMP vendors from registering directly.
Does every business need to register as a Consent Manager?
No. Registration applies only to entities that intend to operate consent infrastructure serving Data Principals across multiple Data Fiduciaries. A business managing consent for its own websites, apps, and customers is a Data Fiduciary and needs a consent management platform — not registration.
Can a foreign consent management platform register in India?
Not directly. The eligibility criteria require incorporation in India, so a global CMP would need an Indian subsidiary that independently satisfies the ₹2 crore net worth and technical capability requirements.
Can a Data Fiduciary also be a registered Consent Manager?
It sits badly with the framework's design. A Consent Manager owes duties to the Data Principal and must not access the personal data it brokers, while a Data Fiduciary determines the purposes of processing and holds the data. Combining both roles in one entity creates a structural conflict of interest that the independence and fit-and-proper requirements are intended to prevent. At minimum it would require genuine separation of entity, systems, and governance.
What does a Consent Manager cost to operate?
Beyond the ₹2 crore net worth threshold, the recurring costs are the ones that decide viability: independent audit, a governance and grievance function, security and continuity obligations, and engineering to maintain interoperability with each Data Fiduciary that connects. Because the role is infrastructure serving Data Principals rather than a product sold to businesses, revenue models are constrained by the independence requirement — which is precisely why this is a strategic decision rather than a compliance step.
What happens if an unregistered entity operates as a Consent Manager?
Once the framework is operational, holding out as a Consent Manager without registration is not permitted. The role and its accountability to Data Principals are defined by registration; operating without it exposes the entity to enforcement action by the Board.
Where Consently Fits
Consently is a consent management platform for Data Fiduciaries — the thing the great majority of Indian businesses actually need. It handles itemised per-purpose consent, notices in all 22 Scheduled languages, one-click withdrawal, immutable zero-PII consent records with notice versioning, Data Principal rights workflows, and India-resident infrastructure. If you are trying to work out whether your situation calls for a platform or for registration, talk to us — the answer is usually clear in one conversation and usually saves a wasted quarter.