Consent Manager
A person registered with the Data Protection Board of India who provides Data Principals with a consent-management interface under the DPDP Act 2023.
A Consent Manager is defined in the Digital Personal Data Protection Act 2023 as a person registered with the Data Protection Board who enables a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform. Section 6(7) of the Act read with Rule 4 of the DPDP Rules 2025 sets out the registration, technical and accountability framework.
The Consent Manager sits between the Data Principal and multiple Data Fiduciaries. When a Data Fiduciary needs consent from a Data Principal, it may route the request through the Consent Manager, which authenticates the Data Principal, records the consent (or refusal or withdrawal), and shares the token or artefact with the Data Fiduciary. The Consent Manager is fiduciary to the Data Principal — it cannot subordinate the Principal's interests to those of any Data Fiduciary.
Rule 4 of the DPDP Rules 2025 prescribes the eligibility criteria (Indian company, minimum net worth, technical capacity), the registration process with the Data Protection Board, and the audit and reporting obligations. As of late 2026 several DEPA-native Consent Managers licenced under the earlier Account Aggregator framework have re-registered under the DPDP regime.