If you are deciding whether your product needs to build consent infrastructure from scratch or hand the job to a regulated intermediary, the Consent Manager is the piece of the DPDP framework built specifically for that question. The Act defines it as a registered entity that acts as a single point of contact, enabling a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.

The Account Aggregator blueprint

A Consent Manager relays consent requests from a Data Fiduciary to a Data Principal, records both the consent given and the notice that preceded it, and routes that consent to the right fiduciary without being able to read the contents passing through it. The architecture borrows directly from India's Account Aggregator system in financial services, relying on data-blind routing. The Data Principal gets one dashboard to review and withdraw consent across every connected app, rather than chasing settings pages across a dozen different platforms.

The high bar for registration

Rule 4 and the First Schedule of the DPDP Rules, 2025 set a deliberately high registration bar, since Consent Managers will be trusted with consent records across an entire ecosystem.

  • Incorporation as a company in India only; no foreign entities or unincorporated platforms.
  • A minimum net worth of two crore rupees, with capital structure commensurate with the role.
  • Demonstrated technical, operational and financial capacity to run the platform reliably.
  • Leadership with a reputation for fairness, and governing documents that hard-wire fiduciary duties.
  • An independent certification confirming the platform meets the data-protection standards the Board publishes.

Do you actually need one?

No. The Rules do not compel a Data Fiduciary to route consent through a Consent Manager. Collecting consent directly is entirely fine if you can independently meet the same notice, withdrawal and record-keeping bar. Where a Consent Manager earns its place is in ecosystems with frequent cross-entity sharing, like healthcare networks or public benefit schemes, where a common, auditable consent layer beats every fiduciary quietly building its own version of the same thing. For most product teams, the near-term task is simply making sure your own direct consent flow already meets the standard.