Consent Managers Explained: A New Regulated Role Under Indian Law
The DPDP Act creates an entirely new regulated intermediary, the Consent Manager, with no direct equivalent under GDPR. Here is what the role is meant to do.
What a Consent Manager is
Section 2 of the DPDP Act defines a Consent Manager as a person registered with the Board who acts as a single point of contact enabling a Data Principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform. Rather than a Data Principal separately negotiating consent with every Data Fiduciary that holds their data, the model envisions a registered intermediary sitting between the individual and multiple fiduciaries, presenting consent choices in a consolidated way.
This is a distinctly Indian regulatory innovation; GDPR has no directly equivalent registered-intermediary role, though various private consent-management platforms exist in the European market without the same statutory registration and accountability structure the DPDP Act contemplates.
Why the role exists
The underlying problem the Consent Manager role is designed to address is consent fatigue and fragmentation, individuals facing a large and growing number of separate consent requests from different apps, websites, and services, often with no easy way to see or manage everything they have consented to in one place. A registered Consent Manager, accountable to the Data Principal and operating under obligations set by the Board, is intended to give individuals a more genuine, centralised handle on their own consent choices.
The concept draws on precedent from India's broader Data Empowerment and Protection Architecture (DEPA) thinking in the financial sector, where account aggregator frameworks perform a structurally similar consent-intermediation function for financial data, suggesting the government sees consent management as a reusable pattern across sectors rather than a DPDP-specific invention.
Obligations and accountability
Because a Consent Manager sits in a position of trust over consent records for potentially many Data Principals across many Data Fiduciaries, the Act contemplates registration with the Board and compliance with obligations the Board or Rules specify, rather than allowing any platform to call itself a Consent Manager informally. The exact operational and technical standards, such as interoperability requirements between different Consent Manager platforms, are expected to be detailed further in the Rules rather than the Act itself.
Data Fiduciaries interacting with Consent Managers will need to think through how their own consent capture and withdrawal workflows integrate with a third-party intermediary's platform, which is a meaningfully different design problem than building a self-contained consent banner.
Open questions
As of this writing, the market structure for Consent Managers, how many will be registered, what business model they will operate under, and how quickly Data Fiduciaries will be expected to support integration with them, remains substantially unsettled. Organisations should watch this space rather than assume a mature Consent Manager ecosystem is already in place.
Where to go next
The Obligation Finder can help identify which of your existing consent flows would need to accommodate a Consent Manager integration once that ecosystem matures, and the /rules page has the fuller procedural detail on registration as it becomes available.