Consent Manager Registration Under DPDP Rules 2025: Eligibility, Process & November 2026 Deadline
Determine if you need to register as a Consent Manager, understand what all Data Fiduciaries must do anyway, and get the complete 5-step registration roadmap.
Rules 4–7Governing Framework
₹12 CrMinimum Net Worth
5 QuestionsSelf-Assessment
Nov 13, 2026Registration Deadline
Quick Answer
What is a Consent Manager under DPDP Rules 2025? A Consent Manager is an entity registered with the Data Protection Board of India under Rules 4–7 of the DPDP Rules 2025. It acts as a single interoperable point through which a Data Principal can give, manage, review, and withdraw consent across multiple Data Fiduciaries — without visiting each platform separately. Registration requires a minimum net worth of ₹12 crore and DPB approval. Not all organisations need to become Consent Managers; however, all Data Fiduciaries must make their consent data interoperable with registered Consent Managers by November 13, 2026.
Time Until November 13, 2026 Deadline
–Days
–Hours
–Minutes
–Seconds
Consent Manager registration deadline: November 13, 2026 — Begin your registration at least 6 months in advance
What Is a Consent Manager? (Rules 4–6 Explained)
The Consent Manager Framework Rule 4
Under Section 6(9) of the DPDP Act 2023, Data Principals may give, manage, review, and withdraw consent through a registered Consent Manager. Rule 4 of the DPDP Rules 2025 establishes the registration framework with the Data Protection Board of India (DPB). A Consent Manager is:
A body corporate registered under Indian law
Accessible to Data Principals through an interoperable platform
Capable of acting as a single point for consent across multiple Data Fiduciaries
Accountable to the Data Principal on whose behalf it acts — not to the Data Fiduciary
Analogy: Think of a Consent Manager like a SEBI-registered stock broker — it acts as the interface between an investor (Data Principal) and the market (Data Fiduciaries), with regulatory oversight from the DPB.
Eligibility Requirements Rule 5
An entity wishing to register as a Consent Manager must meet all of the following criteria before submitting an application to the DPB:
Net worth: Minimum ₹12 crore, verified by a Chartered Accountant
Incorporation: Must be a body corporate incorporated in India
Interoperability: Must implement technical standards prescribed by MeitY for cross-platform consent portability
Accountability: Must demonstrate a contractual obligation to act solely on Data Principal instructions
Audit readiness: Annual independent audit of compliance with DPDP Rules — results submitted to DPB
No conflict of interest: Must not act as both Data Fiduciary and Consent Manager for the same processing activity
Maintain a register of all Data Fiduciaries for whom it manages consent
Provide the Data Principal with a comprehensive dashboard to view, modify, and revoke consents
Notify the Data Principal and relevant Data Fiduciaries within 24 hours of any breach affecting consent records
Withdraw from managing consent for a Data Fiduciary if instructed by the Data Principal
Submit annual compliance audits to the DPB, covering technical interoperability, data accuracy, and grievance resolution
Maintain records of all consent transactions for a minimum of 7 years
Registration is valid for a period specified by the DPB and must be renewed. The DPB may revoke registration for non-compliance, breach of data, or failure to maintain the prescribed net worth.
What ALL Data Fiduciaries Must Do (Even Non-CMs)
Even if your organisation never registers as a Consent Manager, you have mandatory interoperability obligations under the DPDP Rules 2025. Every Data Fiduciary processing personal data of Indian residents must:
Maintain portable consent recordsConsent data must be structured in MeitY-prescribed formats accessible via API or data export
Honour CM instructionsWhen a user appoints a Consent Manager, you must accept and act on consent changes they relay on the user's behalf
Structured consent noticeRule 3 mandates itemised, purpose-specific consent notices in the user's preferred language
Withdrawal mechanismUsers must be able to withdraw any consent as easily as it was given — including through a CM
Processing Activities RegisterMaintain and document a PAR covering all personal data processing, accessible for DPB inspection
Interoperability readiness auditAssess and document your technical readiness to integrate with any registered Consent Manager's platform
Self-Assessment: Do You Need to Register as a Consent Manager?
Answer 5 yes/no questions about your platform to get an instant eligibility determination.
Question 1 of 5
Does your platform allow users to manage consent across multiple services or platforms?
e.g. a single dashboard where users can view and change their privacy settings across two or more different apps or websites
Question 2 of 5
Do you intend to act as an intermediary for consent on behalf of other Data Fiduciaries?
i.e. your platform sits between the user and another organisation, relaying or enforcing their consent decisions on their behalf
Question 3 of 5
Does your business model involve aggregating user consent data at scale across organisations?
e.g. your revenue model or core product depends on collecting, storing, or analysing consent signals from multiple Data Fiduciaries' users
Question 4 of 5
Do you operate a platform where users access multiple third-party services under a unified login or identity?
e.g. a super-app, an identity provider, an account aggregator, or a marketplace where users have a single profile across many sub-services
Question 5 of 5
Does your organisation have a net worth exceeding ₹12 crore?
Net worth of at least ₹12 crore is a mandatory threshold for Consent Manager registration under Rule 5, verified by a Chartered Accountant
You Likely Need to Register as a Consent Manager by November 13, 2026
Based on your responses, your organisation exhibits 3 or more characteristics of a Consent Manager as defined under DPDP Rules 2025 (Rules 4–7). You should begin the DPB registration process now — the 5-step process below takes several months.
Seek qualified legal counsel to confirm your obligations under the DPDP Rules 2025. This self-assessment is indicative and not a substitute for professional legal advice.
You Likely Do Not Need to Register as a Consent Manager
Based on your responses, your organisation does not appear to meet the primary eligibility thresholds for Consent Manager registration. However, you still have mandatory interoperability obligations — your consent data must be portable and accessible to any registered Consent Manager a user appoints.
Note: If your net worth is below ₹12 crore, registration is not possible regardless of other factors. All organisations must still be CM-interoperable by the November 13, 2026 deadline.
5-Step Consent Manager Registration Process
1
Application to the Data Protection Board
Submit a formal registration application to the DPB through the prescribed online portal (to be notified by MeitY). The application must include the entity's incorporation documents, proposed interoperability architecture, and a technical description of the consent management platform.
2
Net Worth Verification (₹12 Crore Threshold)
Submit a certified net worth certificate from a practising Chartered Accountant confirming the entity meets the ₹12 crore minimum. This must be current — dated within 90 days of the application. Failure to meet this threshold results in automatic rejection.
3
Technical Interoperability Assessment
The DPB or a designated technical body assesses whether the platform meets MeitY's interoperability standards — including API architecture, consent record formats, cross-platform data portability protocols, and security controls. Applicants must demonstrate technical readiness before approval is granted.
4
DPB Scrutiny and Approval
The DPB reviews the application, net worth certificate, and technical assessment. It may request additional information, impose conditions, or reject the application with reasons. Upon approval, the entity is added to the public register of Consent Managers maintained by the DPB.
5
Annual Audit and Renewal
Registered Consent Managers must submit an annual compliance audit conducted by an independent auditor. The audit covers technical interoperability, consent record accuracy, grievance resolution timelines, and financial standing. Registration is renewable subject to continued compliance with all prescribed conditions.
Need Help with Your Consent Manager Registration?
Our DPDP specialists can assess your eligibility, prepare your application, and manage the DPB registration process end-to-end. Free initial consultation.
Enquiry received. Our team will be in touch within 24 hours.
Frequently Asked Questions
What is a Consent Manager under DPDP Rules 2025?
A Consent Manager under the Digital Personal Data Protection Rules 2025 (Rules 4–7) is an entity registered with the Data Protection Board of India that acts as a single interoperable point through which a Data Principal can give, manage, review, and withdraw consent across multiple Data Fiduciaries. Think of it as a consent aggregator: instead of a user managing their privacy settings separately on every platform, they can do it through a single registered Consent Manager. The Consent Manager must have a net worth of at least ₹12 crore and meet technical interoperability requirements prescribed by MeitY.
Do all companies need to become Consent Managers under DPDP Rules 2025?
No. Most organisations do not need to register as Consent Managers. Registration is required only for platforms that specifically act as intermediaries — enabling users to manage consent across multiple other Data Fiduciaries. However, ALL Data Fiduciaries must be interoperable with registered Consent Managers. This means your consent data must be accessible and portable to any registered Consent Manager a user chooses to use. The November 13, 2026 deadline applies to Consent Manager registration; interoperability obligations apply to all Data Fiduciaries from the date the Rules come into effect.
What is the net worth requirement for Consent Manager registration?
Rule 5 of the DPDP Rules 2025 prescribes that an entity applying to register as a Consent Manager must have a net worth of at least ₹12 crore (approximately USD 1.4 million) as verified by a chartered accountant. This threshold is designed to ensure that Consent Managers are financially stable and capable of sustaining the technical infrastructure required for interoperable consent management at scale. Entities below this threshold cannot register as Consent Managers but may still use a registered Consent Manager's services for their users.
What happens if we miss the November 13, 2026 Consent Manager deadline?
If your organisation qualifies as a Consent Manager but fails to register by November 13, 2026, you would be operating without the required registration, which constitutes a violation of the DPDP Rules 2025. Penalties under the DPDP Act 2023 can reach up to ₹250 crore per violation, with the Data Protection Board empowered to investigate, issue show-cause notices, and impose financial penalties. Beyond penalties, unregistered platforms offering consent management services would be required to cease those activities until registration is completed. It is strongly advised to begin the registration process at least 6 months before the deadline.
How does Consent Manager interoperability work under DPDP Rules 2025?
Consent Manager interoperability means that a Data Principal's consent records held by one Data Fiduciary must be accessible and manageable through any registered Consent Manager the user chooses. In practice, this requires Data Fiduciaries to maintain consent data in a standardised, portable format using APIs or data standards prescribed by MeitY. When a user appoints a Consent Manager, the Data Fiduciary must honour the Consent Manager's instructions on the user's behalf — including granting, reviewing, or withdrawing consent. All registered Consent Managers must also be interoperable with each other, creating a unified consent ecosystem across India's digital economy.
Trusted by Indian Businesses
70+Compliance Tools Live
₹250 CrMax Penalty at Stake
Nov 2026Consent Manager Deadline
Rules 4–7DPDP Rules Framework
Every Sunday
The Sunday DPDP Brief
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.