Consent Manager registration under Rule 4: what starts on 13 November 2026
By Yashasvi · 5 min read · Updated 8 October 2026
The DPDP Rules, 2025 were notified on 13 November 2025. Rule 1 brings most of them into force in phases, and Rule 4, on the registration and obligations of Consent Managers, comes into force one year after notification: 13 November 2026.
From that date a company can apply to the Data Protection Board of India to become a registered Consent Manager. This guide covers what Rule 4 and the First Schedule require, and what it means if you are a Data Fiduciary rather than an applicant.
What Rule 4 says
Rule 4 is short. It sets up a registration regime and points to the First Schedule for the detail:
- A person who meets the conditions in Part A of the First Schedule may apply to the Board for registration.
- The Board may make enquiries and then either register the applicant or reject the application, giving reasons.
- A registered Consent Manager must meet the obligations in Part B of the First Schedule.
- If a Consent Manager is not meeting its conditions or obligations, the Board may direct it to comply.
- After giving it a chance to be heard, the Board may suspend or cancel its registration, and give directions to protect the interests of Data Principals.
- The Board may require a Consent Manager to furnish any information it calls for.
Who can register: First Schedule, Part A
An applicant must meet all of these conditions:
| # | Condition |
|---|---|
| 1 | It is a company incorporated in India |
| 2 | It has sufficient technical, operational and financial capacity to fulfil its obligations |
| 3 | Its financial condition and the general character of its management are sound |
| 4 | Its net worth is at least ₹2 crore |
| 5 | Its likely volume of business, capital structure and earning prospects are adequate |
| 6 | Its directors, key managerial personnel and senior management have a general reputation and record of fairness and integrity |
| 7 | Its memorandum and articles of association require it to follow the conflict-of-interest obligations (items 9 and 10 of Part B), and those provisions cannot be changed without the Board's approval |
| 8 | Its operations are in the interests of Data Principals |
| 9 | Its interoperable platform has been independently certified as consistent with the Rules' data protection standards, with technical and organisational measures to meet its obligations |
Individuals, partnerships and foreign companies cannot register. Condition 9 means the platform has to be built and certified before an application can succeed.
What a registered Consent Manager must do: First Schedule, Part B
Part B sets out thirteen obligations. In summary, a Consent Manager must:
- let a Data Principal give consent, through its platform, to a Data Fiduciary onboarded onto that platform, either directly to that Data Fiduciary or through another onboarded Data Fiduciary that already holds the data with the person's consent;
- share personal data in a way that keeps its contents unreadable to the Consent Manager itself;
- keep a record of consents given, denied and withdrawn, the notices that came with them, and any sharing of personal data;
- give the Data Principal access to that record, in machine-readable form on request, and keep it for at least seven years;
- offer its services mainly through a website or app;
- not subcontract or assign the performance of its obligations;
- take reasonable security safeguards to prevent personal data breaches;
- act in a fiduciary capacity towards the Data Principal;
- avoid conflicts of interest with Data Fiduciaries, including through directorships, shareholdings or other relationships of its promoters and senior staff;
- publish on its website or app its promoters, directors, key managerial personnel and senior management, everyone holding more than 2% of its shares, and every company in which those people hold more than 2%;
- keep effective audit mechanisms covering its controls, its continued fulfilment of the registration conditions and its compliance with the Act and Rules, and report the outcome to the Board periodically;
- not transfer control of the company without the Board's prior approval.
What it means for Data Fiduciaries
13 November 2026 is not a compliance deadline for ordinary Data Fiduciaries. Most of their obligations, including notices, security, breach reporting and rights, apply from 13 May 2027. See the DPDP Rules 2025 timeline.
It still matters, for four reasons:
- Consent can arrive through a third party. Section 6(7) lets a Data Principal give, manage, review and withdraw consent to you through a Consent Manager. Your systems need to accept that consent, record it and honour a later withdrawal, as they would for consent collected directly.
- The burden of proof stays with you. Under Section 6(10) you must still prove a valid notice and consent, whatever channel it came through. Keep your own record of each consent and its notice version.
- Withdrawal must reach your processors. A withdrawal made through a Consent Manager triggers the same duty under Section 6(6): stop processing, and make your processors stop.
- Check vendor claims. Once registration opens, any vendor calling itself a "Consent Manager" under the DPDP Act should be able to show its registration with the Board. A tool your organisation buys to manage its own consents is a consent management platform, and does not need to be registered.
Thinking of registering?
Registration is a regulated business, not a product feature. Before applying, an organisation would need an Indian company with at least ₹2 crore net worth, governance documents that lock in the conflict-of-interest rules, an independently certified platform, and an operating model in which it acts for individuals rather than for the companies collecting their data. Whether and when the Board starts accepting applications is a matter for the Board; check its official announcements before planning around a date.
Where Consentrio fits
Consentrio is a consent management platform for Data Fiduciaries. It is not a registered Consent Manager. It gives your organisation versioned notices, consent capture through web, mobile and server SDKs, a preference centre for withdrawal, rights and grievance handling, signed notifications to processors, and a tamper-evident audit trail that proves each consent.
For the definition of a Consent Manager and the sections of the Act behind it, see what is a Consent Manager under the DPDP Act?
This guide is general information, not legal advice. Check the Act and the Rules, or ask your counsel, for decisions about your organisation.