Consentrio

Consent Manager vs consent management platform: which do you need?

By Yashasvi · 4 min read · Updated 8 October 2026

Search for "consent manager" in India today and you will find two different things under almost the same name:

  • a Consent Manager, a role defined and regulated by the Digital Personal Data Protection Act, 2023 (DPDP Act); and
  • a consent management platform (CMP), software that an organisation uses to collect and manage the consents it needs.

They solve different problems for different people. Most organisations need a consent management platform. Very few will ever become a Consent Manager, and every organisation may one day receive consents through one.

The short version

Consent Manager (DPDP Act) Consent management platform
Works for The Data Principal, the individual (Section 6(8)) The Data Fiduciary, the organisation
What it is A registered intermediary: one place where a person manages consents given to many organisations A tool an organisation uses to meet its own consent obligations
Legal basis Sections 2(g) and 6(7)–6(9); Rule 4 and the First Schedule of the DPDP Rules, 2025 Your obligations under Sections 5, 6 and 8
Registration Required with the Data Protection Board of India Not required
Who can be one An Indian company with at least ₹2 crore net worth, an independently certified platform and strict conflict-of-interest rules Any vendor, or a system you build yourself
Sees your users' data? Must share data so its contents are not readable by the Consent Manager Holds the consent records your organisation needs as proof
From when Registration provisions apply from 13 November 2026 Needed now; core Data Fiduciary duties apply from 13 May 2027

What a Consent Manager does

Section 2(g) defines a Consent Manager as a person registered with the Board who acts as a single point of contact for a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.

Think of it as an account a person holds, not a tool a company buys. Through it, someone could see every organisation they have consented to, and withdraw from several of them in one place. Section 6(8) makes the Consent Manager accountable to the Data Principal and requires it to act on their behalf. The First Schedule adds that it must act in a fiduciary capacity towards the person and avoid conflicts of interest with the organisations it connects to.

The conditions to register, and the obligations once registered, are covered in our guide to Consent Manager registration under Rule 4.

What a consent management platform does

The DPDP Act makes each Data Fiduciary responsible for its own consents. A consent management platform is how most organisations meet that responsibility across websites, apps and back-office systems. It typically handles:

  • notices that meet Section 5 and Rule 3, versioned and translated (see the consent notice checklist);
  • consent capture that is free, specific, informed and given by a clear affirmative action (Section 6(1));
  • withdrawal as easy as giving consent (Section 6(4)), and passing that withdrawal on to processors (Section 6(6));
  • rights requests and grievances (Sections 11–14);
  • a record that proves each consent, because the burden of proof is on you (Section 6(10)).

A cookie banner is one part of this, not the whole of it. DPDP consent covers every channel that collects personal data, not only cookies on a website.

How the two work together

The Act does not make you choose. Section 6(7) lets a Data Principal give or withdraw consent to you through a Consent Manager, so the two will meet:

  1. A person uses a registered Consent Manager to give you consent for a purpose.
  2. Your systems receive that consent and record it alongside consents collected directly, including the notice it relates to.
  3. Later, the person withdraws through the Consent Manager.
  4. You must stop processing for that purpose within a reasonable time and make your processors stop (Section 6(6)), exactly as if they had withdrawn on your own website.

Throughout, you still carry the burden of proving valid notice and consent under Section 6(10). A Consent Manager keeps records for the person; your consent management platform keeps the records you need.

Which do you need?

  • You are a Data Fiduciary (you decide why and how personal data is processed): you need a way to give notices, collect and record consent, honour withdrawals and rights requests, and prove it all. That is a consent management platform, bought or built.
  • You want to act for individuals across many organisations: that is a Consent Manager, and it means registering with the Board under Rule 4, with the conditions that come with it.
  • A vendor says it is a "Consent Manager": ask which one it means. If it claims the DPDP role, it should be able to show its registration with the Board.

Where Consentrio fits

Consentrio is a consent management platform for India's DPDP Act. It is not a registered Consent Manager. It gives Data Fiduciaries versioned notices, consent capture through web, mobile and server SDKs, a preference centre where users withdraw as easily as they consented, rights and grievance handling, signed notifications to processors, and a tamper-evident audit trail that proves each consent.

For the legal definition and the sections behind it, see what is a Consent Manager under the DPDP Act?

This guide is general information, not legal advice. Check the Act and the Rules, or ask your counsel, for decisions about your organisation.