DPDP Consent Manager Registration in India: 2026 Rules
Published 27 September 2026 · 10 min read
Consent Manager registration under India's DPDP Rules 2025: the Rs 2 crore net worth bar, First Schedule conditions and the 13 November 2026 date.
The short answer
To register as a Consent Manager under India's Digital Personal Data Protection framework, an applicant must be a company incorporated in India with a minimum net worth of ₹2 crore, an independently certified interoperable consent platform, and articles of association that lock in conflict-of-interest safeguards. Rule 4 of the Digital Personal Data Protection Rules, 2025 — the rule that creates the registration route — comes into force on 13 November 2026, one year after the Rules were published.
If you are an ordinary business rather than an aspiring Consent Manager, 13 November 2026 imposes no new duty on you. Your date is 13 May 2027, when the substantive obligations commence.
Stratgik is a technology firm, not a law firm. What follows is an engineering and operations reading of the published Rules, intended to help you scope work and budget. Take a qualified Indian data protection lawyer's view on your specific obligations before you rely on any of it.
What a Consent Manager actually is
The Digital Personal Data Protection Act, 2023 introduced a category of intermediary that has no direct equivalent in the GDPR. A Consent Manager is an entity registered with the Data Protection Board of India that gives a Data Principal — an individual — a single accessible, transparent and interoperable place to grant, review, manage and withdraw consent across many Data Fiduciaries.
The design intent is portability of consent rather than portability of data: a person should be able to see every consent they have given in one dashboard and revoke one without contacting the company holding the data. The Consent Manager is accountable to the Data Principal, not to the businesses paying for the plumbing.
The critical structural point, and the one most commonly misread: the Consent Manager is a route the individual may choose, not a gateway every business must pass through. As AZB & Partners reads the framework, Data Fiduciaries may continue to obtain consent directly, provided they independently meet the Act's notice, consent, withdrawal and record-keeping standards. Some commentary asserts that integration with registered Consent Managers is mandatory for anyone relying on consent. That is a contested reading and, on the text of the Rules as published, an aggressive one. Treat vendor claims of a November 2026 integration mandate with scepticism and ask which rule number creates the duty.
The commencement timetable you should be working to
The Rules were notified on 14 November 2025 and commence in three stages. Getting this table right is the single most valuable thing a technology leader can do with an afternoon, because most internal panic about DPDP is aimed at the wrong date.
| Stage | Effective | Rules | What it covers |
|---|---|---|---|
| One | On publication (13–14 November 2025) | 1, 2, 17–21 | Definitions, the Data Protection Board's constitution, appointment terms, procedure and the staggered commencement scheme itself |
| Two | 13 November 2026 | 4 | Registration of Consent Managers and their continuing obligations under the First Schedule |
| Three | 13 May 2027 | 3, 5–16, 22, 23 | Notice to Data Principals, security safeguards, breach notification, retention and erasure, verifiable parental consent, Significant Data Fiduciary duties, cross-border transfer, rights requests and appeals |
A small discrepancy runs through published commentary: some advisers date stage two to 12 November 2026 and stage three to 12 May 2027, depending on how they count one year and eighteen months from publication. The difference is a day and has no practical planning consequence. Plan to be ready before the month begins.
Part A: the conditions to get registered
Rule 4 requires an applicant to satisfy the conditions in Part A of the First Schedule and to file the specified particulars with the Board. The Board then investigates and either registers the applicant — publishing its details — or refuses with reasons recorded in writing.
The published conditions, as summarised consistently across law firm and professional-services analyses including KPMG in India's guidance on the Rules:
- Indian incorporation. A company incorporated in India, with its registered office in India.
- Net worth above ₹2 crore. Calculated on Companies Act, 2013 principles. This is a capital adequacy test, not a revenue test, and it is the provision that quietly excludes most early-stage consent-tech startups from applying in their current form.
- Demonstrated capacity. Adequate technical, operational and financial capacity to run the platform at the transaction volumes the applicant projects, with a capital structure capable of sustaining operations.
- Sound management. The company's financial condition and the general character of its management must be sound; directors and senior management must have a reputation for fairness and integrity.
- Entrenched conflict safeguards. The articles of association must commit the company to avoiding conflicts of interest with Data Fiduciaries and to internal safeguards against conflicts among its own leadership — and those articles cannot be amended without the Board's prior approval.
- Independent platform certification. A certification from an independent body confirming that the interoperable consent platform meets the standards the Board specifies.
Read together, these are prudential-regulator conditions of the kind applied to payment intermediaries, not the light-touch registration many technology teams assumed.
Part B: what you must do once registered
Part B of the First Schedule sets out continuing obligations. The recurring themes are fiduciary posture, data blindness and evidential durability.
- Act in the Data Principal's interest. The Consent Manager's duty runs to the individual.
- Stay data-blind. The Consent Manager enables consent to move without itself reading the personal data held by Data Fiduciaries.
- Keep records for seven years. Consent records, notices and their movement must be retained for at least seven years from the relevant date, or longer where agreed with the Data Principal or required by another law. Records must be tamper-evident and available to the Data Principal on request.
- Publish and maintain an audit mechanism. Effective audit arrangements with periodic reporting of outcomes to the Board.
- Avoid conflicts, including financial ones. No arrangements with Data Fiduciaries that compromise neutrality; no subcontracting away the core obligations.
- Be genuinely accessible. The platform must work for ordinary users, including across languages and for users relying on assistive technology.
- Handle grievances. A published grievance route with defined response timelines.
The Board may direct remedial action on discovering non-adherence and may, after a hearing, suspend or cancel registration where that is necessary to protect Data Principals. AZB & Partners puts monetary exposure for Consent Manager non-compliance at up to ₹50 crore under the Act's Schedule. Figures circulating online that attach imprisonment or ₹500 crore penalties to Consent Manager breaches do not match the Act, which provides for civil monetary penalties only.
The regulator is not yet fully staffed — and that matters
The Data Protection Board of India exists in law from stage one, but it was not a fully constituted adjudicatory body through mid-2026. The Ministry of Electronics and Information Technology issued a notice in May 2026 inviting applications for the statutory posts of Chairperson and Members. Commentary from Indian counsel tracking the 2026 milestones cautions against describing the Board as already hearing complaints and levying penalties.
Two honest implications follow. First, nobody can yet be registered as a Consent Manager, because there is no fully constituted Board to register them, and the technical standards that the required independent certification must certify against have not been published in detail. Any vendor selling you "DPDP-certified Consent Manager" services today is describing an aspiration. Second, the registration window opening in November 2026 depends on the Board being operational by then — which is pending, not guaranteed.
For a business, the useful conclusion is not to relax. It is that the scarce resource in 2026 is not legal advice but engineering time, and the work that stage three will require is work you can start now at a calm pace instead of buying at a premium in early 2027.
Practical checklist
If you intend to apply as a Consent Manager:
- Confirm Indian incorporation and model net worth above ₹2 crore on Companies Act principles, with headroom, at the date you will file.
- Amend the articles of association now to carry the conflict-of-interest commitments, and record that they cannot be amended without Board approval.
- Document projected transaction volumes and the capital structure that supports them; this is an explicit condition, not a pitch deck exercise.
- Identify candidate independent certification bodies and design the platform against published interoperability and security expectations, accepting that detailed standards may still shift.
- Build consent records as append-only, tamper-evident structures with a seven-year retention floor and a Data Principal-facing export.
- Stand up the audit mechanism and grievance process before you file, not after.
- Accessibility and multilingual support are conditions of the platform, not later polish.
If you are an ordinary Data Fiduciary preparing for May 2027:
- Complete a data map: where personal data lives, which processing rests on consent, and which rests on another lawful ground. This is consistently the largest line item in a DPDP programme and the prerequisite for everything else.
- Audit existing consent capture against the Act's notice standards, and identify legacy data holding no valid notice.
- Extend log retention so you can evidence consent state and access history over a meaningful window.
- Build an erasure and retention workflow that actually reaches every system, including analytics stores, warehouses and backups.
- Design a breach detection and notification path with named owners and a rehearsed timeline.
- Expose a consent API surface capable of receiving and acting on withdrawal signals from an external platform, so that integrating a Consent Manager later is a configuration exercise rather than a rebuild.
- Get a lawyer's view on whether you are likely to be classified a Significant Data Fiduciary, because that changes the work materially.
How this shapes a build decision
The question most Indian technology leaders are really asking is whether to buy a consent platform, build one, or wait. The framework points to a pragmatic middle path. Becoming a registered Consent Manager is a regulated business with capital and governance conditions, and is a strategic decision rather than a compliance one. Consuming consent signals from whichever Consent Managers eventually register is an integration problem, and the sensible hedge is to build your internal consent state as a first-class, API-addressable service now — which is worth doing for May 2027 regardless of whether you ever connect to an external platform.
If you are weighing that trade-off, our build vs buy tool frames the comparison, and a short technology decision sprint is often enough to settle scope before budget season. Teams that need the underlying consent service designed and built usually treat it as a custom software workstream sitting alongside their existing product roadmap.
Frequently asked questions
Is Consent Manager registration open now?
No. Rule 4 comes into force on 13 November 2026, and the Data Protection Board of India was not fully constituted as of mid-2026, with applications for Chairperson and Members invited in May 2026. Until the Board is operational and its technical standards are specified, no entity can complete registration.
What is the minimum net worth to register as a Consent Manager in India?
₹2 crore, calculated on Companies Act, 2013 principles, alongside a broader requirement to show adequate technical, operational and financial capacity for the transaction volumes the applicant expects to handle.
Must every Indian business integrate with a Consent Manager?
On the text of the Rules as published, no. The Consent Manager is a route a Data Principal may use. Data Fiduciaries can continue to take consent directly if they meet the Act's notice, consent, withdrawal and record-keeping standards themselves. Some commentary reads an integration mandate into the framework; if a vendor tells you integration is compulsory, ask which rule creates that duty and take legal advice rather than the vendor's word.
What is the real DPDP deadline for most companies?
13 May 2027, when notice, security safeguards, breach notification, retention and erasure, children's data, cross-border transfer and rights-request rules all commence together. Because they arrive simultaneously, the programme is best sequenced backwards from that date starting in 2026.
How long must consent records be kept?
A registered Consent Manager must retain consent records for at least seven years from the relevant date, or longer where agreed with the Data Principal or required by another law, in a tamper-evident form available to the Data Principal on request. Data Fiduciaries should assume they need comparable evidential durability for consents they hold directly.
What penalties apply to Consent Managers?
Non-compliance by a Consent Manager carries monetary exposure of up to ₹50 crore under the Act's Schedule, per AZB & Partners' reading, and the Board may additionally direct remedial action or suspend or cancel registration after a hearing. The Act provides civil monetary penalties; it does not impose imprisonment.
The Consent Manager framework is the narrow part of DPDP. The broad part — notice, security, breach response, retention and erasure across every system that touches personal data — lands on 13 May 2027 and is mostly an engineering programme. If you want a view of what that programme looks like for your stack, see our DPDP compliance implementation page or the India hub. We implement; we do not give legal advice, and we work alongside your counsel rather than in place of them.
Keep reading
More from Stratgik

26 Sep 2026
ZATCA Phase 2 ERP Integration Cost in Saudi Arabia (2026)
What ZATCA Phase 2 e-invoicing integration costs in Saudi Arabia in 2026: wave deadlines, four routes, SAR budget ranges...

25 Sep 2026
AI Voice Agents in the UAE: TDRA Rules, Arabic and Cost (2026)
What UAE law allows, why local numbers limit outbound calls, how Gulf Arabic performs, and realistic per-minute and buil...

24 Sep 2026
Singapore PDPA Cross-Border Data Transfer Rules (2026)
How section 26 PDPA and the 2021 Regulations govern sending personal data out of Singapore: contracts, BCRs, CBPR certif...

