Consent Managers in India: Navigating Business Models, Liability, and Evolving Landscape
The Digital Personal Data Protection Act, 2023 (DPDPA), now fully effective, has ushered in a new era for data governance in India. Among its most innovative provisions are those concerning Consent Managers (CMs), designed to empower Data Principals (DPs) by providing a centralized, transparent mechanism for managing their consent. With the Digital Personal Data Protection Rules (DPDP Rules) now notified, the operational framework for CMs is taking shape, presenting both opportunities and complexities for businesses and individuals alike.
The Business of Consent Management
At their core, Consent Managers are regulated intermediaries enabling Data Principals to give, manage, review, and withdraw consent for data processing through an accessible, interoperable platform. As defined in Section 2(h) of the DPDPA, a CM is a person registered with the Data Protection Board of India (DPBI) who acts as a single point of contact for DPs to manage their consent. Section 6(8) and 6(9) of the Act explicitly empower DPs to utilize CMs for this purpose, ensuring that consent is freely given, specific, informed, unambiguous, and easily withdrawable.
The business model for CMs is expected to revolve around providing this critical service. Potential revenue streams could include subscription fees from Data Fiduciaries (DFs) for integrating with their platforms, transaction-based fees for consent requests, or value-added services like consent analytics and compliance reporting. The DPDP Rules, particularly those notified under Section 29, detail the technical standards, security protocols, and interoperability requirements that CMs must adhere to. These rules are crucial for ensuring a robust and trustworthy ecosystem. India’s existing Account Aggregator (AA) framework, regulated by the RBI, offers a valuable precedent, demonstrating how a consent-driven architecture can facilitate data sharing across the financial sector. The DPDPA’s CM framework extends this concept across all sectors, promising to revolutionize how personal data flows in the digital economy.
Unpacking Liability for Consent Managers and Data Fiduciaries
The DPDPA establishes a clear, albeit nuanced, liability regime for CMs and DFs. A CM, while facilitating consent, is itself a Data Fiduciary with respect to the consent metadata it processes. Therefore, a CM is liable for any breach of its obligations under the DPDPA, including failure to protect the integrity and confidentiality of consent records, or to act on DP instructions regarding consent withdrawal. Penalties for such breaches would be determined by the DPBI, considering factors outlined in Section 25 of the DPDPA.
Crucially, the existence of a CM does not absolve the Data Fiduciary of its primary responsibility for lawful data processing. A DF remains accountable for ensuring that it obtains valid consent as per Section 6(1) of the DPDPA and that any processing aligns with the purpose for which consent was given. If a CM erroneously communicates consent status, or if a DF relies on consent that was not validly obtained, the DF could still face penalties under Section 24. The DPDP Rules are expected to clarify the extent to which DFs can rely on CM attestations of consent and the due diligence required from DFs when engaging a CM. The concept of joint liability, where both CM and DF could be held responsible for certain breaches, is an area that might require further interpretative guidance from the DPBI, drawing parallels to how joint controllership is viewed under frameworks like the GDPR, albeit adapted to the DPDPA’s distinct structure.
Open Questions and Future Trajectories
Despite the clarity brought by the DPDPA and its rules, several open questions remain concerning the long-term evolution of the CM ecosystem.
Firstly, regulatory oversight beyond the DPBI’s general mandate is a key consideration. While the DPBI is the primary enforcement authority (Section 18), sectoral regulators like RBI, SEBI, and IRDAI may introduce specific licensing or operational norms for CMs operating within their respective domains, similar to the AA framework. Harmonization between these sectoral requirements and the general DPDP Rules will be vital.
Secondly, the technical standards and interoperability specified in the DPDP Rules must be robust enough to foster a competitive and seamless ecosystem. How will these standards evolve with technological advancements? Ensuring easy integration for DFs and a smooth experience for DPs across diverse platforms will be critical for widespread adoption.
Thirdly, the business viability of CMs hinges on their ability to attract both DPs and DFs. Building trust among DPs, particularly in a country with varying levels of digital literacy, will be paramount. Furthermore, the DPDP Rules are expected to contain provisions to prevent “dark patterns” in consent flows, ensuring that CMs genuinely empower DPs rather than nudging them towards specific choices.
Finally, the data minimisation principle (Section 6(1)) applies to CMs themselves. They must only collect and process personal data necessary for managing consent, raising questions about the scope of data they can retain and for how long.
Practical takeaway
For Indian businesses, General Counsels, and Data Protection Officers, the emergence of Consent Managers is not just a compliance requirement but a strategic opportunity. Proactively review your existing consent mechanisms to ensure DPDPA compliance, especially regarding granular, specific, and easily withdrawable consent. Begin evaluating potential CM partners, focusing on their adherence to the DPDP Rules’ technical standards, security protocols, and their commitment to transparency. Understand that while CMs streamline consent management, the ultimate liability for lawful processing rests with the Data Fiduciary. Due diligence in selecting and integrating with a CM will be crucial in mitigating risks and building a trusted data ecosystem. Staying abreast of evolving DPDP Rules and DPBI guidance will be key to navigating this transformative landscape.