Post

Consent Managers Under DPDPA: Business, Liability, and the Road Ahead

Consent Managers Under DPDPA: Business, Liability, and the Road Ahead

The operationalisation of India’s Digital Personal Data Protection Act, 2023 (DPDPA) has brought into sharp focus several innovative mechanisms designed to empower Data Principals and streamline compliance for Data Fiduciaries. Among these, the concept of a “Consent Manager” stands out as a unique Indian contribution to global privacy frameworks, poised to become a cornerstone of our digital economy’s consent architecture. As of September 2026, with the DPDPA and its accompanying rules now in full swing, businesses are actively grappling with the practical implications of integrating Consent Managers into their data processing workflows.

At its core, a Consent Manager is an entity envisioned to act as a single point of contact for Data Principals to manage their consent effectively and transparently. DPDPA Section 6(7) explicitly states that “The consent of the Data Principal may be managed by a Consent Manager, who shall be a Data Fiduciary, registered with the Board, and who shall be accountable to the Data Principal.” This provision lays the legal groundwork for a new class of regulated entities.

The business model for Consent Managers is expected to revolve around providing user-friendly interfaces (e.g., mobile apps, web portals) where Data Principals can grant, review, revoke, or modify their consent for various Data Fiduciaries. This moves beyond the fragmented consent mechanisms prevalent before the DPDPA. They will facilitate the flow of consent signals, ensuring that Data Fiduciaries receive accurate and up-to-date consent instructions. This model aligns with India’s broader vision for digital public infrastructure, drawing parallels with the Account Aggregator framework regulated by the RBI, which facilitates consent-based data sharing in the financial sector. The DPDP Rules, particularly those detailing the registration and operational standards for Consent Managers, are crucial here, stipulating technical requirements, audit mechanisms, and data security protocols.

The DPDPA’s framework introduces a nuanced liability structure concerning Consent Managers. While Consent Managers are designated as “Data Fiduciaries” themselves under Section 6(7) for their specific function, this does not absolve the primary Data Fiduciary (the entity processing personal data for its own purposes) of its overarching obligations.

The Consent Manager’s accountability, as per Section 6(7), is directly to the Data Principal. This implies liability for ensuring the integrity of the consent management process, including accurate recording of consent, timely communication of consent revocation, and robust security measures for the consent data they manage. Any failure in these duties, such as misrepresenting a Data Principal’s consent choice or a breach of their own systems holding consent records, could lead to penalties under DPDPA Section 17.

However, the primary Data Fiduciary remains ultimately responsible for adhering to the core principles of the DPDPA. This includes ensuring that consent obtained, even through a Consent Manager, is specific, informed, unambiguous, and freely given, as mandated by DPDPA Section 6(1)-(6). The Data Fiduciary cannot outsource its responsibility for lawful processing or for honouring Data Principal rights under Section 7. Therefore, Data Fiduciaries must exercise due diligence when selecting and contracting with Consent Managers, ensuring contractual agreements clearly delineate responsibilities and indemnities. This shared liability model requires careful consideration, distinct from some global frameworks like GDPR where the concept of a ‘joint controller’ might apply, but the DPDPA’s explicit designation of the CM as a Data Fiduciary for its specific role is a clear differentiator.

Key Open Questions and Regulatory Gaps

Despite the clarity offered by Section 6(7) and the DPDP Rules, several practical questions continue to emerge as the ecosystem matures:

Firstly, the registration and certification process for Consent Managers by the Data Protection Board of India (DPBI) under DPDPA Section 20 needs ongoing refinement. While the Rules specify broad requirements, granular details on technical standards, interoperability protocols, financial stability criteria, and independent audit mandates are still evolving. The interplay with sectoral regulators like RBI, SEBI, and IRDAI, particularly for regulated entities acting as or engaging Consent Managers, will also require harmonisation.

Secondly, interoperability standards are paramount. For the system to truly empower Data Principals, different Consent Managers must be able to communicate seamlessly, allowing a Data Principal to manage all their consents from a single platform, regardless of which Consent Manager their Data Fiduciary uses. This will necessitate common APIs and data exchange formats.

Finally, the optionality clause in Section 6(7) – “may be managed by a Consent Manager” – raises questions about the long-term vision. While initially optional, there’s a possibility that certain high-risk data processing activities or specific sectors might see Consent Manager usage become mandatory through future amendments or sectoral guidelines. The cost implications for both Data Fiduciaries and Data Principals, and how these will be absorbed or regulated, also remain a subject of debate.

Practical Takeaway

For Indian businesses, including General Counsels and Data Protection Officers, the emergence of Consent Managers presents both an opportunity and a challenge. Leveraging a registered Consent Manager can significantly streamline consent management, enhance transparency, and demonstrate compliance with DPDPA Section 6. However, it is critical to remember that the ultimate accountability for lawful data processing rests with the Data Fiduciary. Conduct thorough due diligence on prospective Consent Managers, scrutinising their registration status with the DPBI, security certifications, technical capabilities, and adherence to DPDP Rules. Ensure robust contractual agreements that clearly define roles, responsibilities, and indemnification clauses. Stay abreast of evolving regulatory guidance from the DPBI and relevant sectoral regulators, as the Consent Manager ecosystem is dynamic and will continue to be shaped by practical implementation and policy refinements.

This post is licensed under CC BY 4.0 by the author.