Consent Managers Under DPDPA: Navigating India's Data Fiduciary Landscape
The Digital Personal Data Protection Act, 2023 (DPDPA) has ushered in a new era for data privacy in India, fundamentally reshaping how personal data is collected, processed, and managed. Among its most innovative provisions is the concept of the Consent Manager, an entity poised to transform the consent landscape for Data Principals. As of August 2026, with the DPDPA and its initial rules in effect, understanding the operational nuances, business models, and liability frameworks surrounding Consent Managers is crucial for all stakeholders in India’s digital economy.
The Business Model of Consent Managers: An Intermediary of Trust
The DPDPA introduces Consent Managers as a critical layer of accountability and empowerment for Data Principals. Under Section 6(7) of the Act, a Data Principal has the option to give, manage, and withdraw their consent through a Consent Manager. This provision aims to simplify the often-complex process of managing multiple consent requests from various Data Fiduciaries, offering a centralised, transparent, and auditable mechanism.
The business model for Consent Managers is likely to revolve around providing a service to Data Principals and Data Fiduciaries. For Data Principals, they offer a user-friendly interface to view, grant, revoke, or modify consents, ensuring greater control over their personal data. For Data Fiduciaries, CMs streamline consent acquisition and record-keeping, helping them demonstrate compliance with DPDPA Section 6 (lawful processing based on consent) and Section 8 (duties of Data Fiduciary, including accountability).
The DPDP Rules, which elaborate on the operational aspects, are expected to mandate stringent technical standards for CMs, including requirements for secure data handling, interoperability, and robust authentication mechanisms. This aligns with existing sectoral norms, such as those from the Reserve Bank of India (RBI) governing Account Aggregators in the financial sector, which already facilitate consent-based data sharing. CMs could generate revenue through subscription fees from Data Fiduciaries, offering premium analytics on consent patterns, or by providing enhanced consent management tools. Transparency regarding their own data practices and potential conflicts of interest will be paramount to building trust.
Liability Framework: A Shared Responsibility
While Consent Managers facilitate the consent process, the DPDPA’s accountability framework ensures that liability remains distributed, primarily resting with the Data Fiduciary. Section 8 of the DPDPA clearly places the onus on Data Fiduciaries to comply with the Act. However, CMs are not without their own responsibilities and potential liabilities.
A Consent Manager could face liability for several reasons:
- Failure to Accurately Transmit Consent/Withdrawal: If a CM fails to accurately convey a Data Principal’s consent or, crucially, their withdrawal of consent, to a Data Fiduciary, this could lead to the Data Fiduciary processing personal data without valid consent, a violation of DPDPA Section 4. The CM’s negligence in this regard could attract penalties.
- Security Breaches: As custodians of sensitive consent records and potentially Data Principal identities, CMs are obligated to implement reasonable security safeguards as per DPDPA Section 24. Any breach leading to unauthorised access, disclosure, or loss of this data would expose the CM to significant penalties and reputational damage.
- Misrepresentation or Non-Compliance with Rules: CMs must adhere to the specific technical, operational, and ethical standards prescribed by the DPDP Rules. Any deviation or misrepresentation of their capabilities could result in regulatory action by the Data Protection Board of India (DPBI) under Section 18.
Despite the involvement of a CM, Data Fiduciaries retain primary accountability. They must conduct thorough due diligence on their chosen Consent Managers, ensuring contractual agreements clearly delineate responsibilities, indemnities, and service level agreements. A Data Fiduciary cannot simply delegate its DPDPA obligations; it must ensure that the CM’s operations align with its own compliance requirements. The relationship between a Data Fiduciary and a CM, while not directly analogous to a controller-processor relationship under GDPR, carries similar implications for shared responsibility and the need for robust contractual safeguards.
Open Questions and Future Directions
The operationalisation of Consent Managers, while promising, presents several open questions that will shape their evolution:
- Regulatory Oversight and Accreditation: While the DPBI is the enforcement authority, will there be a specific accreditation or licensing framework for CMs, potentially overseen by the Ministry of Electronics and Information Technology (MeitY)? Clear guidelines are needed to ensure consistency and trustworthiness across the ecosystem.
- Interoperability Standards: For CMs to truly empower Data Principals, seamless interoperability across different CMs and with various Data Fiduciaries is essential. Will India develop a common API standard, similar to the existing IndiaStack infrastructure, to facilitate this?
- Data Principal Adoption and Trust: The success of CMs hinges on Data Principals embracing them. This requires not only ease of use but also a high degree of trust in the CM’s independence, security, and commitment to privacy. Public awareness campaigns and robust grievance redressal mechanisms will be vital.
- Integration with Sectoral Regulators: How will CMs harmonise with existing sectoral regulations, particularly in finance (RBI’s Account Aggregators), insurance (IRDAI), and healthcare? Avoiding fragmentation and ensuring a unified, consistent consent experience across sectors will be a key challenge. The IT Rules, which govern intermediaries, might also influence the operational framework for CMs.
Practical Takeaway
For Indian businesses acting as Data Fiduciaries, the advent of Consent Managers is an opportunity to enhance DPDPA compliance and build trust with Data Principals. However, it is not an abdication of responsibility. Proactive steps include conducting rigorous due diligence on potential Consent Manager partners, negotiating comprehensive contractual agreements that clearly define roles, responsibilities, and liability allocation, and integrating CM functionality seamlessly into existing data governance frameworks. Data Protection Officers (DPOs) and General Counsels (GCs) must closely monitor the evolving DPDP Rules and industry best practices for CMs, ensuring that their organisations leverage this new tool effectively while upholding their primary accountability under the DPDPA. For aspiring Consent Managers, the focus must be on building secure, transparent, and interoperable platforms that genuinely empower Data Principals, backed by robust legal and technical compliance.