Navigating Consent: India's Managers vs. EU's CMPs
The global landscape of data privacy is increasingly defined by user control, with consent emerging as a cornerstone principle. As India’s Digital Personal Data Protection Act, 2023 (DPDPA) and its accompanying Rules, particularly those governing Consent Managers, solidify their operational framework by August 2026, businesses must understand how these mechanisms compare to established frameworks like the EU’s ePrivacy Directive and General Data Protection Regulation (GDPR) with their market-driven Consent Management Platforms (CMPs). For Indian businesses and Data Protection Officers (DPOs) navigating both domestic and international compliance, a nuanced comparative analysis is crucial.
Regulatory Mandate and Oversight
India’s DPDPA introduces a distinct and formalised role for “Consent Managers” under Section 6(7). These entities are envisioned as fiduciaries to the Data Principal, acting as a single point of contact for managing, reviewing, and withdrawing consent. The DPDPA (Consent Manager) Rules, 202X (as they would be by this date), are expected to detail strict registration requirements, technical standards, and accountability mechanisms for these entities, likely overseen by the Data Protection Board of India. This implies a highly regulated and centralised approach, where the Consent Manager itself is a regulated entity with specific duties and liabilities towards the data principal.
In contrast, the EU framework does not mandate a specific “Consent Manager” entity. Instead, the GDPR places the onus squarely on the Data Controller to obtain and manage consent in compliance with Article 7 (Conditions for Consent) and ensure transparency under Article 5(1)(a). The ePrivacy Directive further specifies requirements for obtaining consent for cookies and similar tracking technologies. While Consent Management Platforms (CMPs) are widely used in the EU, often following standards like IAB Europe’s Transparency and Consent Framework (TCF), these are market-driven solutions. There is no explicit regulatory registration or fiduciary duty imposed on CMP providers themselves; their compliance is indirect, through the data controllers who deploy them. This makes the DPDPA framework significantly stricter in its direct regulation and oversight of the consent management entity itself.
Scope and Granularity of Consent
Both regimes strive for granular, informed, and freely given consent. GDPR Article 4(11) defines consent as “any freely given, specific, informed and unambiguous indication of the Data Subject’s wishes.” This necessitates clear choices for different processing purposes, easily withdrawable at any time (Article 7(3)). The ePrivacy Directive specifically targets electronic communications and cookies, requiring consent for their use, often leading to detailed cookie banners.
The DPDPA’s Consent Manager framework also aims for granular control. Section 6(1) requires consent to be “free, specific, informed, unconditional and unambiguous.” The Consent Manager’s role is to facilitate this by providing a unified interface for Data Principals to manage their consent preferences across multiple Data Fiduciaries. While the DPDPA’s scope is broad, covering all personal data processing, the Consent Manager model implicitly standardises the presentation and management of consent across various services in India. The EU framework, while demanding high granularity, leaves the implementation details to individual controllers and their chosen CMPs, leading to a more varied user experience. India’s approach could be seen as stricter in its potential for standardisation through regulated Consent Managers, potentially simplifying the user experience but imposing a more uniform technical and operational burden on fiduciaries.
Accountability and Enforcement
Under the DPDPA, Consent Managers, as regulated fiduciaries, will be directly accountable for upholding their duties to Data Principals. Breaches of these duties could lead to penalties under the DPDPA, in addition to any liabilities faced by the Data Fiduciary for processing data without valid consent. This creates a dual layer of accountability.
In the EU, accountability for consent management primarily rests with the Data Controller. If a CMP used by a controller fails to secure valid consent, the controller is liable under GDPR (e.g., for unlawful processing under Article 6). While CMPs themselves are not directly regulated, their services must enable controllers to comply. Enforcement is carried out by national Data Protection Authorities. The DPDPA’s direct regulation of Consent Managers introduces an additional, distinct layer of accountability that is largely silent in the EU framework, making the Indian regime potentially stricter for the consent management ecosystem as a whole.
Technical Standards and Interoperability
The DPDPA (Consent Manager) Rules are expected to mandate specific technical standards and interoperability requirements for Consent Managers. This would ensure seamless interaction between Data Principals, Consent Managers, and Data Fiduciaries, promoting a consistent and reliable consent ecosystem. This standardisation is a key feature of India’s approach, aiming to prevent fragmentation and ensure user control.
The EU, while having de facto standards like IAB TCF for advertising, does not legally mandate specific technical standards for CMPs or their interoperability. The market has largely driven these developments, with varying degrees of success and consistency. This makes the EU framework looser regarding mandated technical uniformity, allowing for greater innovation but also potential for inconsistency.
Practical Takeaway
Indian businesses, General Counsels, and DPOs must recognise the profound implications of the DPDPA’s Consent Manager framework. Unlike the EU’s market-driven CMP landscape, India’s approach introduces a regulated, fiduciary entity with direct accountability. This necessitates not only ensuring your own data processing activities are compliant but also engaging with certified Consent Managers that adhere to the DPDPA Rules. For businesses operating globally, this means maintaining separate, tailored consent mechanisms: leveraging regulated Consent Managers for Indian data principals while continuing to deploy GDPR-compliant CMPs for EU data subjects. The Indian framework, while potentially adding a layer of compliance complexity, also offers the promise of a more standardised and trustworthy consent ecosystem for Data Principals.