Navigating Consent: India's Regulated Managers vs. EU's CMP Frameworks
The global landscape of data privacy is increasingly defined by the principle of user control, with consent emerging as a cornerstone. While jurisdictions worldwide grapple with implementing robust consent mechanisms, India’s Digital Personal Data Protection Act, 2023 (DPDPA), introduces a distinct model through “Consent Managers.” This approach stands in contrast to the industry-driven Consent Management Platform (CMP) frameworks prevalent under the European Union’s General Data Protection Regulation (GDPR) and ePrivacy Directive. As of September 2026, with the DPDPA and its accompanying Rules fully operational, understanding these differences is crucial for any entity processing personal data.
Regulatory Foundation and Scope
The foundational difference lies in the statutory recognition and regulatory oversight of these mechanisms. Under the DPDPA, India has established “Consent Managers” (CMs) as legally defined entities. Section 6(8) of the DPDPA mandates that a Data Principal may give, manage, review, or withdraw consent through a Consent Manager. Section 6(9) further stipulates that such a Consent Manager must be a Data Fiduciary accountable to the Data Principal and registered with the Data Protection Board of India (DPBI). The DPDPA Rules, now in effect, detail the registration process, technical standards, audit requirements, and specific responsibilities of these CMs. This framework builds upon precedents like the Reserve Bank of India’s (RBI) Account Aggregator framework for financial data, extending a similar model of regulated consent intermediaries to all sectors. The scope of CMs under DPDPA is broad, covering all personal data processing activities where consent is the lawful basis.
In contrast, the EU’s GDPR and ePrivacy Directive do not legally define or mandate “Consent Management Platforms” (CMPs). CMPs are technical solutions developed by the industry to help Data Controllers comply with their obligations. The GDPR, particularly Article 6 (lawful basis for processing, including consent) and Article 7 (conditions for consent), along with the ePrivacy Directive (requiring consent for storing or accessing information on a user’s device, e.g., cookies), outline the legal requirements for valid consent. CMPs are tools designed to operationalize these requirements, but they are not regulated entities themselves. The primary accountability for obtaining valid consent rests squarely with the Data Controller (GDPR Article 24). The EU framework is silent on the direct regulation of CMPs as separate entities, focusing instead on the controller’s overall compliance.
Operational Mandate and Accountability
The operational mandate and accountability structures also diverge significantly. In India, Consent Managers are explicitly mandated to act on behalf of the Data Principal, providing a centralized interface for consent management. DPDPA Section 6(9) makes CMs directly accountable to the Data Principal, implying a higher degree of responsibility and potential liability for the CM entity itself. The DPDPA Rules prescribe stringent technical and operational standards, ensuring interoperability, security, and auditability of CMs. This makes the Indian regime stricter by establishing a new, regulated intermediary with direct statutory obligations to the data subject.
Under the EU framework, CMPs serve as facilitators, but the ultimate accountability remains with the Data Controller. GDPR Article 7(1) requires controllers to be able to demonstrate that the data subject has consented to processing. While a well-implemented CMP can aid this demonstration, any failure to obtain valid consent or manage withdrawals correctly is the controller’s responsibility. Industry initiatives, such as the IAB Europe’s Transparency and Consent Framework (TCF), provide technical specifications for CMPs to standardize consent signals, but adherence is voluntary and does not shift legal accountability from the controller. The EU’s approach is looser in that it does not impose direct regulatory oversight or accountability on CMP providers as distinct entities.
Consent Granularity and Withdrawal Mechanisms
Both regimes emphasize granular consent and easy withdrawal, but the implementation pathways differ. DPDPA Section 6(1) requires consent to be “free, specific, informed, unconditional, and unambiguous,” with Section 6(2) mandating clear, plain language requests. Crucially, Section 6(3) stipulates that consent withdrawal must be as easy as giving it. Consent Managers, as per Section 6(8), are designed to centralize and standardize this process, offering Data Principals a single dashboard to manage their consent across multiple Data Fiduciaries. This centralized, regulated approach makes the Indian framework potentially stricter in ensuring a consistent and user-friendly experience for granular control and withdrawal across the digital ecosystem.
Similarly, GDPR Article 7(2) requires consent to be clearly distinguishable and Article 7(3) mandates that withdrawal be as easy as giving consent. The ePrivacy Directive also necessitates clear information and consent for device access. CMPs under the EU framework are designed to provide granular choices (e.g., by purpose, by vendor) and facilitate withdrawal mechanisms. However, without a regulated intermediary like India’s CM, the quality and consistency of these implementations vary widely across different websites and services. While the legal requirements for consent are robust, the practical user experience for managing and withdrawing consent can be inconsistent due to the absence of a standardized, regulated CM.
Practical Takeaway
For Indian businesses, General Counsels, and Data Protection Officers, the DPDPA’s Consent Manager model represents a significant shift from the largely self-regulated CMP landscape seen in the EU. Compliance will not merely involve deploying a website consent banner; it will necessitate integrating with registered Consent Managers and robust internal processes to handle consent signals received from these regulated entities. Businesses must prepare for API-driven interoperability with CMs, ensuring their data processing activities accurately reflect the consent status communicated by the CM. This entails meticulous record-keeping, clear data flows, and a fundamental re-evaluation of how consent is obtained, managed, and withdrawn across the entire data processing lifecycle, embracing a new layer of shared responsibility within a regulated ecosystem.