Navigating Consent Managers under DPDPA: Business Models, Liability, and Key Considerations
The Digital Personal Data Protection Act, 2023 (DPDPA), now fully operational with its accompanying rules, has introduced a paradigm shift in how personal data is handled in India. Among its most innovative provisions is the concept of a Consent Manager (CM), an entity poised to reshape the digital consent landscape. By June 2026, the regulatory framework for CMs, detailed in the DPDP Rules, has begun to clarify their role, business models, and the complex web of liabilities.
The Evolving Business Model of Consent Managers
Consent Managers, as defined in Section 2(h) of the DPDPA, are Data Fiduciaries registered with the Data Protection Board of India (DPDPB) and are tasked with enabling a Data Principal to give, manage, review, and withdraw consent through an accessible, interoperable, and transparent platform. Section 6(7) mandates that the Central Government prescribe the registration, obligations, and responsibilities of CMs. The DPDP Rules, now in effect, elaborate on these.
The primary business model for CMs is expected to revolve around providing a service layer for consent management. This could involve charging Data Fiduciaries (DFs) for facilitating consent requests, maintaining consent logs, and ensuring compliance with withdrawal requests. Some CMs might also offer premium services directly to Data Principals, such as advanced analytics on data sharing or enhanced privacy controls, though the core service must remain free and accessible to Data Principals. The Rules likely stipulate that CMs cannot monetise the underlying personal data itself, only the service of managing consent. This distinction is crucial for maintaining trust and neutrality. The success of CMs will hinge on their ability to integrate seamlessly across diverse digital ecosystems, much like the Account Aggregator framework has done in the financial sector, providing a secure and standardised channel for consent flows.
Understanding the Liability Framework
The DPDPA establishes a multi-layered liability structure where CMs play a distinct but interconnected role with Data Fiduciaries.
Consent Manager’s Liability: A CM is directly liable for its own failures to comply with DPDPA and the DPDP Rules. This includes:
- Failure to accurately convey consent or withdrawal: If a CM misrepresents a Data Principal’s consent status to a DF, it could face penalties under Section 33.
- Security breaches: As a Data Fiduciary itself, a CM is obligated under Section 8(5) to implement reasonable security safeguards to prevent personal data breaches. Any breach within its systems, leading to unauthorised access or processing of consent-related information, would trigger liability.
- Non-compliance with DPDPB directives: CMs must adhere to registration conditions and operational guidelines issued by the DPDPB.
- Breach of duties to Data Principal: This includes ensuring transparency, providing accessible interfaces, and enabling easy withdrawal of consent, as outlined in the DPDP Rules.
Data Fiduciary’s Continuing Liability: Crucially, utilising a CM does not absolve the Data Fiduciary of its primary responsibilities. Section 6(1) unequivocally states that a DF must obtain valid consent for processing personal data. While a CM facilitates this, the DF remains accountable for ensuring that the consent obtained via the CM is truly free, specific, informed, unconditional, and unambiguous. If the CM fails in its duty, and as a result, the DF processes data without valid consent, the DF could still be held liable. Therefore, DFs must exercise due diligence in selecting and contracting with CMs, ensuring robust contractual agreements that delineate responsibilities and indemnities. The DPDP Rules likely mandate that DFs verify the registration status and compliance track record of any CM they engage.
Open Questions and Sectoral Integration Challenges
Despite the operationalisation of the DPDPA and its Rules, several open questions remain, particularly regarding the practical implementation and integration of CMs across India’s diverse digital economy.
One significant challenge is interoperability. The DPDP Rules likely prescribe technical standards for CMs, but ensuring seamless integration across various sectors – from finance (where RBI’s Account Aggregator framework already exists) to healthcare (with its own evolving digital health ecosystem) and e-commerce – will be complex. Will CMs be able to act as universal consent gateways, or will sectoral regulators like RBI, SEBI, and IRDAI introduce specific guidelines for CMs operating within their domains? Harmonisation will be key to avoiding fragmented consent experiences.
Another area of debate revolves around trust and adoption. For CMs to be effective, Data Principals must trust them implicitly. Building this trust requires robust security, transparent operations, and clear communication about their role. The DPDPB will play a vital role in fostering this trust through stringent oversight and public awareness campaigns.
Finally, the economic viability of CMs, especially smaller players, is an open question. While large enterprises might readily adopt CM services, ensuring affordability and accessibility for MSMEs will be crucial for widespread adoption. The DPDP Rules might include provisions to encourage a competitive and diverse CM ecosystem.
Practical Takeaway
For Indian businesses, particularly Data Fiduciaries, and their DPOs or GCs, the emergence of Consent Managers presents both opportunities and compliance complexities. It is imperative to thoroughly understand the DPDP Rules governing CMs, particularly those pertaining to registration, technical standards, and liability. Businesses should proactively evaluate potential CM partners, focusing on their security posture, interoperability capabilities, and adherence to DPDPB guidelines. While CMs can streamline consent management, Data Fiduciaries must remember that ultimate accountability for lawful data processing remains with them. Robust contractual agreements with CMs, internal audit trails of consent, and continuous monitoring of CM compliance will be essential to mitigate risks and ensure adherence to the DPDPA’s stringent requirements.