DPDP Act explainer
"Consent Manager" is a defined statutory role in the DPDP Act, not a marketing term for consent software. Section 2(g) describes a person registered with the Data Protection Board who gives data principals a single point at which to give, manage, review and withdraw consent. Confusing the role with a consent management platform leads organisations to buy the wrong thing.
The Act defines a Consent Manager as a person registered with the Data Protection Board who enables a data principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. The defining features are registration with the Board and acting on the data principal's side of the relationship.
That is a different position in the ecosystem from the Data Fiduciary, who determines the purpose and means of processing, and from the Data Processor, who processes on the fiduciary's behalf.
The two are routinely conflated and are not the same thing.
If you run a website, an app or any service that collects personal data from individuals in India, your obligation is to obtain valid consent, record it, and honour withdrawal — a consent management platform problem.
Becoming a Consent Manager is a deliberate business decision to operate as a registered intermediary, and it carries registration and interoperability obligations of its own. It is not a compliance step for an ordinary Data Fiduciary.
Whichever side you are on, the Act's requirements for consent are the operative test.
Under section 2(g), a Consent Manager is a person registered with the Data Protection Board of India who gives data principals a single, accessible, transparent and interoperable point at which to give, manage, review and withdraw their consent across Data Fiduciaries.
No. A Consent Manager is a registered intermediary acting for the data principal. A consent management platform is software a Data Fiduciary runs to collect and honour consent for its own processing. Most organisations need the platform, not the registered role.
No. Ordinary Data Fiduciaries are not required to become or appoint a registered Consent Manager. Their obligation is to obtain valid consent, keep a record of it and honour withdrawal, which is done with a consent management platform.
It must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, requested with a notice available in English or a language in the Eighth Schedule, limited to a stated purpose, and as easy to withdraw as it was to give.
Jupinder Bedi — Jupinder writes on data protection practice at ProtectComply, with a focus on how obligations translate into system behaviour.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →