DPDP Consent Manager: What It Is and Isn't (2026)

By Puneeth · · 7 min read
DPDP Consent Manager: What It Is and Isn't (2026)

A DPDP "Consent Manager" Is Not Your Cookie Banner

Last updated: September 2026

Short answer: A Consent Manager under Rule 4 of the DPDP Rules, 2025 is a registered statutory intermediary that gives individuals one dashboard to grant, review and withdraw consent across many companies. It is not a cookie banner, and it is not the consent management platform on your website. Rule 4 becomes operative in November 2026, but for almost every D2C brand the obligation is not to become a Consent Manager — it is to be able to receive and act on consent signals from one.


The confusion that's about to happen

Over the next few weeks, a lot of Indian marketing teams are going to read a headline about a "Consent Manager deadline in November 2026," glance at the cookie banner on their site, and conclude they're fine.

The two things share a name and almost nothing else.

Your CMP — OneTrust, Cookiebot, a Shopify consent app, something your developer built — is a tool on your own website that shows a notice and records what the visitor chose. It's yours, it serves your site, and nobody registers it with anyone.

A Consent Manager under the DPDP Act is a regulated intermediary. Under Rule 4 it must be a company incorporated in India with a minimum net worth of ₹2 crore, must act in a fiduciary capacity toward the Data Principal, must keep the personal data it routes unreadable to itself, must retain consent records for at least seven years, and must be registered with the Data Protection Board of India before it can operate.

Its purpose is to give an individual one place to see and control every consent they've given across every company they deal with — grant here, review there, withdraw everywhere.

Same two words. Completely different objects.


What Rule 4 actually requires of you

For the overwhelming majority of D2C and e-commerce brands, the answer is: you are not becoming a Consent Manager. The net worth threshold, the fiduciary duty and the seven-year record obligation describe an infrastructure business, not a company that sells skincare.

What Rule 4 creates for you is an interoperability requirement.

If your customers begin using registered Consent Managers to manage their preferences, your systems need to be able to exchange consent signals with whichever one they chose — receive a grant, receive a review, and most importantly receive a withdrawal, and then act on it.

That's a different technical problem from displaying a banner. A banner asks a question once, on your site, and stores the answer locally. Interoperability means accepting an instruction that arrives from outside your stack, about a person, and propagating it through every system that holds their data.

Most consent setups today store consent as a boolean or a set of flags inside a marketing platform, with no external ingestion path and no guarantee that a change propagates anywhere. That's the gap.


The withdrawal problem is the hard part

Section 6(6) of the Act requires that withdrawing consent be as easy as giving it. That single sentence has more architectural consequence than anything else in the framework.

Think about what withdrawal has to do in a typical e-commerce stack. A customer withdraws marketing consent. That needs to reach your email platform, your ad platforms' custom audiences, your analytics, your CDP, your warehouse, your personalisation engine and any partner you've forwarded data to.

If your consent state lives in a banner and syncs to your marketing tools nightly, you have a window — hours, sometimes a day — in which you are processing data you no longer have a basis to process. Under GDPR you might have argued legitimate interests as a fallback. Under DPDP there is no legitimate interests basis. Consent is withdrawn or it isn't.

That's why batch synchronisation is a structural problem rather than a latency inconvenience. The requirement is propagation, promptly, everywhere.

More on the missing lawful basis and what it means for attribution on our DPDP resource page.


Three things that make consent harder under DPDP than under GDPR

Purpose-level granularity. Consent under the Act is specific to the purpose for which data is processed. A single "accept all" that covers analytics, advertising, personalisation and partner sharing is not purpose-specific consent, however it's labelled.

The burden of proof sits with you. As the Data Fiduciary, you must be able to demonstrate that valid consent was obtained. That means an auditable history — what was asked, what was shown, what was chosen, when, and what changed since — not a current-state flag.

No fallback basis. GDPR's Article 6(1)(f) legitimate interests has no equivalent here. If consent fails, there is nothing behind it for marketing processing.


The Board that hasn't been staffed

Worth knowing, because it will shape the next few months and because it is being misread.

The Data Protection Board of India was established in law when the Rules were notified in November 2025. Rules 17 to 21, governing its constitution and procedure, took effect the same day. But the appointments have not followed. MeitY issued a notification on 6 May 2026 inviting applications for Chairperson and Members, and a further notification in June. Reporting through August 2026 indicated the Search-cum-Selection Committees were still soliciting names rather than finalising them.

So the framework arrives in November on a date when the registry that gives it effect may not yet be functioning.

Do not read that as a reprieve. Two reasons.

The May 2027 date — when the substantive obligations around notice, consent, security safeguards, breach reporting and data principal rights become enforceable — has not moved. And a regulator that starts late tends to start with a backlog and something to prove, not with leniency.

The practical read is that the compliance work has a fixed end date and an uncertain start to enforcement. That's an argument for using the time, not for spending it.


What to actually do, in order

Find out where your consent state lives right now. Not which banner you use — where the answer is stored, what reads it, and what happens downstream when it changes. Most teams discover the answer is "one flag in one platform, and nothing else knows."

Map purposes to destinations. For every tool receiving customer data, write down the purpose it serves and which consent covers it. If analytics and advertising ride on the same consent flag, that's a purpose-granularity problem.

Test a withdrawal end to end. Pick a test record, withdraw consent, and time how long it takes to stop appearing in each downstream system. The number you get is your exposure window. Most teams have never measured it.

Build an ingestion path for external consent signals. This is the Rule 4 readiness work. You need somewhere a signal from outside your stack can arrive and be acted on.

Move enforcement to the routing layer. The durable fix is that consent gates the event as it's routed, per event and per destination, rather than being checked at collection and hoped about afterwards. That's the architecture our DPDP page describes, and it's the difference between recording a preference and enforcing it.

Audit what's actually firing on your site. You can't enforce consent on tags you don't know about. Site Intelligence reports what's firing and what's firing before consent, or you can do it manually with the tag audit method.


Frequently asked questions

What is a Consent Manager under the DPDP Act?
A Consent Manager is a registered intermediary under Rule 4 of the DPDP Rules, 2025 that enables a Data Principal to give, review and withdraw consent across multiple Data Fiduciaries through a single interface. It must be a company incorporated in India, meet a minimum net worth requirement of ₹2 crore, act in a fiduciary capacity toward the Data Principal, keep routed personal data unreadable to itself, and register with the Data Protection Board of India.

Is a Consent Manager the same as a consent management platform?
No. A consent management platform is software on your own website that displays a notice and records the visitor's choice. A Consent Manager is a regulated intermediary registered with the Data Protection Board that manages consent on behalf of individuals across many companies. The names overlap; the roles do not.

Does my D2C brand need to register as a Consent Manager?
Almost certainly not. The registration requirements describe an infrastructure business. What Rule 4 creates for most brands is an interoperability obligation — the ability to exchange consent grant, review and withdrawal signals with registered Consent Managers their customers choose to use.

When does the DPDP Consent Manager framework take effect?
Rule 4 becomes operative twelve months after the DPDP Rules, 2025 were notified on 13 November 2025, placing it in November 2026. The remaining substantive obligations become enforceable in May 2027.

Does DPDP have a legitimate interests basis like GDPR?
No. There is no equivalent to GDPR's Article 6(1)(f) legitimate interests under the DPDP Act. If consent fails or is withdrawn, there is no fallback basis for marketing processing.

What does DPDP require when someone withdraws consent?
Section 6(6) requires that withdrawal be as easy as giving consent, and withdrawal must propagate promptly. In practice that means every downstream system holding that person's data — email, ad platforms, analytics, CDP, warehouse, partners — has to stop processing. Batch synchronisation creates a window in which you are processing without a basis.

What are the penalties under the DPDP Act?
The Act's Schedule sets penalties up to ₹250 crore for the most serious contraventions, with a residual tier up to ₹50 crore. Penalties are adjudicated by the Data Protection Board of India.

Is the Data Protection Board operational?
The Board was established in law when the Rules were notified in November 2025, and the provisions governing its constitution took effect immediately. Appointments have lagged: MeitY invited applications for Chairperson and Members in May 2026, and reporting through August 2026 indicated the selection process was still under way. Check the current position before relying on this.