Consent Manager – Understanding Its Role Under the DPDP Act
A clear, practical guide to one of the most important concepts in India's Digital Personal Data Protection Act, 2023 — who a Consent Manager is, why it matters, and how it empowers every individual in the digital age.

The Digital Privacy Challenge We All Face
Every day, millions of Indians interact with dozens of apps, websites, hospitals, banks, and platforms — each collecting personal data and asking for consent in their own way. The result? A fragmented, confusing, and often invisible consent landscape.
Too many platforms
Users juggle consent across dozens of apps and websites simultaneously.
Inconsistent privacy notices
Each organization uses different formats, language, and processes.
Forgotten consents
It is nearly impossible to remember where, when, and what was consented to.
Difficult withdrawal
Withdrawing consent is often buried, technical, or practically inaccessible.

What Is a Consent Manager?
The DPDP Act, 2023 introduces the Consent Manager as an independent, accountable intermediary — a trusted entity registered with the Data Protection Board of India — whose sole purpose is to help individuals manage their consent-related rights in a simple, transparent, and user-friendly manner.
Single Point of Control
One platform to manage consent across multiple Data Fiduciaries.
Registered & Accountable
Must be registered with the Data Protection Board under prescribed conditions.
Acts on Behalf of Data Principals
Empowers individuals — not organizations — to exercise their rights.
Interoperable by Design
Designed to work across the digital privacy ecosystem seamlessly.

What a Consent Manager Is Not
One of the most important clarifications under the DPDP Act is understanding the boundaries of a Consent Manager's role. It is a facilitator — not a data owner, not a processor, and not a regulator.
✅ What a Consent Manager IS
- An independent registered intermediary
- A facilitator of consent management for individuals
- Accountable to the Data Protection Board
- A user-facing platform for consent rights
- An enabler of transparency and user control
❌ What a Consent Manager is NOT
- Not a Data Fiduciary (does not determine purpose of data use)
- Not a Data Processor (does not process personal data on behalf of a fiduciary)
- Not the owner of personal data
- Not a government department or regulator
- Not a substitute for organizational privacy compliance
Consent Manager vs. Data Fiduciary vs. Data Processor
Understanding how a Consent Manager differs from other key roles under the DPDP Act is essential for organizations and individuals alike.
| Dimension | Consent Manager | Data Fiduciary | Data Processor |
|---|---|---|---|
| Primary Role | Manages consent for Data Principals | Determines purpose & means of data processing | Processes data on behalf of a Fiduciary |
| Who does it serve? | The individual (Data Principal) | Itself / its business objectives | The Data Fiduciary |
| Data Ownership | Does not own data | Holds and controls data | Processes but does not own data |
| Registration Required | Yes — with Data Protection Board | May require registration | Not separately required |
| Examples | Dedicated consent management platforms | Hospital, bank, e-commerce app | Cloud provider, analytics firm |
The Consent Lifecycle
A Consent Manager enables Data Principals to exercise full control over their personal data at every stage — from the moment consent is requested to its eventual withdrawal. The lifecycle is designed to be transparent, traceable, and user-friendly.
This lifecycle ensures that consent is never a one-time checkbox — it is an ongoing, manageable, and revocable relationship between the individual and the organizations that use their data.
Data Principal → Consent Manager → Data Fiduciary
The Consent Manager sits at the center of the privacy relationship, acting as a trusted intermediary that ensures individual choices are clearly communicated to, and honored by, Data Fiduciaries. The flow is always driven by the individual.
Data Principal
The individual whose personal data is being processed. Initiates, modifies, or withdraws consent through the Consent Manager's platform.
Consent Manager
The registered intermediary that receives, records, and transmits consent decisions. Provides a single, interoperable dashboard for managing all consents.
Data Fiduciary
The organization collecting and processing personal data. Must honor consent decisions relayed through the Consent Manager.

Consent Manager in Action — Practical Examples
Healthcare
A patient uses a Consent Manager to authorize sharing of medical records with a specialist. They can later review, restrict, or revoke this access — all from a single dashboard — without contacting each hospital separately.
Banking
A customer managing an account-aggregator-linked loan application grants consent for income and transaction data. The Consent Manager records the scope, duration, and purpose — and allows withdrawal at any time.
Insurance
A policyholder reviews consent given for optional wellness and telematics services. Using the Consent Manager, they withdraw consent for services they no longer wish to participate in, simply and instantly.
Mobile Apps
A user who has downloaded twenty apps over two years uses the Consent Manager to see all active consents in one place — and revokes permissions for apps they no longer use, reducing their data footprint.
Benefits for Data Principals
The Consent Manager fundamentally shifts the power dynamic in digital data relationships — placing control firmly in the hands of the individual rather than the organization.
Better Transparency
Individuals can see exactly who has their data and for what purpose.
Greater Control
A single dashboard to manage all consent across multiple organizations.
Simpler Withdrawal
Revoking consent is straightforward, without navigating complex portals.
Improved Confidence
Users feel more secure engaging with digital services knowing they retain control.

Why Businesses Should Embrace the Consent Manager Ecosystem
Even organizations that are not themselves Consent Managers benefit significantly from operating within a well-functioning consent management ecosystem. The standardization and trust it creates reduces compliance risk and builds stronger customer relationships.
1. Standardized Consent Records
Consent obtained through a registered Consent Manager creates a reliable, auditable record — reducing disputes and simplifying regulatory compliance under the DPDP Act.
2. Stronger Customer Trust
Organizations that integrate with Consent Managers signal respect for user rights, building long-term loyalty and differentiated brand reputation.
3. Reduced Compliance Burden
Delegating consent tracking to a registered intermediary reduces the internal effort required to manage, document, and demonstrate valid consent.
4. Interoperable Privacy Infrastructure
As India's privacy ecosystem matures, organizations connected to Consent Manager platforms will be better positioned for future regulatory and technology changes.
Common Misconceptions About Consent Managers
❌ "Consent Managers own personal data"
Fact: A Consent Manager facilitates consent decisions. It does not collect, store, or own the underlying personal data being processed by Data Fiduciaries.
❌ "Every organization is a Consent Manager"
Fact: Only entities specifically registered with the Data Protection Board under prescribed norms can operate as Consent Managers.
❌ "It replaces our privacy obligations"
Fact: Organizations remain fully responsible for their own compliance. A Consent Manager does not substitute for organizational privacy policies, notices, or obligations.
❌ "It operates outside the legal framework"
Fact: Consent Managers operate strictly within the legal framework prescribed under the DPDP Act and regulations issued thereunder.

Why Every Organization Must Understand This Concept
Whether or not your organization plans to become a Consent Manager, the concept reshapes how consent governance, customer trust, and digital privacy operate across India's economy.
Future Privacy Ecosystem
Consent Managers will become core infrastructure in India's digital economy, much like UPI transformed payments.
Customer Trust at Scale
Organizations that respect and enable consent rights will earn a durable competitive advantage.
Better Consent Governance
Interoperable consent platforms set a new standard for how organizations collect, manage, and honor user permissions.
Digital Privacy Innovation
India's DPDP framework positions the country as a global leader in privacy-respecting digital innovation.

Key Takeaways
1. Individuals are empowered
The Consent Manager gives Data Principals a single, trusted platform to manage all their consent rights under the DPDP Act.
2. Consent must be transparent & usable
The Act's design philosophy demands that consent management be accessible, clear, and genuinely within the individual's control.
3. Organizations remain fully responsible
The existence of a Consent Manager does not reduce organizational obligations under the DPDP Act — compliance remains a shared responsibility.
4. Trust is the ultimate outcome
Effective, transparent consent management strengthens accountability, reduces disputes, and builds lasting trust between individuals and organizations.

Section 4 – Grounds for Processing Personal Data
Lawful Bases Under the DPDP Act
The DPDP Act, 2023 sets out specific grounds on which personal data may lawfully be processed. The next session will explore each ground in detail — from consent-based processing to legitimate uses — and what organizations must do to ensure compliance.
Next: Session 4 · DPDP Act Series · Module 3 · Lawful Processing
Disclaimer
This presentation is intended solely for educational and professional awareness purposes. It provides a general overview of the subject matter discussed. While every effort has been made to ensure the accuracy of the information presented, the content should be read in conjunction with the applicable laws, rules, regulations, official guidance, and judicial developments. The application of law and professional practices may vary depending on the specific facts and circumstances of each case.
