DPDP Act 2023 Series · #12 · Module 2 · Core DPDP Concepts

Consent Manager – Understanding Its Role Under the DPDP Act

A clear, practical guide to one of the most important concepts in India's Digital Personal Data Protection Act, 2023 — who a Consent Manager is, why it matters, and how it empowers every individual in the digital age.

Consent Manager illustration
Setting the Stage

The Digital Privacy Challenge We All Face

Every day, millions of Indians interact with dozens of apps, websites, hospitals, banks, and platforms — each collecting personal data and asking for consent in their own way. The result? A fragmented, confusing, and often invisible consent landscape.

Too many platforms

Users juggle consent across dozens of apps and websites simultaneously.

Inconsistent privacy notices

Each organization uses different formats, language, and processes.

Forgotten consents

It is nearly impossible to remember where, when, and what was consented to.

Difficult withdrawal

Withdrawing consent is often buried, technical, or practically inaccessible.

Digital privacy challenges across platforms
The DPDP Act's Answer

What Is a Consent Manager?

The DPDP Act, 2023 introduces the Consent Manager as an independent, accountable intermediary — a trusted entity registered with the Data Protection Board of India — whose sole purpose is to help individuals manage their consent-related rights in a simple, transparent, and user-friendly manner.

Single Point of Control

One platform to manage consent across multiple Data Fiduciaries.

Registered & Accountable

Must be registered with the Data Protection Board under prescribed conditions.

Acts on Behalf of Data Principals

Empowers individuals — not organizations — to exercise their rights.

Interoperable by Design

Designed to work across the digital privacy ecosystem seamlessly.

Consent Manager role illustration
Clearing the Confusion

What a Consent Manager Is Not

One of the most important clarifications under the DPDP Act is understanding the boundaries of a Consent Manager's role. It is a facilitator — not a data owner, not a processor, and not a regulator.

✅ What a Consent Manager IS

  • An independent registered intermediary
  • A facilitator of consent management for individuals
  • Accountable to the Data Protection Board
  • A user-facing platform for consent rights
  • An enabler of transparency and user control

❌ What a Consent Manager is NOT

  • Not a Data Fiduciary (does not determine purpose of data use)
  • Not a Data Processor (does not process personal data on behalf of a fiduciary)
  • Not the owner of personal data
  • Not a government department or regulator
  • Not a substitute for organizational privacy compliance
The Core Roles Compared

Consent Manager vs. Data Fiduciary vs. Data Processor

Understanding how a Consent Manager differs from other key roles under the DPDP Act is essential for organizations and individuals alike.

DimensionConsent ManagerData FiduciaryData Processor
Primary RoleManages consent for Data PrincipalsDetermines purpose & means of data processingProcesses data on behalf of a Fiduciary
Who does it serve?The individual (Data Principal)Itself / its business objectivesThe Data Fiduciary
Data OwnershipDoes not own dataHolds and controls dataProcesses but does not own data
Registration RequiredYes — with Data Protection BoardMay require registrationNot separately required
ExamplesDedicated consent management platformsHospital, bank, e-commerce appCloud provider, analytics firm
How It Works in Practice

The Consent Lifecycle

A Consent Manager enables Data Principals to exercise full control over their personal data at every stage — from the moment consent is requested to its eventual withdrawal. The lifecycle is designed to be transparent, traceable, and user-friendly.

This lifecycle ensures that consent is never a one-time checkbox — it is an ongoing, manageable, and revocable relationship between the individual and the organizations that use their data.

The Flow of Consent

Data Principal → Consent Manager → Data Fiduciary

The Consent Manager sits at the center of the privacy relationship, acting as a trusted intermediary that ensures individual choices are clearly communicated to, and honored by, Data Fiduciaries. The flow is always driven by the individual.

Data Principal

The individual whose personal data is being processed. Initiates, modifies, or withdraws consent through the Consent Manager's platform.

Consent Manager

The registered intermediary that receives, records, and transmits consent decisions. Provides a single, interoperable dashboard for managing all consents.

Data Fiduciary

The organization collecting and processing personal data. Must honor consent decisions relayed through the Consent Manager.

Consent flow between the Data Principal, Consent Manager and Data Fiduciary
Real-World Scenarios

Consent Manager in Action — Practical Examples

Healthcare

A patient uses a Consent Manager to authorize sharing of medical records with a specialist. They can later review, restrict, or revoke this access — all from a single dashboard — without contacting each hospital separately.

Banking

A customer managing an account-aggregator-linked loan application grants consent for income and transaction data. The Consent Manager records the scope, duration, and purpose — and allows withdrawal at any time.

Insurance

A policyholder reviews consent given for optional wellness and telematics services. Using the Consent Manager, they withdraw consent for services they no longer wish to participate in, simply and instantly.

Mobile Apps

A user who has downloaded twenty apps over two years uses the Consent Manager to see all active consents in one place — and revokes permissions for apps they no longer use, reducing their data footprint.

Empowering Individuals

Benefits for Data Principals

The Consent Manager fundamentally shifts the power dynamic in digital data relationships — placing control firmly in the hands of the individual rather than the organization.

Better Transparency

Individuals can see exactly who has their data and for what purpose.

Greater Control

A single dashboard to manage all consent across multiple organizations.

Simpler Withdrawal

Revoking consent is straightforward, without navigating complex portals.

Improved Confidence

Users feel more secure engaging with digital services knowing they retain control.

Benefits of consent management for individuals
Advantages for Organizations

Why Businesses Should Embrace the Consent Manager Ecosystem

Even organizations that are not themselves Consent Managers benefit significantly from operating within a well-functioning consent management ecosystem. The standardization and trust it creates reduces compliance risk and builds stronger customer relationships.

1. Standardized Consent Records

Consent obtained through a registered Consent Manager creates a reliable, auditable record — reducing disputes and simplifying regulatory compliance under the DPDP Act.

2. Stronger Customer Trust

Organizations that integrate with Consent Managers signal respect for user rights, building long-term loyalty and differentiated brand reputation.

3. Reduced Compliance Burden

Delegating consent tracking to a registered intermediary reduces the internal effort required to manage, document, and demonstrate valid consent.

4. Interoperable Privacy Infrastructure

As India's privacy ecosystem matures, organizations connected to Consent Manager platforms will be better positioned for future regulatory and technology changes.

Setting the Record Straight

Common Misconceptions About Consent Managers

❌ "Consent Managers own personal data"

Fact: A Consent Manager facilitates consent decisions. It does not collect, store, or own the underlying personal data being processed by Data Fiduciaries.

❌ "Every organization is a Consent Manager"

Fact: Only entities specifically registered with the Data Protection Board under prescribed norms can operate as Consent Managers.

❌ "It replaces our privacy obligations"

Fact: Organizations remain fully responsible for their own compliance. A Consent Manager does not substitute for organizational privacy policies, notices, or obligations.

❌ "It operates outside the legal framework"

Fact: Consent Managers operate strictly within the legal framework prescribed under the DPDP Act and regulations issued thereunder.

Consent Manager misconceptions illustration
The Bigger Picture

Why Every Organization Must Understand This Concept

Whether or not your organization plans to become a Consent Manager, the concept reshapes how consent governance, customer trust, and digital privacy operate across India's economy.

Future Privacy Ecosystem

Consent Managers will become core infrastructure in India's digital economy, much like UPI transformed payments.

Customer Trust at Scale

Organizations that respect and enable consent rights will earn a durable competitive advantage.

Better Consent Governance

Interoperable consent platforms set a new standard for how organizations collect, manage, and honor user permissions.

Digital Privacy Innovation

India's DPDP framework positions the country as a global leader in privacy-respecting digital innovation.

The broader consent management ecosystem
Wrapping Up

Key Takeaways

1. Individuals are empowered

The Consent Manager gives Data Principals a single, trusted platform to manage all their consent rights under the DPDP Act.

2. Consent must be transparent & usable

The Act's design philosophy demands that consent management be accessible, clear, and genuinely within the individual's control.

3. Organizations remain fully responsible

The existence of a Consent Manager does not reduce organizational obligations under the DPDP Act — compliance remains a shared responsibility.

4. Trust is the ultimate outcome

Effective, transparent consent management strengthens accountability, reduces disputes, and builds lasting trust between individuals and organizations.

A Consent Manager is not just a compliance tool — it is the foundation of a trust-first digital economy.
Consent Manager key takeaways
Coming Up Next in This Series

Section 4 – Grounds for Processing Personal Data

Lawful Bases Under the DPDP Act

The DPDP Act, 2023 sets out specific grounds on which personal data may lawfully be processed. The next session will explore each ground in detail — from consent-based processing to legitimate uses — and what organizations must do to ensure compliance.

Next: Session 4 · DPDP Act Series · Module 3 · Lawful ProcessingUpcoming lawful processing module
⚠️ Important Notice

Disclaimer

This presentation is intended solely for educational and professional awareness purposes. It provides a general overview of the subject matter discussed. While every effort has been made to ensure the accuracy of the information presented, the content should be read in conjunction with the applicable laws, rules, regulations, official guidance, and judicial developments. The application of law and professional practices may vary depending on the specific facts and circumstances of each case.

Disclaimer artwork