The Digital Personal Data Protection Act, 2023 (DPDP Act) introduces a new framework for protecting the digital personal data of individuals in India. One of the most significant features of this framework is the concept of a Consent Manager—an entity that enables individuals (Data Principals) to give, manage, review, and withdraw their consent for the processing of their personal data through an accessible, transparent, and interoperable platform.

To operationalise this framework, the Draft Digital Personal Data Protection Rules, 2025 prescribe detailed conditions that an entity must satisfy before it can be registered as a Consent Manager.

These conditions are set out in Part A of the First Schedule of the Draft Rules. They establish minimum standards relating to legal status, financial capacity, governance, technical capability, integrity, and operational readiness. The objective is to ensure that only competent, reliable, and accountable organizations are entrusted with managing the consent of Data Principals.

This article explains each condition prescribed under Part A of the First Schedule in detail.

What is a Consent Manager?

A Consent Manager is an independent entity registered under the DPDP framework that acts as a trusted intermediary between a Data Principal and a Data Fiduciary.

Its primary role is to provide a secure and interoperable platform through which individuals can:

  • Give consent for processing their personal data.
  • Review the consent they have already provided.
  • Modify or manage existing consent preferences.
  • Withdraw consent at any time.
  • Maintain greater control over how their personal data is processed.

A Consent Manager is expected to operate independently, transparently, and in the best interests of the Data Principal.

Conditions for Registration of a Consent Manager

The First Schedule – Part A of the Draft DPDP Rules, 2025 lays down the eligibility requirements for registration.

1. The Applicant Must Be a Company Incorporated in India

The Rules provide:

“The applicant is a company incorporated in India.”

Only a company incorporated under the applicable laws of India is eligible to apply for registration as a Consent Manager.

This requirement ensures that the entity is subject to Indian corporate laws, regulatory oversight, and legal accountability. Partnerships, sole proprietorships, trusts, or other forms of business organisations are not eligible unless they are incorporated as a company.

2. The Applicant Must Have Sufficient Technical, Operational and Financial Capacity

The Rules provide:

“The applicant has sufficient capacity, including technical, operational and financial capacity, to fulfil its obligations as a Consent Manager.”

A Consent Manager is expected to manage sensitive personal data and provide continuous digital services. Therefore, the applicant must demonstrate adequate resources to discharge its statutory responsibilities effectively.

This includes:

  • Appropriate technological infrastructure.
  • Reliable operational processes.
  • Skilled human resources.
  • Adequate financial resources.
  • Business continuity mechanisms.
  • Information security capabilities.

The objective is to ensure that the Consent Manager can provide uninterrupted, secure, and efficient services to Data Principals.

3. The Financial Condition and General Character of Management Must Be Sound

The Rules provide:

“The financial condition and the general character of management of the applicant are sound.”

The Government intends to register only organizations that demonstrate financial stability and responsible corporate governance.

This assessment may include:

  • Financial health of the company.
  • Corporate governance practices.
  • Regulatory compliance history.
  • Reputation in the market.
  • Quality of internal management.
  • Overall business stability.

A financially stable organization is more likely to maintain secure systems and provide long-term compliance support.

4. Minimum Net Worth Requirement of ₹2 Crore

The Rules provide:

“The net worth of the applicant is not less than two crore rupees.”

Every applicant must possess a minimum net worth of ₹2 crore.

This financial threshold demonstrates that the organization possesses sufficient capital to establish and maintain the technical infrastructure, cybersecurity measures, compliance framework, and operational capabilities necessary for performing the functions of a Consent Manager.

The minimum net worth requirement also serves as a safeguard against undercapitalised entities entering a highly sensitive regulatory ecosystem.

5. Adequate Business Prospects and Capital Structure

The Rules provide:

“The volume of business likely to be available to and the capital structure and earning prospects of the applicant are adequate.”

Registration is not based solely on existing financial strength.

The authorities may also evaluate:

  • Expected business volume.
  • Sustainability of operations.
  • Capital structure.
  • Revenue model.
  • Long-term financial viability.
  • Future earning prospects.

The objective is to ensure that the applicant can continue operating effectively while meeting ongoing compliance obligations.

6. Directors and Senior Management Must Have Integrity

The Rules provide:

“The directors, key managerial personnel and senior management of the applicant company are individuals with a general reputation and record of fairness and integrity.”

Leadership plays a critical role in protecting personal data.

Accordingly, the individuals responsible for managing the company should possess:

  • Professional competence.
  • Ethical conduct.
  • Integrity.
  • Fairness.
  • Good corporate reputation.
  • Responsible management practices.

This requirement helps promote public trust in the Consent Management ecosystem.

7. Constitutional Documents Must Incorporate Compliance Obligations

The Rules provide:

“The memorandum of association and articles of association of the applicant company contain provisions requiring that the obligations under items 9 and 10 of Part B are adhered to, that policies and procedures are in place to ensure such adherence, and that such provisions may be amended only with the previous approval of the Board.”

This is one of the most important governance requirements under the Rules.

The applicant’s Memorandum of Association (MoA) and Articles of Association (AoA) must specifically provide that:

  • The obligations contained in Items 9 and 10 of Part B will be complied with.
  • Appropriate internal policies and procedures exist to ensure compliance.
  • These constitutional provisions cannot be amended without obtaining prior approval from the Board.

Embedding these obligations within the company’s constitutional documents demonstrates a long-term institutional commitment to compliance and accountability.

8. Operations Must Be in the Interests of Data Principals

The Rules provide:

“The operations proposed to be undertaken by the applicant are in the interests of Data Principals.”

Every activity undertaken by a Consent Manager should prioritize the interests of the Data Principal.

The platform should therefore be designed to:

  • Promote transparency.
  • Enable informed decision-making.
  • Provide simple consent management.
  • Protect individual autonomy.
  • Prevent misuse of personal data.
  • Facilitate user-friendly access to consent records.

The Consent Manager should function as a trusted facilitator rather than merely as a technology provider.

9. Independent Certification of Platform and Security Measures

The Rules provide:

“It is independently certified that—

(a) the interoperable platform of the applicant to enable the Data Principal to give, manage, review and withdraw her consent is consistent with such data protection standards and assurance framework as may be published by the Board on its website from time to time; and

(b) appropriate technical and organisational measures are in place to ensure adherence to such standards and framework and effective observance of the obligations under item 11 of Part B.”

This is one of the most technically significant conditions prescribed under the Draft Rules.

The applicant must obtain an independent certification confirming that:

(a) Platform Compliance

The consent management platform should:

  • Be interoperable.
  • Allow individuals to give consent.
  • Enable users to review existing consent.
  • Allow consent to be modified.
  • Permit withdrawal of consent.
  • Comply with data protection standards issued by the Board.

Interoperability ensures that individuals can manage consent efficiently across multiple Data Fiduciaries through a consistent and reliable framework.

(b) Technical and Organisational Measures

The applicant must also demonstrate that appropriate technical and organisational safeguards have been implemented.

These may include:

  • Information security controls.
  • Encryption mechanisms.
  • Identity and access management.
  • Audit logging.
  • Secure software development practices.
  • Cybersecurity governance.
  • Risk management procedures.
  • Internal compliance frameworks.
  • Operational monitoring.
  • Incident response mechanisms.

These measures should ensure continued adherence to the applicable standards and effective compliance with the obligations prescribed under Item 11 of Part B.

Independent certification provides confidence that the Consent Manager’s systems meet the technical expectations of the regulatory framework.

Why These Conditions Matter

The role of a Consent Manager goes beyond providing software. It involves safeguarding one of the most fundamental rights under the DPDP framework—the right of individuals to control how their personal data is processed.

The eligibility conditions prescribed under the Draft Rules ensure that only organizations with:

  • Strong governance,
  • Financial stability,
  • Technical capability,
  • Operational readiness,
  • Ethical leadership, and
  • Robust security controls

are entrusted with this important responsibility.

These requirements collectively strengthen trust, accountability, transparency, and confidence in India’s emerging digital privacy ecosystem.

How Sam O Martin LLP Can Help

At Sam O Martin LLP, we assist organizations in understanding and implementing the requirements of the Digital Personal Data Protection Act, 2023 and the Draft DPDP Rules, 2025.

Our team of DPDP experts has hands-on experience in advising businesses on privacy governance, compliance frameworks, regulatory documentation, gap assessments, consent management processes, and data protection best practices.

Whether you are preparing to establish a Consent Management framework or strengthening your organization’s overall DPDP compliance programme, our practical and business-focused approach helps organizations navigate the evolving data protection landscape with confidence.