The Digital Personal Data Protection Act, 2023 (DPDP Act) establishes a rights-based framework for protecting the digital personal data of individuals in India. One of the key pillars of this framework is the Consent Manager, an independent entity that enables Data Principals to give, manage, review, and withdraw consent for the processing of their personal data.
While the First Schedule – Part A of the Draft Digital Personal Data Protection Rules, 2025 prescribes the eligibility conditions for registration as a Consent Manager, Part B of the First Schedule lays down the obligations that every registered Consent Manager must continuously fulfil.
These obligations are designed to ensure that Consent Managers operate with transparency, integrity, independence, security, and accountability. They also ensure that Data Principals remain in complete control of their personal data while using a Consent Management Platform.
This article explains each obligation prescribed under Part B of the First Schedule in detail.
What is the Role of a Consent Manager?
A Consent Manager is a registered entity that provides an interoperable platform through which a Data Principal can:
- Give consent for processing personal data.
- Review previously given consent.
- Manage consent preferences.
- Withdraw consent at any time.
- Monitor how personal data is shared with Data Fiduciaries.
The Consent Manager acts as a trusted intermediary and must always operate in the best interests of the Data Principal.
Obligations of a Consent Manager
1. Enable Data Principals to Give Consent through its Platform
The Rules provide:
“The Consent Manager shall enable a Data Principal using its platform to give consent to the processing of her personal data by a Data Fiduciary onboarded onto such platform either directly to such Data Fiduciary or through another Data Fiduciary onboarded onto such platform, who maintains such personal data with the consent of that Data Principal.”
A Consent Manager must provide a platform that allows individuals to provide consent digitally and conveniently.
Consent may be given:
- Directly to the Data Fiduciary requesting the information, or
- Through another onboarded Data Fiduciary that already holds the individual’s personal data.
This enables secure and interoperable sharing of personal data without requiring the Data Principal to repeatedly provide the same information.
Illustration provided in the Rules
The Rules explain this concept using the example of a Consent Management platform P, where an individual X is registered and two banks (B1 and B2) are onboarded.
Case 1:
B1 requests X’s consent to access her bank account statement. X stores her statement in a Digital Locker and, using platform P, directly grants consent to B1, which then receives access to the statement.
Case 2:
B1 again requests access to X’s bank account statement. However, this time the statement is maintained by B2. Using platform P, X routes her consent through B2 and digitally instructs B2 to share the bank account statement with B1. B2 then securely transfers the information to B1.
This illustration demonstrates how a Consent Manager enables secure, interoperable and user-controlled sharing of personal data across multiple Data Fiduciaries.
2. Personal Data Must Not Be Readable by the Consent Manager
The Rules provide:
“The Consent Manager shall ensure that the manner of making available the personal data or its sharing is such that the contents thereof are not readable by it.”
A Consent Manager facilitates the transfer of consent—not the processing of personal data.
Accordingly, the platform should be designed so that although it enables the sharing of data, the actual contents of the personal data remain inaccessible to the Consent Manager.
This principle significantly enhances privacy and ensures that the Consent Manager remains a neutral facilitator rather than becoming another processor of personal information.
3. Maintain Complete Consent Records
The Rules require the Consent Manager to maintain records of:
- Consents given.
- Consents denied.
- Consents withdrawn.
- Notices preceding or accompanying consent requests.
- Sharing of personal data with transferee Data Fiduciaries.
Maintaining accurate records creates transparency and allows Data Principals to verify how and when their consent has been used.
4. Provide Access to Consent Records
The Rules further provide that the Consent Manager:
- Shall give the Data Principal access to these records.
- Shall make such information available in a machine-readable format whenever requested and in accordance with its terms of service.
- Shall preserve these records for at least seven years, or for a longer period if agreed upon with the Data Principal or required by law.
This obligation promotes transparency and allows individuals to maintain a complete history of their consent decisions.
5. Maintain a Website or Mobile Application
The Rules provide:
“The Consent Manager shall develop and maintain a website or app, or both, as the primary means through which a Data Principal may access the services provided by the Consent Manager.”
Every Consent Manager must maintain an easily accessible digital platform.
The website or mobile application should enable users to:
- Register securely.
- View consent requests.
- Give or refuse consent.
- Withdraw existing consent.
- Review consent history.
- Access records maintained by the Consent Manager.
The platform should be user-friendly, secure, and continuously available.
6. No Outsourcing of Statutory Obligations
The Rules provide:
“The Consent Manager shall not sub-contract or assign the performance of any of its obligations under the Act and these rules.”
The legal responsibilities assigned to a Consent Manager cannot be delegated to another organization.
This requirement ensures accountability by preventing the transfer of core statutory functions to third parties.
7. Implement Reasonable Security Safeguards
The Rules provide:
“The Consent Manager shall take reasonable security safeguards to prevent personal data breach.”
Appropriate technical and organisational measures should be implemented to protect personal data against unauthorized access, disclosure, alteration, or destruction.
Such safeguards may include:
- Encryption
- Access controls
- Multi-factor authentication
- Security monitoring
- Incident response procedures
- Secure infrastructure
- Regular vulnerability assessments
Strong cybersecurity is essential for maintaining public confidence in the Consent Management ecosystem.
8. Act in a Fiduciary Capacity
The Rules provide:
“The Consent Manager shall act in a fiduciary capacity in relation to the Data Principal.”
A fiduciary relationship requires the Consent Manager to act honestly, fairly, and solely in the interests of the Data Principal.
This means that commercial interests should never override the privacy rights and interests of the individuals using the platform.
9. Avoid Conflicts of Interest with Data Fiduciaries
The Rules provide:
“The Consent Manager shall avoid conflict of interest with Data Fiduciaries, including in respect of their promoters and key managerial personnel.”
A Consent Manager must remain independent.
Its decisions should never be influenced by business relationships, ownership interests, or management connections with Data Fiduciaries.
Maintaining independence is critical to preserving public trust.
10. Prevent Conflicts Involving Directors and Senior Management
The Rules provide:
“The Consent Manager shall have in place measures to ensure that no conflict of interest arises on account of its directors, key managerial personnel and senior management holding a directorship, financial interest, employment or beneficial ownership in Data Fiduciaries, or having a material pecuniary relationship with them.”
The Rules extend conflict-of-interest safeguards to the leadership of the Consent Manager.
Appropriate governance mechanisms should ensure that directors and senior management remain independent and do not have relationships that could compromise impartiality.
11. Publish Transparency Information
The Rules require every Consent Manager to publish, in an easily accessible manner on its website or mobile application:
- Details of its promoters.
- Directors.
- Key managerial personnel.
- Senior management.
- Every shareholder holding more than 2% of its shareholding.
- Every body corporate in which its promoters, directors, KMPs or senior management hold more than 2% shareholding.
- Any additional information directed by the Data Protection Board.
These disclosure requirements promote corporate transparency and public accountability.
12. Establish Effective Audit Mechanisms
The Rules provide:
“The Consent Manager shall have in place effective audit mechanisms to review, monitor, evaluate and report the outcome of such audit to the Board…”
The audit framework should periodically examine:
- Technical controls.
- Organisational safeguards.
- Security systems.
- Internal procedures.
- Continued fulfilment of registration conditions.
- Compliance with the DPDP Act and Rules.
The results of these audits must be reported to the Board whenever required.
Regular audits help ensure continuous compliance and operational effectiveness.
13. Prior Approval Required for Transfer of Control
The Rules provide:
“The control of the company registered as the Consent Manager shall not be transferred by way of sale, merger or otherwise, except with the previous approval of the Board…”
A registered Consent Manager cannot transfer control of its business through:
- Sale
- Merger
- Acquisition
- Restructuring
- Any other transfer of control
without obtaining prior approval from the Data Protection Board and complying with any conditions imposed by the Board.
This safeguard ensures regulatory oversight over changes that could affect the independence or reliability of the Consent Manager.
Why These Obligations Matter
The obligations prescribed under the Draft DPDP Rules ensure that Consent Managers remain independent, transparent, technically secure, and fully accountable.
Together, these requirements aim to:
- Protect the privacy rights of Data Principals.
- Promote informed and meaningful consent.
- Ensure secure and interoperable data sharing.
- Prevent conflicts of interest.
- Strengthen governance and accountability.
- Build trust in India’s digital data protection ecosystem.
Compliance with these obligations is not merely a regulatory requirement—it is fundamental to maintaining confidence in the Consent Management framework envisioned under the DPDP Act.
How Sam O Martin LLP Can Help
At Sam O Martin LLP, we assist businesses, technology companies, financial institutions, and digital platforms in understanding and implementing the requirements of the Digital Personal Data Protection Act, 2023 and the Draft DPDP Rules, 2025.
Our team of DPDP experts has hands-on experience in advising organizations on Consent Management frameworks, privacy governance, regulatory compliance, policy drafting, gap assessments, audit readiness, and data protection best practices.
Whether you are preparing to register as a Consent Manager or strengthening your organization’s DPDP compliance programme, we provide practical, business-focused legal solutions tailored to your operational and regulatory requirements.
Recent Posts
- DPO as a Service in Delhi: Outsourced Data Protection Officer Services by Sam O Martin LLP
- How to Become DPDP Compliant in 2026: A Step-by-Step Guide for Businesses in India
- Data Protection Gap Analysis: The Complete Guide for Businesses in 2026
- GDPR Gap Analysis: Why Your Business Needs One and How Sam O Martin Law Firm Can Help
- Live-in Relationships & Section 498A: Supreme Court Extends Protection Against Cruelty