Sekurzen Logo
DPDP chapter2 / 14

Chapter 2: Registration of Consent Managers

Requirements and procedures for consent manager registration

chapter · 2 min read · Updated 14-Feb-2026 · 2 of 14

Executive Summary

  • "Consent Managers" are a new type of entity, like a 'digital wallet' for your privacy permissions. They act as a bridge between you and companies, allowing you to manage all your consents in one dashboard.

Institutional Impact

  • Know the boundary: Rule 4 and the First Schedule regulate registered Consent Managers; they do not automatically make every Data Fiduciary a Consent Manager.
  • Integration planning: If your service participates in a Consent Manager ecosystem, define how onboarding, consent requests, withdrawal, identity, and audit evidence will work.

Data Principal Rights

  • Consent management: A Data Principal may use a registered Consent Manager to give, manage, review, or withdraw consent.
  • Accountability: Consent Managers are registered by the Board and must follow the obligations in the First Schedule.

Practical application

What this looks like in practice

Use these examples to distinguish a defensible process from a common mistake.

Right

  • A participating service validates Consent Manager interactions and preserves a reliable record of consent and withdrawal events.

Incorrect

  • ×An organization presents itself as a registered Consent Manager without registration or ignores the First Schedule obligations.

Official Reference & Scope

  • Section 6(9): Consent Manager framework
  • Rule 4 and First Schedule: Registration and obligations of Consent Managers

Establishes the framework for registration and operation of Consent Managers under the DPDP Act.

  • Registration process: Application requirements and documentation
  • Eligibility criteria: Technical and organizational requirements
  • Obligations: Responsibilities of registered Consent Managers
  • Interoperability: Standards for consent management platforms

The First Schedule also addresses independence, conflicts of interest, record access, retention, security safeguards, transparency, audits, and changes of control.

Primary sources: DPDP Act, 2023 and rule 4 with the First Schedule.