Consent Manager Framework Goes Live: What Businesses Need to do Before November 2026

POSTED ON JULY 27, 2026 BY DATA SECURE
AUTHOR NAME: Haider M, Intern
breach

Introduction

The DPDP Rules, 2025 were notified on November 14, 2025. Two years of not-quite-knowing when the Act would actually bite finally ended. Since then, most of the compliance conversation in India has gone where you would expect notice language, breach timelines, what qualifies an entity as a Significant Data Fiduciary. One piece of the framework has stayed largely off the agenda, mostly because its effective date sits further down the phased rollout than the rest: the Consent Manager.

That is about to stop being true. November 13, 2026, is the date by which the process for registering Consent Managers has to be operational, twelve months out from notification. And there are already signs that the groundwork, technical specifications, possibly a sandbox, will show up well before that date, not on it. An organization that is still treating this as a 2027 problem is going to find the ecosystem already running by the time it starts paying attention.

What follows covers what a Consent Manager actually is, what the timeline really commits the government to, and more to the point, what it means for the far larger set of organizations that will never register as one but will have to work with them anyway.

What a Consent Manager Actually Does

The DPDP Act, at Section 2(g), defines a Consent Manager as a person registered with the Data Protection Board “who acts as a single point of contact through which a Data Principal can give, manage, review, and withdraw consent, across every organization holding it, from one interoperable platform”. Strip out the statutory language and it is a fairly simple idea: one dashboard where a person can see everyone currently holding their data and switch any of it off without hunting through a dozen separate privacy centres.

None of this is being invented from scratch. It leans on the same logic as the Reserve Bank's Account Aggregator system, which has been doing roughly the same job for financial data for nearly a decade now, an independent intermediary sitting between the individual and whoever holds their data, instead of every bank and lender building its own consent screen.

A point worth being precise about: Section 6(7) does not make the Consent Manager mandatory. A Data Principal can still hand consent straight to a Data Fiduciary through an ordinary web form, and most will probably keep doing exactly that for a while. What changes is that a second route now exists, and once Consent Managers are live, some users are likely to prefer it.

Two more provisions are worth flagging. Under Section 6(8), the Consent Manager answers to the Data Principal, not to the business whose consent it is delivering, which means it has to act against the Fiduciary's interest if that is what the individual wants. Under Section 6(9), it cannot operate at all until it is registered with the Board, and that registration comes with real conditions attached, not a rubber stamp.

The Timeline: From Notification to Registration

breach

The rollout happens in three stages. Stage one took effect the day the Rules were notified, November 13, 2025, when the Data Protection Board of India came into existence. Stage two is what this article is really about: Consent Manager registration has to be up and running twelve months later, by November 13, 2026. Stage three, full compliance across every substantive obligation in the Act, lands eighteen months out, on May 13, 2027.

Written out like that, November 2026 looks comfortably far off. It probably is not, and here is why. Coverage of the government's own compliance calendar points to the Consent Manager framework being operationalized somewhere between June and August 2026, well ahead of the formal deadline, while the interoperability standards get built out. MeitY was already circulating a Business Requirement Document on consent management systems back in June 2025, before the Rules themselves were even notified. Read together, these two facts suggest the technical side of this is further along than the headline date would have you believe.

Which leaves a fairly blunt takeaway: if your organization is waiting for an official circular before it looks at its consent architecture, it is probably going to be looking at it after the fact.

What the Rules Require of a Registered Consent Manager

breach

Rule 4 and the First Schedule spell out who is actually allowed to become a Consent Manager, and it is not a low bar. The applicant has to be a company incorporated in India, carry a minimum net worth of two crore rupees, and be able to show it has the technical, operational, and financial legs to run a secure platform that stays up. Consent records have to be kept for at least seven years from the date consent was given or pulled, whichever comes later. The framework also seeks to preserve the independence of Consent Managers by requiring them to avoid conflicts of interest with Data Fiduciaries and implement governance measures to prevent such conflicts.

Almost none of the organizations reading this will ever apply to become a Consent Manager. That is not really the point. What matters is knowing who you will eventually be integrating with, and for what that party is legally on the hook. Skip the First Schedule and you will not know what questions to ask when one of these platforms comes knocking about integration.

Where This Leaves Data Fiduciaries

The provisions were written with the Data Principal in mind, as they should be, but the actual compliance workload falls on the Data Fiduciary. Once Consent Managers start operating, a Fiduciary has to be able to take a valid consent or withdrawal coming from a platform it does not run and give it exactly the same weight as consent collected on its own site. Four things fall out of that, and none of them are optional extras.

Start with the systems question. Most consent management tools deployed in India were built to record consent collected on the organization's own properties. Very few can currently ingest a signal from an outside, Board-registered platform without some manual patch job. Building that integration layer now costs a lot less than bolting it on after the fact.

Section 6(10) adds an important accountability dimension: the burden of proving valid notice and consent always rests with the Data Fiduciary, even where consent is routed through a Consent Manager. The Consent Manager's records may support that process, but they do not transfer the Data Fiduciary's statutory responsibility to demonstrate compliance.

There is a processing angle too. Section 6(6) already requires a Fiduciary to stop processing, and tell its processors to stop as well, within a reasonable time of withdrawal, regardless of where that withdrawal came from. A withdrawal that arrives through a Consent Manager does not get to sit lower in the queue than one submitted directly on the app.

And finally, grievance redressal under Section 13 covers this relationship too. If a Data Principal is unhappy with how a Fiduciary handled something routed through a Consent Manager, the same escalation path to the Board is available to them as in any other case.

The Readiness Gap: What Most Organizations Are Missing

breach

Most privacy and legal teams have at least heard the term Consent Manager by now. Considerably fewer have sat down and worked out what it actually does to their own systems. The gap between the two tends to show up in the same few places.

No plan for signals coming from outside

Consent platforms bought over the last two years were largely procured to solve one problem: recording consent given directly on the organization's own site or app. Almost none were bought with a requirement that they also accept, verify, and log an instruction arriving from an external, Board-registered intermediary. Retrofitting that once Consent Managers are already live and running is a much bigger job than building it in at the design stage, which is roughly the stage most organizations are still at.

Two ledgers, one truth, no reconciliation

Once real volume starts moving through Consent Managers, an organization's own consent register and the Consent Manager's records have to line up, or the Section 6(10) burden of proof becomes very hard to discharge. Very few teams have actually sat down and mapped out what that reconciliation process looks like in practice, let alone run it once.

Vendor contracts that never saw this coming

A lot of the Data Processing Agreements currently in place with consent management vendors were signed before the Consent Manager provisions had any real timeline attached to them. Ask most of these contracts what the vendor's roadmap for interoperability looks like, and you will get silence. That silence becomes the Data Fiduciary's problem the moment a Board-registered Consent Manager comes asking for integration and the vendor is not ready.

Watching the law, not the rollout

Legal and compliance teams are, reasonably, focused on the Act and the Rules as legal text. Fewer of them are tracking MeitY and Board communications for the technical standards, sandbox windows, or early registration notices that are likely to show up before the formal date. That is exactly the kind of signal worth acting on months ahead, not weeks.

Way Forward

A few things worth doing now rather than in October 2026:

  • Audit the consent management system for whether it can accept and log an instruction from a third-party, Board-registered Consent Manager, not just consent collected directly.
  • Check that Records of Processing Activities and internal consent registers can absorb Consent Manager-sourced records without leaving gaps in the Section 6(10) evidentiary trail.
  • Go back to the CMS vendor contract and ask, in writing, what the integration roadmap for Consent Manager interoperability actually is.
  • Make sure withdrawal-processing workflows treat a Consent Manager-routed withdrawal exactly as urgently as one submitted directly, cascading to processors the same way.
  • Put someone specific in charge of tracking MeitY and Board communications on Consent Manager standards through the rest of 2026.
  • Brief legal, IT, and whoever sits closest to the customer on what a Consent Manager is before the framework goes live rather than after.

Conclusion

November 2026 is the date on paper. The organizations that come out ahead will be the ones that stopped treating it as distant sometime around mid-2026, back when the technical groundwork was still being laid and not yet finished.

None of this asks a Data Fiduciary to do anything conceptually new. Taking a valid instruction about someone's own data seriously, and acting on it fast, is what the DPDP Act has asked for since day one. What is different now is the door that instruction can walk in through, and whether anyone built the system to notice it arriving.

We at Data Secure (Data Privacy Automation Solution) DATA SECURE - Data Privacy Automation Solution  can help you to understand Privacy and Trust while lawfully processing the personal data and provide Privacy Training and Awareness sessions in order to increase the privacy quotient of the organisation.

We can design and implement RoPA, DPIA and PIA assessments for meeting compliance and mitigating risks as per the requirement of legal and regulatory frameworks on privacy regulations across the globe especially conforming to GDPR, UK DPA 2018, CCPA, India Digital Personal Data Protection Act 2023. For more details, kindly visit DPO India – Your outsourced DPO Partner in 2025 (dpo-india.com).

For any demo/presentation of solutions on Data Privacy and Privacy Management as per EU GDPR, CCPA, CPRA or India DPDP Act 2023 and Secure Email transmission, kindly write to us at info@datasecure.ind.in or dpo@dpo-india.com.

For downloading the various Global Privacy Laws kindly visit the Resources page of DPO India - Your Outsourced DPO Partner in 2025

We serve as a comprehensive resource on the Digital Personal Data Protection Act, 2023 (Digital Personal Data Protection Act 2023 & Draft DPDP Rules 2025), India's landmark legislation on digital personal data protection. It provides access to the full text of the Act, the Draft DPDP Rules 2025, and detailed breakdowns of each chapter, covering topics such as data fiduciary obligations, rights of data principals, and the establishment of the Data Protection Board of India. For more details, kindly visit DPDP Act 2023 – Digital Personal Data Protection Act 2023 & Draft DPDP Rules 2025

We provide in-depth solutions and content on AI Risk Assessment and compliance, privacy regulations, and emerging industry trends. Our goal is to establish a credible platform that keeps businesses and professionals informed while also paving the way for future services in AI and privacy assessments. To Know More, Kindly Visit – Your Trusted Partner in AI Risk Assessment and Privacy Compliance | AI-Nexus