AMLEGALS — Strategic Lawyering
Rule 4 — India's Only Licensed Privacy Intermediary

DPDPA for Consent Managers

Rule 4 creates the only registered intermediary in Indian data protection law. Every other privacy vendor sells software. A Consent Manager holds a registration, owes a fiduciary duty, and answers to the Data Protection Board.

Rule 4 RegistrationFirst Schedule Part APart B ObligationsNet Worth ₹2 CroreCommences 13 Nov 2026

A consent management platform is a product. A Consent Manager is a regulated person. The difference is a registration, a fiduciary duty and a Board that can cancel both.

The Position in One Paragraph

What Rule 4 actually creates

Section 2(g) of the Digital Personal Data Protection Act, 2023 defines a Consent Manager as a person registered with the Data Protection Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.

Rule 4 of the DPDP Rules, 2025 operationalises that definition. Part A of the First Schedule sets the conditions of eligibility. Part B sets the obligations that attach on registration. The Board may inquire into an application, register it, or reject it with reasons.

Rule 4 commences on 13 November 2026. The substantive obligations of Data Fiduciaries commence on 13 May 2027. Registration therefore opens roughly six months before the demand it serves becomes compulsory, and that gap is the entire commercial opportunity.

No entity is a Consent Manager today. Every claim to the contrary is a claim about a product, not about a status.

First Schedule, Part A

The Six Conditions of Eligibility

Incorporation

The applicant must be a company incorporated in India. A foreign entity cannot apply directly and must establish an Indian company with its own governance.

First Schedule, Part A

Net Worth

Net worth of not less than two crore rupees. This is a capitalisation filter, not a fee, and it must be demonstrable on audited financials at the date of application.

First Schedule, Part A

Capacity

Sufficient technical, operational and financial capacity to discharge the functions of a Consent Manager. Capacity is proved by architecture and staffing, not by a statement of intent.

First Schedule, Part A

Character of Management

Sound financial condition and general character of management. Directors, key managerial personnel and senior management must carry a general reputation and record of fairness and integrity.

First Schedule, Part A

Business Prospects

The volume of business likely to be available, the capital structure and the earning prospects of the applicant must be adequate. The Board is entitled to test the business model, not merely the balance sheet.

First Schedule, Part A

Conflict of Interest

The memorandum and articles of association must contain provisions preventing conflict of interest, amendable only with the approval of the Data Protection Board. This is the single most underestimated condition in the Schedule.

First Schedule, Part A
First Schedule, Part B

What Attaches on Registration

Operating Obligations

Effective 13 November 2026
  • Enable a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform
  • Ensure that personal data shared through the platform remains unreadable to the Consent Manager
  • Maintain records of consent given, denied and withdrawn, and of every sharing of personal data through the platform
  • Retain those records for seven years, unless the Data Principal requires otherwise or a longer period is required by law
  • Make records available to the Data Principal in a machine readable form and to the Data Protection Board on demand
  • Observe the technical and organisational measures and the interoperability standards published by the Board
  • Act in a fiduciary capacity in relation to the Data Principal, and not in the commercial interest of any Data Fiduciary
  • Report control changes, and comply with directions issued by the Board after an opportunity of being heard

Read Rule 4 with Part A and Part B of the First Schedule to the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 by G.S.R. 846(E).

The Condition Most Applicants Will Fail

The Conflict of Interest Problem

Most companies preparing to apply already sell something else. A consent banner. An identity stack. An analytics product. A lending journey. Each of those businesses earns money from the flow of personal data.

Part A requires the constitutional documents to contain provisions preventing conflict of interest, and those provisions may be amended only with the approval of the Data Protection Board. Part B requires the Consent Manager to act in a fiduciary capacity toward the Data Principal.

Those two requirements read together do something the market has not yet absorbed. They put the Data Principal ahead of the customer who pays the invoice.

A registration that cannot survive that test is worse than no registration. It is a public record of a conflict.

Engagement Architecture

How AMLEGALS Takes an Applicant to Registration

Workstream 01

Structural Eligibility Opinion

A reasoned opinion on whether the entity as currently constituted can qualify under Part A, and what must change. Corporate structure, shareholding, net worth position, and the conflict of interest problem created by any existing fiduciary or processor business.

Workstream 02

Constitutional Documents

Drafting the conflict of interest provisions in the memorandum and articles. These provisions are locked once registration issues. They can be amended only with Board approval, so they must be drafted to survive a decade, not a funding round.

Workstream 03

Platform Legal Specification

Translating Part B into a build specification the engineering team can implement. Consent artefact design, withdrawal parity, unreadability of shared data, the seven year record, machine readable export, and audit logging that will satisfy a Board inspection.

Workstream 04

Fiduciary Governance

Board composition, independence, the fit and proper record of key managerial personnel, the non discrimination policy across Data Fiduciaries, and a published pricing model that cannot be read as consent monetisation.

Workstream 05

Application and Board Correspondence

Preparation and filing of the application, response to inquiries raised by the Board under Rule 4(2), and representation where an application is rejected and the reasons must be answered.

Workstream 06

Post Registration Supervision

Standing counsel for the supervised phase. Rule 4(4) allows the Board to direct remedial measures after a hearing. Suspension and cancellation follow persistent non adherence. Registration is the beginning of the obligation, not the end of it.

Statutory Clock

Dates That Are Not Negotiable

11 August 2023Presidential Assent to the Digital Personal Data Protection Act, 2023.
13 November 2025DPDP Rules, 2025 notified by G.S.R. 846(E). Institutional provisions commence.
13 November 2026Rule 4 commences. Registration of Consent Managers becomes operative.
13 May 2027Substantive obligations of Data Fiduciaries commence, including notice, consent, breach reporting, children's data, Significant Data Fiduciary duties, rights and cross border transfers.

Advisory for Consent Manager Applicants

Registration under Rule 4 is a regulatory application, not a product launch. AMLEGALS advises applicants on eligibility, constitutional documents, platform obligations and correspondence with the Data Protection Board.

Request a Confidential Briefing

Our data privacy counsel will reach out within one working day.

Insights & Answers

What applicants and boards are asking

Who is a Consent Manager under DPDPA?

Section 2(g) of the Act defines a Consent Manager as a person registered with the Data Protection Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. Rule 4 of the DPDP Rules, 2025 governs registration. Part A of the First Schedule sets eligibility and Part B sets operating obligations. Rule 4 commences on 13 November 2026.

What is the minimum net worth for Consent Manager registration in India?

Part A of the First Schedule requires net worth of not less than two crore rupees. The applicant must also be incorporated in India, demonstrate sufficient technical, operational and financial capacity, hold a sound financial condition and general character of management, and its directors, key managerial personnel and senior management must carry a record of fairness and integrity.

Can a Data Fiduciary also register as a Consent Manager?

Not without restructuring. The First Schedule requires conflict of interest provisions in the constitutional documents, amendable only with Board approval, and a Consent Manager must act in a fiduciary capacity toward the Data Principal. An entity that monetises the same personal data on the other side of the transaction carries a structural conflict. In practice this is resolved through a separate legal entity with independent governance and a documented separation of systems.

When does the Consent Manager framework commence?

The DPDP Rules, 2025 were notified on 13 November 2025 by G.S.R. 846(E) with phased commencement. The institutional provisions commenced on notification. Rule 4 commences on 13 November 2026. The substantive obligations of Data Fiduciaries commence on 13 May 2027. The registration window therefore opens before the market it serves becomes compulsory.

How long must a Consent Manager retain consent records?

Part B of the First Schedule requires retention of consent and sharing records for seven years, unless the Data Principal requires otherwise or a law requires longer. The same Part requires that personal data shared through the platform remains unreadable to the Consent Manager, which makes the record architecture a design problem rather than a storage problem.

Is a Consent Manager the same as an Account Aggregator?

No. An Account Aggregator is a non banking financial company registered with the Reserve Bank of India under the 2016 Master Direction and confined to financial information. A Consent Manager is registered with the Data Protection Board under Rule 4 and is not confined to any sector. The two regimes use different consent constructs, different regulators and different registration tests. Holding one registration confers nothing under the other.

What happens if a registered Consent Manager fails its obligations?

Under Rule 4(4) the Board may, after giving an opportunity of being heard, inform the Consent Manager of non adherence and direct remedial measures. Continued non adherence exposes the entity to suspension or cancellation of registration and to penalty proceedings under Section 33 read with the Schedule to the Act, where the ceiling is determined by the Board on the factors in Section 33(2).

Do you advise Consent Managers on interoperability standards?

Yes. Part B requires the platform to observe the standards published by the Board. Interoperability is a legal obligation with an engineering surface. We advise on the specification, on the contractual position with Data Fiduciaries who onboard to the platform, and on the liability allocation when a consent artefact is disputed.