Does Your Business Need to Register as a DPDP Consent Manager?

Insights / Does Your Business Need to Register as a DPDP Consent Manager?

DPDP Consent Manager Framework India

India’s DPDP Consent Manager framework becomes operational on 13 November 2026, and a lot of the coverage leading up to that date makes the same mistake: treating “the framework is coming” and “your business needs to register as a Consent Manager” as the same thing. For the overwhelming majority of Indian businesses — ecommerce, SaaS, banks, hospitals, manufacturers — they are not the same thing at all. Knowing the difference is what actually matters here, more than any other single fact about this framework.

Does Your Business Need to Register as a Consent Manager?

India’s DPDP Consent Manager framework becomes operational on 13 November 2026. But there’s an important distinction that is getting lost in a lot of the discussion:

The Consent Manager framework applies to Consent Managers — not to every business that collects or processes personal data. For most Indian businesses including ecommerce companies, SaaS providers, banks, hospitals and manufacturers the question is not whether they need to register as a Consent Manager.

They don’t. The more important question is: Are your systems and consent practices ready to work with the Consent Manager ecosystem? That distinction is the starting point for understanding what the framework actually means for your business.

What Is a DPDP Consent Manager?

A Consent Manager is a specific regulated role under the DPDP Act.

It is not:

  • A general term for consent management software
  • A business that simply handles customer consent
  • Something every company becomes by collecting consent responsibly

Think of a Consent Manager as a consent broker.

It gives an individual one place to:

  • Give consent
  • Review consent
  • Manage consent
  • Withdraw consent

across multiple businesses.

Instead of managing consent separately with every company, the individual can manage it through one registered platform.

There is another important distinction.

A Consent Manager is accountable to the individual whose consent it manages, rather than to the businesses using it.

It is also specifically restricted from accessing the personal data being exchanged between the individual and those businesses.

Its role is to manage the consent record, not the underlying personal data.

When Does the Framework Take Effect?

WhatDetails
Legal basisSections 6(7) to 6(9) of the DPDP Act and Rule 4 of the DPDP Rules, 2025
Operational date13 November 2026
RegistrationConsent Manager registration formally opens on this date
RegulatorData Protection Board of India

The Data Protection Board can review applications, request additional information, publish the list of approved Consent Managers, direct corrective action and suspend a registration.

Who Actually Needs to Register?

The registration requirements are quite specific.

An applicant must: Be incorporated in India

Only an Indian private or public company, society or trust can apply.

Have sufficient financial capacity

A minimum net worth of ₹2 crore is required.

Have the required technical and operational capability

The applicant must demonstrate that it can operate a secure, interoperable consent platform.

It must also be able to maintain:

  • Audit processes
  • Governance
  • Grievance handling
  • Ongoing operational controls

This isn’t a one-time certification. It is an ongoing responsibility.

Are You a Consent Manager or a Data Fiduciary?

This is probably the most important distinction for most businesses. If your business sells products, provides services or processes customer data as part of its operations, you are most likely a Data Fiduciary under the DPDP Act. You are not automatically a Consent Manager.

Data FiduciaryConsent Manager
Determines why and how personal data is processedManages an individual's consent
Typically a business processing customer dataA specific regulated intermediary
Responsible for its own data-processing obligationsRequires registration
Most businesses fall into this categoryMost businesses will never need this registration

These are two different regulated roles with different obligations.

What Happens If an Entity Operates Without Registration?

The penalty here is important — but it needs to be understood correctly. It applies specifically to an entity that is operating as a Consent Manager without being registered.

It is not a general DPDP penalty that automatically applies to every business. After 13 November 2026, operating as a Consent Manager without registration would violate Section 6(9) of the Act and can carry penalties of up to ₹50 crore per instance under the Act’s residual penalty tier.

So again, the key question is: Are you actually operating in the Consent Manager role?

If not, this particular registration requirement does not apply to you.

DPDP Consent Manager Framework For India

What Should Ordinary Businesses Do?

If your business doesn’t need to register as a Consent Manager, don’t spend your time preparing a registration application. Instead, prepare for the Consent Manager ecosystem.

Your business should be able to recognise and respond when a customer changes their consent through a registered Consent Manager. There are four areas to focus on.

1. Make consent clear and explicit

Consent should be:

  • Purpose-specific
  • Clearly recorded
  • Easy to understand

Avoid relying on blanket consent for multiple unrelated purposes.

2. Make your systems integration-ready

Your systems should be able to recognise and honour a consent change coming through a registered Consent Manager; not just changes made through your own channels.

3. Establish clear ownership

Someone within the organisation should be responsible for tracking how the framework develops and what it means for your specific data practices.

The rules are being implemented in phases, so this shouldn’t be treated as a one-off compliance exercise.

4. Maintain a proper audit trail

You should be able to demonstrate:

  • When consent was given
  • What it covered
  • When it was changed
  • When it was withdrawn

Don’t just rely on being able to say that consent was captured. It is important to be able to show that consent was captured.

Where Worktual Fits

Worktual is not a Consent Manager and does not need to register as one.

Like most businesses affected by the framework, Worktual’s role is as a data processor supporting its customers’ DPDP compliance, rather than as the regulated consent-broker role defined by the Act.

Worktual’s platform supports explicit, purpose-limited consent capture at the point of collection. Its data is hosted on Oracle Cloud in line with standard data policies and security guardrails.

This provides the groundwork needed for systems to recognise and honour a consent change coming through a registered Consent Manager once that ecosystem becomes operational.

What the 13 November 2026 Deadline Actually Means

The Consent Manager framework is real, and 13 November 2026 is an important date.

But for most businesses, it does not mean: “We need to register as a Consent Manager.”

It means: “We need to make sure our consent practices and systems are ready for customers who may manage their consent through a registered Consent Manager.”

For this the basics must be aligned: Clear consent → Proper records → Integration readiness → Auditability

The first step is simply understanding which role your business actually falls into. For most organisations, that is Data Fiduciary — not Consent Manager.

Frequently Asked Questions

1. Does my business need to register as a DPDP Consent Manager?

Probably not. Consent Manager is a specific regulated role under the DPDP Act. Applicants must be incorporated in India, have a minimum net worth of ₹2 crore and meet ongoing technical, operational and governance requirements. Most businesses are Data Fiduciaries instead.

2. What does a Consent Manager actually do?

A Consent Manager acts as a consent broker. It provides individuals with one place to give, review, manage or withdraw consent across multiple businesses. It manages the consent record but cannot access the personal data itself.

3. When does the DPDP Consent Manager framework become operational?

The framework becomes operational on 13 November 2026, when Rule 4 of the DPDP Rules, 2025 comes into force and Consent Manager registration formally opens with the Data Protection Board of India.

4. What is the penalty for operating as an unregistered Consent Manager?

An entity operating as a Consent Manager without registration can face penalties of up to ₹50 crore per instance under Section 6(9) of the DPDP Act. This applies specifically to entities operating in the Consent Manager role, not to businesses generally.

5. What should a typical business do to prepare for the DPDP Consent Manager framework?

Most businesses should focus on explicit and purpose-limited consent, integration readiness, clear internal ownership and a demonstrable audit trail rather than registration.

6. What is the difference between a Consent Manager and a Data Fiduciary?

A Data Fiduciary determines the purpose and means of processing personal data. A Consent Manager is a separate regulated intermediary that manages an individual’s consent across businesses. Most companies fall into the Data Fiduciary category rather than the Consent Manager category.

Related Posts

AI Vendor Feature vs Infrastructure India

Feature or Infrastructure? How to Tell If an AI Customer Service Vendor Actually Owns the Outcome

Financial institutions operate in a highly competitive, regulation-driven, and margin-sensitive environment where revenue growth is no longer driven by acquisition alone. Banks, fintechs, and Non-Banking Financial Companies (NBFCs) continue to invest heavily in digital acquisition, yet face persistent challenges such as low onboarding completion, rising contact centre costs, increasing churn, and fragmented customer data. At the same time, customers expect instant responses, seamless onboarding, personalised financial guidance, and consistent service across digital and assisted channels. When these expectations are not met, conversion drops, churn increases, and cost-to-serve rises, often before the impact is fully visible in performance metrics.

Conversational Ai Loan Status India

How Conversational AI Checks Loan and Disbursement Status in Real Time and When It Still Hands Off to a Human

A loan applicant hears nothing for five days. Unsure whether the application is delayed or simply being processed, she calls customer support—not because something went wrong, but because nobody told her everything was progressing as expected.

Proactive Customer Care India

From Reactive Support to Proactive Care: What Scaling Enterprises in India Need to Rethink

A loan applicant hears nothing for five days. Unsure whether the application is delayed or simply being processed, she calls customer support—not because something went wrong, but because nobody told her everything was progressing as expected.