Consent Managers Under the DPDP Act Go Live in November 2026: What Indian SMEs Need to Do
Rule 4 of the DPDP Rules, 2025 brings registered Consent Managers into force in mid-November 2026. Here is what changes for ordinary businesses when customers start giving and withdrawing consent through a third party.
In about six weeks, a new kind of regulated company starts to exist in India. Rule 4 of the Digital Personal Data Protection Rules, 2025 comes into force one year after the Rules were notified, which puts it in mid-November 2026. From that point, anyone who wants to operate as a Consent Manager under the DPDP Act has to be registered with the Data Protection Board of India.
Most of the commentary so far has been written for companies that want to become Consent Managers. That is a small group. The bigger question for an ordinary SME or startup is simpler: what happens when your customers start showing up with a Consent Manager in the middle of the relationship? This post answers that.
What a Consent Manager actually is
The idea comes from Section 6 of the DPDP Act, 2023. Section 6(7) lets a Data Principal (your customer, employee, or user) give, manage, review and withdraw consent through a Consent Manager. Section 6(8) makes the Consent Manager accountable to that Data Principal, and Section 6(9) says it must be registered with the Board.
Think of it as one dashboard sitting between a person and the many businesses holding their data, instead of twelve "withdraw consent" buttons in twelve apps. The model borrows from India's Account Aggregator system in financial services, where RBI-licensed intermediaries move consent between banks, lenders and customers.
The Rules set a high bar for who can run one. Part A of the First Schedule requires the applicant to be a company incorporated in India, to have a net worth of at least ₹2 crore, and to show the technical, operational and financial capacity to do the job. Directors and senior management must have a record of fairness and integrity. Once registered, Part B obligations apply: the Consent Manager must not be able to read the personal data it helps move, must avoid conflicts of interest with the businesses it serves, and must keep records of consents given, reviewed and withdrawn for at least seven years.
Consent Managers under the DPDP Act: what changes for your business
If you are a Data Fiduciary (any business deciding why and how personal data is processed), you do not need to register as anything in November. Nobody is forcing you to sign up with a Consent Manager either. But three practical things change.
Consent can arrive from a third party. A customer may grant consent for your loyalty programme through a Consent Manager instead of ticking your checkbox. Your systems need to accept that consent as valid and tie it to the right customer record.
Withdrawal can arrive from a third party too. This is the part that catches teams out. Section 6(4) requires withdrawal to be as easy as giving consent, and Section 6(6) says that once consent is withdrawn you must stop processing within a reasonable time (along with your processors). If a withdrawal comes through a Consent Manager and lands in a shared inbox that nobody reads for nine days, your marketing automation keeps running on data you no longer have permission to use.
Your records will be compared with someone else's. The Consent Manager will keep its own seven-year log. If a customer complains, the Board will be able to see two versions of events: yours and the Consent Manager's. A business whose consent records are a spreadsheet export from 2024 will not look good in that comparison.
A note on the Board's readiness
There is an honest caveat here. MeitY published a notice in May 2026 inviting applications for the Chairperson and Members of the Data Protection Board, and commentators, including a widely shared LiveLaw piece, have questioned whether the Board will be fully staffed and able to process registrations on day one. Reports on the exact state of appointments conflict, so we will not guess.
What this means in practice is that the first registered Consent Managers may take some months to appear after November. That gives you breathing room. It does not change the direction of travel, and the core consent, notice and rights obligations still take full effect around 13 May 2027.
Five things to do before Consent Managers go live
A founder and one engineer can work through most of this in a few weeks.
-
Map where consent lives today. List every place you collect consent: signup forms, WhatsApp opt-ins, cookie banners, offline forms at a clinic reception. For each one, note where the record is stored and whether it captures what was consented to, when, and against which notice version.
-
Give every consent a stable ID. A Consent Manager integration (or even a manual email from one) is useless if you cannot match it to a specific consent record. If your CRM only stores "marketing_opt_in = true", add the purpose, timestamp and notice version.
-
Build one withdrawal pipeline. Whether withdrawal comes from your app, an email, a call centre or a Consent Manager, it should hit the same process and switch off the same downstream systems, including vendors. Our data processing agreement post covers how to make processors honour that switch.
-
Name an owner for third-party consent requests. Decide who picks up a request from a Consent Manager and what the internal turnaround is. A 48-hour internal target is a sensible starting point for most SMEs, well inside a "reasonable time".
-
Update your privacy notice. Rule 3 already requires your notice to tell people how to withdraw consent and how to complain to the Board. Add a line saying you will honour requests made through a registered Consent Manager. It costs nothing and signals that you are ready.
If you want a structured way to check these, our free DPDP compliance checklist walks through consent, notice and rights handling item by item.
Should your company become a Consent Manager?
Probably not. A Consent Manager that also sells analytics to the Data Fiduciaries it serves will struggle to meet Part B, and the ₹2 crore floor plus seven-year record-keeping make it a regulated business, not a feature you bolt on. For most SMEs, the smarter investment is being a good counterparty: clean consent records, fast withdrawals, and a notice that tells the truth.
The bottom line
Consent Managers are the first piece of the DPDP framework that puts an outside party in a position to watch how you handle consent. Even if registrations start slowly, the businesses that sort out their consent records now will spend less time scrambling later. If you would like help mapping your consent flows or reviewing your notices, our DPDP Act compliance team does exactly this for SMEs and startups.
This article is general guidance and not legal advice. For advice on your specific situation, please speak with a qualified professional. Start with our free DPDP checklist or get in touch with the Primitra team.
Get help implementing this
Turn this reading into a compliance plan.
Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.
Book a free 30-minute consultation