We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

DPDP Rules 2025 · Rule 4 commences 13 November 2026

DPDP Consent Manager registration readiness

Rule 4 of the DPDP Rules, 2025 creates a registered entity class — the Consent Manager — and comes into force on 13 November 2026. A Consent Manager is registered with the Data Protection Board and is the single point through which a Data Principal gives, manages, reviews and withdraws consent. Registration is conditional: incorporation in India, a minimum net worth of INR 2 crore, demonstrable technical and operational capacity, and a fitness test on management. We assess whether your organisation is eligible at all, then what registration readiness actually requires.

Check your eligibility →Book a 20-minute call
Read this first

The conflict rule disqualifies many obvious candidates

Part B of the First Schedule bars a Consent Manager from acting as Data Fiduciary or Data Processor for the same Data Principal whose consent it manages. In practice that means a platform cannot register to manage consent for its own customers.

This is the first question worth answering, because it determines whether registration readiness is a project you can pursue at all. We would rather tell you the answer is no in a twenty-minute call than sell you a readiness programme you cannot use.

Who this is for

Who would register

Entities intending to operate a neutral consent platform serving multiple Data Fiduciaries — account aggregator-adjacent operators, identity and consent infrastructure providers, and industry utilities — rather than organisations seeking to manage consent for their own user base.

Eligibility

What Part A requires

Indian entity
Incorporation in India, with a constitution consistent with operating as a Consent Manager.
Net worth
A minimum of INR 2 crore, adjusted for inflation — evidenced, and sustainable rather than met once.
Capacity
Sufficient technical, operational and financial capacity, and sound financial condition and character of management.
Obligations

What Part B requires once registered

Fiduciary and data-blind
Act in a fiduciary capacity toward the Data Principal, and route personal data in a form the Consent Manager cannot itself read.
Neutrality
Treat all Data Fiduciaries alike, without preferential access or terms.
Records
Retain consent records for at least seven years, producible on request.
What we do

How we help

Eligibility opinion
A direct answer on the conflict rule, entity structure and net worth position before any build work is scoped.
Readiness assessment
Platform, security, interoperability, record-keeping and governance against the First Schedule.
Evidence pack
The documentation an application would need, assembled and reviewed.
Being honest

What is not settled yet

Rule 4 commences on 13 November 2026 and the Board’s operational detail is still emerging. Anyone claiming a guaranteed registration outcome, or a fixed process the regulator has not published, is guessing.

What can be done now is establish eligibility, close capacity gaps that take months rather than weeks, and have the evidence ready when the process opens.

Proof

See how we’ve done it before

Relevant case study
Our DPDP work spans readiness, DPIA and consent architecture across regulated sectors. Read case studies →
Redacted sample deliverable
See how we document findings. Request a redacted sample →

Not sure where you stand on DPDP readiness?

Get a free DPDP readiness scope and readiness review — share your work email and a senior consultant maps your gaps and next steps. No obligation.

Drawn from the CyberSigma Compliance Registry (updated 11 August 2026). Every statement below is checked against the issuing body’s own publication, with the date it was last verified.

  • Consent and notice (Sections 5-6)

    Under Section 6 of the DPDP Act 2023, consent to process personal data must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the personal data necessary for the specified purpose. A Data Principal may withdraw consent at any time, and withdrawing it must be as easy as giving it. Under Section 5, every request for consent must be accompanied or preceded by a notice, in clear and plain language, that gives an itemised description of the personal data and the purpose of processing, the manner in which the Data Principal may exercise their rights and withdraw consent, and the manner of making a complaint to the Data Protection Board.

  • Personal data breach notification (DPDP Rules 2025, Rule 7)

    On becoming aware of a personal data breach, a Data Fiduciary must, without delay, intimate each affected Data Principal in a concise, plain-language notice describing the breach, its likely consequences, the mitigation measures the Data Fiduciary has taken, the safety measures the Data Principal can take, and contact details for queries. It must also intimate the Data Protection Board of India without delay with the initial facts (nature, extent, timing, location and likely impact), followed by a detailed report - including broad facts, causes, mitigation and the notifications made to Data Principals - within 72 hours of becoming aware, or a longer period the Board allows on request.

  • Rights of the Data Principal (Sections 11-14)

    Chapter III of the DPDP Act 2023 grants every Data Principal four rights against a Data Fiduciary: the right to access information about the personal data being processed and the identities of other fiduciaries with whom it has been shared (Section 11); the right to correction, completion, updating and erasure of personal data (Section 12); the right of grievance redressal through the Data Fiduciary's or Consent Manager's mechanism, exercisable before approaching the Data Protection Board (Section 13); and the right to nominate another individual to exercise these rights in the event of the Data Principal's death or incapacity (Section 14). Section 15 sets out corresponding duties of the Data Principal.

  • Children's personal data (Section 9)

    Under Section 9 of the DPDP Act 2023, a 'child' is a person who has not completed 18 years of age. Before processing a child's personal data (or that of a person with a disability who has a lawful guardian), a Data Fiduciary must obtain verifiable consent of the parent or lawful guardian. A Data Fiduciary must not undertake processing likely to cause a detrimental effect on the well-being of a child, and must not carry out tracking, behavioural monitoring, or targeted advertising directed at children. The Central Government may exempt notified classes of Data Fiduciary, or notified purposes, from some of these conditions.

  • Significant Data Fiduciary (Section 10)

    Under Section 10 of the DPDP Act 2023, the Central Government may notify any Data Fiduciary or class of Data Fiduciaries as a Significant Data Fiduciary (SDF), based on factors including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential effect on the sovereignty and integrity of India, risk to electoral democracy, and security of the State and public order. An SDF must: appoint a Data Protection Officer based in India who represents it under the Act and is the point of contact for grievance redressal; appoint an independent data auditor to evaluate compliance; and undertake periodic Data Protection Impact Assessments, periodic audits, and such other measures as may be prescribed.

  • EnactmentEffective 11 August 2023

    Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023); Presidential assent 11 August 2023; Gazette ID CG-DL-E-12082023-248045.

    Official Gazette text (MeitY PDF) · verified 31 July 2026
  • DPDP Rules 2025 notificationEffective 13 November 2025

    Digital Personal Data Protection Rules, 2025 notified 13 November 2025 as G.S.R. 843(E), Gazette of India Extraordinary Part II s.3(i).

    Gazette date corroborated across multiple law-firm analyses; the PIB document filename carries the press-release date (17 Nov), not the notification date.

    MeitY / PIB — DPDP Rules 2025 · verified 1 August 2026
  • Phase I — in force on notificationEffective 13 November 2025

    Provisions constituting and empowering the Data Protection Board (ss.18–26), definitions, and procedural rules took effect on 13 November 2025.

    DPDP Rules 2025 (phased commencement) · verified 1 August 2026
  • Phase II — one year from notificationEffective 13 November 2026

    Section 6(9) (verifiable parental consent) and section 27(1)(d) (publication duty) commence one year from notification — November 2026.

    DPDP Rules 2025 (phased commencement) · verified 1 August 2026
  • Phase III — substantive frameworkEffective May 2027

    Notice and consent standards, data fiduciary duties, children's data and data principal rights commence eighteen months from notification — May 2027. Published analyses split on 12 vs 13 May; confirm the exact day with counsel before relying on it.

    DPDP Rules 2025 (phased commencement) · verified 1 August 2026
  • Penalty ceilingEffective May 2027

    The Schedule to the Act caps monetary penalties at up to ₹250 crore per instance for the highest tier (failure to take reasonable security safeguards to prevent a personal data breach), with lower tiers at ₹200 crore, ₹150 crore and below; the Data Protection Board determines penalties on the facts.

    Amount verified directly against the Gazette PDF text ('may extend to two hundred and fifty crore rupees'). Enforcement follows the phased commencement (see dpdp-phase-3).

  • Breach notification timeline (Rule 7)Effective May 2027

    Under Rule 7 of the DPDP Rules 2025, a data fiduciary must intimate the Data Protection Board of a personal data breach without delay on becoming aware, follow with a detailed report within 72 hours (extendable by the Board), and notify affected data principals of the breach in plain language.

    Timelines corroborated across multiple legal publishers. Enforcement follows the phased commencement (see dpdp-phase-3). Runs in parallel with CERT-In’s 6-hour incident reporting — the same incident triggers both.

    DPDP Rules 2025, Rule 7 · verified 1 August 2026
  • Notice contents (section 5)Effective May 2027

    Every consent request must be accompanied or preceded by a notice informing the data principal of: (i) the personal data and the purpose of processing; (ii) the manner of exercising rights under s.6(4) (withdrawal) and s.13 (grievance redressal); and (iii) the manner of making a complaint to the Data Protection Board. For consents given before commencement, notice must follow as soon as reasonably practicable.

    Contents verified directly against the Gazette PDF text. Notice must be available in English or any Eighth Schedule language.

  • Consent Manager registration - Rule 4 in force 13 November 2026Effective 13 November 2026

    Rule 4 of the Digital Personal Data Protection Rules, 2025 establishes the registration and oversight framework for Consent Managers and comes into force on 13 November 2026. A Consent Manager is registered with the Data Protection Board of India and acts as a single point of contact through which a Data Principal can give, manage, review and withdraw consent via an accessible, transparent and interoperable platform.

    MeitY returns HTTP 403 to automated retrieval for both the Rules page and its own FAQ PDF, so this is corroborated across independent legal analyses rather than read from the primary text. Verify against the notified Rules before relying on it in a deliverable.

  • Consent Manager eligibility - First Schedule, Part AEffective 13 November 2026

    Part A of the First Schedule sets the conditions the Board must be satisfied of before registering a Consent Manager. They include incorporation in India, a minimum net worth of INR 2 crore (adjusted for inflation), sound financial condition and general character of management, and sufficient technical, operational and financial capacity to discharge the role. Directors, key managerial personnel and senior management must be persons of general reputation and record of fairness and integrity.

    MeitY returns HTTP 403 to automated retrieval for both the Rules page and its own FAQ PDF, so this is corroborated across independent legal analyses rather than read from the primary text. Verify against the notified Rules before relying on it in a deliverable.

  • Consent Manager obligations - First Schedule, Part BEffective 13 November 2026

    A Consent Manager acts in a fiduciary capacity toward the Data Principal. It must not act as Data Fiduciary or Data Processor for the same Data Principal whose consent it manages, must route personal data in a form it cannot itself read, must treat all Data Fiduciaries neutrally without preferential access, and must retain consent records for at least seven years.

    MeitY returns HTTP 403 to automated retrieval for both the Rules page and its own FAQ PDF, so this is corroborated across independent legal analyses rather than read from the primary text. Verify against the notified Rules before relying on it in a deliverable. The conflict rule is the commercially significant one: an organisation cannot register as a Consent Manager for data subjects it also serves as a Data Fiduciary.

Related in this cluster

DPDP Consent Manager — FAQs

When does the Consent Manager framework start?

Rule 4 of the DPDP Rules, 2025 comes into force on 13 November 2026. It establishes registration with the Data Protection Board of India and the obligations in the First Schedule.

Can we register to manage consent for our own customers?

No. Part B of the First Schedule bars a Consent Manager from acting as Data Fiduciary or Data Processor for the same Data Principal whose consent it manages. A Consent Manager is a neutral intermediary serving multiple Data Fiduciaries.

What is the net worth requirement?

A minimum of INR 2 crore, adjusted for inflation, alongside tests on financial condition, character of management and technical and operational capacity. We confirm the current requirement against the notified Rules at the start of any engagement.

Find out if you are eligible

Twenty minutes on the conflict rule, your entity and your net worth position. If the answer is that you cannot register, we will say so.

Book a 20-minute call →

Ready to discuss your DPDP Consent Manager readiness requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.