KaryaFlow
Back to blog

You're probably not a Consent Manager

Kirtesh Sharma7 min read

Practical guidance for planning, not legal advice. Confirm your own obligations with counsel and against the Gazette text.

The next DPDP milestone lands in November 2026, twelve months after the Rules were notified, and it brings the Consent Manager framework into force. If you run a business that collects customer data, you have probably had at least one email telling you to prepare for it.

Here is the thing most of that messaging skips: a Consent Manager is a specific, registered kind of company, and you are almost certainly not going to be one.

What a Consent Manager actually is

It is a regulated intermediary — closer to an account aggregator than to a compliance feature. The conditions of registration in Schedule I of the Rules are explicit. The applicant must be “a company incorporated in India”, and “the net worth of the applicant is not less than two crore rupees”. It must run an interoperable platform that lets a person “give, manage, review and withdraw her consent” across the fiduciaries she deals with.

That ₹2 crore net worth threshold is the tell. This is a licensed industry the Rules are creating, not a box every business ticks. If you sell software, run a clinic, or operate a D2C brand, you are a Data Fiduciary. Different role, different obligations.

So what does change for you

Three things worth planning around, none of which require you to register as anything.

Consent stops being yours alone to manage. Once Consent Managers exist, a person can grant and withdraw consent through a third party rather than through your signup form. Your systems need to be able to receive a withdrawal that did not originate with you, and act on it. If your consent state lives in a spreadsheet or is implied by someone's presence in a mailing list, that is the gap to close.

Cross-border processing and Significant Data Fiduciary obligations are reported to fall in the same phase. Significant Data Fiduciaries are designated by the volume and sensitivity of the data they handle, and carry heavier duties — data protection impact assessments, an independent audit every twelve months, and a named Data Protection Officer. Public reporting does not give a numeric threshold for designation, so if you process a lot of sensitive data, ask counsel rather than assuming you are under the line.

The clock on the main deadline keeps running. November 2026 is not the big one. The core obligations — consent notices, purpose limitation, retention and erasure, children's data, security safeguards — land at the eighteen-month mark in May 2027. November is a good forcing function to start, not the finish line.

What to do in the next ninety days

  1. Find every place consent is recorded. Not every place you think it is recorded — every place it actually is. Most companies find more than they expected, and at least one that nobody owns.
  2. Make withdrawal work end to end. Pick a real record and withdraw it. Time how long until it is honoured everywhere, including your email tool and your analytics.
  3. Write down your retention rule per data type, then check whether any system actually enforces it.
  4. Ask your vendors the eight questions in our vendor diligence guide. Their answers determine how much of this you can solve by configuration rather than by project.

None of this needs a Consent Manager registration. It needs to know where your consent lives and whether you can act on a withdrawal — which is the work May 2027 is going to ask for anyway.

Where the platform you run on matters is step two: a withdrawal that has to be honoured in nine systems is a reconciliation problem, and one that lands in a single data model is a configuration change. What we ship for consent, retention and deletion today is on our security and compliance page, and the platform page covers the nine functions that share the record.

Where this comes from

Registration conditions are quoted from Schedule I, Part A of the DPDP Rules, 2025. Phasing and Significant Data Fiduciary obligations are drawn from India Briefing's summary. Checked 8 August 2026.

Published sources differ by a day on the exact commencement dates, so we have written months rather than dates. If a deadline matters to a decision you are making, confirm it against the Gazette text — not against this post, and not against a vendor selling you a solution to it.