/Glossary · Defined term
Consent Manager
Defined in section 2(g) of the Act.
Act, section 2(g)
(g) “Consent Manager” means a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform;
Under the Digital Personal Data Protection Act, a "Consent Manager" is a specific type of entity registered with the Data Protection Board of India (the Board). The primary purpose of a Consent Manager is to serve as a single point of contact for a Data Principal, which is the individual to whom the personal data relates. By using a Consent Manager, an individual can handle their data preferences in one centralized location.\n\nThis entity provides a platform where the Data Principal can give, manage, review, and withdraw their consent for how their personal data is processed. The law specifically requires that this platform be accessible, transparent, and interoperable. This ensures that the system is easy for individuals to use, clear about how consent is being handled, and technically capable of communicating with the systems of various organizations.
Key points
- A Consent Manager must be officially registered with the Board [Section 2(g)].
- They act as a single point of contact for a Data Principal [Section 2(g)].
- They enable individuals to give, manage, review, and withdraw their consent [Section 2(g)].
- The platform provided by the Consent Manager must be accessible, transparent, and interoperable [Section 2(g)].
Common misreadings
- Assuming anyone who manages user consent is automatically a Consent Manager, whereas the law requires them to be formally registered with the Board.
- Believing a Consent Manager decides how data is used, when their defined role is only to provide a platform for the Data Principal to manage consent.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.