Rule 4 creates the legal and supervisory framework for Consent Managers. The simplest way to understand a Consent Manager is as a regulated consent-control platform acting for the Data Principal. It allows an individual to manage permissions concerning her personal data across participating Data Fiduciaries from a single platform, rather than visiting every bank, insurer, hospital, retailer or digital service separately.
The framework is based on Section 2(g) and Sections 6(7) to 6(9) of the DPDPA. The Act defines the Consent Manager, allows the Data Principal to use one, makes it accountable to her and requires registration with the Data Protection Board. Rule 4 and the First Schedule then prescribe the registration process, eligibility standards and continuing obligations.
The functional design described in is generally built around this statutory model. It envisages consent collection, validation, updating, renewal and withdrawal, supported by dashboards, notifications, grievance workflows, retention controls and audit logs. However, the document is a business requirements document, not legislation. Some of its features are useful system-design choices rather than express statutory requirements, and a few require legal qualification to align precisely with the final Act and Rules.
Commencement position: Rule 4 and Section 6(9) are scheduled to commence on13 November 2026. Sections 6(7) and 6(8), which govern the Data Principal’s use of a Consent Manager and the Consent Manager’s accountability to her, are scheduled to commence on13 May 2027. The registration machinery can therefore begin operating before the substantive consent-management framework becomes fully operational.