SCHEDULE I - FIRST SCHEDULE - CONSENT MANAGER

First Schedule - Consent Manager

Official text

See rule 4

Part A - Conditions for registration of Consent Manager

1.The applicant is a company incorporated in India.
2.The applicant has sufficient capacity, including technical, operational and financial capacity, to fulfil its obligations as a Consent Manager.
3.The financial condition and the general character of management of the applicant are sound.
4.The net worth of the applicant is not less than two crore rupees.
5.The volume of business likely to be available to and the capital structure and earning prospects of the applicant are adequate.
6.The directors, key managerial personnel and senior management of the applicant company are individuals with a general reputation and record of fairness and integrity.
7.The memorandum of association and articles of association of the applicant company contain provisions requiring that the obligations under items 9 and 10 of Part B are adhered to, that policies and procedures are in place to ensure such adherence, and that such provisions may be amended only with the previous approval of the Board.
8.The operations proposed to be undertaken by the applicant are in the interests of Data Principals.
9.It is independently certified that -
(a)the interoperable platform of the applicant to enable the Data Principal to give, manage, review and withdraw her consent is consistent with such data protection standards and assurance framework as may be published by the Board on its website from time to time; and
(b)appropriate technical and organisational measures are in place to ensure adherence to such standards and framework and effective observance of the obligations under item 11 of Part B.

Part B - Obligations of Consent Manager

1.The Consent Manager shall enable a Data Principal using its platform to give consent to the processing of her personal data by a Data Fiduciary onboarded onto such platform either directly to such Data Fiduciary or through another Data Fiduciary onboarded onto such platform, who maintains such personal data with the consent of that Data Principal.

Illustration

Individuals are enabled to give, manage, review and withdraw their consent to the processing of their personal data through P, a platform maintained by a Consent Manager. X, an individual, is a registered user on P. B1 and B2 are banks onboarded onto P. Case 1: B1 sends a request on P to X for consent to process personal data contained in her bank account statement. X maintains the bank account statement as a digital record in her digital locker. X uses P to directly give her consent to B1, and proceeds to give B1 access to her bank account statement. Case 2: B1 sends a request on P to X for consent to process personal data contained in her bank account statement. X maintains her bank account with B2. X uses P to route her consent through B2 to B1, while also digitally instructing B2 to send her bank account statement to B1. B2 proceeds to send the bank account statement to B1.

2.The Consent Manager shall ensure that the manner of making available the personal data or its sharing is such that the contents thereof are not readable by it.
3.The Consent Manager shall maintain on its platform a record of the following, namely: -
(a)Consents given, denied or withdrawn by her;
(b)Notices preceding or accompanying requests for consent; and
(c)Sharing of her personal data with a transferee Data Fiduciary.
4.The Consent Manager: -
(a)shall give the Data Principal using such platform access to such record;
(b)shall, on the request of the Data Principal and in accordance with its terms of service, make available to her the information contained in such record, in machine-readable form; and
(c)shall maintain such record for at least seven years, or for such longer period as the Data Principal and Consent Manager may agree upon or as may be required by law.
5.The Consent Manager shall develop and maintain a website or app, or both, as the primary means through which a Data Principal may access the services provided by the Consent Manager.
6.The Consent Manager shall not sub-contract or assign the performance of any of its obligations under the Act and these rules.
7.The Consent Manager shall take reasonable security safeguards to prevent personal data breach.
8.The Consent Manager shall act in a fiduciary capacity in relation to the Data Principal.
9.The Consent Manager shall avoid conflict of interest with Data Fiduciaries, including in respect of their promoters and key managerial personnel.
10.The Consent Manager shall have in place measures to ensure that no conflict of interest arises on account of its directors, key managerial personnel and senior management holding a directorship, financial interest, employment or beneficial ownership in Data Fiduciaries, or having a material pecuniary relationship with them.
11.The Consent Manager shall publish in an easily accessible manner, on its website or app, or both, as the case may be, information regarding: -
(a)the promoters, directors, key managerial personnel and senior management of the company registered as Consent Manager;
(b)every person who holds shares in excess of two per cent. of the shareholding of the company registered as Consent Manager;
(c)everybody corporate in whose shareholding any promoter, director, key managerial personnel or senior management of the Consent Manager holds shares in excess of two per cent. as on the first day of the preceding calendar month; and
(d)such other information as the Board may direct the Consent Manager to disclose in the interests of transparency.
12.The Consent Manager shall have in place effective audit mechanisms to review, monitor, evaluate and report the outcome of such audit to the Board, periodically and on such other occasions as the Board may direct, in respect of -
(a)technical and organisational controls, systems, procedures and safeguards;
(b)continued fulfilment of the conditions of registration; and
(c)adherence to its obligations under the Act and these rules.
13.The control of the company registered as the Consent Manager shall not be transferred by way of sale, merger or otherwise, except with the previous approval of the Board and subject to fulfilment of such conditions as the Board may specify in this behalf.

Note

In this Schedule, -

(a)the expression “body corporate” shall include a company, a body corporate as defined under clause (11) of section 2 of the Companies Act, 2013 (18 of 2013), a firm, a financial institution, a scheduled bank or a public sector enterprise established or constituted by or under any Central Act, Provincial Act or State Act, and any other incorporated association of persons or body of individuals;
(b)the expressions “company”, “control”, “director” and “key managerial personnel” shall have the same meanings as are respectively assigned to them in the Companies Act, 2013 (18 of 2013);
(c)the expression “net worth” shall mean the aggregate value of total assets as reduced by the value of liabilities of the Consent Manager as appearing in its books of accounts; and
(d)the expressions “promoter” and “senior management” shall have the same meanings as are respectively assigned to them in the Companies Act, 2013 (18 or 2013).

Cross-references

First Schedule

Commentary

The First Schedule establishes the complete regulatory framework governing Consent Managers under the Digital Personal Data Protection Act, 2023. Part A determines whether an applicant is suitable for registration, while Part B governs how a registered Consent Manager must operate after registration. The two Parts form a continuous framework. The conditions in Part A are not merely entry requirements that cease to matter once registration is granted. A Consent Manager must continue satisfying them while performing the obligations in Part B.

A Consent Manager is intended to act as a trusted and interoperable intermediary through which a Data Principal can give, manage, review and withdraw consent. Its role is not to decide why another organisation may process personal data, nor to become the repository or commercial user of the personal data being shared. Its central function is to give the Data Principal practical control over consent while maintaining a reliable record of the consent transaction.

The Schedule is linked to Rule 4, which comes into force one year after publication of the Rules, on 13 November 2026. The official corrigendum dated 10 December 2025 corrected certain textual errors in the final Rules, including a Companies Act citation appearing in the First Schedule.

A Consent Manager is not an ordinary consent-management software vendor. Registration by the Data Protection Board is essential. An organisation supplying cookie banners, privacy dashboards or consent-recording technology does not become a statutory Consent Manager merely because it performs some similar technical functions.

The statutory model gives the registered Consent Manager a position of trust between the Data Principal and participating Data Fiduciaries. Through its platform, the Data Principal may give consent directly to a Data Fiduciary or route her consent and an associated data-sharing instruction through another onboarded Data Fiduciary that already maintains the relevant personal data.

This model permits controlled data sharing without requiring the Data Principal to obtain the information herself and then retransmit it manually. It also allows the consent instruction and subsequent sharing event to be recorded through an interoperable platform. The Consent Manager’s role remains facilitative. The receiving Data Fiduciary remains responsible for establishing the lawful purpose, issuing the required notice, requesting only necessary personal data and complying with the DPDPA in relation to the processing.

Registration does not make the Consent Manager a guarantor of every processing operation undertaken by an onboarded Data Fiduciary. At the same time, the Consent Manager cannot remain indifferent to whether its own platform accurately transmits the Data Principal’s choice, preserves the relevant records and prevents use of the platform contrary to its fiduciary obligations.

1.2 Conditions for registration

Part A requires the applicant to be a company incorporated in India. The registration framework is therefore not available directly to an individual, unincorporated association or foreign company operating solely through an overseas legal entity. Indian incorporation gives the Board a clearly identifiable legal person subject to domestic corporate governance, financial, regulatory and enforcement requirements.

The applicant must demonstrate sufficient technical, operational and financial capacity to perform the Consent Manager’s functions. This requirement recognises that consent management is not fulfilled by maintaining a basic website or recording a binary “yes” or “no.” The platform must be capable of securely identifying users, presenting and preserving notices, recording consent decisions, transmitting instructions, maintaining interoperability, supporting withdrawal and producing reliable evidence over an extended period.

Financial suitability is assessed through several connected criteria. The applicant must have a net worth of at least ₹2 crore, sound financial condition, appropriate capital structure, viable earning prospects and a realistic volume of business. The prescribed minimum is a threshold rather than conclusive proof of continuing financial capability. A company may satisfy the net-worth requirement while lacking the operational resources or financial stability needed to maintain a secure and reliable platform. Conversely, the Board’s assessment should remain connected to the applicant’s actual proposed operations and risk profile.

The applicant’s management must also be fit and proper in substance. Directors, key managerial personnel and senior management must have a general reputation and record of fairness and integrity. The requirement reflects the fiduciary character of the service. Persons controlling the Consent Manager may influence platform design, onboarding, commercial arrangements, security expenditure and handling of conflicts. Their suitability is therefore directly relevant to whether Data Principals can trust the platform.

The applicant’s constitutional documents must contain provisions requiring compliance with the conflict-of-interest obligations in Part B and the maintenance of policies and procedures supporting that compliance. Those provisions may be amended only with the Board’s prior approval. This embeds independence into the company’s corporate constitution rather than leaving it solely to an operational policy that management could change unilaterally.

The proposed operations must be in the interests of Data Principals. A business model primarily designed to monetise consent history, steer individuals towards preferred Data Fiduciaries or exploit data-sharing patterns would be difficult to reconcile with this condition. Commercial viability is permitted, but the organisation’s revenue model cannot displace its fiduciary responsibility or compromise the Data Principal’s freedom of choice.

Independent certification provides the principal technical assurance at the registration stage. The applicant’s interoperable platform must conform to the data-protection standards and assurance framework published by the Board, and the applicant must have appropriate technical and organisational measures to maintain that conformity and fulfil the transparency obligations in Part B. Certification is not a permanent substitute for supervision. The Board may revise its standards, and the Consent Manager remains responsible for continuing compliance after registration.

Part B requires the platform to enable the Data Principal to give consent to an onboarded Data Fiduciary either directly or through another onboarded Data Fiduciary that holds the relevant personal data with her consent.

The Schedule therefore contemplates a structured relationship among:

  • the Data Principal;

  • the Consent Manager;

  • the Data Fiduciary requesting consent;

  • the Data Fiduciary holding the information, where different;

  • and the actual data-sharing mechanism.

The Consent Manager must accurately transmit the Data Principal’s choice. Consent cannot be inferred from inactivity, preselected by platform design or expanded beyond the purpose and personal data covered by the request. Refusal must be as operationally effective as approval, and withdrawal must reach the relevant Data Fiduciary through a reliable process.

The platform should preserve the distinction between consent and data transfer. A Data Principal may give consent to specified processing and separately authorise the entity holding her information to share it with the intended recipient. The Consent Manager must maintain evidence of how those linked actions occurred without representing that its involvement independently validates the receiving Data Fiduciary’s purpose.

A central protection in the Schedule is that the personal data being made available or shared must not be readable by the Consent Manager. This establishes a data-blind architecture. The Consent Manager may facilitate and record the consent instruction, but it should not obtain intelligible access to the underlying bank statement, medical record, identity document or other personal data transferred between Data Fiduciaries.

That requirement substantially limits the Consent Manager’s role and risk exposure. It should not decrypt, inspect, analyse or monetise the contents of the transferred data. The technical structure may rely on encryption, secure routing or another method that allows the data to move to the authorised recipient without becoming readable to the Consent Manager.

The unreadability requirement does not mean that the Consent Manager processes no personal data. It will still process information necessary to administer the relationship, such as the Data Principal’s account particulars, consent history, notices, participating Data Fiduciaries, transaction references and sharing records. Those records can reveal significant information about the individual even without revealing the contents of the transferred file. They must therefore be protected and confined to the Consent Manager’s statutory functions.

The Consent Manager must maintain records of consents given, denied and withdrawn, notices preceding or accompanying the consent requests, and the sharing of personal data with a transferee Data Fiduciary. Together, these records create an auditable history of the Data Principal’s interactions.

The record must be detailed enough to establish:

  • which Data Fiduciary requested consent;

  • what notice accompanied the request;

  • what decision the Data Principal made;

  • when the decision was made;

  • whether consent was later withdrawn;

  • and whether personal data was shared with another Data Fiduciary.

A record stating only that “consent was obtained” would not demonstrate what the individual agreed to or which notice informed her choice. Preservation of the accompanying notice is particularly important because the meaning and validity of consent depend on the information presented at the time.

The Data Principal must be able to access this history through the platform. On request and in accordance with the terms of service, the information must also be made available in machine-readable form. This supports portability and independent review of the consent record and reduces dependency on the Consent Manager’s interface.

The prescribed retention period is at least seven years. A longer period may apply where the Data Principal and Consent Manager agree or where another law requires it. The seven-year rule establishes a minimum evidentiary period, not permission to retain every associated record indefinitely. Information retained should remain accurate, secure and limited to what is necessary to preserve the relevant consent history.

The Consent Manager should also distinguish the statutory consent record from the underlying personal data being shared. The seven-year retention requirement applies to the records prescribed in the Schedule. It does not authorise the Consent Manager to retain a readable copy of the underlying information transferred between Data Fiduciaries.

1.5 Direct responsibility and prohibition on subcontracting

The Consent Manager must maintain a website or application, or both, as the primary means through which Data Principals access its services. The primary interface should allow individuals to understand outstanding consent requests, review active and withdrawn consents, access prior notices and inspect data-sharing records.

The Schedule prohibits subcontracting or assigning performance of the Consent Manager’s obligations under the Act and Rules. This reflects the trust and regulatory scrutiny involved in registration. The Board registers the particular company after assessing its financial condition, management, capacity, platform, independence and certification. That company cannot transfer the regulated function to an unassessed third party while retaining only its statutory label.

The prohibition should not necessarily be understood as preventing every procurement of ordinary supporting services. Like other digital platforms, a Consent Manager may require infrastructure, telecommunications, cybersecurity or professional support. However, it cannot subcontract or assign the performance of the substantive statutory obligations for which it was registered.

Any supporting arrangement must therefore be structured so that the Consent Manager retains genuine operational control and responsibility. A vendor should not independently determine consent flows, read underlying personal data, exercise the Consent Manager’s fiduciary discretion or replace the registered entity in its relationship with the Data Principal.

1.6 Security and fiduciary duty

The Consent Manager must take reasonable security safeguards to prevent personal data breaches. This obligation applies despite the requirement that transferred data remain unreadable to it. Its own records, authentication systems, consent instructions and transaction history remain sensitive and can expose Data Principals to serious risks if compromised.

A breach affecting a Consent Manager could allow an attacker to:

  • impersonate Data Principals;

  • give or withdraw consent;

  • redirect data-sharing instructions;

  • identify relationships with financial or healthcare institutions;

  • alter consent histories;

  • or obtain information about the Data Principal’s service usage.

Security must therefore extend beyond confidentiality of stored data. It should protect the integrity and authenticity of consent decisions and ensure that a person cannot give, alter or withdraw another individual’s consent without authority.

The fiduciary obligation requires the Consent Manager to place the Data Principal’s interests at the centre of its functioning. This includes acting honestly, avoiding manipulation, accurately implementing instructions, giving meaningful access to records and refusing to design the service in a manner that favours the commercial objectives of participating Data Fiduciaries over the individual’s choices.

Fiduciary responsibility is especially important because Consent Managers may occupy a structurally influential position. The platform can shape how consent requests are presented, which Data Fiduciaries are onboarded, how refusals and withdrawals are displayed and how easily information can be transferred. Interface design and commercial arrangements must therefore not undermine the Data Principal’s autonomy.

1.7 Independence and conflicts of interest

The Schedule imposes strong structural safeguards against conflicts between the Consent Manager and onboarded Data Fiduciaries. The Consent Manager must avoid conflicts involving Data Fiduciaries and their promoters or key managerial personnel. It must also maintain measures preventing conflicts arising from the interests and relationships of its own directors, key managerial personnel and senior management.

Relevant conflicts may arise through:

  • directorships;

  • financial interests;

  • employment;

  • beneficial ownership;

  • or material pecuniary relationships.

These restrictions are intended to prevent a Data Fiduciary from exercising concealed influence over the entity expected to manage the Data Principal’s consent independently.

The corporate-governance requirement in Part A reinforces this protection by placing the conflict rules in the memorandum and articles of association and restricting amendments without the Board’s prior approval. Independence is therefore both a condition of registration and a continuing operational obligation.

A Consent Manager may earn revenue and enter legitimate commercial arrangements, but those arrangements cannot create incentives to steer individuals towards giving consent, delay withdrawals, favour particular Data Fiduciaries or design interfaces that make refusal more difficult.

1.8 Public transparency

The Consent Manager must make specified ownership and management information readily accessible on its website or application. This includes information about its promoters, directors, key managerial personnel and senior management, shareholders holding more than two per cent, and bodies corporate in which the relevant controlling or managerial persons hold more than two per cent as of the first day of the preceding calendar month.

The two-per-cent threshold creates a relatively broad transparency framework. It is intended to reveal ownership and cross-holding relationships that may bear upon independence, even where they do not amount to formal corporate control.

The information must remain current rather than being published only at registration. Changes in shareholding, management or relevant corporate interests may alter the Consent Manager’s conflict profile. The requirement linked to the preceding calendar month implies regular review and updating.

The Board may also direct disclosure of additional information in the interests of transparency. This permits regulatory response where formally disclosed shareholding information does not reveal the complete economic or governance relationship relevant to the Consent Manager’s independence.

The disclosure obligation should be read together with applicable corporate and personal-data laws. It requires publication of the specified information, but not publication of unrelated personal details concerning directors, shareholders or managers.

1.9 Audit and continuing supervision

The Consent Manager must maintain effective audit mechanisms to examine:

  • technical and organisational controls;

  • systems, procedures and security safeguards;

  • continuing satisfaction of the registration conditions; and

  • compliance with the Act and Rules.

The audit obligation confirms that registration is not a one-time approval. Financial condition, management integrity, platform conformity, independence and operational capacity must continue throughout the registration period.

Audit results must be reported to the Board periodically and whenever the Board otherwise directs. The audit mechanism should therefore be capable of producing current and reliable evidence concerning the Consent Manager’s operation, rather than functioning only as an annual compliance checklist.

A meaningful audit should determine whether:

  • consent choices are recorded and transmitted accurately;

  • withdrawal reaches the relevant Data Fiduciary;

  • underlying personal data remains unreadable to the Consent Manager;

  • records are complete and accessible;

  • security safeguards operate effectively;

  • conflicts are identified and managed;

  • public disclosures are accurate;

  • and supporting providers do not perform functions that the Schedule prohibits from being subcontracted.

The obligation to report audit outcomes to the Board supports continuing regulatory oversight and enables the Board to address deterioration in capacity or independence before it materially harms Data Principals.

1.10 Transfer of control

Control of the registered company cannot be transferred through sale, merger or another arrangement without the Board’s prior approval. The Board may attach conditions to its approval.

This restriction follows from the personal and institutional character of registration. The Board registers a company after examining its ownership, management, integrity, capacity, financial condition, technology, independence and business model. A transfer of control could materially change every part of that assessment.

A transaction completed without prior approval could place the platform, consent records and influence over Data Principal choices in the hands of a person who was never assessed by the Board. Prior approval allows the Board to consider whether the proposed controller:

  • satisfies the registration conditions;

  • creates a conflict with Data Fiduciaries;

  • maintains financial and operational capacity;

  • will preserve the certified platform;

  • and can continue protecting Data Principals.

The restriction covers more than direct sale of shares. A merger, restructuring, beneficial-ownership change or other arrangement may transfer control even if the registered company remains formally in existence. The Companies Act meaning of “control,” incorporated by the Schedule, will be relevant to that assessment.

1.11 Effect of non-compliance

Failure to maintain compliance with Part A or Part B may lead to regulatory action under Rule 4 and the First Schedule. Depending on the nature of the failure, the Board may issue corrective directions or take action affecting the Consent Manager’s registration through the applicable procedure.

Serious failures may include:

  • operation without adequate capacity;

  • deterioration below the required financial threshold;

  • loss of platform certification;

  • readable access to personal data being transferred;

  • inaccurate or manipulated consent records;

  • ineffective withdrawal;

  • prohibited subcontracting;

  • unresolved conflicts of interest;

  • false ownership disclosures;

  • inadequate security;

  • failure to submit audit outcomes;

  • or transfer of control without prior approval.

A failure may also amount to a breach of another provision of the Act or Rules. A security incident may engage the personal-data breach framework. Misrepresentation of consent may affect the legality of processing undertaken by a Data Fiduciary. Unauthorised use of readable personal data may place the Consent Manager in a different processing role from the limited role contemplated by the Schedule.

The Consent Manager’s registration does not protect an onboarded Data Fiduciary from responsibility for defective consent. Each Data Fiduciary remains accountable for ensuring that its consent request satisfies Sections 5 and 6 and that subsequent processing remains within the specified purpose. The Consent Manager provides the infrastructure and record; it does not cure a vague notice, bundled purpose or unnecessary collection by the Data Fiduciary.

1.12 Concluding interpretation

The First Schedule creates a regulated trust infrastructure for consent rather than a conventional consent-recording service.

Part A ensures that only an India-incorporated company with adequate capital, capacity, sound management, institutional integrity, technical certification and genuine independence may be registered. Part B then requires the registered company to operate an interoperable and data-blind platform, preserve a reliable consent and sharing history, act in the Data Principal’s interests, remain independent from Data Fiduciaries, maintain security and audit controls, disclose its ownership relationships and obtain approval before any transfer of control.

The Schedule’s design separates three functions:

  • the Data Fiduciary determines the purpose and requests consent;

  • the Data Principal makes and manages the consent decision;

  • the Consent Manager provides a trusted platform through which that decision is communicated and evidenced.

The Consent Manager is therefore neither the owner of the Data Principal’s consent nor the beneficiary of the underlying processing. Its statutory position is that of a regulated fiduciary entrusted with making individual control over consent practical, interoperable, secure and verifiable.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.