India’s Consent Manager Framework – a substantive policy innovation

Saket Bisani, of Bisani Legal, explains how this intermediary entity works, and sets out what it means for multinational and national controllers operating in India.

On 13 November 2025, the Government of India notified the Digital Personal Data Protection Rules 2025 (DPDP Rules) under the Digital Personal Data Protection Act 2023 (DPDP Act). Among the 23 rules that operationalise the Act, Rule 4 stands out. It establishes a registration and supervision framework for a new category of regulated intermediary: the Consent Manager. The Rule commences on 13 November 2026, one year after notification, and on a faster timetable than the eighteen-month commencement applicable to most of the other operational rules.

The Consent Manager mechanism is genuinely novel. It is not a relabelled cookie-consent platform, a privacy management system or a typical data trust. It is a regulated intermediary that sits between the data principal (individual) and the data fiduciary (organisation) and brokers consent on the data principal’s behalf. Indian regulators have, in effect, decided to address the asymmetry of consent in the digital economy by introducing a third entity into the transaction. For privacy professionals advising multinational businesses with Indian operations, the Consent Manager framework warrants close attention because it adds a regulatory layer not generally present in data protection law.

Continue Reading

International Report subscribers, please login to access the full article

LOGIN

If you wish to subscribe, please see our subscription information.

Subscribe