Chapter 11 — Consent Managers and Consent-Management Software
1. A role the market keeps confusing with a product
“Consent Manager” is a defined role, not a product feature. Section 2(g) describes a Board-registered person acting as a single point of contact enabling a principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform (ACT:65–67).[1] A cookie banner, preference centre or event ledger can be useful enterprise tooling without occupying that role.
Five load-bearing elements: a person (an entity in law, not a feature flag); registered with the Board (a statutory registration, not a vendor claim); single point of contact for the principal — give, manage, review, withdraw, the full Chapter 9–10 lifecycle, from the principal’s side of the table; accessible, transparent and interoperable (three enforceable platform properties, not marketing adjectives); and the direction of accountability that follows from the principal-side role — the Act’s own words elsewhere make it explicit: the Consent Manager is accountable to the Data Principal and acts on her behalf in the prescribed manner (ACT:258–263).[1]
The distinction changes diligence. Buying software leaves the fiduciary responsible for its own processing. Engaging a statutory Consent Manager requires evidence of the registration and role-specific obligations, plus a workable onboarding and reconciliation boundary. Neither a product label nor a consent-challenge award proves Board registration. SYS-010 in the Company’s dossier is enterprise tooling, not a registered intermediary.
The objective is not universal unauthenticated connectivity. It is to preserve the principal’s statutory channel when applicable while verifying the intermediary, onboarding, message provenance and purpose mapping. The definition’s word “interoperable” is not a transport protocol or an exemption from those checks.
2. The statutory mechanics, in full
Rule 4 opens registration to applicants meeting First Schedule Part A; the Board may inquire, register and publish particulars, or reject with reasons. Part B governs registered managers. Rule 4(4) provides hearing and adherence measures; Rule 4(5) permits reasoned suspension/cancellation and protective directions after hearing; Rule 4(6) is an information-call provision, not the protective-directions clause (RULES:1039–1063).[3]
The following source-backed diligence table replaces an unread-Schedule placeholder. These are conditions/obligations of the CM role; the consequence column is the author’s procurement recommendation.
| Primary requirement | Operational consequence for diligence |
|---|---|
| Part A: Indian-incorporated company; adequate technical, operational and financial capacity; sound financial condition/management; net worth at least two crore rupees; adequate business/capital/earning prospects; management integrity | collect official registration and scoped corporate/capacity evidence; the figure is a CM eligibility requirement, not the Company’s software budget |
| Part A: constitutional documents protect Part B9/10 conflict obligations; principal-interest operations; independent certification against Board-published standards/framework and transparency controls | inspect actual framework/version and certification scope; missing published evidence is unresolved, not self-certified compliance |
| Part B1: direct or routed consent for fiduciaries onboarded onto the platform | establish onboarding and mappings; no zero-onboarding claim for every registered CM |
| Part B2: personal-data contents made available/shared are not readable by CM | separate control metadata from customer payload; a readable bank-statement debug log fails the design |
| Part B3/4: consent given/denied/withdrawn, notices and sharing records; principal access, requested machine-readable export; at least seven years or agreed/legal longer retention | test export and independent reconstruction; this seven-year CM record duty is not a blanket fiduciary data-retention period |
| Part B5–8: website/app primary access, no subcontract/assignment of statutory obligations, safeguards, fiduciary capacity | inspect operating chain and responsibility, not only a hosting diagram |
| Part B9–11: conflict avoidance, management-interest controls and accessible ownership/management disclosures including specified over-two-percent interests | conflicts and corporate relationships need scrutiny even when the API works |
| Part B12/13: effective audits and reports to Board; previous Board approval for transfer of control | require scoped audit evidence and change notification; software migration cannot substitute for corporate approval |
The source locations are Part A (RULES:1413–1446) and Part B/definitions (RULES:1448–1550).[3] Corrigendum corrections to “every body” and Companies Act “18 of 2013” are applied to the reading, not silently overwritten in the retained source (CORR:33–35).[4] Indian incorporation is not a claimed blanket Indian-shareholding requirement. Some technology support arrangements may require legal analysis against nondelegation; do not assume any outsourcing label resolves it.
Sections 6(7)/(8) give the principal the CM channel and make the CM accountable to her; Section 6(9) supplies registration. Section 13 separately requires a grievance response from the relevant fiduciary or CM for its act/omission (ACT:258–268,477–487).[1] Under Rule 14(3), publish a reasonable grievance-response period not exceeding ninety days and implement effectiveness measures; this is not a universal rights SLA (RULES:1308–1311).[3] Coordination must not erase either recipient’s own duty.
The coordination problem is harder than it looks. The Consent Manager’s own grievance duty runs independently — the Act imposes it on the Consent Manager as a separate obligation, not as a relay service. When the principal grieves to both doors simultaneously, the enterprise and the Consent Manager must not duplicate contradictory answers or, worse, each wait for the other. The integration boundary (Section 4 below) must specify the coordination protocol: who leads the response, how the other party’s concurrent handling is acknowledged, and how the case record captures the coordination without either party assuming the other’s duty was discharged. The alternative — an uncoordinated pair of services — is how a timely answer is given twice and a deadline is missed once.
Withdrawal through the channel. Once the applicable rights channel operates, an authenticated CM-mediated withdrawal must reach the same purpose-scoped coordination as a direct request; it must not sit indefinitely in a support queue. Equal event handling is an author design recommendation. The statutory test is comparable ease and cessation within reasonable time with lawful exceptions, not a specified identical latency (ACT:232–259).[1]
Commencement is provision-specific. Section 6(9), Section 27(1)(d) and Rule 4 are scheduled for 13 November 2026. Sections 6(7)/(8), the other core consent/rights duties and Rule 14 are scheduled for 13 May 2027, on the retained baseline. Registration readiness is earlier than the core channel; it does not create an early universal enterprise-integration mandate (COMM:49–59; RULES:1005–1010, corrected CORR:28–30).[2][3][4] Voluntary early design and onboarding can reduce delivery risk, but must be described as readiness work. No live Board register, actual CM appointment, later technical standard or operational service is proved by this local exercise.
3. The tension: the principal’s convenience versus the enterprise’s control
The tension this chapter holds is genuine, because the Consent Manager is meant to shift power toward the principal — and the shift has real operational consequences for the enterprise.
The convenience pull. A principal may value one place to manage several consents. Whether a sector ecosystem achieves that benefit is a design and adoption question, not an observed result in this book. Sector-specific intermediary obligations must be established from their own operative instruments, not borrowed from a visual resemblance to account-aggregation or health-data flows.
The pull toward control. But the enterprise built Chapter 9’s evidence chain and Chapter 10’s machine, and the intermediary’s arrival raises uncomfortable questions: where does the canonical consent record live when the principal manages consent through a third party? Who answers the Section 6 evidence question — “show me the notice, the items, the affirmative action” — when the action happened on another platform? How does the withdrawal propagate to the enterprise’s derived stores when the trigger arrived from outside? The unexamined instinct is to keep everything in-house and treat the Consent Manager as a threat; the equally unexamined instinct is to assume the intermediary absorbs the obligations. Both instincts are wrong for the same reason:
Section 8(1) leaves the fiduciary responsible for processing by it or on its behalf regardless of contrary agreement; Section 6(10) supplies its proceeding-specific consent/notice proof burden (ACT:264–268,330–334).[1] A CM’s own obligations do not absorb those duties. The practical answer is a documented integration boundary with source-specific evidence, not a declaration that one company’s database is legally authoritative over all others.
4. The boundary decision, per surface
For each purpose, record the direct channel, applicable CM pathway, onboarding state, external-to-internal purpose mapping, evidence exchange and continuity fallback. Direct application consent and CM-mediated management are not necessarily exclusive product choices. Once an applicable obligation exists, “core user experience” is not a reason to ignore it. Conversely, a currently unverified or unonboarded sender does not receive blanket permission to mutate customer authority.
The Company proposes to retain a direct channel for PUR-001/PUR-002 while building a CM adapter for both, subject to real registration, published-standard and onboarding checks. Optional-marketing is the first synthetic adapter test because WITHDRAW-001 already exercises its failure semantics. PUR-010 insurance referral needs its own disclosure and receiving-fiduciary assessment. No channel supplies a missing PUR-003 training grant.
Reconciliation keeps both origin evidence and a derived current state. A conflict between records is an incident to investigate, not resolved by declaring the Company’s copy canonical and discarding the principal-side withdrawal. SYS-010 sequences accepted authority changes only after trusted validation. External timestamps and counters remain source evidence; independent clocks or per-CM counters do not define a shared global order. A consistent state requires agreed revision semantics and explicit conflict handling.
| Item being procured | Legal identity / evidence | Acceptance boundary |
|---|---|---|
| Statutory CM | Board-registered principal-side role, Section 2(g)/Rule 4 and First Schedule | official registration, applicable standards and onboarding plus channel/record/opacity controls |
| Enterprise consent software | component operated for fiduciary; SYS-010 remains tooling | actual configured notice, authority, export and failure behaviour; no registration inferred from branding |
| Account Aggregator integration | separate sector regime; applicability and instruments require the sector chapter’s evidence | inspect its own role/consent contract; neither automatic DPDP equivalence nor automatic incompatibility is assumed |
The comparison is conceptual, not a vendor capability ranking. No product demonstration or commercial API test is claimed. A bidder must substantiate the particular capability, evidence version and customer-controlled export path; a slide saying “DPDP ready” is not a test result.
5. Authenticated integration contract and negative acceptance
out/remediation/Q03/cm-integration.json is the populated synthetic Q03-CM-001 adapter contract, not a Board standard. It uses an explicitly fictional Q03-CM-TEST identity; its registration field is synthetic_assumed, never a fabricated Gazette number. Production onboarding remains blocked without official evidence. The Company remains ENT-001, not a CM.
A recommended message carries sender/key identifier, event ID, subject and separately authenticated actor, mapped purpose, original consent and notice version, source revision, occurred/received timestamps, audience, payload hash and authentication result. The adapter binds these to a trusted onboarding record; it rejects unknown sender, wrong audience, stale key, tampered content, ambiguous purpose and absent actor authority. Customer payload is not inserted into control messages merely because the CM can manage consent. Keys and certificates require rotation and revocation procedures; a hash without authenticated provenance does not authenticate a sender.
The local demonstration signs a synthetic withdrawal envelope with a fixture-only HMAC key, changes the body to show authentication failure, and tests stale replay. This exercises message integrity semantics only; it is not PKI, a Board-prescribed signature scheme or a production identity system. The signature authenticates a message under a key, not the truth of its asserted authority. An authenticated but unauthorised actor still fails.
| Input | Required observable result | Continuity / evidence |
|---|---|---|
| Valid test withdrawal for CONSENT-002/PUR-002 | route WITHDRAW-001 once to coordinator, mark local authority withdrawn | retain origin envelope and local revision; remote ACK still tracked |
| Same event, identical payload | idempotent replay, no duplicate effect | return original accepted state |
| Same event, changed payload | conflict rejection | keep failure evidence, no regrant |
| Old grant after withdrawal | deny stale grant even if received later | keep occurred/received times distinct |
| Unknown external purpose | quarantine, no broad grant or person-wide delete | assisted authenticated withdrawal path stays available |
| Registration suspended / key revoked | stop accepting new grants through affected trust path pending directions/review | preserve prior evidence; offer verified direct withdrawal and reconcile queued events |
| CM unavailable | Company cannot reconstruct response solely by calling it | independent retained proof and export permit response; gaps are explicit |
Tests that verify messages alone do not establish content opacity, conflict governance or the seven-year record lifecycle. Those require scoped architecture, inspection and retention evidence at procurement acceptance. The failed branches belong in the bid decision rather than being averaged away by successful API calls.
6. Two worked walkthroughs
Walkthrough one — channel readiness without deadline inflation. At the September 2026 planning point, Product separates the November CM-registration milestone from May’s core rights channel. Legal monitors actual publications and onboarding particulars. Engineering prepares an adapter and a direct fallback; procurement does not promise universal connectivity to any future registrant. Before production acceptance, the evidence pack must contain the actual registered legal person, current status, protocol/version, purpose mapping and trust material. None of those is supplied by the hypothetical test identity.
Assuming the retained commencement schedule holds, the June 2027 scenario passes a correctly authenticated synthetic WITHDRAW-001 into the adapter. It revokes PUR-002 without changing PUR-001. ACK-001 remains absent at the processor target in Chapter 10. A CM’s “accepted” receipt therefore cannot become a Company claim that marketing has ceased remotely. A record-export request returns the CM’s specified consent/notice/sharing record in the agreed machine-readable form; it is not the transfer of a readable bank statement through the CM.
Walkthrough two — a procurement rejection that changes the design. A fictional bidder offers a preference centre labelled “Consent Manager” but supplies no official registration evidence. Procurement classifies it as software and evaluates the configured tooling; it does not reject useful tooling solely because it lacks a statutory role it was never shown to hold. Its separate proposal to relay full readable loan documents through a would-be CM fails the First Schedule opacity requirement. Its promise to delegate all statutory CM obligations to an unnamed subcontractor also fails diligence. Both are documented rejection reasons, not low scores that price can offset.
The bidder can propose a revised architecture with a consent-control channel and independently authorised data transfer, but this book supplies no actual retest or supplier acceptance. A product-level local fixture can only show that its own envelope checks behave as coded. Governance, corporate conflicts, independent certification and live registration remain independent conditions, not fields engineers can fill with true to manufacture compliance.
7. The state analysis: what happens when registration changes
The Consent Manager register is a living thing. Consent Managers will be added, and Consent Managers will be suspended or cancelled. The enterprise’s interop must handle the lifecycle, not just the steady state.
Registration addition. Verify the new official entry, applicable standards, onboarding relationship, audience/purpose mapping and keys before enabling mutations. The Schedule explicitly refers to onboarded fiduciaries (RULES:1451–1467).[3] It does not establish a universal zero-onboarding transport. A valid principal who arrives through a not-yet-mapped surface needs visible assistance and a direct route; technical rejection must not become silent rights abandonment.
Suspension or cancellation. Read the Board’s actual order and protective directions under Rule 4(5), preserve origin records and reconcile queued events. Do not assert that every historical grant automatically survives or automatically becomes void: validity, provenance, continuing conditions and the order require review. Nor should a suspended intermediary’s new unsigned message blindly mutate authority. A previously authenticated withdrawal must be reconciled, and the principal must retain an independently verified way to withdraw. Rule 4(6) concerns information requests (RULES:1050–1063).[3]
This continuity design separates three questions: whether the person remains registered, whether a message is authentic and authorised, and whether the original grant still supports the particular processing. A single registered=true flag cannot answer all three. Preserve the fiduciary’s independently scoped proof retention and the CM’s distinct at-least-seven-year record obligation without applying that period indiscriminately to customer payloads (ACT:264–268; RULES:1471–1485).[1][3]
8. What remains for the reader and the reviewer
The open items, each <residual>:
- Verify current official registration, application particulars, technical standards and any suspension order before actual integration. Q01’s bounded search is not negative assurance about all later publications.
- Obtain entity-specific sector instruments for any AA/health intermediary requirement; resemblance is not legal equivalence.
- Implement and observe production identity, cryptography, ordering, opacity, export and continuity. The fixture remains a bounded teaching test, not integration certification.
- Resolve the earlier-registration enforcement interaction QL-006 without accelerating deferred general procedure or penalties. The First Schedule’s retained requirements are no longer unread residuals.
The question that hands the book its next chapter
Consent can now be given, managed, reviewed and withdrawn through channels the enterprise does not fully control — and every one of those channels eventually connects to the same place: the principal’s other rights. Access, correction, erasure, grievance, nomination — the rights that are not consents but services, and that must run whether the principal arrives in-app, through an intermediary, or at the worst moment of her family’s life. Chapter 12 takes up Rights, Grievances, Identity and Nomination: the case lifecycle that turns Sections 11 to 15 into a machine.
Evidence and reusable artifacts
The primary-text line keys ACT, COMM, RULES and CORR resolve to the retained files below. Line numbers count physical newlines, not PDF form feeds. The canonical provision register supplies actor, trigger, conditions, exceptions and effective dates; chapter recommendations and synthetic examples are not statutory forms. The Q03 source manifest preserves URL, retained retrieval metadata and recalculated hashes.
ACT:research/legal/evidence/01_dpdp_act_2023_gazette.txtCOMM:research/legal/evidence/02_gsr_843e_commencement.txtRULES:research/legal/evidence/05_gsr_846e_dpdp_rules_2025.txtCORR:research/legal/evidence/06_gsr_892e_corrigendum.txt
Completed chapter fragments, before/after evidence and actual local checks: out/remediation/Q03/. Blank operating templates remain under research/operations/templates/; The reconciled integrated dossier is the reader working copy; these chapter fragments preserve the earlier bounded examples and their run evidence.
Sources
[1] https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf — ACT [2] https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf — COMM [3] https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf — RULES [4] https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf — CORR
Contents · Reader guide and citation conventions · Artifact index