OBL-47: Consent Manager Interface & Security Standards (Rule 4)
Implements secure APIs, cryptographic logs, and technical specifications for Consent Managers.
Statutory scope: Rule 4 · Assigned to Legal / CM integration owner · Systems: Consent Ledger & Policy Decision Point (SYS-010); synthetic external CM adapter
Recommended interface: Remove real registration/onboarding evidence; expected outcome is production integration blocked, with toy registration never treated as an official record.
Remove real registration/onboarding evidence; expected outcome is production integration blocked, with toy registration never treated as an official record.
Governance & Architecture
Verification Specification & Workpaper
proposed per-row review/acceptance specification; not a claim of executed statutory coverage
populated hypothetical decision/specimen; not actual enterprise execution
Canonical Statutory Grounding
Source references verified against the official Gazette of India publication baseline.
Applicant Consent Manager; Board; registered CM
Application/registration/non-adherence
First Schedule eligibility; published application particulars; Board inquiry/reasoned rejection; obligations; hearing and suspension/cancellation/directions; information power.
No universal unauthenticated interoperability mandate.
CM applicant and registered CM; Board
r4 eligibility/operation
PartA nine eligibility items incl Indian company, >=INR2 crore net worth, independent certification; PartB13 obligations incl onboarded fiduciaries, unreadable data, records/export >=7 years, nondelegation, conflicts, audit/control transfer.
Record term may be longer by agreement/law; control transfer needs Board approval.