Consent Managers vs Compliance Tools: What the DPDP Act Actually Regulates

By Aditya Jain · 28 Jul 2026

A Consent Manager is a registered entity with a ₹2 crore net-worth requirement. A compliance tool is software you run. Vendors blur the two, and SMEs buy the wrong thing.

A Consent Manager under India's DPDP Act is a registered, regulated entity — an Indian company, registered with the Data Protection Board, holding a net worth of at least ₹2 crore — that gives individuals a single dashboard to give and withdraw consent across the companies they deal with. A compliance tool is software a business runs to meet its own duties. They are not competing products. They are different layers, and only one of them is registered.

Vendors have spent the last year blurring this, and SMEs are buying accordingly.

What a Consent Manager actually is

Think of it as infrastructure sitting between individuals and the companies holding their data. A person logs into one interface and sees every consent they have given: which company, for what purpose, granted when. They can withdraw one without emailing anybody.

For that to work, the entity running it has to be trustworthy and interoperable, so the Rules put a gate in front of it:

  • Incorporated in India
  • Registered with the Data Protection Board
  • Net worth of at least ₹2 crore
  • Technical capacity to run an interoperable platform
  • Obligations on independence, record-keeping and data handling

The registration window opens in November 2026. This is a small number of specialised entities, not a product category every business shops in.

What a compliance tool is

Software that helps a Data Fiduciary discharge its own duties. It typically holds the data inventory, captures and logs consent at each collection point, tracks data-principal requests against the 90-day clock, stores processing agreements, and keeps the audit trail.

Nothing about that is registered by the Board. If the tool processes personal data on your instructions, it is your Data Processor, and it needs a processing agreement — the same as your payroll vendor or cloud host.

The comparison

Consent ManagerCompliance tool
Who it servesThe individual (Data Principal)The business (Data Fiduciary)
Registered with the BoardYesNo
Net-worth requirement₹2 crore minimumNone
Must be an Indian companyYesNo
Available fromNovember 2026 registration windowNow
Relationship to youIndependent entityYour Data Processor
Does it reduce your liabilityNoNo
Do you need oneOptionalPractically, yes — or an equivalent manual process

The row that matters most is the last-but-one. Neither moves accountability off the Data Fiduciary. The Board comes to you.

Why the confusion is expensive

Three ways this goes wrong in practice.

You buy a "Consent Manager" that is not one. A vendor uses the phrase as marketing for a consent-capture widget. You believe you have engaged a registered entity. You have engaged a Processor, without the processing agreement that should accompany it.

You wait for something you never needed. A founder hears that Consent Manager registration opens in November 2026 and treats that as the start date for their own compliance. It is not. Your duties do not wait on somebody else's registration window, and the inventory work takes months.

You assume liability moved. The most costly version. A tool captured consent, so consent feels handled — but notice quality, purpose limitation, security safeguards, breach reporting within 72 hours, retention and erasure, and the rights-request process are all still yours.

What to ask a vendor

Five questions, and the answers should be immediate:

  1. Are you registered with the Data Protection Board as a Consent Manager, or applying to be? (Before November 2026 the honest answer is no, and that is fine.)
  2. In our arrangement, are you a Data Processor?
  3. Will you sign a processing agreement covering security, breach notification timelines, audit rights, and deletion on termination?
  4. Where is the data stored, who on your side can access it, and how long do you retain it after we leave?
  5. What exactly stays our responsibility?

A vendor that answers the fifth question clearly is worth more than one who claims there is nothing left for you to do.

What you actually need

For most SMEs, in this order:

  1. A data inventory — everywhere personal data lives, why, who can see it, how long it stays.
  2. A consent mechanism at each collection point, with records of what was shown and when.
  3. Processing agreements with every vendor that touches personal data.
  4. A rights-request route with a named owner and the 90-day clock tracked.
  5. A breach playbook that survives being read at 2am.

Software helps with 1, 2 and 4, and stores 3. None of it decides your purposes or runs your breach response. That part stays human.

Where CapEasy fits

We run the inventory, close the gaps, and put the notices, agreements and playbooks in place for companies without in-house counsel.

Pramaan is our DPDP platform for Data Fiduciaries: it maps what you hold, tracks consent and data-principal requests, and keeps the audit trail that becomes your evidence if the Board asks. *(Pramaan is a compliance tool for Data Fiduciaries. It is not a registered Consent Manager under the DPDP Rules — and if a vendor tells you their software is one before the registration window opens, ask to see the registration.)*

This article is general information, not legal advice. Regulations change and interpretations evolve. Verify against the current Gazette notification or consult a qualified professional before acting.

Frequently asked questions

Does every business need to appoint a Consent Manager?

No. A Consent Manager is an optional route for individuals to manage their consents, not a vendor every Data Fiduciary must engage. Nothing in the Act requires you to appoint one. What you must do is obtain, record and honour consent yourself.

What does it take to become a registered Consent Manager?

Registration with the Data Protection Board, incorporation as an Indian company, a net worth of at least ₹2 crore, demonstrated technical capacity to operate an interoperable consent platform, and obligations around independence and record-keeping. It is an infrastructure role, not a software licence.

When does Consent Manager registration open?

The registration window opens in November 2026 under the phased schedule in the DPDP Rules, 2025. Substantive obligations for Data Fiduciaries become enforceable in May 2027.

Is compliance software regulated under the DPDP Act?

Not as a category. If a tool processes personal data on your instructions it is your Data Processor, and you need a processing agreement with the vendor. But the software itself is not registered or licensed by the Board the way a Consent Manager is.

A vendor told us their product makes us DPDP compliant. Is that possible?

No product delivers compliance on its own. Software can hold the inventory, capture consent, track requests and keep the audit trail. It cannot decide your purposes, write your contracts with processors, or run your breach response. Treat any 'fully compliant in one click' claim as a reason to read the contract more carefully.

If we use a registered Consent Manager, does our liability shift to them?

No. You remain the Data Fiduciary. A Consent Manager gives individuals a way to manage consents across companies; it does not take on your notice, security, breach reporting or erasure duties.

Aditya Jain

Co-Founder, CapEasy

Co-founder of CapEasy, working with Indian startups and SMEs on compliance, structuring and growth.

Connect on LinkedIn

Book a free consultation.

An honest assessment of where you are and what comes next — no cost, no pressure, no inflated promises.