Most descriptions of India's DPDP Rules move quickly past the Consent Manager framework, treating it as a technical footnote to the bigger story of notice and consent obligations. That undersells how structurally unusual it is. A Consent Manager is a registered, interoperable platform through which an individual — a Data Principal, in the Act's language — can give, manage, review, and withdraw consent across multiple organisations from a single interface, rather than managing separate consent relationships with every bank, app, and service provider that touches their data.
The closest working analogy in Indian regulation is the account aggregator framework already operating in financial services, where a licensed intermediary moves financial data between institutions with the customer's explicit, revocable consent, rather than each bank negotiating data-sharing bilaterally. The DPDP framework borrows that architecture and applies it economy-wide, to any personal data processing, not just financial data.
Registration for Consent Managers opens on 13 November 2026, run by the Data Protection Board. Once the framework is live, any organisation processing personal data in India needs to think about a channel it has never had to design for before: consent that arrives not directly from the individual, but through a third-party intermediary acting on the individual's instruction, with its own registration requirements, technical standards, and revocation obligations. Organisations that have only ever built a checkbox-based consent flow will need an integration layer they do not currently have.
It is early enough in the rollout that the practical shape of Consent Manager adoption — how many register, how quickly individuals actually use them instead of managing consent directly — is still unknown. But the design intention is clear: India is building a market for consent infrastructure, not just a compliance obligation, and that is a meaningfully different bet than GDPR ever made.