Consent Manager vs. Data Fiduciary: Who Needs to Register With the Data Protection Board?

    Confused about Data Protection Board registration? Here's the real difference between a Data Fiduciary and a Consent Manager under the DPDPA, and what applies to you.

    OneConsentBlog
    10 min read
    Tuesday, 15 September 2026
    Consent Manager vs Data Fiduciary under DPDPA, explaining who needs to register with the Data Protection Board of India.

    A vendor onboarding form asks your organisation to confirm its "registration status with the Data Protection Board of India." A procurement questionnaire from a BFSI client asks the same thing in different words. Your legal team pulls up the DPDP Act looking for a registration section that applies to your organisation, and does not find one that does.

    This is a common point of confusion, and it is worth resolving directly: under the DPDPA, registration with the Data Protection Board of India (DPBI) is a requirement for Consent Managers, not for Data Fiduciaries. Most organisations reading this article are Data Fiduciaries, and Data Fiduciaries are not required to register with the Board before processing personal data.

    This article sets out why that distinction exists, what Consent Manager registration involves, and how to avoid the two related mix-ups that cause most of the confusion: treating Significant Data Fiduciary designation as a form of registration, and treating a Consent Management Platform as the same thing as a registered Consent Manager.

    What Is a Data Fiduciary Under the DPDPA?

    A Data Fiduciary is any person or entity that determines the purpose and means of processing personal data. When an organisation decides why customer data is collected and how it gets used, that organisation is a Data Fiduciary for that data relationship. Most businesses that collect data directly from customers, employees, or users fall into this category.

    For a full breakdown of how this role differs from a Data Processor and a Data Principal, see our guide on Data Fiduciary vs Data Processor vs Data Principal: Who Is Who Under DPDPA? This article focuses narrowly on one question that guide does not answer: what a Data Fiduciary owes the Data Protection Board by way of registration, and the answer is nothing, on the basis of that role alone.

    Whether a Data Fiduciary Needs to Register With the Data Protection Board

    The direct answer, for almost every organisation reading this: no. A Data Fiduciary does not register with the Data Protection Board of India in order to process personal data, hold customer data, or run its business. Registration is not one of the obligations the DPDPA places on Data Fiduciaries.

    This is confirmed by the structure of the Act itself. The DPDPA sets out substantial obligations for Data Fiduciaries, including consent standards under Section 6, notice requirements under Section 5, security safeguards under Section 8, and grievance redressal under Section 13. None of these sections, and no other section of the Act, requires a Data Fiduciary to apply for or hold a registration with the Board. Registration appears in the Act specifically, and only, in connection with Consent Managers, a separate and optional role covered in the next section.

    A useful way to hold this distinction: Data Fiduciaries carry compliance obligations. Consent Managers carry a compliance obligation and a registration requirement, because they are performing a role the Act treats as a regulated function in its own right, distinct from a data processing activity. If your organisation processes personal data for its own business purposes and has not applied to become a Consent Manager, no Board registration step applies to it, now or at any future date under the current Rules.

    What Is a Consent Manager Under the DPDPA?

    A Consent Manager is a different kind of entity entirely. Section 2(g) of the DPDPA defines a Consent Manager as a person registered with the Board who acts as a single point of contact, enabling a Data Principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform.

    A Consent Manager operates as an intermediary between Data Principals and the Data Fiduciaries they interact with. Instead of managing consent separately with a bank, an insurer, and an e-commerce platform, a Data Principal can use a registered Consent Manager as a single dashboard for all of them. The model is closely related to the Account Aggregator framework the Reserve Bank of India already regulates for financial data, and the DPDP Rules, 2025 build on that same architecture.

    Registration is the defining feature of the Consent Manager role, not an incidental requirement attached to it. Section 6(9), read with the definition in Section 2(g), makes registration with the Board a precondition for functioning as a Consent Manager at all. An entity cannot describe itself as a Consent Manager under the DPDPA without being registered. There is no equivalent unregistered version of the role.

    Why This Gets Confused in Practice

    Three things tend to blur this distinction for compliance teams, and each is worth separating out on its own.

    Significant Data Fiduciary designation is often mistaken for registration. Under Section 10, the Central Government may notify a Data Fiduciary, or a class of Data Fiduciaries, as a Significant Data Fiduciary, based on factors such as data volume, sensitivity, and risk. This is a government notification applied to an organisation, not an application the organisation files, and it follows a different process from Consent Manager registration. Our guide on Significant Data Fiduciary obligations under Section 10 covers this designation and its DPO, DPIA, and audit obligations in detail. It does not involve registering with the Board in the sense the Consent Manager framework uses the term.

    A Consent Management Platform is software an organisation deploys, not a registered entity. A Consent Management Platform, commonly shortened to CMP, is a tool a Data Fiduciary uses internally to capture, log, and enforce consent across its own channels. Using a CMP keeps an organisation firmly in its existing Data Fiduciary role, without adding any registration requirement. The two terms sound similar, and procurement and legal teams sometimes conflate them. They describe entirely different things: one is software an organisation operates, the other is a registered third party that individuals use across multiple organisations.

    A Consent Manager is, in one sense, also a Data Fiduciary. Some legal commentary on the Act notes that a registered Consent Manager itself falls within the general Data Fiduciary definition for certain purposes, since it processes consent-related data as part of its function. This relationship does not run in the other direction: being a Data Fiduciary keeps an organisation in that role alone, and moves it toward Consent Manager status only if it specifically applies to become one.

    What Consent Manager Registration Requires

    For organisations weighing whether to take on the Consent Manager role itself, registration is a defined process under Rule 4 of the DPDP Rules, 2025, and Part A of the First Schedule.

    1. Incorporation in India. Only companies incorporated in India are eligible to apply. Foreign entities cannot register directly as Consent Managers.

    2. Minimum net worth of INR 2 crore. The applicant must demonstrate this level of financial standing at the time of application.

    3. Technical, operational, and financial capacity. The applicant must show it can build and run a fully functioning interoperable platform meeting the Board's standards.

    4. Sound management. Directors and key personnel must meet fit-and-proper criteria, and the applicant's business volume, capital structure, and earning prospects must be adequate to sustain the role.

    5. Independence from conflicts of interest. A Consent Manager must not have ownership or management links to the Data Fiduciaries whose consent flows it handles, to preserve its position as a neutral intermediary.

    Once registered, a Consent Manager takes on ongoing obligations under Part B of the First Schedule: maintaining detailed records of every consent given, denied, or withdrawn, retaining those records for a minimum of seven years, giving Data Principals machine-readable access to their own records, and ensuring that personal data routed through the platform is not itself readable by the Consent Manager.

    Rule 4 comes into force on 13 November 2026, which is when the registration framework becomes operational and applications can formally proceed.

    Where the Data Protection Board Stands Today

    This is worth stating plainly, since it affects how organisations should read the timeline above. The Data Protection Board of India was established under Section 18 of the DPDPA through a notification dated 13 November 2025. As of writing, its Chairperson and Members have not been appointed. MeitY invited applications for these posts on 6 May 2026, with a further notification on the appointment process on 6 June 2026. Our guide on how the Data Protection Board of India works covers its powers, procedure, and current status in full.

    The practical effect for this topic is straightforward. Consent Manager registration under Rule 4 depends on a functioning Board to review and approve applications. Organisations exploring the Consent Manager path should track both milestones: the 13 November 2026 commencement of Rule 4, and the Board reaching full strength. Either milestone on its own does not signal that registration is live.

    A Practical Comparison

    The comparison below sets out the distinction in the terms most compliance teams need for a quick internal reference.

    1. Registration with the Board. Data Fiduciary: not required. Consent Manager: mandatory, under Rule 4 and Section 6(9).

    2. Who operates the entity. Data Fiduciary: the organisation itself, for the data it collects directly. Consent Manager: a separate, independently registered third party.

    3. Relationship to the Data Principal. Data Fiduciary: holds a direct relationship as the party collecting and using the data. Consent Manager: acts on the Data Principal's behalf as a neutral intermediary across multiple Data Fiduciaries.

    4. Eligibility to take on the role. Data Fiduciary: any organisation processing personal data for its own purposes. Consent Manager: an India-incorporated company meeting net worth, capacity, and governance criteria under the First Schedule.

    5. Whether the role is optional. Data Fiduciary: not optional. Any organisation determining the purpose and means of processing personal data is automatically a Data Fiduciary. Consent Manager: entirely optional. An organisation applies for this role by choice, and most businesses will never need to.

    What This Means for Your Organisation Today

    Registering as a Consent Manager is a deliberate business decision, relevant mainly to organisations that want to operate the interoperable consent platform itself as a service. It is not something that happens to a business as a byproduct of processing data. If a vendor questionnaire or a client's procurement team asks about your organisation's "DPB registration status," the accurate answer for almost every Data Fiduciary is that no such registration exists for that role, and the question likely stems from the same Consent Manager and Data Fiduciary conflation this article addresses.

    Where OneConsent Comes In

    OneConsent is a Consent Management Platform. It helps an organisation, as a Data Fiduciary, capture purpose-based consent, maintain notice and consent records, and keep that evidence audit-ready across every channel it operates. OneConsent is not the Board-registered Consent Manager entity defined under Rule 4, and does not require that registration.

    For a Data Fiduciary, that distinction works in its favour operationally. An organisation can build a defensible, audit-ready consent programme through a platform like OneConsent today, without waiting for the Consent Manager ecosystem, or the Board itself, to reach full operational strength.

    Answering the Next Vendor Registration Question

    If a compliance or legal team receives a vendor or client query about Board registration, a useful starting point is confirming which role the question is actually asking about: the organisation's status as a Data Fiduciary, or a Consent Manager status it has not applied for and, in the large majority of cases, does not need. OneConsent helps by keeping the underlying evidence, consent records, notice logs, and audit trails ready, so that answer can be backed up with documentation rather than explanation alone.

    Book a demo to see how OneConsent supports Data Fiduciary consent and evidence requirements.

    Visit OneConsent to explore the platform in more detail.

    Frequently Asked Questions

    Have more questions?

    Search our full DPDP knowledge base for more answers.

    See it live

    See OneConsent in action

    Get a personalised walkthrough of how OneConsent helps your teams stay DPDPA compliant.

    • 30-minute walkthrough
    • DPDPA-ready by design
    • Tailored to your stack