General awareness
Kya aapka startup bhi anjaane mein DPDP law tod raha hai?
- Does building a consent banner make you a Consent Manager?
- No. A consent notice and a grievance form are standard duties for any organisation handling personal data. A Consent Manager is a specific role registered with the Data Protection Board, and the claim is one investors and regulators can test.
- Who this affects
- Founders, and anyone writing product or investor material.
- What to do about it
- Say you manage consent, not that you are a Consent Manager, unless you are actually registered.
Surya's startup shipped a clean consent banner and a grievance email that auto generates a ticket. That evening, in the investor deck, he added a line under "Product Moat": "We are a certified Consent Manager for our users' data."
A friend on the review call paused. "Wait, are you actually registered as a Consent Manager? With the Board?"
Surya wasn't. He had built a consent notice and a grievance form, standard for any company handling personal data. Somewhere along the way, "we manage consent" became "we are a Consent Manager" in his head, and it was now sitting in a deck investors would expect proof for.
The distinction matters before it lands in a legal filing instead of a slide.
What Surya actually is
Every company that collects and uses personal data is a Data Fiduciary. That is Surya's startup. Under the DPDP Rules, a Data Fiduciary must issue a clear notice before collecting data, make consent as easy to withdraw as it was to give, and run a grievance channel for its users. These are baseline duties. You do not apply for them and you do not get certified for them. You just have to do them.
What a Consent Manager is
A Consent Manager is something else entirely, defined under Rule 4 and the First Schedule. It is an independent, India incorporated company registered with the Data Protection Board, with a minimum net worth of Rs 2 crore, running a platform where a person manages consent across many companies, not just yours. It is legally required to be data blind, routing your bank statement between companies without reading it, and it cannot simultaneously act as a Data Fiduciary or a processor for that same person.
So Surya's consent banner and grievance form do not make his startup a Consent Manager. They make it a compliant Data Fiduciary. That is a real achievement, just not the one on his slide.
The twist in the timeline
Worth checking before your next investor call. Consent Manager registration under Rule 4 goes live on 13 November 2026. But the baseline Data Fiduciary duties Surya already built only become fully enforceable later, on 13 May 2027. The licensing track for professional Consent Managers switches on before the obligations ordinary companies must meet do.
Surya edited the slide: "DPDP ready consent and grievance infrastructure, built ahead of the compliance deadline." True, defensible, and no Board certificate required.
If your deck or your compliance policy calls your company a Consent Manager, it is worth checking whether that is true, or whether it is Surya's mistake in a different outfit.