DPDP Roles, explained simply

India's Digital Personal Data Protection Act. Who is who.

‹ General awareness

General awareness

Kya aapka startup bhi anjaane mein DPDP law tod raha hai?

Does building a consent banner make you a Consent Manager?
No. A consent notice and a grievance form are standard duties for any organisation handling personal data. A Consent Manager is a specific role registered with the Data Protection Board, and the claim is one investors and regulators can test.
Who this affects
Founders, and anyone writing product or investor material.
What to do about it
Say you manage consent, not that you are a Consent Manager, unless you are actually registered.

Surya's startup shipped a clean consent banner and a grievance email that auto generates a ticket. That evening, in the investor deck, he added a line under "Product Moat": "We are a certified Consent Manager for our users' data."

A friend on the review call paused. "Wait, are you actually registered as a Consent Manager? With the Board?"

Surya wasn't. He had built a consent notice and a grievance form, standard for any company handling personal data. Somewhere along the way, "we manage consent" became "we are a Consent Manager" in his head, and it was now sitting in a deck investors would expect proof for.

The distinction matters before it lands in a legal filing instead of a slide.

What Surya actually is

Every company that collects and uses personal data is a Data Fiduciary. That is Surya's startup. Under the DPDP Rules, a Data Fiduciary must issue a clear notice before collecting data, make consent as easy to withdraw as it was to give, and run a grievance channel for its users. These are baseline duties. You do not apply for them and you do not get certified for them. You just have to do them.

What a Consent Manager is

A Consent Manager is something else entirely, defined under Rule 4 and the First Schedule. It is an independent, India incorporated company registered with the Data Protection Board, with a minimum net worth of Rs 2 crore, running a platform where a person manages consent across many companies, not just yours. It is legally required to be data blind, routing your bank statement between companies without reading it, and it cannot simultaneously act as a Data Fiduciary or a processor for that same person.

So Surya's consent banner and grievance form do not make his startup a Consent Manager. They make it a compliant Data Fiduciary. That is a real achievement, just not the one on his slide.

The twist in the timeline

Worth checking before your next investor call. Consent Manager registration under Rule 4 goes live on 13 November 2026. But the baseline Data Fiduciary duties Surya already built only become fully enforceable later, on 13 May 2027. The licensing track for professional Consent Managers switches on before the obligations ordinary companies must meet do.

Surya edited the slide: "DPDP ready consent and grievance infrastructure, built ahead of the compliance deadline." True, defensible, and no Board certificate required.

If your deck or your compliance policy calls your company a Consent Manager, it is worth checking whether that is true, or whether it is Surya's mistake in a different outfit.

#DPDP #StartupLife #FounderTips #DataPrivacy #TechLaw #Regulatory #DigitalIndia #PitchDeck #PrivacyRules #Startup

An infographic contrasting the confusion, a founder writing we are a certified Consent Manager in an investor deck, with the reality, that a consent banner and a grievance email do not make you a Consent Manager. A Data Fiduciary must issue a clear notice before collecting data, make consent as easy to withdraw as to give, and run a grievance channel; these are baseline duties you do not apply for. A Consent Manager is different: an independent India incorporated company registered with the Data Protection Board, minimum net worth Rs 2 crore, running an interoperable platform that manages consent across many companies, data blind so it can route data but not read it, and barred from acting as a Data Fiduciary or processor for the same person. The timeline: Consent Manager registration under Rule 4 goes live on 13 November 2026, while baseline duties for Data Fiduciaries become fully enforceable on 13 May 2027, so the licence for Consent Managers starts before companies' basic duties become enforceable.
Doing your duty as a Data Fiduciary is not the same as being a registered Consent Manager. Tap to enlarge.

Get DPDP ready in hours, not weeks

Take the readiness assessment and generate your compliance documents from your answers.

Assess My Readiness