DPDP Act Section 9 + Rule 4

Become a Registered Consent Manager Under DPDP Act 2023

A Consent Manager is not just a compliance tool, it is a registered business entity under Section 9 that manages consent for Data Principals across multiple Data Fiduciaries. dcomply gives you the technical stack, consent artefact architecture, API management layer, and structured DPB application workflow to operate as a compliant Consent Manager from day one.

Try the live product
Consent Manager Registration. Draft
Entity: Sharma Digital Services Pvt Ltd
CIN: U72900MH2019PTC324xxx  Verified ✓
─────────────────────────────────
Section 9 Checklist:
[✓] Incorporation proof
[✓] Net worth certificate (>₹2 Cr)
[✓] Technical architecture diagram
[⚠] API interoperability test report ← pending
[✓] Security audit (ISO 27001)
[✗] DPB prescribed format form ← awaiting DPB
─────────────────────────────────
Application Completeness: 83%
Status: READY TO SUBMIT (when DPB opens)
Live application tracker. Section 9 + Rule 4 compliance
The Problem

Three Obstacles Standing Between You and the Consent Manager Market

The Consent Manager framework under DPDP Act is India's Account Aggregator equivalent for data, the first entrants will dominate the market for years. Most companies are blocked by the same three gaps.

No Template for Consent Manager Technical Architecture

Rule 4 requires proof of API interoperability and consent artefact generation capability, but most companies do not know what these mean in regulatory context, let alone how to architect and document them for a DPB application

Consent Artefact Format Not Yet Standardised

DPDP Rules require tamper-proof consent records but do not specify the exact schema. Companies building systems now risk non-compliance when the DPB publishes final technical specifications, dcomply tracks spec evolution and updates your architecture accordingly

First-Mover Advantage Is Real and Time-Limited

India's Account Aggregator framework (NBFC-AA) showed the pattern clearly: the first 3–4 registered entities captured over 80% of market share in year one. The same concentration will happen with Consent Managers, the window to be first is measured in months, not years

Capabilities

The Full Technical and Regulatory Stack for a Consent Manager Business

dcomply is not a form builder, it is the operational platform for companies that want to register and run a Consent Manager under DPDP Act Section 9 + Rule 4.

Section 9 + Rule 4 Compliance Checklist

Every DPB requirement for Consent Manager registration mapped into a structured checklist with regulatory citations: entity eligibility (India-incorporated company with minimum net worth), technical capability proof, security audit requirements (ISO 27001 or equivalent), interoperability standards, grievance redressal mechanism, and net worth declaration. Each item links to the exact provision in the DPDP Act 2023 or DPDP Rules 2025, no guesswork, no gaps.

Consent Artefact Architecture (Rule 4)

The core technical obligation of a Consent Manager: every consent event must generate a tamper-proof "consent artefact", a cryptographically signed, timestamped record that links the Data Principal's pseudonymised identity, the Data Fiduciary's identity, the specific purposes consented to, the lawful basis, and the withdrawal mechanism. dcomply provides the consent artefact schema, signing workflow, storage architecture, and integrity-verification API, all pre-aligned to Rule 4 requirements and ready to demonstrate to the DPB.

Multi-Data Fiduciary API Management (Rule 4(3))

As a registered Consent Manager you connect multiple Data Fiduciaries to your platform via standardised APIs. Rule 4(3) requires Consent Managers to maintain interoperability, dcomply provides the API management layer to onboard each Data Fiduciary, track integration status (endpoint, consent categories mapped, last sync, SLA uptime), flag API drift, and generate the interoperability test report required for DPB registration. Each connected Data Fiduciary's consent flow is isolated, auditable, and configurable.

Data Principal Consent Wallet Interface

The core product a Consent Manager sells: a single interface where Data Principals see all consents they have given, across every connected Data Fiduciary, and can withdraw specific consents, update preferences, or request purpose-wise consent history. This is not a form; it is a live consent management wallet. dcomply provides the white-label Consent Wallet UI, consent state API, withdrawal propagation logic (notifies each Data Fiduciary via API on withdrawal), and audit trail, everything needed to deliver Section 9's mandate to Data Principals.

Audit Log for 5-Year Retention (Rule 4(4))

DPDP Rules require Consent Managers to retain records of every consent transaction for five years, immutably. dcomply's audit log captures every event: consent given, consent modified, consent withdrawn, timestamp, Data Fiduciary identifier, purpose code, Data Principal pseudonym, and artefact hash. The log is append-only, tamper-evident, and exportable in structured format for DPB audit requests. Retention policy, data classification, and cross-border storage restrictions are enforced automatically, nothing falls outside the 5-year window without an alert.

DPB Application Workflow & Submission Tracker

Structured application builder pre-mapped to the anticipated DPB format: entity details, technical specification document, security certifications upload, interoperability proof, financial standing declaration, and grievance mechanism description. Save as draft, iterate as your documentation matures, and attach evidence files directly. When the DPB opens registration, convert the draft to final submission in one step. Track DPB acknowledgment, query responses, and registration status, with automated reminders on pending items and response deadlines.

How It Works

Build Your Consent Manager Business in Four Phases

dcomply takes you from entity check to live Consent Manager operation, covering the regulatory, technical, and operational requirements of Rule 4 end to end.

Phase 1. Eligibility & Entity Readiness

Run the Section 9 eligibility checklist: confirm India incorporation, assess net worth against DPB threshold, verify authorised signatory structure, and identify documentation gaps. dcomply flags every missing item with the specific DPB requirement it maps to, so you know exactly what to fix before investing in the technical build.

Phase 2. Technical Architecture Build

Deploy the consent artefact schema, signing infrastructure, and storage layer inside your environment. Configure the API management layer for your first Data Fiduciary integrations. Run the interoperability test suite and generate the test report the DPB requires as registration evidence. Complete the security audit documentation (ISO 27001 or equivalent) and upload certifications to your application draft.

Phase 3. DPB Application Submission

Finalise the structured DPB application with all entity, technical, and financial documentation attached. When DPB opens registration, submit in one action. Track acknowledgment, respond to DPB queries within deadline, and monitor registration status, all inside dcomply's submission tracker.

Phase 4. Live Consent Manager Operations

Onboard Data Fiduciaries via the API management dashboard. Launch the Data Principal Consent Wallet. Enforce 5-year audit log retention. Run grievance redressal workflows. Generate DPB compliance reports on demand. Operate a Consent Manager business with the same platform you used to build it.

FAQ

Frequently Asked Questions

A Data Fiduciary is any entity that determines the purpose and means of processing personal data, a hospital, an e-commerce platform, a fintech app. A Consent Manager, defined under Section 9 of the DPDP Act 2023, is a registered entity that sits above Data Fiduciaries and provides Data Principals with a single interface to give, manage, and withdraw consent across all the Data Fiduciaries they interact with. The Consent Manager does not itself process the underlying personal data, it manages the consent metadata and consent state on behalf of the Data Principal. Think of the Account Aggregator framework in banking (NBFC-AA under RBI): the AA does not hold your bank data; it manages the consent flow that allows financial institutions to share your data. Consent Managers under DPDP Act 2023 operate on the same principle, but for all personal data, not just financial data.

The Data Protection Board has not yet published the official registration fee schedule for Consent Managers. Based on the DPDP Act 2023 text and the draft DPDP Rules 2025, the anticipated requirements include a minimum net worth threshold (expected to be in the range of ₹2 crore or higher, pending final DPB notification), an application processing fee (to be specified in the official DPB application format, which is not yet published), ongoing compliance costs including security audits, API interoperability certification, and 5-year audit log infrastructure. dcomply monitors DPB notifications and will update fee and format requirements as soon as the official registration process is announced.

Rule 4 of the DPDP Rules 2025 sets out the core technical obligations for registered Consent Managers. The key requirements are: (1) consent artefact generation, every consent event must produce a tamper-proof, signed, and timestamped record linking the Data Principal, Data Fiduciary, and specific purposes; (2) interoperability, the Consent Manager must provide a standardised API layer that Data Fiduciaries can integrate with to send and receive consent state; (3) withdrawal propagation, when a Data Principal withdraws consent, the Consent Manager must notify all relevant Data Fiduciaries via the API in real time; (4) audit log retention, all consent transactions must be retained for a minimum of five years in an immutable log; and (5) grievance redressal, a mechanism for Data Principals to raise complaints about consent management failures. dcomply's technical platform is designed to satisfy all five requirements out of the box.

An existing company incorporated in India can apply for Consent Manager registration, a new entity is not required by the Act. However, Section 9 requires the Consent Manager to operate as a distinct registered entity with the DPB, which means if an existing business also acts as a Data Fiduciary (processes personal data for its own purposes), there may be structural considerations about separation of the Consent Manager function. The DPB's final application format and conditions, which are not yet published, will clarify whether a single legal entity can hold both a Data Fiduciary role and a Consent Manager registration, or whether a separate subsidiary is required. dcomply's application workflow supports both scenarios and will update the eligibility guidance when the DPB publishes final conditions.

Start Building India's Next Consent Manager

The Account Aggregator market showed what first-mover advantage looks like, register early, build the technical stack now, and be ready to submit the moment DPB opens applications

Try the live product View All Features