DPDP Rule 4 · First Schedule Parts A + B · Commences 13 Nov 2026

DPDP Consent Manager registration eligibility, in 6 factors.

Only a Companies-Act company with audited net worth of at least ₹2 crore, fit-and-proper directors, technical capability to interoperate with every Data Fiduciary, and true independence from any Fiduciary customer can register as a Consent Manager. This tool walks the six Rule 4 factors, flags the four hard statutory gates, and returns your readiness score with a full reasoning trace citing First Schedule Parts A and B. You can print the result as a Board memo.

Rule 4 commencement
13 November 2026
CMs formally registered
0 · window opens 13 Nov 2026
MeitY Code-for-Consent prototype builders
Jio · IDfy · Redacto · Zoop · Concur · Aurelion
Statutory floor
₹2 crore audited net worth

Factor 1 — Corporate structure

DPDP Rule 4 · Section 6(7)–(9) · First Schedule Part A HARD GATE
Yes, private/public/OPC
Yes
< 1 yr

Factor 2 — Financial threshold

First Schedule Part A · ₹2 crore floor HARD GATE
< ₹2 cr
Yes, statutory audit signed
Yes, all 3

Factor 3 — Fit-and-proper directors

First Schedule Part A · Companies Act Sec. 164 HARD GATE
No
No
Yes, all Indian residents

Factor 5 — Independence

First Schedule Part A · Independence & no conflict HARD GATE
No, fully independent
No, CM function only

Factor 4 — Technical capability

First Schedule Part B · interoperability, notice rendering, audit log
Yes, in prod
Yes, India-only region
Yes, published
Yes, all 22
Both

Factor 6 — Operational readiness (First Schedule Part B)

7-year consent-log retention, grievance officer, periodic DPB returns
Yes, WORM / immutable
Yes
Yes, compliance team in place
Please answer all 15 questions. question(s) still need an answer. We scrolled to the first one for you.
100% client-side. No data leaves your browser.

Reasoning trace

Your 10-item pre-application checklist

Print this as a Board memo

Use browser print (Cmd/Ctrl+P) → Save as PDF. Landscape orientation recommended.

Ready to prepare an actual application?

dcomply's Consent Manager Registration module (Business tier) covers First Schedule Parts A + B compliance mapping, document assembly, board resolutions, technical-capability evidence pack, and DPB submission workflow.

How this tool scores

4 hard gates (incorporation, ₹2 cr net worth, fit-and-proper, independence) — failing any one makes registration impossible in current form.

Weighted score /100 across technical capability + operational readiness — determines whether you're application-ready today or need 6-18 months of build.

All logic runs client-side. Nothing leaves your browser. This is guidance, not legal advice.

Rule 4 in 60 seconds

Commences: 13 November 2026

Applicant must be: Companies-Act-2013 company, India-incorporated, ₹2 cr audited net worth

First Schedule Part A: fit-and-proper directors, independence, capital adequacy

First Schedule Part B: 22-language notices, 7-year consent-log retention, DPB-notified interoperability, periodic returns

Read the full DPDP Act guide →

Context

The Consent Manager landscape today

0 registered so far

No Consent Manager has been formally registered under Rule 4. The registration window opens 13 November 2026 with Rule 4 commencement.

6 MeitY prototype builders

Code-for-Consent challenge (2025) selected Jio Platforms, Baldor (IDfy), VertexTech (Redacto), Zoop (Quagga), Concur, and Aurelion Future Forge as reference builders.

₹2 cr floor squeezes startups

Net-worth threshold plus independence requirement narrows the eligible pool. Most bootstrapped consent-tech vendors will not qualify without external capital.

Answers

Frequently asked about Consent Manager registration

DPDP Rule 4 (Registration and obligations of Consent Managers) commences 13 November 2026 per the second phase of the DPDP Rules 2025 notification. The full substantive framework in Rules 3, 5-16, 22, 23 follows on 13 May 2027.

Only a company incorporated under the Companies Act 2013 with audited net worth of at least ₹2 crore. LLPs, partnerships, sole proprietorships, and foreign entities are ineligible. The applicant must also demonstrate technical, operational, and financial capability, and comply with the operational obligations in the First Schedule Parts A and B.

Rule 4 read with First Schedule Part A requires the applicant to have audited net worth of not less than ₹2 crore at the time of application, based on the most recent audited financial statements. The DPB may seek 3-year solvency evidence in practice.

The First Schedule requires directors and key managerial personnel to be persons of integrity, not disqualified under Section 164 of the Companies Act 2013, and not convicted of an economic offence in the last 5 years. Any conviction, disqualification, or ongoing insolvency proceeding is a bar.

The First Schedule Part B requires: interoperability with Data Fiduciaries in the DPB-notified format; secure storage of consent artifacts for at least 7 years; ability to render consent notices in the 22 Eighth Schedule languages; audit-log capabilities; grievance redressal within statutory timelines; and periodic reporting to the DPB.

No. The independence requirement in First Schedule Part A prohibits a Consent Manager from being controlled by, or having material commercial interest in, any Data Fiduciary that would use its services. A CM cannot process personal data outside its consent-management function.

No. As of the last public update, no Consent Manager has been formally registered. The registration window opens with Rule 4 commencement on 13 November 2026. MeitY's 2025 Code-for-Consent challenge selected 6 prototype builders: Jio Platforms, Baldor Technologies (IDfy), VertexTech Labs (Redacto), Zoop (Quagga Tech), Concur, and Aurelion Future Forge.

First Schedule Part B requires retention of consent artifacts for at least 7 years after the consent lifecycle ends (given, updated, withdrawn, or expired). The consent artifact must remain retrievable by the Data Principal and the DPB for that period.

Continuing capital adequacy at the ₹2 crore floor, periodic technical audits, annual returns to the DPB, immediate incident reporting, grievance-redressal SLAs, and full cooperation during any DPB inquiry under Section 28. Non-compliance may result in de-registration.

Depending on which factor failed, the path differs. Corporate structure gap: consider re-incorporating as a Companies Act 2013 company. Net-worth gap: raise capital or wait until audited financials support the ₹2 crore floor. Fit-and-proper gap: restructure the board. Independence gap: unwind commercial ties with any prospective Data Fiduciary customer. Technical gap: partner with a platform provider or build over 12-18 months. dcomply's Consent Manager Registration module (in the paid Business tier) helps with document preparation, First Schedule compliance mapping, and DPB submission workflow.