Published On: August 18, 2026
Authored By: Kalpita Krishnakumar
Woxsen University
Introduction
India’s data protection regulatory framework has seen significant developments following the enactment of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.[1] Under Section 2(g) of the DPDP Act, 2023, a Consent Manager is defined as a person registered with the Board who acts as the single point of contact enabling a Data Principal (user) to give, manage, review, and withdraw her consent through an accessible and transparent platform.[2] A Data Principal means the individual to whom the personal data relates, as defined under Section 2(j) of the DPDP Act, 2023.
The DPDP Rules, 2025 operationalise the DPDP Act, 2023. The Act’s implementation has proceeded in phases: the first phase established the Data Protection Board of India (DPBI),[3] while the second phase, which brings the Consent Manager framework into force, is set to take effect on November 13, 2026.
Under Section 6(7) of the DPDP Act, 2023, the Consent Manager operates as a new intermediary mechanism between the Data Principal and the digital platform.[4] The user can now grant, review, manage, and withdraw consent through the Consent Manager. By November 2026, enterprises that rely on consent-based data processing will be required to technically integrate with these registered platforms through mandatory application programming interfaces.
However, this also creates a paradox: although the Consent Manager is intended to relieve consent fatigue, it inserts itself between the Data Principal and the Data Fiduciary, introducing a difficult legal question about statutory accountability when systemic or technical failures occur within that intermediary layer.
Legal Analysis: The Mechanics of the Friction
Making the Consent Manager mandatory restructures the lifecycle of user consent into discrete digital tokens. Instead of the enterprise directly maintaining the record of user consent, that record now becomes a variable controlled by an external, third-party intermediary.
Under Section 6(1) of the DPDP Act, any consent must be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action.[5] Consider a high-frequency scenario: a Data Principal withdraws consent from a Data Fiduciary — an e-commerce platform — that uses their location data. The Consent Manager records the withdrawal, but an API failure prevents this information from reaching the Data Fiduciary. From that moment, the platform continues processing the user’s data on the basis of consent that is no longer valid. Under Section 6(6) of the Act, a Data Fiduciary is required to cease processing personal data within a reasonable time once consent has been withdrawn.[6]
The fiduciary, in this scenario, is therefore in breach of the Act — through no fault of its own technical systems, but because of a failure in the intermediary’s pipeline.
This raises a genuine legal question: can a fiduciary be penalised for a violation caused entirely by the intermediary’s failure of performance? Under data protection regimes generally, good faith reliance on a broken API pipeline is rarely accepted as a defence. This leaves the fiduciary exposed to the legal consequences of a violation it did not directly cause.
Allocation of Fault and the ₹250 Crore Penalty Ceiling
This tension between technical failure and legal liability becomes especially acute when viewed against the penalty structure set out in the DPDP Act’s Schedule. The Data Protection Board may impose penalties of up to ₹250 crore for failure to implement reasonable security safeguards resulting in a personal data breach, and up to ₹50 crore for other, more general violations of the Act or its Rules.
No mechanism currently exists to apportion liability between the Data Fiduciary and the Consent Manager where a tokenised consent-flow failure occurs. The extent of the Consent Manager’s own liability is left almost entirely to the Data Protection Board’s interpretation.
Supporting Authority: Statutes, Policies, and Precedents
1. Statutory Provisions of the DPDP Rules, 2025
Rule 4 of the DPDP Rules, 2025, read with the First Schedule, establishes the foundational obligations and liabilities of Consent Managers. It requires them to operate a secure and neutral platform, maintain grievance redressal mechanisms independent of the Data Fiduciaries they work with, and refrain from sub-contracting their core tokenisation function to any other entity. In doing so, the Rule treats Consent Managers as distinct legal actors, separate from the Data Fiduciary, and subjects them to close and continuing regulatory oversight rather than treating them as a plug-and-forget technical layer. The Data Protection Board of India is responsible for supervising this compliance: where a Consent Manager’s system fails, the Board may direct corrective action and, in serious cases of non-compliance, suspend or cancel its registration.
2. Comparative Policy Frameworks
The Consent Manager framework draws on the Reserve Bank of India’s Account Aggregator framework, which governs financial data sharing across banks. Account Aggregators function as data-blind pipelines: they cannot read, view, or store the consumer data that passes through their systems, which protects that data from misuse by the intermediary itself. Given how sensitive financial data is, this safeguard is treated as a top priority in that sector. Unlike Consent Managers under the DPDP framework, these financial intermediaries are directly accountable to the RBI for the financial information that passes through their systems. A similar direct-accountability model should arguably be built into the DPDP framework, since holding the Data Fiduciary liable for the intermediary’s failures creates a disproportionate burden on the fiduciary even where the fault lies entirely with the Consent Manager. Failures in the data-transfer pipeline should, in principle, be attributed to the intermediary responsible for them.
Constitutional Foundation in K.S. Puttaswamy v. Union of India (2017)
The Supreme Court’s landmark nine-judge bench decision in K.S. Puttaswamy v. Union of India[7] held that the right to privacy is a fundamental right under Article 21 of the Constitution of India.[8] The Court laid down a threefold test for evaluating any state or regulatory intrusion into privacy: legality, legitimate aim, and proportionality.
Legality requires that the state cannot restrict a person’s fundamental right to privacy merely on the basis of executive discretion; there must be a clear, enacted statute passed by Parliament. Legitimate aim requires that the state’s objective not be arbitrary, trivial, or politically motivated — it must serve a defined purpose such as public policy, crime prevention, or national security. The third limb, proportionality, requires that the state’s intrusive method be rationally connected to its goal, that no less intrusive alternative was reasonably available, and that the public genuinely benefits from the state’s action.
Applying this framework to the DPDP Act, any processing of an individual’s data must be conducted in a manner consistent with law, and any intrusion into that data outside these bounds would amount to a violation of the individual’s fundamental rights.
Conclusion: The Outlook for Corporate Architecture
The introduction of the Consent Manager framework on November 13, 2026 creates an unavoidable challenge for corporate compliance architecture. To navigate it, enterprises must look beyond baseline IT adjustments and carefully structure their contractual and legal protections.
Because the DPDP framework does not currently resolve liability for intermediary errors, businesses cannot rely on Consent Managers blindly; they must actively oversee the intermediary’s functioning and its compliance with data protection obligations. Until the Data Protection Board of India clarifies these liability gaps through formal guidance or case law, every incoming digital consent token should be treated as a potential regulatory risk.
In the absence of statutory guidance, businesses will need to take the lead in building their own legal and technical safeguards. This means negotiating strong SLAs with clear technical indemnities that place financial responsibility on the intermediary when an API failure occurs, and implementing real-time consent verification systems and immutable data logs within the enterprise. Ultimately, navigating the DPDP transition will depend on an enterprise’s capacity to legally partition its liability and demonstrably prove its own compliance even when automated data pipelines inevitably fail.
References
[1] Digital Personal Data Protection Act, No. 22 of 2023, India Code (2023); Digital Personal Data Protection Rules, 2025, Gazette of India, pt. II sec. 3(i) (Nov. 13, 2025).
[2] Digital Personal Data Protection Act, No. 22 of 2023, § 2(g), India Code (2023).
[3] Digital Personal Data Protection Act, No. 22 of 2023, § 18, India Code (2023).
[4] Digital Personal Data Protection Act, No. 22 of 2023, § 6(7), India Code (2023).
[5] Digital Personal Data Protection Act, No. 22 of 2023, § 6(1), India Code (2023).
[6] Digital Personal Data Protection Act, No. 22 of 2023, § 6(6), India Code (2023).
[7] Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
[8] INDIA CONST. art. 21.




