Section 6 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Sections 6(7) to (9) create a way for individuals to handle consent through a registered intermediary. A Data Principal may give, manage, review or withdraw consent through a Consent Manager. The Consent Manager is accountable to her, acts on her behalf, and must be registered with the Board. The detailed duties and registration conditions are left to the Rules. If you plan to work with or become a Consent Manager, a legal consultation can help you frame the arrangement.
A Data Principal may give, manage, review or withdraw consent through a Consent Manager (section 6(7)). The Consent Manager is accountable to the Data Principal and acts on her behalf in the manner and subject to the obligations as may be prescribed (section 6(8)). Every Consent Manager must be registered with the Board on technical, operational, financial and other conditions as may be prescribed (section 6(9)). The Board can penalise breach of its obligations (section 27(1)(c) and (d)).
Sub-sections (7) to (9) at a glance
| Sub-section | Rule | Left to the Rules |
|---|---|---|
| 6(7) | Data Principal may give, manage, review or withdraw consent to the Data Fiduciary through a Consent Manager | No |
| 6(8) | Consent Manager is accountable to the Data Principal and acts on her behalf | Manner of acting and obligations |
| 6(9) | Every Consent Manager is registered with the Board | Manner of registration and conditions |
| 2(g) (definition) | A person registered with the Board acting as single point of contact through an accessible, transparent and interoperable platform | No |
What a Consent Manager is
The definition in section 2(g) describes a person registered with the Board who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. The key features are:
- registered with the Board: a person who is not registered is not a Consent Manager under the Act;
- single point of contact: one interface for the Data Principal, instead of dealing with each Data Fiduciary separately; and
- accessible, transparent and interoperable platform: the platform should work across different Data Fiduciaries.
Using a Consent Manager: section 6(7)
Section 6(7) is permissive. The Data Principal "may" use a Consent Manager to give, manage, review or withdraw consent to the Data Fiduciary. It does not oblige her to use one. A Data Fiduciary should therefore keep its own direct consent and withdrawal routes, because section 6(4) requires that the ease of withdrawal be comparable to giving consent, and not every Data Principal will use a Consent Manager.
The four verbs are worth noting: give, manage, review and withdraw. Managing and reviewing go beyond the first grant, so the platform is meant to give the Data Principal an ongoing view of her consents.
Accountability: section 6(8)
The Consent Manager "shall be accountable to the Data Principal and shall act on her behalf". Two consequences follow from the text.
- The Consent Manager owes its accountability to the individual, not to the Data Fiduciary that receives the consent.
- The manner in which it acts and the obligations it owes are "as may be prescribed", so the content of those obligations comes from the rules under section 40(2)(c). The DPDP Rules, 2025 (notified November 2025) prescribe the detail, and different provisions commence on different dates; check the Rules. This article states no obligation beyond the Act's text.
The Act separately lists a grievance right against a Consent Manager. Section 13(1) says a Data Principal has the right to readily available grievance redressal from a Data Fiduciary or Consent Manager, and section 13(2) requires the Consent Manager to respond within the prescribed period.
Registration: section 6(9)
Every Consent Manager must be registered with the Board "in such manner and subject to such technical, operational, financial and other conditions as may be prescribed". The Act fixes the authority (the Board) and leaves the conditions to the rules under section 40(2)(d). As the Board is established by notification under section 18, the registration process depends on the Board's existence and on the Rules.
Enforcement against Consent Managers
The Board has two functions relevant here in section 27(1):
- clause (c): on a complaint by a Data Principal about a Consent Manager's breach of its obligations in relation to her personal data, to inquire and impose penalty as provided in the Act; and
- clause (d): on receipt of an intimation of breach of any condition of registration of a Consent Manager, to inquire and impose penalty.
The Schedule has no entry specific to Consent Managers, so a breach falls under entry 7 (any other provision of the Act or the rules), where the penalty may extend to fifty crore rupees, subject to the "significant" breach test in section 33(1). See the articles on section 27 and on section 33 in this cluster.
What the Act does not say
- It does not say Data Fiduciaries must accept consent only through a Consent Manager.
- It does not say who may become a Consent Manager, other than that registration is required.
- It does not say how fees, if any, work between the Data Principal, the Consent Manager and the Data Fiduciary. Do not assume a model.
- It does not give the Consent Manager rights over the data. It acts on the Data Principal's behalf.
Practical examples
Example 1: one dashboard. A Data Principal has given consent to a bank, an insurer and an online retailer. Through a registered Consent Manager she reviews all three and withdraws consent for the retailer. The retailer must treat the withdrawal like any other under section 6(4) to (6).
Example 2: a Data Fiduciary's system. A lender wants to accept consent through Consent Managers. It should confirm the Consent Manager's registration with the Board and keep its direct consent route open for others.
Example 3: complaint. A Data Principal believes a Consent Manager mishandled her consent record. She can complain to the Consent Manager under section 13 and, after exhausting that, to the Board, which may act under section 27(1)(c).
Common mistakes
- Assuming an unregistered intermediary is a Consent Manager.
- Dropping direct withdrawal routes because a Consent Manager exists.
- Stating specific duties or timelines of Consent Managers without checking the Rules.
Need help with Consent Manager arrangements?
If you plan to accept consent through Consent Managers, or are thinking of building one, you will need to line your contracts and processes up with the Act and the Rules. Speak to us through our legal consultation service and we will look at how the pieces fit.
Key takeaways
- A Data Principal may, but need not, use a Consent Manager to give, manage, review or withdraw consent.
- A Consent Manager is accountable to the Data Principal and acts on her behalf.
- Every Consent Manager must be registered with the Board.
- Obligations and registration conditions are left to the Rules.
- The Board can inquire into a Consent Manager's breach under section 27(1)(c) and (d).
Read next
- Section 6 of the DPDP Act, 2023: withdrawal of consent
- Section 6 of the DPDP Act, 2023: burden of proving notice and consent
- Consent under the DPDP Act: specific and informed
- Data Protection Board of India under section 18
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
