What are the requirements for a Consent Manager under the DPDP Rules, 2025?
Answer:
A Consent Manager must be a company registered with the Data Protection Board, with a minimum net worth of Rs 2 crore. It must provide a secure, interoperable and platform-neutral way for individuals to give, manage, review and withdraw consent, act in a fiduciary capacity to the Data Principal, avoid conflicts of interest, and maintain auditable records of consents for at least seven years.
consent manager registration net worth 2 crore seven years records
Related Questions:
- By when do organizations need to technically integrate with Board-registered Consent Managers?
- Is the consent notice required to give contact details?
- What makes consent valid under Section 6 of the DPDP Act?
- Must a Data Fiduciary maintain data accuracy?
- What is the right to correction and erasure?
- How are DPDP penalties determined by the Board?