A platform recently published a blog titled "List of Govt-Registered Consent Managers in India 2026."
Eight companies. Polished logos. Confident framing. Positioned as the definitive guide to India's consent management ecosystem before the Digital Personal Data Protection Act kicks in.
We read it carefully. Then we read the fine print at the bottom.
Their own disclaimer states:
"For the purposes of this list, 'Government registered' refers to entities that are formally incorporated as companies under the laws of the Government of India."
Companies Act incorporation.
Not Data Protection Board registration. Not DPDPA Consent Manager registration. Not anything to do with Section 6(9) of the Act.
So let's answer the actual question plainly:
How many platforms are registered as Consent Managers under the DPDPA with the Data Protection Board of India?
Zero.
Not eight. Not one. Zero.
Because registration isn't open yet — and won't be at least until November 13, 2026.
Anyone calling themselves a "government-registered Consent Manager" before that date is not describing their DPDPA status. They are describing the fact that they filed their company incorporation papers.
What Is a DPDPB-Registered Consent Manager, Actually?
The term "Consent Manager" has a precise legal definition under the DPDPA, 2023 and the DPDP Rules, 2025. It is not a product category. It is not a marketing label. It is not something you become by building a consent banner.
Under Section 6(9) of the DPDPA, a Consent Manager is a registered entity through which a Data Principal — a person — can give, manage, review, and withdraw consent across multiple Data Fiduciaries through a single, interoperable platform. The Consent Manager is accountable to the Data Principal, not the Data Fiduciary. That distinction matters enormously.
To be a Consent Manager under the DPDPA, an entity must:
- Be incorporated as a company in India
- Maintain a minimum net worth of ₹2 crore
- Register with the Data Protection Board of India (DPDPB)
- Maintain interoperability with other Consent Managers
- Operate under a fiduciary obligation to the Data Principal
- Undergo periodic audits as specified by the Board
This is a regulated role. Not a feature. Not a module. Not an upsell.
When Does Registration Open?
DPDPB Consent Manager registration opens on November 13, 2026 — exactly one year after the DPDP Rules were notified on November 13, 2025.
The Rules explicitly state that provisions relating to Consent Managers come into force twelve months post-notification. Until that date, no entity can be registered. No entity has been reviewed. No entity has been assessed by the Board.
Every company currently calling itself a Consent Manager — registered or otherwise — is describing a product, not a legal status. That is fine, as far as it goes. But conflating the two is a disservice to every Data Fiduciary trying to make informed compliance decisions in a genuinely complex regulatory environment.
"But Registration Isn't Mandatory" — A Word on Risk Transfer
Some interpret the DPDPA framework to mean that Consent Manager registration is not mandatory — that a Data Fiduciary may choose any tool, registered or not, to manage consent. We cannot definitively dispute that interpretation.
What we can say is this: if you choose an unregistered Consent Manager and that choice is later scrutinised by the Data Protection Board, the burden of that decision rests entirely with you — the Data Fiduciary. The registration framework exists precisely to create accountability. Opting outside it doesn't eliminate accountability; it relocates it. Assess the consequence, then decide.
Who Was on That List — and Why It Matters
The eight platforms span a US-headquartered GDPR tool, KYC and identity verification products, a listed cybersecurity company, eSign infrastructure players, and an AI-driven data redaction startup. Several are serious products. None are DPDPB-registered Consent Managers — because that registration framework does not yet exist.
What the list actually shows is which companies have incorporated in India and are positioning ahead of November 2026. That is a legitimate observation. Calling it a government registration list is not.
What Should a Data Fiduciary Actually Look For Right Now?
Since DPDPB registration isn't open, the meaningful questions for any Data Fiduciary evaluating a consent management platform today are:
1. Is it purpose-built for DPDPA — or adapted from GDPR? The DPDPA has fundamental structural differences from GDPR. Legitimate Use processing, for instance is fundamentally different for DPDPA. The 2D consent matrix — one-time vs. recurring, legitimate use vs. business case — has no GDPR equivalent. Platforms built around GDPR's legal basis framework have to be reverse-engineered to fit India's framework. That shows.
2. Does it handle India-specific rights correctly? Section 14 of the DPDPA — the Right to Nominate a representative in the event of incapacitation — is unique to DPDPA. Does the platform support it?
3. Does discovery go beyond data scanning? Finding PII in databases is table stakes. The harder problem is finding PII collection points in application source code — the forms, the API parameters, the third-party SDK calls — before that data ever reaches a database. Code-level discovery is what makes consent configuration accurate and defensible. Is this offered?
4. Is data processed and stored in India? DPDPA's data localisation expectations, combined with the sensitivity of consent records, make APAC-hosted infrastructure non-negotiable for serious compliance. Add this to your evaluation metris.
5. Is breach management human-led — or fully automated? The DPDPA's 72-hour notification obligation to the Data Protection Board is not a box to be auto-ticked. A breach notification sent without human review of scope, attribution, and regulatory language is a liability, not a compliance act. Certain platform have confirmed fully automated breach notification — no human gate before the notification fires. We believe that is wrong. Decide and plan this pre-requisite.
6. Is the vendor prepared to register on Day 1? Who is actually building toward Consent Manager registration — with the governance structure, the interoperability standards, the Board-compliant data architecture — not just building a product and hoping the label fits?
7. Does your advisory have a conflict of interest in the tool they recommend? The DPDPA and MeitY's framework for Consent Managers explicitly contemplates the need to avoid material pecuniary relationships that could compromise independence. That same standard should apply to the advisories recommending these tools. If the firm advising you on consent manager selection has a financial relationship — equity, referral fees, reseller arrangements — with the platform they're recommending, that is a conflict of interest. Ask the question directly before you take the recommendation.
Where truConsent Stands
truConsent is India's Privacy Intelligence Suite — purpose-built for DPDPA from the ground up.
Not a GDPR tool with an India checkbox. Not a KYC platform with a consent module bolted on. Not a cybersecurity company treating CMP as an upsell opportunity.
On transparency: we are, as far as we know, the only consent management platform that already displays the transparency disclosures expected of a registered Consent Manager — publicly, on our site. You can read them today at truconsent.io/why-truconsent. We are not waiting for November 13 to start behaving like a registered entity.
We will not call ourselves registered until we are. We will not use regulatory-sounding language to describe a Companies Act filing. We are building toward Consent Manager registration with the Data Protection Board of India, and we intend to be among the first registered on November 13, 2026.
We believe the Indian enterprises making DPDPA compliance decisions deserve better than that — and we intend to earn their trust by being precise about what we are and what we are not, at every stage.
The Bottom Line
If you are a Data Fiduciary evaluating consent management platforms ahead of the DPDPA enforcement window, ask a simple question of every vendor on any list you read:
"Are you registered as a Consent Manager with the Data Protection Board of India?"
The honest answer, from every platform in the market today, is: No. Registration opens November 13, 2026.
Any other answer is either a misunderstanding of the regulatory framework, or a deliberate use of language designed to mislead.
Choose your compliance partner accordingly.
truConsent is India's Privacy Intelligence Suite, incubated at IIT Madras Incubation Cell. Platform live at truconsent.io. For questions on DPDPA compliance architecture, write to us at [email protected].