5 min
Cookie CMP vs DPDP Consent Manager for Scheduled Banks
An analysis of the operational differences between frontend cookie platforms and DPDP-registered Consent Managers for BFSI compliance teams.
Last updated:
Cookie CMP Preference Center Versus DPDP Consent Manager
A website cookie Consent Management Platform captures browser marketing preferences. A DPDP Consent Manager is a legally distinct entity acting on behalf of the Data Principal under Section 6 of the Digital Personal Data Protection Act, 2023. Compliance officers at scheduled banks evaluate both systems. The CMP runs on the bank domain to govern browser scripts and advertising tags. The Consent Manager operates externally. It brokers consent requests across multiple fiduciaries.
Section 6(8) defines this manager as accountable to the Data Principal. Section 6(9) requires every Consent Manager to be registered with the Data Protection Board of India. These entities operate subject to specific technical and operational conditions. Your existing website CMP manages cookie banners on public domains. It does not integrate deeply into core banking systems to manage transactional consent states. Resolving this architecture gap requires mapping external signals to internal databases.
Translating Section 5 Notice Obligations
Section 5(1) requires a Data Fiduciary to provide a notice before or during a consent request. This notice informs the individual of the personal data collected and the proposed purpose of processing. The fiduciary outlines the withdrawal mechanism and the right to complain to the Board. A standard cookie CMP presents a brief paragraph and an accept button. A DPDP Consent Manager handles structured consent artifacts. These artifacts tie a specific Section 5 notice version to a timestamped user action.
Section 6(10) requires the Data Fiduciary to prove that notice was given and consent was obtained. Relying on an isolated website CMP to log consent for backend operations fails this evidence test. A core banking application needs an immutable record. It links the user identity to the exact notice text presented at the time of data collection. Banks process high volumes of personal data for loan originations and credit card issuance. A registered Consent Manager allows a customer to govern all these interactions from a single external dashboard.
Integrating Core Banking Systems With External Managers
Scheduled banks do not need to discard existing web CMPs. These tools adequately log frontend analytics preferences for marketing domains. The compliance gap lies in core banking applications that lack interfaces with DPBI-registered Consent Managers. An institution needs a mechanism to receive verifiable consent artifacts from these external entities in real time. Control owners deploy a system that translates inbound artifacts into runtime enforcement across legacy databases.
When an external consent signal arrives, the internal architecture applies the preference to the specific customer profile. Engineers map data elements to the purposes declared in the Section 5 notice. A customer might grant consent for a wealth management review but deny it for third-party insurance cross-selling. The backend systems process these signals. They activate or restrict data flows to respective departments. Frontend cookie banners cannot enforce this internal data segregation.
Processing Withdrawals Under Section 6
Section 6(4) grants the Data Principal the right to withdraw consent at any time. The ease of withdrawal needs to be comparable to the ease of giving consent. A customer who provided consent via an external Consent Manager will likely trigger their withdrawal through that same platform. The manager sends a secure payload to the bank indicating the revocation. Section 6(5) states the individual bears the consequences of this withdrawal. Prior processing based on consent remains legal.
A core banking system receives the withdrawal signal. It flags the specific processing purpose as inactive. The bank stops the relevant marketing flow or elective service. It does not purge the underlying financial transaction histories or structural account data. Configuring a withdrawal to trigger widespread database deletion is a common operational failure. Compliance teams enforce purpose-level granularity in their records of processing activities. This separation protects legal records.
Navigating Section 7 Legitimate Uses and Retention
Data Fiduciaries process personal data based on consent or Section 7 legitimate uses. Banks hold massive volumes of Know Your Customer records and anti-money laundering documentation. A withdrawal request via a Consent Manager does not override statutory retention requirements set by the Reserve Bank of India. An auditor reviews the data architecture. They verify that a withdrawal only stops the specified elective processing purpose.
Mandated regulatory data remains intact and secure. Deleting core banking records due to a consent withdrawal introduces severe regulatory risk. Teams separate consent-based processing from operations driven by legal mandates. A registered Consent Manager gives the individual visibility into elective processing activities. The fiduciary retains control over the statutory records required to maintain the banking relationship.
Procurement Acceptance Tests for Technical Validation
Evaluating a DPDP compliance platform requires technical validation by the risk team. The solution needs a clear audit trail for every data lifecycle event. A Head of Compliance executes four specific tests to validate vendor claims regarding external integration.
1. Feed a withdrawal request from a mock Consent Manager into the system to verify it correctly identifies the Data Principal in India. 2. Request an evidence pack correlating the initial Section 5 notice with the specific time of consent. 3. Check if the tool automatically notifies downstream processors of the withdrawal event. 4. Initiate a mock data breach to confirm the platform generates an intimation report for the DPBI.
Validating the Compliance Architecture
The Consent Manager framework requires standardized data governance. Banks operate as fiduciaries interacting with millions of daily transactions. Processing consent through a DPBI-registered intermediary demands functional API gateways and reliable identity resolution. ComplyDP provides the control frameworks banks need to map granular consent and automate evidence generation. Schedule a session at https://www.complydp.com/audit-preview to review our compliance formats.
Sources
Frequently asked questions
What is a DPDP Consent Manager under the Act 2023?
Section 6(8) defines a Consent Manager as an entity accountable to the Data Principal that acts on their behalf. They are registered with the Data Protection Board of India subject to conditions outlined in the Rules 2025.
Can we use our existing website CMP to meet Consent Manager obligations?
No. A website Consent Management Platform controls browser cookies and local scripts. A DPDP Consent Manager is a standalone registered entity that routes consent requests between the user and various Data Fiduciaries.
Does a consent withdrawal mean a bank must delete KYC records?
No. Banks retain KYC data to comply with established RBI regulations under Section 7 legitimate uses. A withdrawal stops the specific processing purpose tied to that explicit consent. It does not mandate the deletion of statutory financial records.
Who handles the registration of a DPDP Consent Manager?
Section 6(9) of the DPDP Act 2023 mandates that every Consent Manager must be registered with the Data Protection Board of India (DPBI). They are not registered directly by MeitY, though they operate under the rules prescribed by the central government.
ComplyDP