5 mins

Cookie CMP vs DPBI Registered DPDP Consent Manager for Scheduled Banks

Understand the technical and legal gaps between a website cookie preference center and a DPBI-registered Consent Manager for scheduled banks.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

A cookie consent management platform handles front-end website tracking preferences. A Consent Manager under Section 6 of the Digital Personal Data Protection Act, 2023, is a regulated entity acting on behalf of the Data Principal. For a scheduled bank, a standard web CMP fails the itemized notice requirements of Section 5. It cannot manage multi-channel consent artifacts across mobile apps, video-KYC flows, and branch onboarding. Registration is mandated under Section 6(8), while Section 6(9) governs accountability. Consent Managers operate under specific technical, operational, and financial conditions. A registered Consent Manager interfaces directly with the Board ecosystem. This provides individuals a unified dashboard of their permissions across fiduciaries. Banks integrate with these managers to receive customer instructions. The financial institution maintains its own internal consent logs to satisfy regulatory audits under the DPDP Rules, 2025. Standard cookie banners deploy scripts to block third-party analytics trackers. They do not authenticate the user or record a legally binding digital signature against a specific banking purpose. A Section 6 Consent Manager acts as an intermediary. It standardizes how individuals grant, review, and withdraw permissions across different data fiduciaries. When a retail customer interacts with the Consent Manager app, the bank receives a standardized data payload. The bank configures an API gateway to parse this payload. It maps the incoming signal to the correct internal customer profile.

Scheduled banks separate marketing data from core financial processing. A bank keeps its existing web CMP to handle cookie banners for anonymous website visitors. It implements a dedicated DPDP consent engine for authenticated customer journeys. When a customer opens a bank account via live video customer identification, Section 5 requires an explicit notice. This notice details the personal data collected and the specific purpose. The DPDP Act illustration specifically mentions opening a bank account using a mobile app. The bank presents the notice before the video KYC begins. The Rules mandate verifiable consent artifacts linked to an authenticated identity. They do not accept an anonymous browser session. Internal governance architecture dictates the outcome for every banking product. A runtime enforcement layer captures the actual consent logs. This restricts legacy core banking systems to process data only with current customer permissions. A standalone CMP drops a functional cookie on a laptop. A DPDP-compliant architecture writes a time-stamped log to a centralized database. The database syncs with the customer relationship management software. The core banking system queries this database before executing automated marketing campaigns. A bank enacts these controls at the architectural level. Web cookies expire or clear based on browser settings. True consent records persist as long as the fiduciary relationship requires them.

A Head of Compliance evaluates a DPDP solution based on specific technical capabilities. The procurement team verifies if the platform generates an evidence pack proving a Section 5 notice preceded the data collection. Section 6(10) places the burden of proof entirely on the Data Fiduciary. The fiduciary is obliged to prove that it gave a notice to the Data Principal and that the Data Principal gave consent in accordance with the Act. The system logs the exact notice text, timestamp, and user action to produce a regulator-ready audit trail. Evaluators check how the platform handles incoming signals from a DPBI-registered Consent Manager. The tool maps these external signals to internal control owners. It executes this without requiring a multi-year IT overhaul of existing systems. The solution triggers downstream API calls to halt processing in legacy databases when a withdrawal signal arrives. Banks do not rely on screenshots to prove compliance. They require a cryptographic hash of the transaction. Procurement teams ask vendors to demonstrate a simulated Board inquiry. The vendor retrieves the exact notice language displayed to a specific user on a specific date. If the tool only shows the current version of the privacy policy, it fails the Section 6(10) test. Fiduciaries enforce strict standards for these data retention mechanics.

A frequent error in compliance implementation is treating a purpose-level consent withdrawal as a mandatory data erasure request. Section 6(4) grants the Data Principal the right to withdraw consent at any time. The ease of withdrawal matches the ease of the initial grant. Section 6(5) clarifies that the consequences of this withdrawal fall on the Data Principal. The withdrawal does not affect the legality of processing based on consent before its withdrawal. When a retail banking customer withdraws consent via a registered Consent Manager, they stop targeted financial product cross-selling. The bank ceases marketing activities immediately. The bank does not delete the customer PAN card, transaction history, or KYC records. Processing for regulatory compliance relies on Section 7 legitimate uses. A system isolates the withdrawal to the marketing purpose. It leaves the core banking relationship intact. If a customer demands the deletion of their credit history, the bank rejects the request citing Reserve Bank of India retention mandates. The DPDP Act does not override sectoral regulations. A clear map details which data elements belong to consent and which belong to legitimate uses. The compliance team completes this data mapping before the technical implementation begins.

Compliance teams configure audit trails and processor oversight mechanisms well before enforcement begins. A fiduciary maps its data processing activities to actual consent collection points. Integration work with DPBI-registered Consent Managers requires early planning. Late integration causes bottlenecks in customer onboarding flows. The architecture routes withdrawal notices to the marketing automation tool within milliseconds. Legacy databases take longer to update. The IT department builds asynchronous queues to handle this delay. The fiduciary bears the risk of any processing that occurs after the withdrawal signal hits the gateway. The Board investigates the timestamp of the request versus the timestamp of the last marketing email sent. See how a platform generates the evidence packs an organization requires at https://www.complydp.com/audit-preview today.

Sources

Frequently asked questions

Does our existing website cookie CMP meet the DPDP Act requirements for customer onboarding?

A standard cookie preference center manages anonymous browser tracking. It does not fulfill the Section 5 notice requirements or generate the verifiable, identity-linked consent artifacts required under the DPDP Rules, 2025 for financial services.

What is the role of a DPBI-registered Consent Manager for a scheduled bank?

A registered Consent Manager acts on behalf of the Data Principal to provide a unified view of their data permissions. Banks configure technical endpoints to receive and execute consent and withdrawal signals sent from these registered entities.

If a customer withdraws consent via a Consent Manager, do we have to delete their KYC data?

Fiduciaries do not delete data required by sector regulators like the RBI. Section 6(5) states withdrawal applies to the specific consented purpose. Retention for legal compliance falls under Section 7 legitimate uses.

How can our compliance team prove we obtained proper consent if investigated?

Section 6(10) places the burden of proof on the Data Fiduciary. Organizations deploy a centralized consent engine that logs the specific itemized notice displayed, the timestamp, and the individual verifiable action as an immutable audit trail.

What is the timeline to implement a DPDP-compliant consent architecture?

Banks map their data processing to actual consent collection points immediately to avoid last-minute disruptions to customer onboarding flows. The DPDP Act requires functioning consent and withdrawal architectures before enforcement begins.