7 min

Section 6 Consent Manager Duties and Defensibility Under the DPDP Act

A definitive guide for General Counsel on Section 6 and Section 13 obligations regarding Consent Managers, defensibility of consent records, and liability allocation under the DPDP Act.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

The Obligation in Plain Language

Section 6 of the Digital Personal Data Protection Act, 2023 establishes the Consent Manager as a distinct entity. The statute makes this entity accountable directly to the Data Principal. The Act dictates that consent is the primary basis for processing, except where Section 7 legitimate uses apply. A Consent Manager acts on behalf of the individual. It allows individuals to give, manage, review, and withdraw consent through an accessible platform. General Counsel face a specific reality here. While operational mechanics shift to a Consent Manager, the legal burden to prove valid consent remains fixed on the Data Fiduciary. The Data Fiduciary cannot outsource this burden. Transferring the collection process does not transfer the statutory liability. Companies need a clear understanding of this division of responsibility. You own the compliance outcome. The intermediary owns the platform mechanics.

Statutory Text and Core Anchors

Section 6 contains three core subsections governing these entities. Section 6(8) states the Consent Manager is accountable to the Data Principal and acts on her behalf. Section 6(9) dictates that every Consent Manager requires registration with the Data Protection Board. The registration process is subject to technical, operational, and financial conditions outlined in the Rules, 2025. Section 6(10) assigns the burden of proof to the enterprise. If a proceeding questions the validity of consent, the Data Fiduciary is obliged to prove that it gave notice. The Fiduciary has the additional duty to prove that it obtained valid consent in accordance with the Act. This statutory allocation removes ambiguity. The Data Protection Board will not look to the Consent Manager to prove the Fiduciary acquired lawful consent. The enterprise holds the liability.

Who This Binds and When

These provisions apply to any enterprise processing digital personal data within India. They also apply to processing outside India connected to offering goods or services to Data Principals in India. Large organizations often try to outsource consent operations to third-party platforms. Section 6 restricts this practice. Any independent consent intermediary requires formal status as a Board-registered Consent Manager. A standard software vendor cannot act as a Consent Manager without completing the Board registration. Organizations have exactly 255 days remaining until the 13 May 2027 compliance deadline. Legal teams need to use this time to restructure their vendor agreements. Every unverified consent integration presents a direct compliance risk. The statute demands a registered entity. Failing to verify the registration status of your consent software vendor violates the rules.

Liability Allocation and Contractual Defensibility

Enterprise legal teams face a specific challenge under Section 6(10). Defending against regulatory inquiries requires clean audit trails. Your vendor contracts need clear liability allocation. A Consent Manager might fail to record a withdrawal. The vendor could breach the interoperability standards prescribed by the Rules, 2025. You cannot contract out of your Section 6(10) burden of proof. Legal teams need to evaluate indemnities closely. Demand tamper-evident consent logs in all service agreements. Accountability remains with the Fiduciary if the tool errs. The Data Protection Board will hold the Fiduciary responsible for unlawful processing. You need contractual mechanisms to recover costs if the Consent Manager causes the compliance failure. A master service agreement without specific indemnities for consent capture failures leaves the Fiduciary exposed.

Interaction With Other Sections

Section 6 interacts directly with Section 4 and Section 13. Section 4 specifies the grounds for processing. A person may process digital personal data only for a lawful purpose. This lawful purpose relies on either valid consent or a Section 7 legitimate use. Section 13 establishes the right to readily available means of grievance redressal. The Data Principal can seek redress from both the Data Fiduciary and the Consent Manager. Section 13(2) mandates a response within the period prescribed by the rules. Section 13(3) imposes an exhaustion requirement. The Data Principal must exhaust the opportunity of redressing her grievance with the Fiduciary or Consent Manager before approaching the Board. This creates a mandatory first-line defense for enterprises. You have a prescribed window to resolve the issue internally.

How to Comply

1. Verify Registration. Confirm any third party acting as a Consent Manager holds active registration with the Data Protection Board under Section 6(9). Require proof of registration in the master service agreement. Do not deploy the tool until the vendor provides this documentation.

2. Secure Audit Trails. Build integration pipelines that pull verifiable, time-stamped logs of every consent event into your internal systems. This data is your sole defense under Section 6(10). Relying on a third-party dashboard is insufficient. You need direct custody of the logs.

3. Update Grievance Workflows. Section 13(1) gives the Data Principal the right to readily available grievance redressal. Draft operating procedures that route these complaints efficiently. Resolve them within the timeline prescribed by the Rules, 2025. Document every resolution attempt.

4. Revise Vendor Indemnities. Update limitation of liability clauses with all consent intermediaries. Draft indemnification provisions covering regulatory fines. These provisions apply if the vendor fails to register or maintain the required operational conditions.

Penalties for Getting It Wrong

Failing to meet these obligations carries specific financial exposure. The Schedule to the DPDP Act sets a penalty ceiling. The Board can levy up to 250 crore rupees for a breach in observing the general obligations of a Data Fiduciary. If a Consent Manager fails to register or breaches the prescribed conditions, they face separate regulatory action. The Data Fiduciary bears the brunt of the 250 crore rupees exposure. This occurs if they process data based on a consent signal that they later cannot prove was validly obtained under Section 6(10). The law treats unproven consent as absent consent. Processing data without a provable basis violates Section 4. The Board calculates fines based on the severity and scale of the unapproved processing.

Next Steps

Defending against a Data Protection Board inquiry requires verifiable consent records and tight vendor contracts. Assess your current consent architecture before the deadline. Review all third-party integrations handling user preferences. Run a section-level gap check at freescan.complydp.com to identify exposure in your Consent Manager setups.

Sources

Frequently asked questions

Does using a Consent Manager transfer our liability under the DPDP Act?

No. Under Section 6(10), the Data Fiduciary retains the legal burden to prove that notice was given and valid consent was obtained. While a Consent Manager handles the operational collection, accountability for unlawful processing stays with the Fiduciary if the records fail an audit.

Who must register as a Consent Manager under Section 6(9)?

Any entity acting as an independent intermediary to manage, review, or withdraw consent on behalf of a Data Principal requires registration with the Data Protection Board. They face specific technical, financial, and operational conditions prescribed in the Rules, 2025.

What is the penalty for failing to prove valid consent?

If a Data Fiduciary cannot prove valid consent was obtained in accordance with Section 6(10), it constitutes a breach of general obligations. The Schedule to the DPDP Act caps the penalty for such breaches at 250 crore rupees.

Do Data Principals complain directly to the Board about a Consent Manager?

Section 13(3) requires the Data Principal to first exhaust the grievance redressal mechanism provided by the Consent Manager or the Data Fiduciary. Only after attempting resolution through these readily available means can they approach the Data Protection Board.

How much time do we have to implement compliant Consent Manager agreements?

Organizations have exactly 255 days remaining until the hard compliance deadline of 13 May 2027. Legal teams need to use this window to audit vendor registrations, build time-stamped audit trails, and renegotiate limitation of liability clauses.