DPDP Sections • 6 mins
Section 6 Explained: Consent Managers and Burden of Proof for Fintechs
A definitive guide to Section 6 of the DPDP Act and the DPDP Rules, 2025, detailing how fintech startups must integrate with registered Consent Managers, prove consent validity, and clear investor DD checklists.
Last updated:
Understanding Section 6 Consent Managers Under DPDP
Section 6 of the Digital Personal Data Protection Act, 2023, along with the detailed framework in the DPDP Rules, 2025, fundamentally changes how fintech startups handle customer data approvals. It introduces the Consent Manager, a regulated entity that acts on behalf of the Data Principal to manage, review, and withdraw consent through an accessible, transparent platform. For a lending or payments startup, this means you will increasingly interface with these intermediaries rather than collecting consent solely through your own proprietary user interface screens. While the Consent Manager acts as an agent for the Data Principal, you, as the Data Fiduciary, remain obligated to prove that valid notice and consent occurred. Making your integration with these managers technically robust is a critical compliance and product design requirement.
Exact Statutory Requirements Under Section 6
The legislative text provides a strict operational framework. Section 6 sub-section 8 mandates that a Consent Manager is accountable to the Data Principal and acts on her behalf, subject to obligations specifically prescribed under the DPDP Rules, 2025. Under Section 6 sub-section 9, every Consent Manager must be registered with the Data Protection Board. This registration is directly contingent on meeting specific technical, operational, financial, and other conditions as outlined in the DPDP Rules, 2025. Crucially for fintech founders, Section 6 sub-section 10 dictates the burden of proof. If a dispute arises regarding consent in any proceeding, the Data Fiduciary is obliged to prove that a notice was given to the Data Principal and that consent was obtained in accordance with the provisions of the Act and the rules made thereunder.
Section 4 Lawful Purposes and Consent Integrations
To understand the role of a Consent Manager, one must look at Section 4. Section 4 sub-section 1 states that a person may process the personal data of a Data Principal only in accordance with the Act and for a lawful purpose. This lawful purpose relies on two primary pillars: either the Data Principal has given her consent, or the processing falls under certain legitimate uses outlined in Section 7. Consent is the primary basis except where Section 7 legitimate uses apply. Furthermore, Section 4 sub-section 2 clarifies that a "lawful purpose" means any purpose which is not expressly forbidden by law. The Consent Manager facilitates the consent pillar of Section 4.
Section 13 Grievance Redressal Mechanisms
Managing grievances is another critical intersection for platforms utilizing Consent Managers. Section 13 sub-section 1 dictates that a Data Principal shall have the right to readily available means of grievance redressal. This must be provided by both the Data Fiduciary and the Consent Manager regarding any act or omission in the performance of their obligations. Section 13 sub-section 2 requires that the Fiduciary or Consent Manager respond to these grievances within a prescribed period from the date of receipt, as established by the DPDP Rules, 2025, for all or any class of Data Fiduciaries. Importantly, Section 13 sub-section 3 creates a mandatory escalation path: the Data Principal must exhaust the opportunity of redressing her grievance with the Fiduciary or Consent Manager before approaching the Board.
Applicability For Fintech Fiduciaries And Processors
This statutory framework binds both the registered Consent Managers and the Data Fiduciaries who rely on them. If you operate a fintech platform processing payments, insurance, or digital lending data, you act as a Data Fiduciary. You cannot use unregistered entities to manage consent on behalf of your users. The integration between your systems and the Consent Manager must be flawless. For founders and engineering leads, this is not just a legal checklist but a core product requirement that overlaps directly with broader financial data sharing architectures, such as the Reserve Bank of India’s Account Aggregator framework APIs.
How To Comply With Section 6 Step By Step
Getting your product enterprise-ready requires embedding the DPDP Act and DPDP Rules, 2025 compliance directly into your agile sprint cycles. Do not treat this as a manual legal review, but as a technical infrastructure upgrade essential to clear investor due diligence checklists. As a founder scaling a platform, mapping data flows for external consent intermediaries must become part of your core engineering roadmap.
Step 1: Verify Consent Manager Registration. Your product and legal teams must ensure that any third-party intermediary managing consent for your Data Principals is officially registered with the Board pursuant to Section 6(9) and meets the criteria outlined in the DPDP Rules, 2025. Establish a recurring audit to check their status against the Board's registry, documenting this vendor assessment.
Step 2: Map Consent Trails and Notice Delivery. Under Section 6 sub-section 10, you bear the absolute burden of proof in a dispute. Your engineering team must build resilient database logs that record exactly when an itemised notice was presented to the Data Principal, what the notice contained, and the cryptographic or timestamped proof that consent was granted via the Consent Manager.
Step 3: Implement Grievance Redressal APIs. Under Section 13, you must offer readily available grievance redressal. Establish an automated ticketing workflow that logs user complaints regarding consent management and tracks the response timeline to ensure you reply within the legally prescribed days set under the DPDP Rules, 2025, avoiding escalations to the Board.
Penalties For Failing To Prove Consent
Ignoring the intricacies of Section 6 exposes your startup to severe financial and operational risks. If you cannot prove valid consent was obtained under Section 6 sub-section 10, your processing immediately becomes unlawful under Section 4. Under the Schedule to the Act, a breach of the general obligations of a Data Fiduciary - which includes proving consent and providing grievance mechanisms - carries a penalty ceiling of up to 250 crore rupees. The Data Protection Board will evaluate aggravating factors, such as the volume of personal data processed. In the private market, an investor running a due diligence checklist will view an inability to produce itemised consent logs as an immediate deal blocker, threatening your startup's runway and enterprise sales pipeline.
Deadline Pressure And Next Steps
Time is running out to update your onboarding and consent flows to support Consent Manager integrations. Exactly 288 days remain until the DPDP hard compliance deadline of 13 May 2027. Relying on manual spreadsheets, fragmented databases, or delaying architectural updates until the DPDP Rules, 2025 are strictly enforced will leave your engineering team scrambling during a critical product launch phase. Find out exactly where your current data flows fail the Section 6 burden of proof. Check your startup compliance gaps today at freescan.complydp.com and protect your venture from regulatory action.
Sources
Frequently asked questions
Do fintech startups have to use a Consent Manager for all user data?
No. A Data Fiduciary can still obtain consent directly through their own application interface. However, if a Data Principal chooses to manage their preferences through a registered Consent Manager, your platform must technically support that integration under Section 6 of the DPDP Act and the DPDP Rules, 2025.
What happens if a user disputes their consent during investor due diligence?
Under Section 6 sub-section 10, the burden of proof falls entirely on the Data Fiduciary. If your engineering team cannot produce the itemised notice and timestamped consent logs proving the Data Principal agreed, the processing is deemed unlawful under Section 4, creating a major deal blocker for investors.
How does the Consent Manager model overlap with RBI Account Aggregator rules?
Both frameworks require standardized, API-driven mechanisms for Data Principals to share and revoke access to financial data securely. Preparing your product for DPDP consent integration often utilizes similar architectural principles to RBI digital lending and Account Aggregator flows, focusing on user-centric control.
What is the penalty for failing to provide grievance redressal for consent issues?
Section 13 mandates readily available grievance redressal from both the Fiduciary and Consent Manager, with response timelines prescribed under the DPDP Rules, 2025. Failing to meet general obligations, including proper consent management and grievance response, can expose a Data Fiduciary to regulatory penalties of up to 250 crore rupees under the Schedule to the Act.
Can our startup build its own Consent Manager in-house?
A Consent Manager is a separate operational entity that is accountable to the Data Principal and acts on her behalf. It must be formally registered with the Data Protection Board under Section 6 sub-section 9, meeting specific financial, technical, and operational conditions as prescribed by the DPDP Rules, 2025. Most fintech startups will operate solely as Data Fiduciaries integrating with these specialized managers.
ComplyDP