Data Protection in India

Registration in India

There is no registration requirement for Data Fiduciaries under the DPDP Act. However, Consent Managers are required to register themselves with the Board.

Consent Managers

The DPDP Act provides for Consent Managers to registered with the Board, and defines them as a single point of contact to enable a Data Principal to give, manage, review and withdraw their consent through an accessible, transparent and interoperable platform. 

A Data Principal may give, manage, review or withdraw their consent through a Consent Manager. Consent Managers are accountable to the Data Principal and act on behalf of the Data Principal in such manner and subject to obligations as may be prescribed. 

The DPDP Rules set out a detailed framework governing the registration, eligibility conditions and obligations of Consent Managers. The DPDP Rules prescribe that:

  • a Consent Manager must apply to the Board for registration in the form and manner specified under the DPDP Rules;
  • the Board may grant registration subject to satisfaction of prescribed eligibility conditions and may impose conditions as part of the registration;
  • Consent Managers are required to operate their platforms in a manner that is interoperable, secure, and transparent, and that enables Data Principals to easily manage their consent preferences;
  • Consent Managers must implement appropriate technical and organisational measures to protect personal data and ensure the integrity of consent records;
  • Consent Managers are subject to ongoing compliance obligations, including record-keeping, grievance redressal mechanisms, and cooperation with the Board; and
  • the Board has the power to suspend or cancel the registration of a Consent Manager for breach of the DPDP Act, the DPDP Rules, or any condition of registration, after following the prescribed procedure.

However, neither the DPDP Act nor the DPDP Rules mandate that all Data Fiduciaries must integrate with the Consent Managers for seeking consent of the Data Principals and the way the Consent Manager is required to perform its functions. 

Additionally, the Board may impose penalties on Consent Managers, in respect of breach in observance of its obligations in relation to Data Principal’s personal data, or breach of any condition of registration of the Consent Manager.

Continue reading

  • no results

Previous topic
Back to top