From the blog · 26 August 2026

Three terms worth
getting right.

"Consent Manager," "Significant Data Fiduciary," and "Data Protection Board" get used loosely in a lot of DPDP explainers. The Act defines all three precisely. Here's what each one actually means — and, since it matters, where Consent Tree itself stands against each.

1 · Consent Manager

S.2(g) doesn't describe a function and then say whoever performs it qualifies. It defines the term as a status: "a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform." Registration is not optional or implied — S.6(9) states every Consent Manager shall be registered with the Board, and the Rules describe an actual application the Board either approves and publishes, or rejects with reasons. Either an organisation is on that list or it isn't; there's no informal version of being one.

The Consent Manager provisions (S.6(7)–(9)) become live law on 13 November 2026 — the date the whole ecosystem this term describes actually starts existing in practice, not just on paper.

Where we stand: Consent Tree is not a registered Consent Manager, and we don't describe ourselves as one. What we've built is the machinery a Consent Manager needs — consent capture, federation, an interoperable record — engineered so it can plug into one, or become one later if that's ever the right call. Capability and status aren't the same claim, and only one of them is true today.

2 · Significant Data Fiduciary

S.10(1) gives the Central Government the power to notify any Data Fiduciary, or class of Data Fiduciaries, as a Significant Data Fiduciary — weighing factors like the volume and sensitivity of personal data processed, and risk to things like electoral democracy, state security, or public order. It's a designation handed down, not one an organisation claims for itself. Being significant in the plain-English sense of the word — a lot of customers, a lot of data — doesn't make an organisation a Significant Data Fiduciary under the Act. Being notified does.

The designation isn't just a label — it comes with real, added obligations: appointing a Data Protection Officer (S.2(l) defines that role specifically as an appointee of a Significant Data Fiduciary), running Data Protection Impact Assessments, and commissioning independent data audits. A fiduciary that isn't notified still has to answer for how it handles data — S.8(9) and Rule 9 both require "a Data Protection Officer, if applicable, or a person who is able to answer" — that second phrase is doing real work: it's the Act's own acknowledgment that not every organisation handling personal data needs the first thing.

Where we stand: Consent Tree has not been notified as a Significant Data Fiduciary, so we're not one. We're the second kind — a named person able to answer, reachable at cdpo@consentree.in — same posture our own privacy notice states about itself.

3 · Data Protection Board

The Data Protection Board of India is the Act's adjudicating body — the entity that receives complaints, investigates breach notifications, registers Consent Managers, and can act on non-compliance. It's a regulator, not a certifier: nothing in the Act gives the Board a role approving or endorsing individual products, and no vendor's compliance claim gets stronger by naming the Board next to it. The Board itself was among the first parts of the Act actually stood up, made effective in late 2025, well before most of the Act's substantive obligations come into force.

Where we stand: we have no relationship with the Board beyond what any regulated entity has — we're not implying endorsement, because there isn't one to imply. If we ever pursue Consent Manager registration, that's the kind of fact that gets a date attached to it, the day the Board actually publishes it — not before.