Table of contents

NeGD Empanelled Consent Manager: What It Means & How to Choose One

By
AK
Last Updated on:
August 27, 2026

When a procurement team asks for a “NeGD Empanelled Consent Manager,” vendors may answer with a challenge ranking, a shortlisting letter, or a product claim, and the file can move forward before anyone checks what the label proves, although each document answers a different question about the provider’s history and carries different weight in due diligence.

The term does not describe a legal status under the Digital Personal Data Protection Act, 2023. NeGD helped run an innovation challenge for consent management systems, while registration as a Consent Manager belongs to the Data Protection Board of India under Rule 4 of the 2025 Rules.

For an enterprise buyer, NeGD recognition can support technical due diligence, but it cannot replace product and security review. Contract checks also remain necessary, as does eventual Board registration when a provider wants to act as a statutory Consent Manager.

TL;DR: NeGD recognition is not Board registration

There is no official category called a “NeGD Empanelled Consent Manager” in the Act or Rules. The labels are not interchangeable.

What people usually mean is a company that participated in or was recognised through Code for Consent: The DPDP Innovation Challenge. The official MeitY Startup Hub challenge page describes a competition to develop a modular consent management system for integration into Data Fiduciaries’ platforms. It does not describe a regulatory licence.

The legal term is Consent Manager, and the distinction matters because the statutory role carries duties that a challenge label does not. Section 2(g) of the Act defines one as a person registered with the Board that gives a Data Principal a single point of contact. Through it, the individual can give or withdraw consent and can also review or manage that consent. Section 6(9) makes the Consent Manager accountable to the Data Principal.

That distinction changes the buying question because a vendor may have demonstrated technical merit, may plan to perform a statutory role later, and may still lack the evidence your own operating workflow requires today.

Why the “empanelled” label causes confusion

NeGD does run formal empanelments in other service categories. Its current empanelment directory lists defined engagements such as consulting organisations and security audit services. Consent Managers do not appear there as an empanelled service category.

Code for Consent followed a different path. The challenge asked eligible Indian entities to build a consent management system against functional and technical requirements, and six applicants advanced from Round 1, including VertexTech Labs Private Limited, the company behind Redacto, the product discussed later in this article. In July 2026, the MeitY Startup Hub results listing announced the final result. IDfy won and Jio Platforms was runner-up.

Challenge recognition shows that a submission survived a government-backed evaluation, which is useful evidence during a technical shortlist. Yet it neither proves Board registration nor makes that provider mandatory for a Data Fiduciary.

Precision matters here. The record decides.

Use these labels precisely:

Label Authority What it proves What it does not prove
Code for Consent participant or finalist MeitY Startup Hub and NeGD The entity entered or advanced in the innovation challenge Board registration or legal exclusivity
Code for Consent winner or runner-up Challenge jury The submission ranked in the final evaluation Fit for every enterprise workflow
Registered Consent Manager Data Protection Board of India Registration under Rule 4 of the 2025 Rules That every Data Fiduciary needs that provider
Consent management platform Commercial provider or internal team Software can manage defined consent operations Authority to claim statutory registration

Registration starts with the Board, not NeGD

Rule 4 of the 2025 Rules assigns registration to the Board. Part A of the First Schedule sets the conditions. An applicant must be an Indian company with at least ₹2 crore in net worth, and it must show the technical capacity to run the service, the operational capacity to support it, and the financial capacity to remain accountable.

The platform must be interoperable and independently certified against standards published by the Board, while its governance has to withstand the same review. The applicant needs sound management, a fair reputation, and controls for conflicts of interest.

After registration, Part B of the First Schedule governs how the service operates, how its records are retained, and how the registered entity remains accountable to the person using it. A registered Consent Manager must let a Data Principal give or withdraw consent. It must also support consent review and management. It must maintain consent records for at least seven years. Its platform must prevent the Consent Manager from reading the personal data being shared.

The official 2025 Rules phase Rule 4 in one year after publication. That places its commencement on 13 November 2026. As of 27 August 2026, challenge recognition and statutory registration remain separate stages.

From challenge recognition to statutory registration
This image shows from challenge recognition to statutory registration

How I evaluated a consent management platform

I would assess the platform by tracing one consent from notice to withdrawal, watching what changes in downstream systems, and checking the audit record after each handoff, because legal judgment still belongs with the DPO or counsel when the workflow reaches an exception.

  • Purpose mapping: Can the system bind each consent to a specific purpose and the personal data involved?

  • Withdrawal propagation: Does withdrawal reach the CRM and marketing tools? Check analytics and processor systems separately for stale permissions.

  • Evidence quality: Can the team export a timestamped record with the notice version and action? The same record should show purpose and downstream status.

  • Interoperability: Are APIs and consent artefacts documented well enough to connect existing apps and identity systems?

  • Governance boundary: Can the workflow route exceptions to legal or privacy staff instead of letting automation decide them?

7 checks before you choose a provider

1. Ask for the exact recognition document

Request the document behind any NeGD or MeitY claim. Check the exact status. It may say participant or Round 1 shortlist; a final result may say winner or runner-up. Record the issuing body and date in the procurement file.

This keeps a real achievement from being stretched into a different claim: a challenge ranking can carry weight, the issuing body can support its authenticity, and the procurement file should still name the status accurately.

2. Define the role you are buying

A statutory Consent Manager acts as a single point of contact for a Data Principal. An enterprise consent platform helps a Data Fiduciary operate notices and consent. It also carries withdrawals into the company’s systems. One provider may eventually support both roles, but the contract should say which role applies now.

Write one sentence before the demo: “We need the system to capture consent for named purposes and propagate withdrawal across these systems.” That sentence gives the evaluation a boundary.

3. Trace a withdrawal end to end

Start with a customer withdrawing marketing consent in the mobile app. Follow the event through the consent ledger and CRM. Continue into the campaign tool and processor queue, then inspect the evidence available to the DPO.

Rule 3 of the 2025 Rules requires a notice to provide a means for withdrawal that is comparable in ease to giving consent. A clean front-end button is only the first step because the operating risk sits in downstream propagation, where an old permission can remain active after the user has withdrawn it.

4. Inspect the consent artefact

Ask the vendor to export one record. It should identify the Data Principal and notice version. The record also needs the purpose and action, followed by a timestamp and the affected systems. Check how the record changes after withdrawal or a notice update.

The point is whether the workflow produces evidence. A screenshot of a dashboard cannot prove that the processor stopped using the data.

5. Test interoperability with your estate

Run a technical session using one real application and one processor. Review API authentication and retry behaviour. Then test event ordering and reconciliation. Ask what happens when the CRM is unavailable during withdrawal.

A generic demo loses value here because a bank may need to reconcile consent across onboarding and campaign systems, then prove that the same decision reached its processors. A hospital may need to separate care workflows from optional outreach.

6. Review security and conflict controls

Part A of the First Schedule to Rule 4 of the 2025 Rules makes technical capacity and governance part of registration. Part B adds security safeguards, audits, and conflict controls.

Your review should cover access roles and encryption. Test incident handling and audit exports in a separate session. Legal and security teams should also inspect ownership links that could create a conflict with a Data Fiduciary.

7. Price the integration and evidence work

Licence cost is one line. Add connector development and consent migration. Price notice versioning separately, then account for processor changes and audit support. A lower subscription can become expensive when every withdrawal requires manual reconciliation.

Ask the provider to price a defined deployment. State the number of applications and purposes. Add the required languages and downstream systems as separate scope lines. Keep renewal terms and implementation fees in the same comparison.

Where Redacto fits

Disclosure: VertexTech Labs Private Limited, the company behind Redacto, was one of the six Round 1 applicants selected for Code for Consent.

Redacto’s Unified Consent Manager links consent capture to lifecycle records and withdrawal handling. Redacto pricing is license-based and available on request; buyers comparing Redacto with broad, pre-built coverage across several privacy regimes may prefer a mature multi-jurisdiction suite, while buyers evaluating Redacto should also account for the company’s shorter public track record.

Unified Consent Manager and DPDPA compliance capabilities
This image shows the Unified Consent Manager and DPDPA compliance capabilities

Redacto automation can map records, route reviews, and show missing evidence. The DPO, legal team, and security owner still decide how the law applies and whether a risk is accepted.

A decision rule for your procurement file

How to assess a NeGD-recognised consent platform
This image shows how to assess a NeGD-recognised consent platform

Treat Code for Consent recognition as one input, give it weight when the claim is documented, and test the product against your own systems, since a procurement decision still depends on the workflow and evidence your organisation needs.

Choose a provider only when your team can answer four questions:

  • Which legal and operational role will the provider perform?

  • Can withdrawal propagate through a real application and processor?

  • What record proves each step happened?

  • Where does a human approve exceptions and legal interpretations?

This Monday, take one consent flow and trace it from notice to the last downstream processor. Record every manual handoff and missing timestamp. That map will tell you what to ask in the next vendor demo.

Your Trusted partner