The Business Requirement Document (“BRD”) for consent management released by the Ministry of Electronics and Information Technology (MeitY) on June 6, 2025, provides a technical blueprint for organizations to design and implement a consent management system (“CMS”) in compliance with theDigital Personal Data Protection Act, 2023(“DPDP Act”) and its rules.Pursuant to such framework, organizations can design a CMS that enables them to undertake comprehensive consent lifecycle management in a manner that aligns with the DPDP Act’s emphasis on data minimization, purpose limitation, transparency, and accountability.
This note discusses the BRD, including with respect to the functional and operational aspects of consent management, the roles and responsibilities of various stakeholders, and the implications for organizations building or updating their CMS.
