DPDP EDITORIAL DESK · REVIEWED
Consent Managers as infrastructure: interfaces, accountability and open questions
An engineering reading of the boundary between a registered intermediary, a Data Principal and connected Data Fiduciaries.
Rule 4 is notified to commence one year after Gazette publication; its exact scope should be read in the corrected final text.
Interoperability, receipt semantics, revocation reliability and minimised identity binding deserve design attention before integration claims are made.
Interface before marketplace
Treat the consent-management boundary as a protocol and accountability question, not a vendor ranking. Define message meaning, authentication, acknowledgement and failure handling.
Evidence without over-collection
A receipt can establish event context without copying every underlying attribute. The design should make purpose, notice version and withdrawal state inspectable.
Open questions stay open
Registration, operational availability and integration specifics must be verified from current official records. This note does not predict providers or approval outcomes.
SOURCE TRAIL
Official records used for the factual lane
Source IDs show provenance. They do not turn the engineering analysis into official guidance.
CONNECTED PATTERNS
Consent event and withdrawal propagationCONTENT CHANGE LOG
Official MeitY/PIB source trail rechecked; architecture-to-evidence connections added without changing the fact/analysis boundary.
Official status sources rechecked; navigation index and review metadata refreshed.
Official source status rechecked; fact and analysis lanes reviewed.
Initial private-preview research note published.