Wednesday, September 16, 2026
होमLegal KnowledgeConsent Managers vs Account Aggregators | The Legal Observer

Consent Managers vs Account Aggregators | The Legal Observer

Published on

DPDP Rules 2025 create a potential overlap between Consent Managers and RBI-regulated Account Aggregators in consent-based data flows.

India’s data-protection framework now places two consent-based intermediaries around similar digital data flows, but under different regulatory regimes.

What happens when two guards protect two entrances to the same vault, but the qualifications for becoming each guard are different? The visitor may simply choose the easier door. That analogy captures a regulatory question emerging from the Digital Personal Data Protection Rules, 2025: the possible overlap between Consent Managers and RBI-regulated Account Aggregators.

The final DPDP Rules were notified by the Ministry of Electronics and Information Technology in November 2025. They create a framework for Consent Managers covering consent management across personal-data processing, while the Reserve Bank of India’s Account Aggregator framework operates specifically in the financial-information ecosystem.

At first glance, the two systems serve different purposes. The difficulty emerges when their functions intersect.

Two Intermediaries, Similar Architecture

An Account Aggregator (AA) is an RBI-regulated entity designed to facilitate the secure transfer of a customer’s financial information between financial institutions with the customer’s consent. RBI itself describes the AA model as one in which the intermediary does not see or store the customer’s financial information.

The DPDP Rules, meanwhile, establish the Consent Manager as an intermediary through which a Data Principal can give, manage, review and withdraw consent. The First Schedule lays down conditions for registration and obligations applicable to Consent Managers.

The potential overlap becomes clearer where personal data is transferred between Data Fiduciaries pursuant to consent. A financial statement, for instance, is both personal data and financial information.

This raises a fundamental regulatory question: if a Consent Manager can facilitate such a consent-based movement of personal data, where does the distinct role of an Account Aggregator begin and end?

Different Entry Requirements

The distinction becomes particularly important because the two regulatory regimes impose different entry conditions.

RBI’s regulatory framework recognises NBFC-Account Aggregators as a separate category and requires a minimum Net Owned Fund of ₹2 crore. The AA ecosystem also operates through technical specifications developed for secure and interoperable data transfer.

The DPDP framework similarly prescribes a ₹2 crore financial threshold for Consent Managers, but the regulatory architecture and eligibility requirements are different.

The concern, therefore, is not merely that two entities perform similar functions. It is that an intermediary could potentially approach the same underlying data flow through a regulatory route carrying a different set of obligations.

Could Financial Data Move Through the DPDP Route?

The issue becomes particularly significant because the DPDP framework is sector-neutral in its application to personal data, whereas the AA framework is specifically structured around financial information.

If a Consent Manager facilitates the movement of financial information between a bank and another Data Fiduciary, the question is whether that activity should additionally attract the safeguards and restrictions applicable to an RBI-regulated Account Aggregator.

The answer cannot be derived simply from the existence of a Consent Manager registration. Banks and other financial entities remain subject to their own sector-specific regulatory obligations, including RBI requirements governing financial information and data-sharing arrangements.

Consequently, the DPDP Rules cannot automatically be treated as replacing the RBI’s regulatory framework for financial institutions.

The Regulatory Arbitrage Question

The more difficult issue is the possibility of regulatory arbitrage.

Account Aggregators have been developed within a specialised financial-data architecture, with RBI supervision and prescribed technical standards. A Consent Manager, by contrast, is designed to operate across sectors.

If substantially similar consent-mediated data transfers can be structured through either framework, businesses may have an incentive to select the regulatory route with fewer compliance burdens.

This could create uncertainty for fintech companies, banks and Data Fiduciaries, while also making it harder for individuals to understand which safeguards apply when their financial information is being transferred.

The problem is therefore less about immediate redundancy and more about regulatory clarity.

Need for Harmonisation

The DPDP framework expressly operates alongside other laws and regulatory regimes. That makes coordination between the DPDP architecture and sectoral regulators particularly important.

A clear delineation of functions could prevent overlapping registrations, inconsistent compliance requirements and uncertainty over supervisory jurisdiction.

The Consent Manager and Account Aggregator models are both built around an important principle: individuals should control the movement of their data. The regulatory challenge is ensuring that the same consent-based transaction does not become subject to two competing rulebooks—or allow regulated entities to choose between them merely because one route is easier.

As India’s digital-data ecosystem expands, harmonisation between the DPDP Rules, 2025 and sector-specific frameworks such as RBI’s Account Aggregator regime may become essential to ensure that innovation does not come at the cost of regulatory certainty.

For more legal developments and policy analysis, readers can follow The Legal Observer’s news section.

The central question now is not whether India needs consent intermediaries, but how two overlapping models can coexist without creating a regulatory gap—or an unintended shortcut around stricter sectoral safeguards.

For further legal and regulatory updates, follow The Legal Observer on YouTube.

Latest articles

IT SC Order Cannot Be Reopened By AO | The Legal Observer

Supreme Court holds that an Assessing Officer cannot reopen an assessment settled by the...

HC Judge’s Enquiry Report Not Judicial Order | The Legal Observer

Calcutta High Court rules that an enquiry report prepared by a sitting judge in...

PMLA Adjudicating Authority: SC Reserves Judgment | The Legal Observer

PMLA Adjudicating Authority: Supreme Court reserves judgment on whether a judicial member is mandatory...

CJI Surya Kant On Judicial Accountability | The Legal Observer

CJI Surya Kant says judicial scrutiny and constructive criticism are necessary for accountability, public...

More like this

FSSAI Rules: 24 FAQs on Food Compliance | The Legal Observer

FSSAI rules explained through 24 FAQs on licensing, labelling, claims, inspections and enforcement for...

Curd Adulteration Case | Calcutta HC Sets Conviction Aside | The Legal Observer

Calcutta HC sets aside a 26-year-old curd adulteration conviction, holding that low fat content...

S.362 CrPC: SC Upholds High Court Recall Power | The Legal Observer

Supreme Court holds Section 362 CrPC does not bar High Court from recalling a...