When a procurement team asks for a “NeGD Empanelled Consent Manager,” vendors may answer with a challenge ranking, a shortlisting letter, or a product claim, and the file can move forward before anyone checks what the label proves, although each document answers a different question about the provider’s history and carries different weight in due diligence.
The term does not describe a legal status under the Digital Personal Data Protection Act, 2023. NeGD helped run an innovation challenge for consent management systems, while registration as a Consent Manager belongs to the Data Protection Board of India under Rule 4 of the 2025 Rules.
For an enterprise buyer, NeGD recognition can support technical due diligence, but it cannot replace product and security review. Contract checks also remain necessary, as does eventual Board registration when a provider wants to act as a statutory Consent Manager.
There is no official category called a “NeGD Empanelled Consent Manager” in the Act or Rules. The labels are not interchangeable.
What people usually mean is a company that participated in or was recognised through Code for Consent: The DPDP Innovation Challenge. The official MeitY Startup Hub challenge page describes a competition to develop a modular consent management system for integration into Data Fiduciaries’ platforms. It does not describe a regulatory licence.
The legal term is Consent Manager, and the distinction matters because the statutory role carries duties that a challenge label does not. Section 2(g) of the Act defines one as a person registered with the Board that gives a Data Principal a single point of contact. Through it, the individual can give or withdraw consent and can also review or manage that consent. Section 6(9) makes the Consent Manager accountable to the Data Principal.
That distinction changes the buying question because a vendor may have demonstrated technical merit, may plan to perform a statutory role later, and may still lack the evidence your own operating workflow requires today.
NeGD does run formal empanelments in other service categories. Its current empanelment directory lists defined engagements such as consulting organisations and security audit services. Consent Managers do not appear there as an empanelled service category.
Code for Consent followed a different path. The challenge asked eligible Indian entities to build a consent management system against functional and technical requirements, and six applicants advanced from Round 1, including VertexTech Labs Private Limited, the company behind Redacto, the product discussed later in this article. In July 2026, the MeitY Startup Hub results listing announced the final result. IDfy won and Jio Platforms was runner-up.
Challenge recognition shows that a submission survived a government-backed evaluation, which is useful evidence during a technical shortlist. Yet it neither proves Board registration nor makes that provider mandatory for a Data Fiduciary.
Precision matters here. The record decides.
Use these labels precisely:
Rule 4 of the 2025 Rules assigns registration to the Board. Part A of the First Schedule sets the conditions. An applicant must be an Indian company with at least ₹2 crore in net worth, and it must show the technical capacity to run the service, the operational capacity to support it, and the financial capacity to remain accountable.
The platform must be interoperable and independently certified against standards published by the Board, while its governance has to withstand the same review. The applicant needs sound management, a fair reputation, and controls for conflicts of interest.
After registration, Part B of the First Schedule governs how the service operates, how its records are retained, and how the registered entity remains accountable to the person using it. A registered Consent Manager must let a Data Principal give or withdraw consent. It must also support consent review and management. It must maintain consent records for at least seven years. Its platform must prevent the Consent Manager from reading the personal data being shared.
The official 2025 Rules phase Rule 4 in one year after publication. That places its commencement on 13 November 2026. As of 27 August 2026, challenge recognition and statutory registration remain separate stages.

I would assess the platform by tracing one consent from notice to withdrawal, watching what changes in downstream systems, and checking the audit record after each handoff, because legal judgment still belongs with the DPO or counsel when the workflow reaches an exception.
Request the document behind any NeGD or MeitY claim. Check the exact status. It may say participant or Round 1 shortlist; a final result may say winner or runner-up. Record the issuing body and date in the procurement file.
This keeps a real achievement from being stretched into a different claim: a challenge ranking can carry weight, the issuing body can support its authenticity, and the procurement file should still name the status accurately.
A statutory Consent Manager acts as a single point of contact for a Data Principal. An enterprise consent platform helps a Data Fiduciary operate notices and consent. It also carries withdrawals into the company’s systems. One provider may eventually support both roles, but the contract should say which role applies now.
Write one sentence before the demo: “We need the system to capture consent for named purposes and propagate withdrawal across these systems.” That sentence gives the evaluation a boundary.
Start with a customer withdrawing marketing consent in the mobile app. Follow the event through the consent ledger and CRM. Continue into the campaign tool and processor queue, then inspect the evidence available to the DPO.
Rule 3 of the 2025 Rules requires a notice to provide a means for withdrawal that is comparable in ease to giving consent. A clean front-end button is only the first step because the operating risk sits in downstream propagation, where an old permission can remain active after the user has withdrawn it.
Ask the vendor to export one record. It should identify the Data Principal and notice version. The record also needs the purpose and action, followed by a timestamp and the affected systems. Check how the record changes after withdrawal or a notice update.
The point is whether the workflow produces evidence. A screenshot of a dashboard cannot prove that the processor stopped using the data.
Run a technical session using one real application and one processor. Review API authentication and retry behaviour. Then test event ordering and reconciliation. Ask what happens when the CRM is unavailable during withdrawal.
A generic demo loses value here because a bank may need to reconcile consent across onboarding and campaign systems, then prove that the same decision reached its processors. A hospital may need to separate care workflows from optional outreach.
Part A of the First Schedule to Rule 4 of the 2025 Rules makes technical capacity and governance part of registration. Part B adds security safeguards, audits, and conflict controls.
Your review should cover access roles and encryption. Test incident handling and audit exports in a separate session. Legal and security teams should also inspect ownership links that could create a conflict with a Data Fiduciary.
Licence cost is one line. Add connector development and consent migration. Price notice versioning separately, then account for processor changes and audit support. A lower subscription can become expensive when every withdrawal requires manual reconciliation.
Ask the provider to price a defined deployment. State the number of applications and purposes. Add the required languages and downstream systems as separate scope lines. Keep renewal terms and implementation fees in the same comparison.
Disclosure: VertexTech Labs Private Limited, the company behind Redacto, was one of the six Round 1 applicants selected for Code for Consent.
Redacto’s Unified Consent Manager links consent capture to lifecycle records and withdrawal handling. Redacto pricing is license-based and available on request; buyers comparing Redacto with broad, pre-built coverage across several privacy regimes may prefer a mature multi-jurisdiction suite, while buyers evaluating Redacto should also account for the company’s shorter public track record.

Redacto automation can map records, route reviews, and show missing evidence. The DPO, legal team, and security owner still decide how the law applies and whether a risk is accepted.

Treat Code for Consent recognition as one input, give it weight when the claim is documented, and test the product against your own systems, since a procurement decision still depends on the workflow and evidence your organisation needs.
Choose a provider only when your team can answer four questions:
This Monday, take one consent flow and trace it from notice to the last downstream processor. Record every manual handoff and missing timestamp. That map will tell you what to ask in the next vendor demo.

