
Introduction
Data is frequently hailed as the new currency of the digital economy; like traditional currency, its stability hinges entirely on trust. India addressed the fundamental question of data ownership by anchoring its regulatory philosophy to explicit, informed consent as the prerequisite for any data transfer.
Today, two distinct frameworks operationalize this philosophy: the Reserve Bank of India’s Account Aggregator (AA) ecosystem, launched in 2016, and the broader Consent Manager (CM) mechanism established under the Digital Personal Data Protection (DPDP) Act, 2023.
While both architectures stem from the core principle that consent must be informed, specific, and revocable, they were conceived in silos—resulting in distinct regulatory authorities and legal regimes. This article explores where these two frameworks align, where they diverge, and the regulatory gaps that emerge at their intersection.
What is an account aggregator?
The 2025 NBFC Directions released by RBI describe Account Aggregators (AAs) as consent based frameworks for the secure retrieval and sharing of financial information . the entire process is driven by explicit consent of the customer. They have the right to revoke consent access to whole or parts of the information at any time. The framework allows secure data movement between:
Financial Information Providers (FIPs): they include banks, NBFCs, insurance companies. Once the valid consent artefact is presented, verification of AA’s credentials and consent’s validity happens successfully, then FIPs digitally sign the data and transmit it to the AAs in real time.
Financial Information Users (FIUs): they are entities registered with and regulated by financial sector regulators (e.g. RBI, SEBI etc.). Further, FIUs are entities in the Account Aggregator (AA) framework that requests and consumes a customer's financial data to provide a financial product or service.
AAs operate under certain strict restrictions:
Financial information cannot reside with the aggregator.
They are strictly prohibited from supporting or facilitating any financial transactions initiated by customers.
Their business of account aggregation cannot be outsourced to third party service providers.
All AAs must adopt technical specifications like APIs published by Reserve Bank Information Technology Private Limited to ensure secure data movement.
Who are Consent Managers in the DPDP Regime?
Section 2(g) of the DPDPA, 2023 defines Consent Manager (CM) as a person registered with the Data Protection Board of India who acts as a single point of contact for the Data Principal. This framework concerns itself with digital personal data.
In essence, consent managers provide an accessible, transparent and interoperable platform that empowers individuals to give, manage, review and revoke their consent for data processing. They operate in a fiduciary capacity for the data principal and are accountable to them. The DPDP rules clarify that CMs must be companies incorprated in India with a minimum net worth of two crore rupees and must possess the technical and operational capacity to fulfil their duties.
CMs act as a facilitator for data sharing in two cases:
Data Principal to Data Fiduciary: in this case the CM enables the data principal to give consent directly to the data fiduciary.
Data Fiduciary to another Data Fiduciary: in this case the CM enables the data principal to route consent from one data fiduciary to another.
CMs face certain restrictions:
They must ensure that the personal data being shared is not readable by the CM itself.
Sub-contracting or assigning its obligations to any other party is prohibited.
CMs must avoid all conflicts of interest with the data fiduciary (e.g. relationships that include their promoters or key managerial personnel).
Transfer of control of a registered consent management company cannot happen through sale or merger without the previous approval of the Data Protection Board (DPB).
All CMs must maintain an interoperable platform consistent with data protection standards and the assurance framework published by the DPB and implement reasonable security frameworks to keep personal data breaches at bay.
Comparative analysis: Complementary or Contradictory?
The Account Aggregator and Consent Manager frameworks are both techno legal systems designed with the goal of empowering individuals with control over their digital personal data.
Points of convergence:
The customer has the ultimate authority to grant, manage, review and revoke consent for data processing.
Data cannot reside with either framework. Both of them are conduits and data blind.
For the sake of auditability and transparency, the electronic consent logs must be capable of being audited and verified to ensure that every instance of data sharing is authorised.
Both of them operate as interoperable platforms in order to connect with various authorised entities across their respective ecosystems.
Despite their functional similarities, they diverge on the following fronts:
AAs are specialised NBFCs that are regulated by RBI whereas the CMs are registered with and are held accountable to the DPBI.
AAs are vertical intermediaries focused on financial sector, designed to handle specific information like bank deposits, tax returns etc. However, consent managers are horizontal intermediaries that manage consent for digital personal data across all sectors.
The AA framework has been operational since 2016 with millions of successfully fulfilled consent requests, the consent management framework is a relatively less mature ecosystem that is yet to come in force.
As far as business restrictions are concerned, NBFC AAs face a strict no other business rule. While consent managers must avoid conflicts of interest and act in fiduciary capacity, they do not face a strict no other business activity restriction.
These contradictions give rise to certain regulatory and operational questions that are discussed in the ensuing section.
The Gaps That Remain
The intersection of these two frameworks brings three major points of conflict to the fore:
Jurisdictional Conflicts: If a consent violation occurs within the AA ecosystem, which authority holds primary jurisdiction? The RBI regulates AAs as licensed financial entities, while the DPBI oversees individual personal data rights for the exact same transaction. Section 38 of the DPDPA indicates that data principals can appeal to the DPBI even in matters involving RBI-regulated entities, but formal statutory clarity remains lacking.
Registration and Interoperability: Since an Account Aggregator acts as a localized consent manager for financial data, should it be required to register as a Consent Manager with the DPBI? If not, how will a consent revocation issued via a general CM propagate through an RBI-regulated AA network? This is more than a technical issue; it questions whether an individual's right to manage consent under the DPDPA is truly meaningful in practice when data moves through sector-specific ecosystems.
Metadata vs. Data: By design, AAs process consent artefacts containing details on user identities, receiving institutions, processing purposes, and validity periods. Even without reading underlying bank statements, an AA can assemble a detailed map of a user's financial footprint through consent records alone. Given that these platforms unavoidably rely on metadata, where exactly do regulators draw the line between consent metadata and protected personal data?
Why This Matters > This extends far beyond the financial sector. As India deploys a broader Consent Manager framework under the DPDPA, CMs will be statutorily required to remain data-blind across all industries. If the established, narrowly focused AA framework has not settled what data blindness means in practice, the wider CM ecosystem will inevitably face these same challenges at a much larger scale.
Conclusion
The Account Aggregator and Consent Manager frameworks discussed above share a common philosophy but not yet a common language. AAs have operational credibility whereas CMs have broader ambition. India has shown a proactive approach by implementing the AA framework, but the questions of jurisdiction, interoperability, and accountability need more clarity as they will only become more pressing as the CMs come into play from 13 November 2026, when the DPDP Law becomes completely effective.