Consent Management
Customer-First Consent Management Built for DPDP Act, 2023 & RBI Account Aggregator Master Directions, 2025
OMS AA's Consent Management solution enables financial institutions to collect, manage, and revoke customer consent in full compliance with the Digital Personal Data Protection Act, 2023, and RBI Account Aggregator Master Directions, 2025.
Why It Matters
Why Consent Management Matters
Regulatory Requirement
- DPDP Act, 2023 Sec 6 mandates free, specific, informed, unambiguous consent via clear affirmative action
- Sec 6(4) requires revocation to be "as easy as" giving consent
- RBI Account Aggregator Master Directions, 2025, require immutable consent records for audit
Business Requirement
- Customers expect transparency and control over their data
- Poor consent practices lead to regulatory fines and reputational damage
- Audit readiness is critical in a regulated industry
Operational Requirement
- Manual consent tracking is error-prone and costly
- Multiple institution-specific consent flows are complex
- Proving consent compliance during audits is challenging
The Platform
OMS AA's Consent Management Platform
1
Itemized, Granular Consent
- Customers see exactly which data categories are requested
- Can approve/reject each category separately
- Example: "Approve bank statements, but reject loan account details"
2
Clear Disclosure
- Purpose of data access is clearly stated in plain language
- Validity period is transparent (e.g., "Valid for 1 year or until revoked")
- Customer is informed of their data rights (access, correction, erasure)
3
Clear Affirmative Action
- No pre-ticked boxes; customer must actively select and approve
- No bundled or conditional consent
- Digital signature or MFA confirmation recorded
4
Instant Revocation
- Customer can revoke consent anytime via dashboard or support
- Revocation takes effect immediately
- Notification sent to FIP and FIU automatically
5
Audit & Compliance Records
- Immutable consent artifact with timestamp, customer ID, data categories, purpose, FIU identity
- Automatically retained per regulatory requirements
- Exportable for regulatory audit and compliance reporting
Onboarding
Implementation
For FIPs (Banks)
- OMS AA receives consent notification from customer
- FIP verifies consent digitally
- Only after verified consent does FIP share data
For FIUs (NBFCs, Fintech)
- FIU initiates consent request via OMS AA API
- OMS AA displays to customer
- FIU receives consent ID once approved
- FIU can then request data with consent ID
Regulatory
DPDP Act, 2023 Compliance Features
| DPDP Act, 2023 Requirement | OMS AA Implementation |
|---|---|
| Sec 5: Notice | Itemized description of data and purpose; plain language |
| Sec 6: Free Consent | No conditioning on unrelated services |
| Sec 6: Specific Consent | Consent specific to each data category and FIU |
| Sec 6: Informed Consent | Clear notice of data, purpose, and validity |
| Sec 6: Affirmative Action | No pre-ticks; customer must actively approve |
| Sec 6(4): Revocation | 1-click revocation; as easy as giving consent |
| Sec 6(4): Withdrawal | Withdrawal doesn't affect prior lawful processing |
| Audit Trail | Immutable consent records with all metadata |