Consent Manager and Account Aggregator Overlap Under DPDP Rules Creates Regulatory Arbitrage

India's data protection framework has taken a curious turn. With the release of the final DPDP Rules in November 2025, the country now operates two parallel consent intermediaries—Consent Managers under the Digital Personal Data Protection Act, 2023, and Non-Banking Financial Company-Account Aggregators under the Reserve Bank of India—both built on the same architectural principle of data-blind consent mediation, yet answerable to different regulators, different compliance standards, and different cost structures. The result, as legal analysts warn, is a textbook case of regulatory arbitrage that could undermine the very purpose of both regimes.

At the heart of the problem lies Illustration 2 of Part B, Schedule 1 of the DPDP Rules. The illustration depicts a scenario where a Consent Manager (P) facilitates the transfer of a bank statement directly from a financial information provider (B2) to a requesting fiduciary (B1), with the data principal (X) giving consent. The function described is identical to that of an Account Aggregator: retrieving, consolidating, and securely transferring financial information between institutions on the basis of customer consent. Yet the Consent Manager operates under the DPDP framework, while the Account Aggregator remains tethered to the RBI's NBFC-AA Master Directions.

The Overlap Problem

The source material frames the dilemma succinctly: "One Function, Two Rulebooks." A Consent Manager can take the exact seat of an Account Aggregator for financial data without assuming the additional obligations that the RBI imposes on Account Aggregators. The DPDP Rules attach no extra layer of regulatory rigour to a Consent Manager handling bank statements—no single-purpose entity restriction, no conservative net owned funds calculation, no leverage ratio , no mandatory trial period . "What happens when there are two guards guarding two entrances but into the same vault?" the analysis asks. "The qualifications for both guards are different, one had to prove himself for years to earn the post; the other was waved in on far lighter terms."

The divergence is stark. Under the RBI framework, an Account Aggregator must be a single-purpose entity barred from any business other than account aggregation. A Consent Manager under the DPDP Rules faces no such limitation—it cannot be a fiduciary or processor for the same data principal, but it can operate across multiple sectors simultaneously. The capital requirement of ₹2 crore sounds identical, but the RBI measures "Net Owned Funds" (net worth minus intangible assets and investments in group companies), while the DPDP Rules use simple "Net Worth" under the Companies Act. The former is far more conservative and difficult to satisfy.

Moreover, an Account Aggregator must undergo a 12-month trial period before obtaining a final Certificate of Registration, and thereafter maintain a leverage ratio of total outside liabilities not exceeding seven times net owned funds for three consecutive years before declaring dividends. A Consent Manager merely registers with the Data Protection Board—which, as of now, exists only on paper, with chairperson and members yet to be appointed—and awaits technical standards that remain unpublished.

Regulatory Arbitrage in Practice

The immediate consequence is a clear arbitrage opportunity. Entities that cannot clear the RBI's conservative entry bar may simply register as Consent Managers and route financial information through the DPDP channel, performing the identical function under a lighter rulebook at a fraction of the compliance cost. As the source notes, "Considering the contemporary world that everyone wants a service with the lowest cost and the most efficiency, two scenarios may arise: first, an organization would avail Consent Managers as it allows Data Portability on all types of data, making Account Aggregators redundant; second, entities that cannot clear RBI's conservative entry bar may simply register as Consent Managers."

This is not a hypothetical concern. India has witnessed similar regulatory loopholes before—most notably under the FSS (Health Supplements, Nutraceuticals) Regulations, 2016, where manufacturers exploited the overlapping jurisdiction of FSSAI and CDSCO to bypass stricter drug regulations. The pattern repeats itself: two regulators, two rulebooks, one function, and a race to the bottom.

Legal Safeguards or Paper Tigers?

The DPDP Act contains a saving clauseSection 38—which states that the Act is in addition to, and not in derogation of, any other law, and in case of conflict, the DPDP Act prevails to the extent of the conflict. On paper, this tilts the balance toward Consent Managers. But several practical barriers stand in the way.

First, the bank at the centre of Illustration 2 remains a regulated entity of the RBI. Its authority to part with financial information continues to be governed by the NBFC-AA Master Directions, banking secrecy obligations, and RBI's data-sharing norms. An illustration in a Schedule cannot compel a bank to open its systems to an intermediary the RBI has never licensed. As the source observes, "The real danger is not that Consent Managers will make Account Aggregators redundant tomorrow. It is that the Rules, as drafted, create arbitrage on paper."

Second, the Supreme Court has held that sectoral regulators must exercise jurisdiction first before the general regulator steps in. Applied here, the RBI—not the Data Protection Board—would have the first word on how financial information moves. The NBFC-AA ecosystem already runs on mandatory ReBIT APIs across more than 600 regulated entities; a Consent Manager cannot compel a single financial information provider onto its rails without the RBI's blessing.

Third, the machinery gap is enormous. Consent Manager registration opens only on 14 November 2026, and the interoperability standards required by the DPDP Rules are yet to be published. The Account Aggregator framework, by contrast, is operational, battle-tested, and backed by a mature regulatory apparatus.

Implications for Fintech and Data Principals

For the legal community, the overlap raises serious questions about forum shopping and compliance costs. Fintechs seeking to offer data portability services must now evaluate two distinct regulatory paths—one under the RBI with high entry barriers and ongoing leverage restrictions, the other under the DPDP Board with lighter requirements but uncertain technical standards and potential jurisdictional challenges. The confusion is compounded for data principals, who may not understand which intermediary they are dealing with or which regulator offers them stronger protection.

The analysis concludes that the DPDP Rules, as drafted, invite " forum shopping , compliance costs for fintechs and confusion for the very Data Principal both entities claim to empower." Without harmonisation—either through the RBI relaxing its AA norms or the DPDP Board imposing equivalent safeguards—the two regimes will remain in tension, each undermining the other's credibility.

Conclusion

The Consent Manager-Account Aggregator overlap under the DPDP Rules, 2025, is a cautionary tale of regulatory design. What was intended as a parallel, sector-agnostic consent mechanism has inadvertently created a lighter-touch alternative to the RBI's carefully constructed financial data-sharing framework. While practical barriers may delay immediate arbitrage, the Rules provide a roadmap for it. The Data Protection Board and the RBI must act swiftly to align standards, close loopholes, and ensure that one function does not end up with two rulebooks—especially when the safety of financial information is at stake.