India’s Digital Personal Data Protection regime has spent three years as a statute without operational deadlines. That ends on 13 November 2026, when the Consent Manager framework under Rule 4 becomes live — the first hard, date-bound obligation the regime imposes on anyone.

What a consent manager actually is

The DPDP Act was passed in 2023 and the Rules were finalised in November 2025. Together they create India’s first comprehensive framework for the collection, processing, storage and transfer of digital personal data. The architecture borrows from India’s account aggregator model in financial services rather than from European data protection law, and that difference matters more than most compliance teams have registered.

A consent manager is a registered intermediary through which individuals grant, review and withdraw consent across multiple services from one interface. The data principal, to use the statute’s term, does not approach each company separately. Consent becomes portable and revocable at platform level.

There is no GDPR equivalent. European programmes built around lawful bases, privacy notices and subject access workflows do not map onto an interoperable consent registry, and firms that assumed otherwise will find the gap wider than expected.

The compliance calendar

Date Obligation
June–August 2026 Government expected to operationalise the Consent Manager framework
13 November 2026 Rule 4 Consent Manager framework becomes operational
13 May 2027 Full substantive compliance: notice, consent, security safeguards, breach reporting, data principal rights

Most day-to-day obligations become enforceable across an eighteen-month implementation phase ending in May 2027. Practitioners call 2026 the build-and-test year.

Penalties that will focus attention

The financial exposure is substantial by any standard.

Failure Statutory basis Maximum penalty
Failure to maintain reasonable security safeguards Section 8(5) ₹250 crore
Failure to notify the Board or data principals of a breach Section 8(6) ₹200 crore
Non-compliance with children’s data provisions Section 9 ₹200 crore
Significant data fiduciary obligations ₹150 crore
General non-compliance ₹50 crore

At current exchange rates the top figure is roughly US$30 million, and penalties apply per incident. For a global capability centre or a large domestic platform, that is a board-level number.

Rule 7 sets a demanding notification sequence. On discovering a breach, the organisation must notify the Data Protection Board immediately, describing the breach, the categories and approximate number of individuals affected, the likely consequences and the measures taken. Affected individuals follow within 72 hours. Teams used to GDPR’s single 72-hour clock should note that India front-loads the regulator and runs individual notification behind it.

Who should be paying attention

Any organisation processing the personal data of individuals in India falls within scope. That covers the global capability centres multinationals have built across Bengaluru, Hyderabad and Pune, business process operators handling customer data for overseas clients, software vendors with Indian users, e-commerce and fintech platforms, and employers with Indian staff, since employment data is personal data.

Two questions deserve early attention. Can existing consent flows integrate with a registered consent manager? That is an engineering problem with a fixed deadline attached. And do outsourcing agreements written before the Rules were finalised allocate DPDP responsibilities between controller and processor with any precision? Most do not.

Summary

India’s data protection regime acquires its first enforceable deadline on 13 November 2026, when the consent manager framework goes live, with full compliance due 13 May 2027 and penalties reaching ₹250 crore. The consent manager architecture has no Western analogue, so existing GDPR programmes will not port across unmodified. Organisations processing Indian personal data have roughly three months to establish whether their consent infrastructure can connect to a registry that did not exist when those systems were built.


Leave a Reply

Your email address will not be published. Required fields are marked *