India passed a data protection statute in 2023 and then left the market waiting for the rules that would make it operational. Those rules arrived in late 2025, and with them a phased implementation timetable that runs through to mid-May 2027. Companies treating 2026 as a quiet year are misreading the calendar.
The dates that matter
The implementation is staged rather than immediate. The central government is operationalising the Consent Manager framework during 2026, with registration for third-party consent managers opening around 13 November 2026. That date also marks roughly the end of the initial soft-enforcement phase, after which the Data Protection Board of India is expected to shift from guidance and awareness toward active supervision.
Full compliance with the substantive obligations, covering notice and consent operations, breach notification and the handling of individual rights requests, is required by mid-May 2027, eighteen months from notification. Penalties run to ₹250 crore per violation.
The consent manager is the unusual part
Most of the DPDP framework will feel familiar to anyone who has implemented GDPR: notice, purpose limitation, breach reporting, data principal rights. The consent manager is different. It creates a registered intermediary through which individuals can grant, review and withdraw consent across multiple services from a single interface.
There is no direct European equivalent. For businesses, it means consent will not always be captured and held inside the organisation’s own systems. Withdrawal may arrive through a third party, in a machine-readable form, and must be honoured. Consent architecture built for a self-managed model will need rework, and the interface obligations run in both directions. Organisations must be able to receive and act on instructions from registered consent managers.
Who is in scope
The territorial reach is broad. Businesses processing the personal data of individuals in India in connection with offering goods or services to them fall within the statute regardless of where they sit. For regional firms, the practical exposure often runs through back-office and technology operations located in India, which process data belonging to customers elsewhere while themselves being subject to Indian law.
What to do in the remaining window
Treat the next twelve months as build-and-test rather than wait-and-see. Map where consent is currently captured and stored. Identify systems that cannot presently accept an external withdrawal signal. Review breach detection and notification timelines against the rules. Confirm whether any of the group’s Indian entities will need to register or interface with consent managers. And revisit vendor contracts, because processor obligations flow through the chain.
Summary
India’s DPDP Rules are in phased implementation, with the Consent Manager framework becoming operational around 13 November 2026 and full compliance required by mid-May 2027, backed by penalties up to ₹250 crore per violation. The consent manager intermediary has no GDPR analogue and will require most organisations to rebuild how consent is received, recorded and withdrawn. Businesses with Indian customers, employees or operations should use 2026 to build and test rather than waiting for enforcement to begin.
Leave a Reply