DPDP Rules 2025: The November 13, 2026 Consent Manager Deadline — What Every Indian Business Must Do Now
The DPDP Consent Manager Framework opens 13 November 2026 — 89 days away. Full enforcement follows 13 May 2027. Here is your 7-step checklist to build DPDP compliance before the deadline.
CA Harun Raaj
Chartered Accountant · Harun Raaj & Associates
India's Digital Personal Data Protection (DPDP) Rules, 2025 were notified on 13 November 2025. They operate in three phases, and the second phase — Consent Manager registration — opens on 13 November 2026, exactly 89 days from today. For most Indian businesses, this is the starting gun for the full compliance race.
Here is what the three-phase structure means, why November matters, and the seven concrete steps your business should take before the deadline.
---
The Three-Phase DPDP Compliance Timeline
Source: Digital Personal Data Protection Rules, 2025 (Rule 4, MeitY notification).
---
Who Is a Data Fiduciary?
Under the DPDPA 2023, a Data Fiduciary is any person or entity that determines the purpose and means of processing personal data. This includes:
- Any business that collects customer names, phone numbers, or email addresses
- Any employer that maintains employee HR records
- Any website that uses analytics or remarketing cookies
- Any CA firm or professional practice that holds client financial records
If your business operates in India and processes any personal data of Indian residents, the DPDPA applies to you.
---
What Is a Consent Manager and Why Does November 13 Matter?
A Consent Manager (Rule 4, DPDP Rules 2025) is a registered intermediary that helps Data Principals (i.e., your customers or employees) give, manage, withdraw, and track their consent. Consent Managers must be:
- Indian companies registered under the Companies Act
- Minimum ₹2 crore net worth
- Registered with the Data Protection Board
For most businesses, you will not become a Consent Manager — instead, you will work with registered Consent Managers to manage your users' consent, or build your own in-house consent infrastructure. November 13 is when the Consent Manager ecosystem formally opens, signalling that DPB enforcement of consent obligations is imminent.
---
Your Seven-Step Compliance Checklist (Act Before November 2026)
Step 1: Data Mapping
Identify every category of personal data your business collects — customers, employees, vendors. Document the purpose for each category.
Step 2: Consent Notice (Rule 3)
Draft a clear, itemised consent notice for each processing purpose. The notice must be in plain language, separate from other terms, and specify: what data is collected, why, how long it is retained, and the Data Principal's rights.
Step 3: Appoint a Grievance Officer (Rule 13)
Every Data Fiduciary must designate a Grievance Officer with a name and contact details published on your website. The officer must respond to complaints within 30 days.
Step 4: Breach Response Plan (Rule 22)
Build a 72-hour breach notification protocol. If personal data is breached, you must notify the DPB and affected Data Principals within 72 hours — with no provision for extension.
Step 5: Children's Data Safeguards (Rule 10)
If your service is accessible to anyone under 18, you must implement verifiable parental consent before processing the child's data. Age verification mechanisms must be in place.
Step 6: Retention Policy (Rule 8)
Personal data must be deleted once the purpose for which it was collected is fulfilled. Document retention timelines for each data category and build deletion workflows.
Step 7: Security Safeguards
Implement encryption, obfuscation, or tokenisation for stored personal data. The Rules mandate "reasonable security safeguards" — for a business of any size, this means at minimum encrypted databases and access controls.
---
Illustrative Example
Illustrative Example — not a real client.
Priya runs a boutique accounting firm in Bengaluru with 40 clients. Under DPDPA 2023, she is a Data Fiduciary because she holds client PAN numbers, income details, bank statements, and email addresses. Before May 2027, she must: publish a consent notice on her client intake form, designate herself as Grievance Officer, build a 72-hour breach response plan, delete client data she no longer needs for any active engagement, and encrypt her document management system. Starting November 2026, she should verify whether the Consent Managers she relies on (e.g., her CRM provider) are DPB-registered.
---
Penalty Framework (Section 33, DPDPA 2023)
---
A Note on the Data Protection Board
As of August 2026, the DPB has been constituted but Consent Manager registration processes are not yet fully announced. Some practitioners note the DPB may not be fully operationalised before the November 13 deadline. Regardless: the obligation to build consent infrastructure, appoint a Grievance Officer, and map your data is yours — it does not depend on the DPB being ready.
---
FAQ
Q1. Does DPDPA apply to my small business?
Yes, if you process personal data of Indian residents for any commercial purpose, the Act applies. There is no turnover or headcount exemption for most obligations (though "significant Data Fiduciaries" face additional obligations).
Q2. When do penalties start?
Full enforcement begins 13 May 2027. However, breach notification obligations begin as soon as the DPB is operationalised — do not wait.
Q3. Do I need to delete all my historical customer data?
Not immediately — but you must document a retention policy and delete data once the purpose it was collected for is fulfilled. Indefinite retention of personal data is non-compliant.
Q4. What is a "reasonable security safeguard"?
The Rules specify encryption, obfuscation, masking, or use of virtual tokens mapped to personal data. For most SMEs: encrypted databases, strong access controls, and regular security patches are the baseline.
---
Harun Raaj & Associates advises businesses on DPDPA compliance frameworks including data mapping, consent notices, and Grievance Officer designations. See our DPDP Compliance service and HR & Labour Compliance services.
Disclaimer: This article is for general information only and does not constitute legal advice. The DPDP Rules 2025 are subject to further notifications and DPB circulars — verify all compliance requirements from meity.gov.in and your legal counsel.
---
See Also
Go deeper with our hub guides
Statute-cited, section-by-section guides covering the same ground this article does.
Need help with this?
Our team handles the paperwork. You focus on your business.