Connect on WhatsApp
Technology, Media & Privacy (GDPR)

DPDP Consent Managers Go Live in November 2026: What Indian Businesses Need to Know Before the Next Compliance Phase

By Akash Sinha|
DPDP Consent Managers Go Live in November 2026: What Indian Businesses Need to Know Before the Next Compliance Phase

On 13 November 2026, exactly one year after the Digital Personal Data Protection Rules, 2025 were published in the Gazette of India, Rule 4 of those Rules comes into force. With it, India switches on the registration regime for Consent Managers, a new category of regulated intermediary that has no equivalent in the GDPR or in any other major privacy statute. Search interest in this milestone is rising fast, and so is confusion. Much of the commentary published so far either sells registration services to companies that will never need them, or assumes that every business collecting customer consent must now register with the Data Protection Board of India.

Both readings are wrong, and correcting them matters commercially. Here is the editorial line every Indian business should internalise before the November wave of generic explainers arrives:

November 2026 does not suddenly make every Indian business a Consent Manager. It does, however, mark the beginning of India's regulated consent infrastructure, and businesses have only another six months before the wider DPDP compliance architecture follows.

This article answers six questions: what actually changes in November 2026, what a statutory Consent Manager is and is not, whether your company needs to register, what Rule 4 demands from genuine applicants, what ordinary Data Fiduciaries should do instead, and how to use the six-month window between November 2026 and May 2027. For the complete statutory framework behind these milestones, start with our pillar guide, Data Privacy Compliance in India: The DPDP Act Framework.

What Actually Changes on 13 November 2026?

The Three-Phase Commencement Calendar

The DPDP Rules, 2025 were notified on 13 November 2025, and Rule 1 of the Rules staggers commencement across three tranches. Understanding this calendar is the foundation for everything else, because most compliance errors begin with misreading which obligations are live on which date.

PhaseDateWhat CommencesWho It Directly Affects
Phase 113 November 2025 (already in force)Rules 1, 2 and 17 to 21: definitions and the institutional framework of the Data Protection Board of IndiaThe regulator itself; businesses only indirectly
Phase 213 November 2026Rule 4 and the First Schedule: Consent Manager registration and obligations, alongside Sections 6(9) and 27(1)(d) of the ActCompanies that want to operate as registered Consent Managers
Phase 313 May 2027Rules 3, 5 to 16, 22 and 23, plus the bulk of the Act: notice, consent, Data Principal rights, Data Fiduciary obligations, breach reporting, penaltiesEvery Data Fiduciary processing digital personal data in India

Two details in this table deserve emphasis. First, the Act's commencement notification pairs Rule 4 with Section 6(9), which requires every Consent Manager to be registered with the Board, and Section 27(1)(d), which gives the Board its enforcement hook over them. The licensing regime and the power to police it were deliberately switched on together.

Second, and this is the point almost every generic explainer misses: Sections 6(7) and 6(8) of the Act, the provisions that give a Data Principal the right to route consent through a Consent Manager and make the Consent Manager accountable to her, sit in the eighteen-month tranche and commence only in May 2027. The registration window opens six months before the enabling rights that give Consent Managers their commercial reason to exist. November 2026 is a licensing milestone, not a consumer-facing one.

What Rule 4 Switches On

From 13 November 2026, the following becomes operative:

  • A person fulfilling the conditions in Part A of the First Schedule may apply to the Data Protection Board for registration as a Consent Manager, with particulars and documents the Board will publish on its website.
  • The Board may inquire into the application, register the applicant and publish its particulars, or reject the application with reasons.
  • Registered Consent Managers become bound by the obligations in Part B of the First Schedule.
  • The Board gains the power to direct corrective measures, call for information, and, after a hearing, suspend or cancel registration in the interests of Data Principals.

What Stays Dormant Until May 2027

Just as important is what does not commence in November 2026. The substantive machinery of the Act remains dormant for a further six months:

  • Notice and consent obligations under Sections 5 and 6(1) to 6(8), including the requirement that notice be available in English or any of the 22 languages in the Eighth Schedule to the Constitution
  • The Section 7 closed list of certain legitimate uses
  • Data Principal rights (access, correction, erasure, grievance redressal) under Sections 11 to 14
  • Data Fiduciary obligations under Sections 8 to 10, including security safeguards, retention limits and Significant Data Fiduciary duties
  • Breach notification to the Board and affected individuals
  • The penalty Schedule, with ceilings up to Rs. 250 crore per contravention

One live development to track: in January 2026, MeitY held a stakeholder consultation on compressing the compliance window for Significant Data Fiduciaries from eighteen months to twelve, which would pull their substantive deadline forward to November 2026. This remains a proposal, not notified law, but organisations likely to be designated as SDFs should plan against the earlier date as a prudent assumption.

What Is a Statutory Consent Manager, and What Is It Not?

The Statutory Definition

Under Section 2(g) of the DPDP Act, a Consent Manager is a person registered with the Board who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. Three features of this definition do the real work:

  1. Registered: it is a licensed role. No entity can hold itself out as a DPDP Consent Manager without Board registration, and none can be registered before 13 November 2026. Any vendor claiming current DPDP Consent Manager status today should be treated with caution.
  2. Interoperable: the platform must work across many Data Fiduciaries, not just one company's preference centre.
  3. Data Principal-facing: the Consent Manager acts in a fiduciary capacity toward the individual, not toward the business collecting consent. This inverts the commercial logic of most consent tooling sold today.

Consent Manager vs CMP vs Your Own Consent Flow

The most expensive confusion in the market right now is between a statutory Consent Manager and the consent management platforms (CMPs) that websites already use for cookie banners and preference capture. They are not the same thing, and buying one does not give you the other.

DimensionStatutory Consent Manager (Rule 4)CMP / Cookie Consent ToolYour Own Consent Mechanism
Legal statusRegistered intermediary licensed by the Data Protection BoardUnregulated software vendorAn internal process, not a legal person
Who it servesThe Data Principal, in a fiduciary capacityThe Data Fiduciary that buys itThe Data Fiduciary that operates it
ScopeConsent across multiple onboarded Data FiduciariesOne company's sites and appsOne company's sites and apps
Can it read your data?No; the First Schedule requires that shared personal data remain unreadable to itOften processes consent metadataYes, it is your own system
Registration needed?Yes, from 13 November 2026NoNo
ExamplesNone registered yet; regime opens November 2026CookieYes, OneTrust, Cookiebot-style toolsYour signup form, checkout consent, app permissions

A CMP remains perfectly lawful after November 2026. It simply is not, and cannot become without registration, a Consent Manager under the Act. Our companion piece on first-party collection, What Indian Websites Get Wrong About DPDP, covers how to fix the consent capture layer you already own.

The Closest Analogy: India's Account Aggregator Framework

The Consent Manager is one of the genuinely original pieces of the Indian framework, and the best way to understand it is not through European privacy law but through Indian financial regulation. The design is closest to the Account Aggregator system under the RBI's NBFC-Account Aggregator directions: a neutral, data-blind intermediary that routes consent and data between institutions without ever reading the payload, owes its duty to the customer, and operates under a licence with governance, audit and conflict-of-interest conditions. The First Schedule's banking illustration, in which an individual routes consent through one bank to share her statement with another, mirrors the Account Aggregator flow almost exactly. Businesses that have integrated with Account Aggregators already understand the architectural pattern India is now generalising to all personal data.

Does Your Company Need to Register as a Consent Manager?

Five Business Scenarios

For the overwhelming majority of Indian businesses, the answer is no. Registration is a business model choice for specialist intermediaries, not a compliance obligation for ordinary companies. Work through which scenario describes you:

Business ScenarioMust Register as Consent Manager?What You Should Actually Do
Ordinary e-commerce company collecting customer consentNoBuild your own compliant notice, consent, withdrawal and records architecture before May 2027
SaaS platform processing client dataNoYou are likely a Data Processor; focus on contract terms, breach-flow clauses and client enablement. See The Hidden Liability in Your Tech Stack
Bank, NBFC or fintechNo (unless launching a consent intermediary product)Prepare to interoperate with registered Consent Managers; your Account Aggregator experience is directly relevant
Privacy-tech company building a consent intermediaryYesMap yourself against Part A of the First Schedule now: Indian incorporation, Rs. 2 crore net worth, independent platform certification
Multinational consent platform (global CMP)Cannot directlyOnly a company incorporated in India can register; a foreign CMP needs an Indian subsidiary that independently satisfies the First Schedule

The Misconception Worth Correcting

A growing body of vendor marketing claims that "Data Fiduciaries must use Consent Managers" from November 2026, or that collecting consent from your own customers makes you a Consent Manager. Neither is true. An ordinary company collecting consent from its own customers through its own website or app does not thereby become a statutory Consent Manager, any more than operating a bank account makes you a bank. Rule 4 governs the specially registered intermediary contemplated by the Act, and Sections 6(7) and 6(8) make clear that using a Consent Manager is the Data Principal's choice, not the Data Fiduciary's obligation. If a vendor sells you a "November 2026 DPDP registration deadline," the first question to ask is whether they have read Rule 1.

What Rule 4 Requires From Businesses That Do Want to Become Consent Managers

For the narrower population of privacy-tech companies, fintech infrastructure players and industry consortia that genuinely intend to operate as Consent Managers, Rule 4 and the First Schedule create one of the most demanding registration regimes in Indian digital regulation. The conditions fall into two parts.

Part A: Eligibility and Registration Conditions

An applicant must satisfy all of the following, verified against the First Schedule text:

  • Indian incorporation: the applicant must be a company incorporated in India. Foreign consent platforms cannot register directly.
  • Minimum net worth of Rs. 2 crore, with adequate business volume, capital structure and earning prospects.
  • Sufficient technical, operational and financial capacity to discharge Consent Manager obligations.
  • Sound financial condition and general character of management; directors, key managerial personnel and senior management must have a general reputation and record of fairness and integrity.
  • Entrenched constitutional documents: the memorandum and articles of association must require adherence to the conflict-of-interest obligations in Part B, with policies to ensure it, and those provisions may be amended only with the previous approval of the Board.
  • Independent certification that the interoperable platform meets the data protection standards and assurance framework the Board will publish, and that technical and organisational measures are in place to keep it that way.
  • The proposed operations must be in the interests of Data Principals.

Part B: Continuing Obligations

Registration is the beginning, not the end. A registered Consent Manager must, on a continuing basis:

  • Remain data-blind: personal data shared through the platform must be made available in a manner whose contents are not readable by the Consent Manager.
  • Maintain consent records: every consent given, denied or withdrawn, the notices preceding each request, and every sharing of personal data with a transferee Data Fiduciary.
  • Retain records for at least seven years, give the Data Principal access to them, and provide them in machine-readable form on request.
  • Operate a website or app as the primary means of access for Data Principals.
  • Not sub-contract or assign any of its obligations under the Act and the Rules.
  • Maintain reasonable security safeguards against personal data breach.
  • Act in a fiduciary capacity toward the Data Principal.
  • Avoid conflicts of interest with Data Fiduciaries, including measures covering directors, key managerial personnel and senior management holding directorships, financial interests, employment or beneficial ownership in Data Fiduciaries.
  • Publish transparency disclosures: promoters, directors, key managerial personnel, senior management, every person holding more than two per cent of its shareholding, and every body corporate in which its insiders hold more than two per cent.
  • Maintain audit mechanisms covering technical and organisational controls, continued fulfilment of registration conditions, and adherence to obligations, with outcomes reported to the Board.
  • Obtain the Board's previous approval for any transfer of control, whether by sale, merger or otherwise.

Supervision, Suspension and Control Transfers

The Board's supervisory toolkit under Rule 4(4) to 4(6) is graduated: it may point out non-adherence and direct corrective measures, call for information at any time, and, where necessary in the interests of Data Principals and after a hearing, suspend or cancel registration with reasons recorded in writing. Combined with the approval requirement for control transfers, the regime is structured so that a Consent Manager cannot be flipped, sold or quietly repurposed without regulatory oversight. For investors looking at India's emerging consent infrastructure, this is a licensed, closely supervised utility-style business, not a conventional SaaS play.

What Should Ordinary Data Fiduciaries Do About Consent Managers?

Your November 2026 Obligation Is Zero. Your May 2027 Obligation Is Not.

If your company is a Data Fiduciary rather than an aspiring Consent Manager, Rule 4 imposes no direct obligation on you in November 2026. The correct response is not registration; it is preparation. From May 2027, three Consent Manager-related realities will apply to you whether or not you plan for them:

  1. Your customers may route consent through a registered Consent Manager. Sections 6(7) and 6(8) make this the individual's right. Your systems will need to receive, honour and audit externally managed consent state.
  2. Withdrawal must be as easy as the giving of consent, and its effects must propagate through your stack, including to your processors. If your withdrawal workflow is a support email address, it will not survive contact with an interoperable consent rail.
  3. Your consent records become your defence. When the Board inquires, the burden of demonstrating valid consent sits with the Data Fiduciary. Machine-readable, purpose-mapped consent records are an evidentiary necessity, not a feature.

Interoperability Questions to Ask Your Stack Now

Before the first Consent Managers are registered, every Data Fiduciary should be able to answer:

  • Can our consent system ingest a consent signal from an external platform via API, or does it only recognise our own banner?
  • Are consent records stored in a structured, exportable, machine-readable form, mapped to specific purposes?
  • When consent is withdrawn, does that event propagate automatically to analytics tools, CRMs, marketing automation and processors?
  • Can we produce, within days, a complete record of who consented to what, when, under which notice version?
  • Do our vendor contracts oblige processors to honour withdrawal signals and assist with rights requests? If not, the analysis in The Hidden Liability in Your Tech Stack is the place to start.

Foreign companies processing Indian customer data face the same interoperability questions, compounded by cross-border structuring issues; our international law practice advises on exactly this intersection.

The November 2026 to May 2027 Window: A Practical Readiness Roadmap

Six Months, Seven Workstreams

The gap between the Consent Manager milestone and full substantive commencement is only six months. Treat November 2026 as the starting gun for the final build phase, not as a deadline in itself.

WorkstreamWhat It InvolvesTarget Completion
1. Data inventoryMap what personal data you hold, where, why, and on what basis; reconcile what departments say against what systems containNovember to December 2026
2. Notice architectureRewrite privacy notices to Rule 3 standards: itemised data description, specified purpose, withdrawal and complaint mechanisms, plain language, 22-language availability strategyDecember 2026 to January 2027
3. Consent recordsDeploy structured, purpose-mapped, machine-readable consent capture with version-controlled noticesJanuary to February 2027
4. Withdrawal workflowsBuild withdrawal that is as easy as consent, with automatic propagation across systems and vendorsFebruary to March 2027
5. Vendor mappingAudit every processor contract for breach-flow, assistance, deletion and audit clauses; remediate gapsFebruary to March 2027
6. Retention and deletionImplement retention schedules with automated deletion when purpose is served or consent withdrawnMarch to April 2027
7. Breach responseStand up detection, Board notification and individual notification workflows that run alongside CERT-In's existing six-hour incident clockApril to May 2027

Who Should Own This Internally

DPDP readiness fails when it is assigned to IT alone or to legal alone. The organisations that will be compliant in May 2027 are running it now as a joint programme: legal owns notice, consent standards and vendor contracts; engineering owns consent records, withdrawal propagation and deletion automation; leadership owns the penalty exposure, which at up to Rs. 250 crore per contravention is a board-level number. Startups and SMEs without in-house counsel should treat this as a structured engagement rather than an ad hoc question queue; our Startup Hub and corporate advisory teams run DPDP readiness programmes on exactly this workstream model.

The Bottom Line

November 2026 is a genuine statutory milestone, but it is a milestone about who may be licensed to intermediate consent, not about ordinary businesses registering for anything. The companies that should act now fall into two groups: the small set of privacy-tech and fintech infrastructure players that must map themselves against the First Schedule before the registration window opens, and the much larger set of Data Fiduciaries that should use the next six months to build consent architecture that can survive May 2027. The businesses that misread November 2026 as their deadline will relax for six months and discover in May 2027 that the real obligations arrived all at once, with no grace period and a functioning regulator already in place.

If you are assessing whether your organisation should register as a Consent Manager, integrating with consent infrastructure, or building your Data Fiduciary compliance programme for May 2027, book a consultation with Vera Causa Legal and we will map your position against the Rules as notified.

Strategic Legal Counsel

Discuss the implications of this briefing for your specific corporate or cross-border operations.

Request Private Consultation