The 13 November 2026 Consent Manager Deadline: What Every Business Must Do

The DPDP Rules 2025 Consent Manager framework becomes operational on 13 November 2026. Here is what Indian businesses need to know and prepare.

ComplianceCheck Team·Published 30 May 2026

The Consent Manager registration framework under the DPDP Rules 2025 becomes operational on 13 November 2026. This date does not mark the deadline for full DPDP compliance, but it is the point from which the consent-management ecosystem that many businesses will eventually rely on starts taking shape.

Key facts at a glance

  • The Digital Personal Data Protection (DPDP) Act, 2023 is India's principal data-protection law.
  • Under the DPDP Rules 2025, the Data Protection Board provisions took effect immediately on notification.
  • The Consent Manager registration framework (Rule 4) becomes operational on 13 November 2026.
  • Full substantive DPDP obligations, notice, consent, security safeguards, breach reporting, data-principal rights, become enforceable on 13 May 2027, with no stated grace period.
  • Penalties for non-compliance, including failure to implement reasonable security safeguards, can reach up to Rs 250 crore per instance.
  • A Consent Manager acts as an interoperable intermediary through which individuals manage consent across multiple businesses, not a tool built by each business independently.

What a Consent Manager actually is

Under the DPDP framework, a Consent Manager is a registered entity that gives individuals, referred to in the Act as Data Principals, a single, standardised place to grant, review, and withdraw consent for how their personal data is used by different businesses. Rather than each business building its own bespoke consent interface, individuals interact with a Consent Manager, which then communicates their choices to the relevant businesses (Data Fiduciaries) in an interoperable, auditable way.

This is a significant departure from the fragmented "accept cookies" or "check this box" consent experiences common today. It is closer in spirit to how account-aggregator frameworks work in financial services, a licensed intermediary standing between the individual and the many entities that hold their data.

Why 13 November 2026 matters, even if it is not the compliance deadline

The date activates Rule 4, the mechanism by which entities can formally register with the Data Protection Board as Consent Managers. It is an infrastructure milestone, not an enforcement milestone. Businesses that process personal data do not need a live Consent Manager integration in place by this date. What changes is that the regulatory pathway for Consent Managers to exist and operate becomes real, which matters because the broader compliance ecosystem, and the vendors and platforms businesses may eventually rely on for consent management, can only mature once this registration process is live.

The two key DPDP dates compared

DateWhat it meansWho it directly affects first
13 November 2026Consent Manager registration framework (Rule 4) becomes operationalEntities seeking to register and operate as Consent Managers
13 May 2027Full substantive DPDP obligations become enforceable, no stated grace periodEvery business that processes personal data of individuals in India

What businesses should actually do before these dates

  1. Do not wait for the Consent Manager ecosystem to build your compliance programme. Full obligations arrive 13 May 2027 regardless of how mature the Consent Manager market is by then, businesses are still responsible for their own notice, consent and security practices.
  2. Start a data inventory now. Know what personal data you collect, why, where it is stored, and who has access, this is foundational work that takes time regardless of which specific consent mechanism you eventually use.
  3. Review your current consent flows. Are you collecting clear, specific, informed consent today, or relying on buried terms-of-service language? The DPDP Act requires the former.
  4. Watch for Consent Manager options as they register. Once the framework is operational from November 2026, businesses in consent-heavy sectors, finance, healthcare, e-commerce, should evaluate whether integrating with a registered Consent Manager makes sense for their consent workflows ahead of the May 2027 deadline.
  5. Budget for security safeguards now. Given the scale of potential penalties, up to Rs 250 crore per instance for security-safeguard failures, this is not an area to defer to the last quarter before enforcement.

The bigger picture

The gap between November 2026 and May 2027 is effectively a runway. The Consent Manager framework going live gives the market time to build registered, interoperable consent infrastructure before businesses are legally required to have their full consent and data-protection practices in place. Businesses that treat November 2026 as a planning checkpoint, rather than either ignoring it or mistaking it for the actual compliance deadline, will be in a stronger position by May 2027.

If you are not sure where your business stands on DPDP readiness, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.

Sources

  • Ministry of Electronics and Information Technology - meity.gov.in
  • Data Protection Board of India notifications, via meity.gov.in
  • DPDP Rules 2025, as published on meity.gov.in

This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.

Frequently Asked Questions

What happens on 13 November 2026 under the DPDP Rules?
The Consent Manager registration framework under Rule 4 of the DPDP Rules 2025 becomes operational on this date, allowing entities to register as Consent Managers with the Data Protection Board.
What is a Consent Manager under the DPDP Act?
A Consent Manager is a registered, interoperable platform through which individuals, called Data Principals, can give, manage, review and withdraw their consent for how businesses use their personal data, acting as an intermediary between individuals and data-processing businesses.
Do businesses have to use a Consent Manager by 13 November 2026?
The 13 November 2026 date makes the Consent Manager registration framework operational, it is not the deadline for full DPDP substantive compliance, which becomes enforceable on 13 May 2027. Businesses are not required to have a live Consent Manager integration by November 2026, but the ecosystem to support one becomes available from that date.
What is the difference between the Consent Manager deadline and the full DPDP compliance deadline?
13 November 2026 activates the framework for registering Consent Managers. 13 May 2027 is when the DPDP Act's full substantive obligations, notice, consent, security safeguards, breach reporting and data-principal rights, become enforceable with no stated grace period.
What penalty can a business face for DPDP non-compliance?
Penalties under the DPDP Act can reach up to Rs 250 crore per instance for failing to implement reasonable security safeguards, among other provisions in the Act's penalty schedule.
Should a small business start preparing for DPDP now even though the deadline is in 2027?
Yes. Building consent flows, data inventories and security safeguards takes time, and starting only close to the 13 May 2027 deadline leaves little room to fix gaps discovered during implementation.

Check your status

DPDP Gap Assessment

A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.

Start free assessment →From ₹2,499 · no subscription
Share:LinkedInXWhatsApp