News
India’s DPDP Consent Manager Rules Take Effect in November 2026
India’s DPDP compliance timeline is taking shape, with Rule 4 effective from November 2026 and broader requirements following in May 2027.
Prem Kumar Dvivedi · ١٢ سبتمبر ٢٠٢٦
India’s data protection framework is moving closer to full implementation. The Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 on 13 November 2025. The Rules follow a phased approach instead of making every requirement effective at once.
Under the notified timeline, Rule 4, which covers Consent Managers, will take effect one year after notification. The remaining major operational requirements will come into force 18 months after notification. This places the key compliance date in May 2027.
Source: India Briefing — India's DPDP timeline: critical compliance deadlines for 2026-27
For businesses, this timeline provides a clear message: the time to build a data privacy framework is now.
India’s DPDP Rules Put Consent Managers in the Spotlight
A Consent Manager is designed to help individuals give, review and withdraw consent through a registered intermediary.
This changes how businesses may need to manage consent. Organisations will need to ensure that their consent records are accurate and can support requests to withdraw consent. Their systems must also be able to act when an individual changes their consent preferences.
India Briefing notes that businesses will need to prepare their consent systems and data management processes as the Consent Manager ecosystem develops.
This means consent cannot remain a simple checkbox on a website. Businesses will need processes that show when consent was given, what it covered and how the organisation responded when consent changed.
DPDP Rules Make 2026 a Crucial Year for Business Readiness
The phased timeline gives organisations time to prepare before the major requirements become applicable. India Briefing describes 2026 as a period for businesses to build and test their compliance systems before the transition to stronger regulatory accountability in 2027.
Businesses can use this period to review how they collect and process personal data. They can also check whether their privacy notices, consent records, security controls, retention processes and data request procedures are working properly.
Waiting until 2027 to begin this work could leave organisations with limited time to identify gaps and fix them.
DPDP Compliance Brings ISO/IEC 27701 Into Focus
A structured privacy management system can help organisations bring these activities under one framework.
ISO/IEC 27701:2025 provides requirements and guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS). The standard is designed for organisations that act as PII controllers or processors.
An ISO/IEC 27701-based system can help an organisation structure important privacy activity such as:
Identifying and managing personal information.
Recording privacy responsibilities and processes.
Managing privacy risks.
Maintaining evidence of privacy controls.
Handling data subject requests through defined processes.
Managing relationships with processors and other third parties.
Supporting accountability and continual improvement.
These management system practices do not automatically mean that an organisation complies with the DPDP Act or Rules. ISO/IEC 27701 is a management system standard. The DPDP framework has its own legal requirements. Organisations therefore need to assess the specific requirements that apply to their operations.
DPDP Compliance Moves Beyond Policies to Documented Evidence
One of the biggest challenges for organisations will not simply be having privacy policies. Businesses will need to show that their privacy processes actually work.
For example, an organisation may have a privacy notice. However, it should also be able to demonstrate how consent is collected and managed. It may have a data retention policy. However, it should also have a process for applying retention and deletion requirements.
This is where a management system approach can add value. It helps organisations move from policies sitting in documents to defined processes, responsibilities, records and continual improvement.
For businesses preparing for India’s changing data protection requirements, 2026 is an opportunity to identify gaps and strengthen their privacy management systems before the major compliance requirements take effect in 2027.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for DPDP Act Compliance, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
١٣ سبتمبر ٢٠٢٦
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
١٣ سبتمبر ٢٠٢٦
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
١٣ سبتمبر ٢٠٢٦
