News
India's DPDP consent manager rules bite in November 2026
Rule 4 of the DPDP Rules comes into force on 13 November 2026, with full compliance due by May 2027. What Indian businesses have to have ready.
Prem Kumar Dvivedi · September 12, 2026
The Digital Personal Data Protection Rules were notified by MeitY on 13 November 2025, and they phase in rather than land at once. Rule 4, covering consent managers, comes into force on 13 November 2026. Full substantive compliance — notice, consent, security safeguards, breach reporting and data principal rights — is due by 13 May 2027.
Source: India Briefing — India's DPDP timeline: critical compliance deadlines for 2026-27
What a consent manager is, and why it matters
A consent manager is a registered intermediary through which a person can give, review and withdraw consent across many services from one place. For a business, it means consent stops being something you collect and store privately and becomes something that can be checked, and withdrawn, from outside your systems. A consent record that cannot be produced on demand, or a withdrawal your systems cannot act on, becomes visible in a way it never was before.
2026 is the build year
Enforcement through 2026 is expected to be soft — guidance and warnings — with May 2027 the point at which it is not. That makes this year the one in which the work is affordable. The organisations that will struggle are the ones treating the 2027 date as the start of the project rather than the end of it.
Where a management system helps
ISO/IEC 27701 is the certifiable form of most of this: a record of processing activities, a lawful basis recorded against each purpose, retention periods, a procedure for data subject requests with response records, and processor agreements. None of that is required by the DPDP Act in those words. All of it is what you will be asked to produce when somebody checks.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for DPDP Act Compliance, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- DPDP Act: documentation and compliance requirements
Everything DPDP Act requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
September 12, 2026
- ISO/IEC 27001:2022: documentation and compliance requirements
Everything ISO/IEC 27001:2022 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checkli
September 12, 2026
- ISO/IEC 27701:2025: documentation and compliance requirements
Everything ISO/IEC 27701:2025 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checkli
September 12, 2026
