Startups5 min read

India DPDP Phase 2: Consent Manager Deadline Arrives 13 November

India's DPDP Consent Manager registration framework activates on 13 November 2026, the first hard date-bound deadline under the Rules. With 83% of organisations unprepared, here is what software teams must know.

India DPDP Phase 2: Consent Manager Deadline Arrives 13 November

India's DPDP Phase 2 Deadline Is 52 Days Away

On 13 November 2026 — 52 days from today — India's Digital Personal Data Protection Act reaches its second phase deadline, when the Consent Manager registration framework under Rule 4 of the DPDP Rules 2025 becomes operational. The Rules were notified by the Ministry of Electronics and Information Technology on 14 November 2025, and this November marks the first hard, date-bound obligation that companies building consent infrastructure must plan against. Despite the deadline's proximity, legal and compliance analyses published in September 2026 estimate that 83 per cent of Indian organisations have not yet begun comprehensive DPDP implementation. With the full compliance deadline following on 13 May 2027, the window for unhurried preparation has effectively closed.

What Phase 2 Actually Activates on 13 November

The November 13 deadline is specific and narrower than it is often described. What activates on that date is Rule 4 and the First Schedule to the DPDP Rules 2025 — the Consent Manager registration framework. A Consent Manager, under the Act, is an intermediary that manages the consent of Data Principals on behalf of Data Fiduciaries. The registration requirement applies to entities that wish to operate as a Consent Manager: they must register with the Data Protection Board of India before 13 November 2026. The First Schedule sets eligibility criteria, including that the applicant must be an Indian-incorporated company with a minimum net worth of Rs 2 crore. Operating as an unregistered Consent Manager after 13 November 2026 carries penalties of up to Rs 50 crore per instance under Section 6(9) of the Act.

For an ordinary Data Fiduciary — a company that collects and processes the personal data of Indian users but does not function as a third-party Consent Manager — November 13 does not itself create new obligations. However, any organisation planning to integrate with Consent Manager infrastructure needs API-level development work completed by this date, not after it.

The Data Protection Board Problem

A significant practical complication sits at the centre of the November 13 timeline: the Data Protection Board of India, the independent regulatory body designated to receive and process Consent Manager registrations, had not been formally constituted as a functioning body at the time of writing. The DPDP Rules require the DPBI to process Consent Manager applications, but a body that does not yet exist in operational form cannot process them. Legal and compliance commentators have flagged this as the primary tension in the Phase 2 deadline. The regulatory mechanism prescribed by the Act is not yet operational. This creates meaningful uncertainty for organisations preparing Consent Manager applications and for enterprises planning integration timelines around the DPBI's processing capacity and published procedures.

Phase 3 and the Full Compliance Deadline

Phase 3 of the DPDP rollout takes effect on 13 May 2027, when all covered Data Fiduciaries must comply with the full range of obligations under the Act and Rules. These include implementing data collection consent flows, appointing Data Protection Officers where required, honouring Data Principal rights including access, correction, erasure, and nomination, establishing data retention and deletion procedures, and reporting data breaches to the DPBI within prescribed timelines. The penalty structure for significant failures under Phase 3 reaches Rs 250 crore per instance. There is no indication of a further grace period beyond May 2027.

What This Means for Indian Software and Product Teams

For Indian software product companies and technology teams, the DPDP compliance timeline creates two distinct workstreams differentiated by whether the product touches consent infrastructure directly.

Teams building customer-facing digital products — mobile apps, SaaS platforms, fintech tools, healthtech applications, e-commerce — must audit their data collection, processing, and consent flows now, with May 2027 as the target for end-to-end compliance. This means reviewing what personal data the product collects, identifying the legal basis under the Act for each processing purpose, designing consent flows that satisfy the Act's requirements for free, informed, and specific consent, and building the infrastructure to honour Data Principal rights requests.

For teams whose architecture involves a third-party Consent Manager — or who are evaluating building one to serve other Data Fiduciaries — November 13 is the earlier pressure point. A consent management product that is DPBI-registered before November 13 will hold a first-mover position in a compliance services market that is expanding rapidly as the May 2027 deadline approaches. Legal and compliance SaaS tools covering consent record management, Data Principal rights request processing, and breach reporting automation are among the categories most directly enabled by the DPDP framework.

AI product teams face an additional consideration: applications that process personal data for model training, personalisation, inference over user-generated content, or behavioural profiling are squarely within the DPDP's scope. Consent flows for AI data collection require particular care under the Act's emphasis on purpose limitation — consent obtained for one processing purpose does not extend automatically to AI training or profiling.

The Bottom Line

India's DPDP Phase 2 deadline arrives on 13 November 2026, activating the Consent Manager registration framework under Rule 4 of the DPDP Rules 2025. Entities wishing to operate as Consent Managers must register with the Data Protection Board of India before this date; eligibility requires Indian incorporation and a minimum net worth of Rs 2 crore, with penalties of up to Rs 50 crore per instance for operating without registration. A practical complication is that the DPBI had not yet been formally constituted at the time of writing. Full DPDP compliance for all Data Fiduciaries follows on 13 May 2027, with penalties reaching Rs 250 crore per instance for significant violations. With 83 per cent of Indian organisations yet to begin comprehensive implementation, the six weeks before November 13 and the eight months before May 2027 are the operative window for Indian software teams to bring consent flows, rights handling, and breach reporting infrastructure into compliance.

Frequently Asked Questions

What is the DPDP Phase 2 deadline and what does it require?+

India's Digital Personal Data Protection Act Phase 2 deadline falls on 13 November 2026, when Rule 4 and the First Schedule to the DPDP Rules 2025 become operational. This activates the Consent Manager registration framework: any entity that wishes to operate as a Consent Manager — a third-party intermediary that manages data consent on behalf of organisations — must register with the Data Protection Board of India before this date. The First Schedule sets eligibility requirements: the applicant must be an Indian-incorporated company with a minimum net worth of Rs 2 crore. Operating as an unregistered Consent Manager after 13 November 2026 carries penalties of up to Rs 50 crore per instance under Section 6(9) of the Act. For ordinary businesses that collect and process user data but do not act as third-party Consent Managers, November 13 does not create new direct obligations, though it is a signal that regulatory enforcement is approaching.

When is the full India DPDP compliance deadline and what does it cover?+

The full India DPDP compliance deadline for all Data Fiduciaries is 13 May 2027, which constitutes Phase 3 of the Act's phased rollout. By this date, all organisations covered by the Act must have compliant data collection consent flows, processes to honour Data Principal rights including access, correction, erasure, and nomination of a nominee, Data Protection Officers appointed where required, data retention and deletion procedures in place, and breach reporting infrastructure capable of notifying the Data Protection Board of India within prescribed timelines. The penalty structure for significant failures under Phase 3 reaches Rs 250 crore per instance, and there is no indication of a further grace period. The Act applies to any organisation that processes the digital personal data of Indian residents, regardless of where the organisation is incorporated or where its servers are located.

What is a Consent Manager under the DPDP Act and why does it matter for software companies?+

A Consent Manager under India's Digital Personal Data Protection Act is a registered intermediary that manages the consent of Data Principals — users — on behalf of Data Fiduciaries — the organisations that collect and use their data. Rather than every app or service managing its own consent infrastructure independently, a Consent Manager acts as a centralised consent layer: users can grant, modify, and withdraw consent across multiple services through a single registered platform. For software companies and startups, this creates two distinct opportunities. First, companies building consent management infrastructure can register as Consent Managers before the 13 November 2026 deadline and serve other Data Fiduciaries as clients, which is a growing compliance services market. Second, software companies building customer-facing apps need to decide whether to build their own consent infrastructure or integrate with a registered Consent Manager, which will influence their product architecture and compliance timeline planning.

What should Indian software and AI product teams do now to prepare for DPDP compliance?+

Indian software and AI product teams should take three immediate steps before the May 2027 full compliance deadline. First, audit data collection: catalogue every category of personal data the product collects, the stated purpose for each category, and the legal basis the product relies on under the DPDP Act. Second, design or update consent flows: the Act requires consent that is free, informed, specific, and unconditional — bundled consent checkboxes or consent buried in terms of service do not meet this standard. Third, build Data Principal rights handling: users have the right to access what data you hold, correct errors, withdraw consent, and have their data erased — these rights must be honoured within defined timelines. AI product teams specifically need to review any use of personal data for model training or behavioural profiling, since the Act's purpose limitation principle means consent for one use does not cover secondary AI-specific uses without separate, explicit consent.

Work with us

TechPillow builds custom software development for teams across India and beyond.

Explore
TT

Written by

TechPillow Team

Sharing insights on technology, product development, and the Indian tech ecosystem.

Ready to Build Something Extraordinary?

From ideation to launch, we're your end-to-end technology partner.

Book a Free Strategy Call