Insights · 27 September 2026

India's DPDP clock: consent managers open on 13 November 2026. What to have running

On 13 November 2026, Rule 4 of India's Digital Personal Data Protection Rules comes into force, and companies can apply to the Data Protection Board to register as consent managers. Your business does not need to become one. It needs its own consent register, notices and request handling running before people start reaching it through them, and before the main duties bind on 13 May 2027.

What opens on 13 November 2026

The DPDP Rules were published in the Gazette as G.S.R. 846(E), dated 13 November 2025. Rule 1 phases them in. The rules on the Data Protection Board took effect that day. Rule 4, on consent managers, comes into force one year after publication. Rules 3, 5 to 16, 22 and 23 follow eighteen months after publication, on 13 May 2027.

A consent manager is a platform through which a person gives, manages, reviews and withdraws consent across the businesses onboarded onto it. The First Schedule sets a high bar. It must be a company incorporated in India with a net worth of at least ₹2 crore. Its platform must be independently certified against standards the Board publishes. It must not be able to read the data it helps share, it keeps each person's consent record for at least seven years, and it acts in a fiduciary capacity towards the person, with rules against conflicts of interest with the businesses it serves.

What a consent manager does not do for you

A consent manager works for the person. When someone gives or withdraws consent through one, your business is still the data fiduciary. You still owe the Rule 3 notice, you still stop processing when consent is withdrawn, and you still answer that person's requests.

So the real question for 13 November is plumbing. When a withdrawal arrives from outside, how many of your systems hear about it, and how long does it take? If the answer is an email to IT, the consent manager has made your problem easier to see. It has not made it smaller.

What binds on 13 May 2027

These are the rules most businesses will be measured on. Each one needs something running, not a policy document.

  1. Notice (Rule 3). A notice that stands on its own, itemises the personal data and each purpose in plain language, and links to a way of withdrawing consent as easy as giving it.
  2. Security safeguards (Rule 6). Encryption, masking or tokens, access control, logs that let you detect and investigate unauthorised access, backups, and a security clause in every data processor's contract. The logs and data kept for this are held for a year.
  3. Breach intimation (Rule 7). Every affected person told without delay, in plain words, what happened, the likely consequences, what you are doing, what they can do and who to contact. The Board told without delay, then sent a detailed report within 72 hours of your becoming aware, unless it allows longer on a written request.
  4. Retention (Rule 8). Businesses in the Third Schedule classes erase data once the purpose lapses, and warn the person at least 48 hours before. Every business keeps personal data, traffic data and logs of processing for at least a year.
  5. Contact and grievances (Rules 9 and 14). A published contact who can answer questions about processing, and grievances answered within a period not exceeding ninety days.
  6. Children (Rule 10). Verifiable consent from a parent before any of a child's personal data is processed.

The Act's Schedule sets the stakes. The Government's own summary puts the highest penalty, for failing to keep reasonable security safeguards, at up to ₹250 crore. Failing to notify a breach, or breaking the obligations on children, can each cost up to ₹200 crore, and other violations up to ₹50 crore.

What to have running by 13 November

Six months is enough to get these live on one system, then spread them to the rest before May.

  1. A register of every purpose. One place that says whose data you hold, for which purpose, under which version of the notice.
  2. A consent check before sending. A marketing message is checked against current consent before it goes out, not after the complaint.
  3. A withdrawal that reaches every system. One withdrawal, however it arrives, stops use in the CRM, the messaging tool and the data warehouse.
  4. Requests with a clock. Access, correction, erasure and nomination requests routed to each system that holds the person's data, with a deadline everyone can see.
  5. A breach runbook with the 72-hour report drafted. Who decides, who writes to affected people, and who files with the Board.
  6. An audit trail nobody can edit. The evidence you will show the Board, kept so it cannot be changed after the fact.

How we would set it up

NeauraPrivPro is the consent register behind our own products, and it was built for the DPDP Act. It checks consent before a message goes out and sends a withdrawal to every connected system. It routes each data request to the systems holding the person's data against a deadline, and tracks grievances against a ninety-day clock.

For breaches, it starts a 72-hour clock at detection and escalates at 60 hours if the Board report is not in. Its notice to affected people will not send while any of the five parts Rule 7 asks for is empty. Its retention sweep warns a person 48 hours before erasing their data for inactivity. Its audit log is append-only and hash-chained.

It has limits, and we state them. NeauraPrivPro is your register as a data fiduciary. It is not a consent manager, and connecting it to the consent managers the Board registers is work we would scope once their interfaces are published. It reaches only the systems connected to it. Whether you fall in a Third Schedule class, or count as a Significant Data Fiduciary, is for your legal adviser, and we would configure the register to their answer. We would start on one system and its consent flows, then add the next.

Sources

THE PROMISE

We stay until the ROI you were promised is the ROI you get.

Most projects fail after go-live, not before it: the software works and nobody uses it. So we do not stop at delivery. We advise, build, implement, operate, and only then transfer, with change management and adoption run as hard as the code.

ADVISE→BUILD→IMPLEMENT→OPERATE→TRANSFER
THE FORCE

A force of AI agents, on one framework that fits any business.

Named, scoped, switchable agents that read, reconcile, forecast, flag and draft, taking the work off your people’s desks and putting revenue back on your books. A person approves every move that touches money.

See the framework →

Read next: NeauraPrivPro · NeauraPrivPro pricing · Identity, security and privacy · India · All insights