Skip to main content
13 November 2026 Is Not Your DPDP Deadline. Here Is What It Actually Starts.
Compliance Guides
DPDP Rules 2025
Consent Manager
Rule 4
Compliance Deadline
DPDPA
13 May 2027

13 November 2026 Is Not Your DPDP Deadline. Here Is What It Actually Starts.

13 November 2026 opens Consent Manager registration under Rule 4 of the DPDP Rules, 2025. It places no new obligation on an ordinary Data Fiduciary. Your notice, consent, security, breach and rights obligations start on 13 May 2027. Here is who should act in November, and how to use the months in between.

Consently Team
29 September 2026
8 min read

Short answer: 13 November 2026 is the date the Consent Manager framework under Rule 4 of the DPDP Rules, 2025 comes into force. From that day, companies that want to act as Consent Managers can register with the Data Protection Board. It places no new obligation on an ordinary Data Fiduciary. The obligations most businesses are preparing for (notice, consent, security safeguards, breach notification and Data Principal rights) begin on 13 May 2027.

With six weeks to go, "the November deadline" is showing up in vendor emails, board decks and LinkedIn posts. Some of that is honest confusion. Some of it is urgency being sold. This guide sets out what the Rules actually phase in and when, who genuinely needs to act in November, and how to use the roughly 32 weeks between now and May 2027.

Key takeaways

  • The DPDP Rules, 2025 were notified on 13 November 2025 and commence in three phases: on notification, after one year, and after eighteen months.
  • The one-year phase, on 13 November 2026, brings in Rule 4: the registration and obligations of Consent Managers.
  • The eighteen-month phase, on 13 May 2027, brings in the rules most businesses care about, including Rule 3 notices, security safeguards, breach intimation and Data Principal rights.
  • You do not need to register as, or sign up with, a Consent Manager to comply with the DPDP Act. Using one is an option the Act gives Data Principals.
  • The risk in November is not a missed deadline. It is buying in a panic, or relaxing when the date passes quietly.

What the Rules phase in, and when

MeitY notified the DPDP Rules, 2025 on 13 November 2025. Rule 1 sets out a phased commencement:

DateWhat commencesWho it affects
13 November 2025Rules 1, 2 and 17 to 21: definitions and the constitution and working of the Data Protection BoardThe Board and the government
13 November 2026Rule 4 and the First Schedule: registration and obligations of Consent ManagersCompanies applying to be Consent Managers
13 May 2027Rule 3 and Rules 5 to 16, 22 and 23: notice, security safeguards, breach intimation, retention and erasure, children's data, Significant Data Fiduciaries, Data Principal rights, cross-border transfers and moreEvery Data Fiduciary

In January 2026, MeitY consulted stakeholders on shortening the eighteen-month window to twelve months for some entities. As of September 2026 no amendment has been notified, so 13 May 2027 remains the operative date. Watch for a change, but do not plan around one that has not happened.

For a month-by-month view, see our DPDP deadline calendar.

What starts on 13 November 2026

A Consent Manager is a defined role under the Act: a person registered with the Data Protection Board who acts as a single point of contact through which a Data Principal can give, manage, review and withdraw consent across multiple Data Fiduciaries, through an accessible, transparent and interoperable platform. Sections 6(7) to 6(9) of the Act create the role. Rule 4 and the First Schedule set out how it works.

From 13 November 2026, a company that wants to operate as a Consent Manager can apply to the Board. On the same date, the matching provisions of the Act, Section 6(9) and Section 27(1)(d), come into force. One practical caveat: as of September 2026 the Board had no appointed Chairperson or Members, and no application portal or process had been announced, so registration becomes legally possible before it is operationally possible. The conditions in the First Schedule include incorporation in India, a net worth of at least ₹2 crore, adequate technical, operational and financial capacity, and a platform that lets Data Principals manage consent without the Consent Manager being able to read the personal data being shared. Registered Consent Managers must also keep records of consents given, denied and withdrawn, and the notices behind them, for at least seven years.

If you are considering applying, our Consent Manager registration checklist covers eligibility in detail.

What does not change on 13 November

For an ordinary Data Fiduciary, which covers almost every business that collects personal data, nothing new becomes enforceable on 13 November 2026:

  • The itemised notice requirements in Rule 3 do not apply yet.
  • The reasonable security safeguards in Rule 6 do not apply yet.
  • The breach intimation duties in Rule 7, including the 72-hour detailed report to the Board, do not apply yet.
  • The retention, erasure, children's data and Data Principal rights rules do not apply yet.

None of this means you should wait. It means the deadline to plan against is 13 May 2027, and the work between now and then is mostly your own: data inventory, notices, consent capture, withdrawal, security and breach response.

Who should actually act in November

Three groups have a genuine reason to care about 13 November:

  1. Companies applying to become Consent Managers. For them, 13 November is the start line. Registration has conditions to meet and evidence to prepare, and the Board decides who is registered.
  2. Data Fiduciaries in sectors likely to see Consent Managers early. Under Section 6(7) and 6(8), a Data Principal may give, manage, review or withdraw consent through a Consent Manager. If you operate in a sector where people already use consent intermediaries, such as financial services, keep an eye on who registers and what integration would involve. That is a product question, not a compliance deadline.
  3. Anyone buying compliance software. From 13 November, "Consent Manager" is a registered status. A vendor that is not on the Board's register is not a Consent Manager, whatever its marketing says. A consent management platform (CMP) is software a Data Fiduciary uses on its own websites and apps. It is useful, and most businesses need one, but it is a different thing. Our explainer on Consent Manager vs CMP goes deeper.

Why the wrong date is dangerous

Treating 13 November as your deadline causes two opposite failures.

Panic buying. Teams rush a tool purchase to "be compliant by November", before they know their processing activities, purposes and data flows. The result is a banner or form that looks compliant and records nothing useful. The hard part of DPDP compliance is deciding what you process and why, and designing notices and consent around that. No tool does that for you in six weeks.

False relief. The date passes, nothing visible happens, and the programme loses its budget and urgency. Six months later, 13 May 2027 arrives with the same gaps.

How to use the months until 13 May 2027

From the end of September 2026 there are roughly 32 weeks until 13 May 2027. A realistic sequence:

WindowFocus
October to November 2026Inventory every processing activity: what personal data, which purpose, which systems, which vendors. Mark which purposes rely on consent and which may fall under Section 7 legitimate uses, with legal sign-off.
December 2026 to January 2027Write itemised Rule 3 notices per purpose, in the languages your users use. Redesign forms for granular, purpose-level consent.
February to March 2027Build withdrawal and rights handling: a withdrawal route as easy as giving consent, a process for access, correction and erasure requests, and consent records you can prove.
April 2027Security safeguards review, vendor contracts, and a breach-response drill against the Rule 7 timelines. Re-notify Data Principals whose consent predates the Act.
May 2027Go live, monitor, and fix what the first weeks surface.

To see where you stand today, try the DPDP compliance calculator.

Where Consently fits

Consently is a DPDP-native consent management platform for Data Fiduciaries. It captures consent per processing activity and purpose, shows notices in English and the 22 languages of the Eighth Schedule, gives Data Principals a preference centre to review and withdraw consent, and keeps an append-only record of every consent event. Consently is not a registered Consent Manager under Section 6(9), and most businesses do not need one to comply. If you want to plan the next 32 weeks around your own forms and data, book a demo.

Frequently asked questions

Is 13 November 2026 a DPDP compliance deadline?

Not for an ordinary Data Fiduciary. It is the date Rule 4 commences, which lets companies register with the Data Protection Board as Consent Managers. The main obligations for Data Fiduciaries, including notice, consent, security, breach intimation and Data Principal rights, apply from 13 May 2027.

Do I need to use a registered Consent Manager to comply with the DPDP Act?

No. The Act lets a Data Principal give and manage consent through a Consent Manager, but it does not require every Data Fiduciary to use one. You can collect and manage consent directly, as long as you meet the notice and consent requirements.

What happens on 13 May 2027?

The eighteen-month phase of the DPDP Rules, 2025 commences. This includes Rule 3 on notices, Rule 6 on security safeguards, Rule 7 on breach intimation, the rules on retention and erasure, children's data and Data Principal rights, and the obligations of Significant Data Fiduciaries.

Is a consent management platform the same as a Consent Manager?

No. A Consent Manager is registered with the Data Protection Board and acts for Data Principals across many Data Fiduciaries. A consent management platform is software a Data Fiduciary uses to collect and record consent on its own websites and apps. No registration exists for it.

Should I wait until 2027 to start?

No. Inventory, notice redesign, consent capture, withdrawal and records take months, and consents you collect before May 2027 will still need to be defensible afterwards. Starting now leaves room to do it properly.

This article is for general information and is not legal advice. Please consult a qualified lawyer for advice on your specific situation.

Share this article

Related Articles

DPDP Granular Consent: Why One Checkbox Is No Longer Enough
Compliance Guides

DPDP Granular Consent: Why One Checkbox Is No Longer Enough

One checkbox covering terms, marketing, WhatsApp and partner sharing is unlikely to hold up under the DPDP Act. Here is what Section 6 and Rule 3 require, what purpose-level consent looks like on a real form, and a checklist to finish before 13 May 2027.

29 Sept 20267 min
Proving Consent Under the DPDP Act: What Your Consent Records Must Show
Compliance Guides

Proving Consent Under the DPDP Act: What Your Consent Records Must Show

Under Section 6(10) of the DPDP Act, the Data Fiduciary has to prove that notice was given and consent was obtained. A "true" in your users table will not do that. This guide covers what a defensible consent record contains, why refusals and withdrawals must be recorded too, and a checklist for 13 May 2027.

29 Sept 202610 min
Compliance Guides

DPDP Consent Manager Registration: Eligibility, the ₹2 Crore Net Worth Bar, and the Application Checklist

The Consent Manager framework goes live on 13 November 2026. Registration requires incorporation in India, a minimum net worth of ₹2 crore, and demonstrated technical capability to run consent across fiduciaries. Here is who qualifies, what the application needs, and — importantly — why most businesses should not apply.

14 Jul 20269 min