The DPDP Consent Manager Deadline: What Data Fiduciaries Must Have Ready by 13 November 2026

The date of 13 November 2026 has been interpreted as a general obligation date for all data fiduciaries in the compliance commentary, but that is not the case when it comes to the instrument itself. The Digital Personal Data Protection Rules 2025 have been notified on 13 November 2025, with rule 1(2) providing a staggered commencement of the rules, namely that rules 1, 2 and 17-21 (Data Protection Board) come into effect on the date of notification, while rules 3 and 5-16 (notice, consent mechanics, data-breach intimation and data principal rights) come into effect eighteen months after notification, on 13 May 2027.
The November 2026 date thus opens a registration gateway for a particular type of intermediary.It does not create any new obligations for data fiduciaries in general.The immediate legal effect of the date is more limited than most of the coverage implies.From then on, it is required to be registered with the Board under rule 4, which stipulates that it must meet certain eligibility requirements, including that it be an Indian company with a minimum net-worth, and must accept certain obligations, including interoperability across platforms, that it may not sub-contract core consent-management functions, and that it keep records of consents, notices and data-sharing logs for at least one year.On 13 November 2026, an ordinary data fiduciary that does not register as a Consent Manager will not have any new duty.
A lack of direct obligation does not, however, equal irrelevance. Rules 3 and 5-16 (consent capture, notice content and breach reporting) will actually apply to data fiduciaries in the ordinary course in May 2027, and will have no further transition period after triggering. The integration of a third-party Consent Manager must be well developed and tested ahead of time, and the marketplace for registered Consent Managers is just beginning to emerge once rule 4 goes into effect. Whether or not a fiduciary registers itself, the compliance benchmark rule 4 imposes on Consent Managers is likely to serve as the de facto standard for evaluating the consent-record architecture of a fiduciary’s consent record. The more precise definition of the task at the end of the year is therefore not compliance on 13 November 2026, but architectural readiness for May 2027.




