Saya & Associates Get in touch
Insights · Privacy

India's Consent Manager regime: what 13 November 2026 actually means

June 20266 min readDPDP · Consent Managers

"Consent Manager registration deadline: November 2026" has become one of the most repeated lines in Indian compliance commentary — and it is wrong in both halves. The date is real. What it does is widely misunderstood. Since misreading it leads businesses to spend on the wrong things in the wrong order, it is worth being precise.

What a Consent Manager is

Under the DPDP Act, 2023, a Consent Manager is a registered entity that gives individuals a single, interoperable platform to give, manage, review and withdraw consent for the processing of their personal data. Think of it as consent infrastructure: instead of every business building its own opaque consent silo, individuals get one dashboard, and businesses get a standardised interface to verifiable consent. The model follows India's account-aggregator playbook — regulated intermediaries, technical standards, an ecosystem expected to mature over years, not weeks.

What 13 November 2026 actually is

The DPDP Rules, 2025 were notified on 13 November 2025 with a phased commencement. Rule 4 — the registration and obligations of Consent Managers — comes into force twelve months later, on 13 November 2026. From that date, an entity wishing to operate as a Consent Manager may apply to the Data Protection Board for registration.

Three things follow, each routinely garbled in commentary:

  1. It is an opening, not a closing. 13 November 2026 is when the registration window opens. It is not a date by which anyone must have registered.
  2. It binds aspirant Consent Managers, not ordinary businesses. The registration obligation applies to entities that want to be Consent Managers. A company that merely processes customer data — a retailer, a bank, a SaaS product — has no Consent Manager registration duty at all, in November 2026 or ever.
  3. Eligibility is demanding. An applicant must be an Indian-incorporated company with a minimum net worth of ₹2 crore and demonstrated technical, operational and financial capacity, among other conditions in the First Schedule to the Rules. This is licensed-infrastructure territory, not a checkbox.

The dates that do bind ordinary businesses

  • 13 November 2025 (passed): the administrative provisions commenced and the Data Protection Board was constituted. The transition clock started.
  • 13 May 2027: the substantive obligations take effect — notice and consent standards, security safeguards, breach notification to the Board and affected individuals, retention and erasure, children's data rules, Significant Data Fiduciary duties and Data Principal rights — with Board penalties of up to ₹250 crore per violation for failures of reasonable security safeguards. This, not November 2026, is the deadline that should organise your programme.

So what should a business do about Consent Managers?

  1. Nothing panicked, by November 2026. There is no registration to complete and no integration mandate in force.
  2. Design consent flows that could plug in later. The Consent Manager ecosystem will develop technical standards for interoperability. Consent architecture built in 2026 should be modular — itemised purposes, auditable records, clean withdrawal — so that connecting to registered Consent Managers, if and when your sector expects it, is an integration project rather than a redesign.
  3. Watch the Board's first registrations. The first cohort of registered Consent Managers, expected after the window opens in late 2026, will reveal the technical standards and sector expectations that follow.
  4. If you want to BE a Consent Manager — and the account-aggregator history suggests real businesses will be built here — the time to assemble the net-worth, governance and technical file is now, so the application is ready when the window opens.

Why the distinction matters

Compliance budgets are finite. A company that spends 2026 chasing a non-existent November registration deadline arrives at the real one — 13 May 2027 — with its notices unwritten, its breach playbook untested and its vendor contracts unamended. Read the dates correctly and the same budget covers what the law actually demands.

Note. This analysis reflects the statutory position as of June 2026 and is published for general information only. It is not legal advice and does not create a lawyer–client relationship.