India's DPDP Deadline on 13 November 2026: What Actually Changes — and What Doesn't
13 November 2026 isn't the DPDP compliance deadline most people think. What the Consent Manager rules change, what applies from May 2027, the penalties, what it means for GCCs and offshore vendors, and a seven-month action plan.
By Pavan Kumar Verma · · 9 min read

If you work in Indian technology, you've probably seen a date doing the rounds: 13 November 2026. LinkedIn posts, vendor webinars and compliance emails are calling it the DPDP deadline — the day India's data protection law "kicks in".
It isn't quite that. And the confusion matters, because it is leading some businesses to panic about the wrong things and others to relax when they shouldn't.
This post explains, in plain language, what actually changes on 13 November, what doesn't, what comes next in May 2027 — and what businesses, Global Capability Centres and technology vendors should be doing right now.
This is a practical overview, not legal advice. For decisions about your organisation, speak to a qualified privacy lawyer.
The short answer
- On 13 November 2026, the rules for Consent Managers come into force. These are registered platforms that will let individuals give, manage and withdraw their consent across many companies from one place. From that date, eligible companies can apply to become Consent Managers.
- 13 November does not switch on most obligations for ordinary businesses. The core duties — notices, consent, security safeguards, breach reporting, data erasure, children's data and individual rights — come into force on 13 May 2027.
- But seven months is not long. For most organisations, redesigning consent journeys, logging, breach processes, retention and vendor contracts will take most of that time. If you haven't started, 13 November is a good moment to start — just not because it's the legal deadline.
The timeline
India's Digital Personal Data Protection (DPDP) Act was passed in 2023. The DPDP Rules, 2025, which explain how it works in practice, were notified on 13 November 2025 and phased in over 18 months.
| Date | What comes into force | What it means |
|---|---|---|
| 13 Nov 2025 | Provisions setting up the Data Protection Board of India | The enforcement body exists in law; in May 2026 the government invited applications for its Chairperson and Members |
| 13 Nov 2026 | Rule 4: Consent Managers | Registration opens for platforms that help people manage consent; no new duties for ordinary businesses on this date |
| 13 May 2027 | Most remaining Rules and core obligations | Notices, consent, security, breach notification, erasure, children's data, rights, and extra duties for Significant Data Fiduciaries |
Two things to watch:
- A possible faster timeline for the largest companies. In January 2026, the government consulted on shortening the 18-month period to 12 months for Significant Data Fiduciaries — large or high-risk data processors. As of the latest guidance I could find (September 2026), no amendment had been notified. If one is, those companies could face obligations much sooner.
- The Board's readiness. The Data Protection Board is the body that will investigate complaints and impose penalties. Reports differ on whether its leadership has been appointed yet. Until it is fully operational, enforcement can't begin in practice — but the law's deadlines still apply.
What is a Consent Manager?
Imagine having one app where you can see every company you've allowed to use your personal data, for what purpose — and switch any of those permissions off with a tap. That's the idea behind a Consent Manager.
Under the Rules, a Consent Manager must:
- be a company incorporated in India, with a minimum net worth of ₹2 crore and the technical and operational capacity to do the job;
- run an accessible, transparent and interoperable platform;
- avoid conflicts of interest with the companies whose consents it manages;
- not sub-contract its core obligations;
- keep records for seven years.
For individuals, using a Consent Manager is an option, not a requirement. For businesses, there's no rule saying you must integrate with one on 13 November. But once Consent Managers are live and people start using them, any business that relies on consent will need to receive and act on consent decisions from them — and that integration takes time to build.
What comes into force in May 2027
This is where the real work is. From 13 May 2027, any organisation that processes digital personal data in India — a "Data Fiduciary" — must meet the following obligations.
1. Clear notices
Before asking for consent, you must give people a clear, standalone notice in plain language, listing what personal data you collect, the specific purposes, and how they can withdraw consent, exercise their rights and complain.
2. Real consent
Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action. Withdrawing consent must be as easy as giving it. You need to be able to prove what consent was given, when and for what.
3. Reasonable security safeguards
You must protect personal data with appropriate measures — such as encryption, access controls, monitoring and backups — and keep logs that allow breaches to be detected and investigated, generally for at least one year. This duty also covers data handled by your vendors (Data Processors), so your contracts must require it.
4. Breach notification
If there is a personal data breach, you must inform affected individuals without delay, and report it to the Data Protection Board — with a detailed report within 72 hours of becoming aware of it, covering what happened, the likely impact and what you're doing about it.
5. Erasure when data is no longer needed
Personal data must be erased once its purpose is served or consent is withdrawn, unless the law requires you to keep it. For large e-commerce and social media platforms (2 crore or more registered users in India) and online gaming platforms (50 lakh or more), data must generally be erased after three years of user inactivity, with 48 hours' notice to the user beforehand.
6. Children's data
Before processing the personal data of a child (anyone under 18), you must obtain verifiable consent from a parent or guardian. Tracking, behavioural monitoring and targeted advertising aimed at children are prohibited, subject to limited exemptions.
7. Individual rights
People have the right to access information about their data, request correction and erasure, have a grievance handled, and nominate someone to exercise their rights if they die or become incapacitated. You must publish how to exercise these rights and respond within set timelines.
8. Extra duties for Significant Data Fiduciaries
Organisations the government designates as Significant Data Fiduciaries — based on the volume and sensitivity of data they process and the risks involved — must appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out a Data Protection Impact Assessment and audit every year. They may also face requirements to keep certain data within India.
9. Cross-border transfers
Personal data can generally be transferred outside India, unless the government restricts transfers to specific countries, and subject to any requirements it specifies.
The penalties
The DPDP Act sets out maximum penalties per instance of non-compliance:
| Breach | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards to prevent a data breach | ₹250 crore |
| Failure to notify the Board or affected individuals of a breach | ₹200 crore |
| Failure to meet obligations on children's data | ₹200 crore |
| Failure to meet additional obligations of Significant Data Fiduciaries | ₹150 crore |
| Breach of any other provision of the Act or Rules | ₹50 crore |
| Breach of duties by individuals (e.g. false complaints) | ₹10,000 |
There is no size exemption in the law itself — startups and small businesses are covered, although the government has the power to exempt certain categories in future.
What this means for GCCs, BPOs and offshore vendors
This is one of the most misunderstood parts of the law, and it matters enormously for India's technology industry.
- Processing data of people outside India under a foreign contract is largely exempt. If an Indian company or GCC processes the personal data of non-residents under a contract with a company outside India — the classic outsourcing or captive-centre model — most of the Act's obligations don't apply. But security safeguard duties still do, and so do your clients' own laws, such as the GDPR or US state privacy laws.
- Your own employees are covered. A GCC's data about its Indian staff — payroll, HR records, monitoring — is personal data of people in India. The law allows processing for employment purposes without consent in many cases, but security, retention and other duties still apply.
- Indian customers bring full obligations. If your centre also serves customers in India, those operations are fully covered.
- Expect clients to ask. Global clients will want to know that their Indian vendors and centres meet DPDP security, breach and erasure requirements. Being ready is a selling point — especially as companies move more work to India in response to US visa restrictions (more on that here).
A seven-month action plan
If you're starting now, here's a realistic path to May 2027.
October–November 2026: Understand your data
- Appoint an accountable owner for DPDP compliance.
- Map what personal data you collect, where it lives, why you use it and who you share it with.
- Check whether you're likely to be designated a Significant Data Fiduciary.
December 2026–January 2027: Fix notices and consent
- Rewrite privacy notices in clear, itemised, purpose-specific language.
- Redesign consent journeys so consent is specific and withdrawal is easy.
- Build a consent record you can prove — what was agreed, when and for what purpose — and plan how you'll accept decisions from Consent Managers.
February–March 2027: Secure and prepare for breaches
- Strengthen encryption, access control and monitoring.
- Set log retention to at least a year.
- Write and rehearse a breach response plan that meets the 72-hour reporting requirement.
- Update contracts with every vendor that processes personal data for you.
March–April 2027: Retention and rights
- Define retention periods and automate erasure, including advance notice where required.
- Set up processes and tools to handle access, correction, erasure, grievance and nomination requests.
April–May 2027: Children, testing and training
- Implement verifiable parental consent where you process children's data.
- Train staff, test end-to-end, and consider an independent review before the deadline.
What the government should do next
To make the law work well, a few things would help businesses enormously:
- Make the Data Protection Board fully operational — with its leadership, processes and digital complaint systems in place well before May 2027.
- Publish practical guidance and FAQs, especially on consent design, breach reporting and children's data.
- Clarify early which organisations will be Significant Data Fiduciaries, and confirm whether their timeline will be shortened.
- Publish technical standards for Consent Managers, so businesses know how to integrate.
- Offer proportionate support for startups and small businesses, which will find compliance hardest.
Final thought
India's data protection law is arriving in stages, and 13 November 2026 is an important step — but it isn't the cliff edge many people think it is. The real deadline is 13 May 2027, and the real risk is treating November as either a panic or a reprieve.
The organisations that do best will use the next seven months to build something more valuable than compliance: customer trust. In an economy where more of the world's digital work is moving to India, showing that personal data is handled responsibly isn't just a legal requirement — it's a competitive advantage.
Is your organisation ready for May 2027? What's proving hardest — consent, security, erasure or vendor contracts? Share your experience in the comments.
Sources: Digital Personal Data Protection Act, 2023 (including the Schedule of penalties and section 17 exemptions) and Digital Personal Data Protection Rules, 2025 (Ministry of Electronics and Information Technology, notified 13 November 2025); Press Information Bureau notification of the DPDP Rules; analysis by Mondaq, MirvoLegal (law as at September 2026), MatrixGard, OpenIAM, ConsentOS and Veritect on the phased timeline, Consent Manager framework, proposed compressed timeline and Data Protection Board recruitment.