India's DPDP Consent Manager Framework: What Every Business Must Build Before November 2026
Published: August 2026 | DPDP Compliance Series | AnantaQuanta Consulting
There are two dates every business in India needs to have marked on its compliance calendar right now. The first is November 13, 2026 — when India’s DPDP Consent Manager framework becomes operational. The second is May 13, 2027 — when full enforcement under the Digital Personal Data Protection Act, 2023 begins, with penalties that can reach ₹250 crore per violation category.
The challenge is that most organisations are treating these as future events. They are not. The infrastructure, processes, and legal architecture required to meet both deadlines takes between eight and eighteen months to build — which means the build window for many Indian enterprises is already open, or about to close.
The Core Question to move forward by companies across BFSI, SaaS, healthcare, and e-commerce ––– what exactly do we need to have in place before November 2026? This article answers that question directly.
What Is a DPDP Consent Manager — And Why It Matters for Your Business
Under Sections 6(7) to 6(9) of the DPDP Act and Rule 4 of the DPDP Rules 2025, a Consent Manager is a specific category of registered entity. It acts as a single, interoperable interface through which an individual — called a Data Principal under the Act — can give, review, manage, and withdraw consent across multiple Data Fiduciaries from one place.
Think of it like the Account Aggregator model that transformed India’s financial data sharing — except this applies across all digital services that process personal data.
The Consent Manager registration window opens on November 13, 2026. To register, an entity must be a company incorporated in India, carry a minimum net worth of ₹2 crore, demonstrate technical interoperability capabilities, maintain a data-blind transport layer so personal data is never readable to the Consent Manager itself, and retain consent records for at least seven years.
Here is what most business leaders misread: the November 2026 deadline is not the moment to start preparing. It is the moment when the Consent Manager ecosystem switches on — and your systems either connect to it or they do not.
The Three Types of Organisations and What Each Must Do
1. Businesses Wanting to Operate as a Consent Manager
If your organisation intends to register and operate as a Consent Manager — effectively becoming a licensed consent intermediary in India’s data economy — registration preparation should have already started. The eligibility verification, technical infrastructure build, security certifications such as ISO 27001 or SOC 2, and board-level governance documentation required by the Data Protection Board will not be assembled in weeks.
2. Data Fiduciaries Planning to Integrate With a Consent Manager
Most businesses will not register as a Consent Manager. Instead, they will need their internal systems to connect with one. Under the DPDP framework, if you rely on consent as your lawful basis for processing personal data, your infrastructure must be capable of ingesting consent signals from a registered Consent Manager at the API level, honouring withdrawals in real time — not in batch — and keeping your internal consent ledger synchronised with the external Consent Manager state.
This is an API and systems-integration project that sits on top of a legal and policy redesign project. Enterprises that delay scoping this until late 2026 consistently run into the same bottleneck: legacy consent capture systems — sign-up forms, cookie banners, IVR scripts, paper onboarding — were never engineered to communicate with an external consent registry.
3. All Data Fiduciaries — Consent Architecture Regardless of Integration
Whether or not you integrate with a Consent Manager in November 2026, the DPDP Act requires every Data Fiduciary to build a compliant consent architecture before full enforcement in May 2027. The five requirements are non-negotiable.
DPDP CONSENT MUST BE — Free, Specific, Informed, Unconditional, and Unambiguous
Under DPDP Clause 6, all five attributes must be demonstrable through logs, controls, and withdrawal mechanisms. Bundled consent buried in Terms and Conditions is not valid. Each processing purpose requires separate, explicit consent — and your systems must prove this on demand.
Five Things Every Business Must Build Before November 2026
- Purpose-specific consent notices — redesign every consent touchpoint to capture consent separately for each processing purpose. A single omnibus consent box is non-compliant.
- Multilingual notice capability — the Act requires notices to be available in all 22 scheduled languages of the Indian Constitution. This is operationally demanding and is consistently underestimated during planning.
- One-click withdrawal mechanism — if consent was given in one click, it must be withdrawable in one click. Complex withdrawal processes are a direct violation. On withdrawal, you must cease processing and erase the data across all systems and processors — not just stop new collection.
- Seven-year consent record retention — consent records must be retained and audit-ready for seven years. This is a data architecture decision, not a documentation exercise. Legacy CRMs and marketing platforms frequently cannot store the metadata required.
- Consent Manager API readiness — your identity and consent infrastructure must be capable of receiving and honouring consent state changes arriving via API from a registered Consent Manager, not just from your own application interfaces.
The DPDP Act’s penalty schedule is structured to sting. Up to ₹250 crore for failure to implement reasonable security safeguards. Up to ₹200 crore for processing without valid consent or failure to notify a breach. These penalties stack per violation category. A single breach event involving inadequate consent records and missing security safeguards could simultaneously trigger multiple penalty heads. Early, documented compliance directly reduces both your probability of a penalty and its quantum if a breach occurs.
What the Data Governance Foundation Looks Like
Consent architecture does not exist in isolation. It sits on top of a data governance foundation — a clear inventory of what personal data your organisation collects, where it lives, for what purpose, and under which legal basis. Without that foundation, building a compliant consent layer is structurally impossible.
This is where many organisations in India are currently underinvested. Data scattered across CRMs, marketing platforms, cloud databases, and third-party processors with no unified view of consent state creates a compliance gap that no consent management platform can close on its own.
Building that foundation — a data inventory, a purpose register, a processing activity record — is the prerequisite work that must happen before a consent architecture makes sense. AnantaQuanta Consulting’s DPDP compliance programmes typically begin here: with a gap assessment that maps your current data flows against the Act’s requirements, identifies the highest-priority remediation items, and sequences the build in a way that hits both the November 2026 and May 2027 deadlines without disrupting business operations.
Where to Start
The organisations navigating this most effectively are not the ones that waited for a final regulatory deadline. They are the ones that started a structured gap assessment in early 2026, gave their legal, technology, and data governance teams enough runway to build properly, and treated the November 2026 Consent Manager milestone as their build completion target — not their build start date.
If your organisation has not yet mapped its DPDP obligations, assessed its consent architecture readiness, or assigned ownership of the compliance programme, now is precisely the right time. The full enforcement deadline of May 2027 sounds distant. The engineering, legal, and governance work required to get there does not accommodate late starts.
ANANTAQUANTA CONSULTING — DPDP COMPLIANCE SUPPORT
We help Indian enterprises across BFSI, SaaS, healthcare, manufacturing, and e-commerce build DPDP-compliant consent architectures, data governance foundations, and Data Fiduciary obligations frameworks. Our DPDP Readiness Assessment maps your current state against all obligations under the DPDP Act 2023 and DPDP Rules 2025, across consent design, data governance, AI risk, breach notification, and Significant Data Fiduciary readiness — and delivers a sequenced implementation roadmap. We also advise on the interaction between DPDP, GDPR for businesses with European exposure, and sector-specific requirements from RBI, SEBI, and IRDAI.
Conclusion
India’s DPDP Consent Manager framework is not just a regulatory formality. It is the infrastructure layer through which Indian citizens will exercise data rights at scale — the same way Account Aggregators changed financial data sharing. The businesses that build the right consent architecture now are not just avoiding penalties. They are building the foundation of customer trust that will define competitive positioning in India’s data economy over the next decade.
The November 2026 deadline is ninety-five days away. The May 2027 enforcement deadline is nine months after that. Neither is far enough away to defer action.
Frequently Asked Questions — DPDP Consent Manager
What is a DPDP Consent Manager?
A Consent Manager under India’s DPDP Act 2023 is a regulated entity registered with the Data Protection Board of India. It operates as a neutral intermediary that allows Data Principals — individuals whose personal data is being processed — to give, manage, review, and withdraw consent across multiple Data Fiduciaries from a single, interoperable platform.
When does the DPDP Consent Manager framework become operational?
The Consent Manager registration window opens on November 13, 2026 — exactly twelve months after the DPDP Rules 2025 were notified by MeitY on November 13, 2025. This is Phase 2 of the DPDP implementation timeline. Full substantive compliance for all Data Fiduciaries becomes enforceable on May 13, 2027.
Does every business need to register as a Consent Manager?
No. Most businesses will not register as a Consent Manager. Registration is only required for entities that want to operate as a licensed consent intermediary in India’s data ecosystem. However, all Data Fiduciaries that rely on consent as a lawful basis for processing personal data must build internal consent architectures that are compatible with registered Consent Managers at the API level.
What is the minimum net worth requirement to register as a Consent Manager?
Under Rule 4 of the DPDP Rules 2025, a Consent Manager must be a company incorporated in India with a minimum net worth of ₹2 crore. Additional requirements include technical interoperability capabilities, a data-blind transport layer so the Consent Manager cannot read the personal data it routes, and retention of consent records for at least seven years.
What are the penalties for non-compliance under the DPDP Act?
The DPDP Act’s penalty schedule reaches up to ₹250 crore for failure to implement reasonable security safeguards, up to ₹200 crore for processing personal data without valid consent or failing to notify a data breach, and up to ₹200 crore for failing to protect children’s personal data. Penalties stack per violation category, meaning a single incident can create exposure across multiple penalty heads simultaneously.
What does a DPDP-compliant consent notice look like?
A compliant DPDP consent notice must be independent of your Terms and Conditions, must clearly state every category of personal data being processed and the specific purpose for each category, must include a withdrawal mechanism as easy as the consent mechanism, and must be available in the user’s preferred language from India’s 22 scheduled languages. Bundled or implied consent does not satisfy the Act’s requirements.
What happens when a Data Principal withdraws consent?
On withdrawal, your organisation must immediately cease processing the personal data and erase it across all your systems, databases, and third-party processors — not just stop new collection. The withdrawal mechanism must be as simple as the consent mechanism. Batch-processing withdrawals or delaying deletion creates a direct compliance gap under the Act.
How does the DPDP Act interact with GDPR for businesses with European operations?
Both frameworks require a lawful basis for data processing, robust consent management, data subject/principal rights, breach notification obligations, and accountability documentation. However, DPDP does not currently require a Data Protection Impact Assessment for all high-risk processing, does not have explicit legitimate interest provisions, and imposes India-specific requirements including multilingual notices and the Consent Manager integration layer. Businesses operating under both regimes benefit from a unified compliance programme that maps obligations across both frameworks rather than managing them separately.