Regulation · India
Consent Managers, and the November 2026 date
The DPDP framework introduces a role with no direct equivalent in the GDPR, and its registration provisions are the second phase to commence.
Facts checked — 2026-09-11
What is a Consent Manager under the DPDP Act?
A Consent Manager is a registered entity that gives data principals a single point to give, manage, review and withdraw consent across the fiduciaries they deal with. It is registered with the Data Protection Board and subject to conditions including a net worth threshold.
Rule 4, covering Consent Manager registration, commences on 13 November 2026 — one year after the Rules were notified. The substantive obligations on data fiduciaries follow later, on 13 May 2027.
The bottom line
Unless you intend to become one, this changes how consent may reach you rather than what you must do. Watch it; do not build for it yet.
Related services
ISO/IEC 27701 — Privacy Information Management
Turn privacy from a policy document into a management system, with the records a regulator or an enterprise buyer will ask to see.
Related insights
Regulation · India
Is the DPDP Act in force? What applies today, and the deadline that matters
The Act is law today and its obligations bite on 13 May 2027. Penalties reach ₹250 crore, and the work that takes longest is the work nobody has started.
Regulation · EU
Does the GDPR apply to an Indian company? Scope, roles and the EU representative question
Most Indian firms are caught through a contract rather than by a regulator — and most do not need the EU representative they are being sold.
Regulation
Breach notification: the clock starts before you know what happened
Both regimes start counting when you become aware — and India’s rules have no risk threshold for telling the people affected.