HALVERTON & CO.

Technology & AI Law · 3 October 2026 · 7 min read

Consent Managers Go Live: What November 2026 Means for DPDP Compliance

An infographic titled Consent Managers Go Live showing what becomes mandatory from 13 November 2026 under Rule 4 of the DPDP Rules and what it means for data fiduciaries.

If you’ve sat through a DPDP compliance presentation this year, someone has probably told you that “the November 2026 deadline” is coming. That’s half true. On 13 November 2026, one specific part of India’s data protection law switches on: the registration of consent managers. For most businesses it doesn’t create a new obligation that day, but it does change the consent environment they’ll be operating in.

This guide explains what a consent manager is under the Digital Personal Data Protection Act, 2023, what Rule 4 of the DPDP Rules, 2025 requires, who can register, what it means for ordinary businesses, and the remedies available when consent goes wrong. For the full compliance picture, start with our DPDP Act compliance checklist.

What a consent manager is under the DPDP Act

A consent manager is a registered intermediary that lets individuals give, review, manage and withdraw their consent across multiple Data Fiduciaries from a single platform. Think of it as a dashboard for your data permissions: instead of hunting through dozens of apps to see who has your consent and for what, you use one interoperable platform.

The DPDP Act defines a consent manager as a person registered with the Data Protection Board of India, and Section 6(9) requires every consent manager to register with the Board and comply with prescribed technical, operational and financial conditions.

It’s important to separate two things that are often confused. A consent manager is a statutory role with registration and regulatory duties. A “consent management platform” is simply a software product, such as a cookie banner or a preference centre, and it needs no registration at all. Most businesses will use consent management software. Very few will become registered consent managers.

Consent manager vs consent management platform
Consent managerConsent management platform
What it isA registered statutory intermediaryA software product such as a preference centre or cookie banner
RegistrationMust register with the Data Protection BoardNone required
Who uses itIndividuals, to manage consent across many fiduciariesA single business, to manage its own consent records
Regulated byThe Data Protection Board, under Section 6(9) and Rule 4Not separately regulated; the business remains the Data Fiduciary

What actually commences in November 2026

The DPDP Rules, 2025 were notified on 13 November 2025 and come into force in phases. Rule 4, which governs the registration and obligations of consent managers, takes effect one year after publication, in November 2026, while most substantive obligations on Data Fiduciaries wait a further six months, until 13 May 2027. Section 6(9) of the Act and the Board’s power under Section 27(1)(d) to inquire into breaches of registration conditions commence alongside Rule 4.

Most commentators give the date as 13 November 2026, though one reads Rule 1(3) as making it 14 November. The difference matters only to applicants planning to file on day one, so check the Gazette notification if that’s you.

What 13 November doesn’t do is impose a new obligation on ordinary businesses. It switches on consent manager registration, not your obligation to use one. Anyone presenting it as a universal “DPDP compliance deadline” is overselling. The deadline that matters for most Data Fiduciaries is still 13 May 2027.

Who can register as a consent manager

The registration bar is deliberately high. Under Part A of the First Schedule to the DPDP Rules, an applicant must be a company incorporated in India with a net worth of at least ₹2 crore, sufficient technical, operational and financial capacity, and directors and senior management of sound reputation and integrity. Net worth is defined as total assets less liabilities as shown in the books of account. The company’s memorandum and articles must embed consent manager obligations and require the Board’s approval for amendments.

Registration isn’t a one-time event. Once registered, a consent manager is subject to ongoing obligations under the First Schedule, and the Board can monitor compliance, require corrective action and suspend or cancel registration in the interest of Data Principals. A key design feature is that personal data routed through the platform must not be readable by the consent manager itself.

The net worth requirement and the conflict-of-interest rules exclude most Data Fiduciaries. In practice, consent managers are likely to be specialised technology providers, fintech infrastructure players and companies building on India’s account aggregator and DigiLocker experience.

What it means for ordinary businesses

If you’re a startup, an e-commerce company, a hospital or a SaaS provider, you probably won’t register as a consent manager. But the consent infrastructure you may have to interoperate with starts to exist from November 2026. Once the main DPDP obligations apply in May 2027, a customer may give, manage or withdraw consent through a registered consent manager rather than your own app, and you’ll need to honour it.

Practically, that means three things. First, your consent records should be structured, itemised and machine-readable, not buried in PDFs and emails. Second, your systems should be able to receive a consent or withdrawal signal from an external platform and act on it, including stopping processing and deleting data where required. Third, your privacy notice should explain how individuals can use a consent manager to deal with you.

Consider a simple scenario. A customer of an online pharmacy uses a registered consent manager to withdraw consent for marketing messages across several apps at once. From May 2027, the pharmacy must act on that withdrawal just as if the customer had clicked “unsubscribe” in its own app, and must be able to show that it did. If its systems can’t receive the signal, the failure is the pharmacy’s, not the consent manager’s.

For a startup, the cost of getting this right early is small: a structured consent log, an API endpoint that can accept a withdrawal, and a privacy notice that mentions consent managers. The cost of getting it wrong arrives later, in complaints to the Data Protection Board, and those complaints will turn on whether you can prove what consent you had and when. Businesses building consent tooling now should design for interoperability from the start. Retrofitting a closed consent system in 2027 will cost far more than building it properly in 2026. If your product serves children, the consent rules are stricter still; see our guide to children’s data under the DPDP Act. Employee and candidate data raises its own questions, covered in our guide to AI in hiring and employee monitoring, and gig platforms face parallel registration duties under the Social Security Code.

Consent flows also have to be honest in design. A consent screen that nudges users towards “accept all” can be both a weak consent and a dark pattern; see our guide to dark patterns in Indian apps.

Remedies, enforcement and quick answers

For individuals, a consent manager adds a route to control consent, but the core remedies remain the same. A Data Principal must first raise a grievance with the Data Fiduciary or consent manager, and can then complain to the Data Protection Board. Consent managers are accountable to the Board, which can inquire into breaches of registration conditions and suspend or cancel registration. For businesses, failing to honour consent or its withdrawal will, from May 2027, expose them to penalties under the Schedule to the DPDP Act, with the highest ceilings reaching ₹250 crore for security failures. Disputes about whether consent was validly given will turn on records, so keep them. Security failures also trigger CERT-In reporting; see our guide to the CERT-In 6-hour rule.

Quick answers

Do I need to register as a consent manager?

Only if you want to operate as one. Ordinary businesses don’t need to register, though they’ll need to work with consent managers once the main DPDP obligations apply.

What is the net worth requirement for a consent manager?

At least ₹2 crore, along with incorporation in India and adequate technical, operational and financial capacity.

Is 13 November 2026 the DPDP compliance deadline?

No. It switches on consent manager registration. Most Data Fiduciary obligations apply from 13 May 2027.

Final word

At Halverton & Co., we advise founders, technology companies, investors and individuals on DPDP compliance, consent architecture and data protection disputes. We practise in Jharkhand, Maharashtra and before the Supreme Court of India, and act as fractional legal counsel for technology-driven businesses that need senior legal support without a full in-house legal team. Halverton & Co. is built on a simple idea: Where tech needs law! If this issue affects you or your business, write to us at office@halvertonandco.com, or get in touch, and we’ll help you work out where you stand.

This article reflects the law and developments reported up to early October 2026. It is for general information only and is not legal advice. Please take advice on your specific facts before acting.

Related practice area

Technology & AI Law

Contracts, data protection and AI policies for products that handle other people’s data.

View the practice area
Email this

This article is part of our Technology and AI law guides.

Questions

Write to us about what you are building.

This article is general information, not legal advice for your situation. If something here applies to your business, tell us briefly what you are working on.