India's DPDP Compliance Emergency: 71% of Enterprises Unprepared as the Consent Manager Window Opens
An EY India survey finds 71% of enterprises can't interpret the DPDP Act, 83% haven't begun implementation — and the consent manager deadline is weeks away.

#India's DPDP Compliance Emergency: 71% of Enterprises Unprepared as the Consent Manager Window Opens
Seven in ten Indian enterprises cannot adequately interpret India's Digital Personal Data Protection Act — and the Consent Manager framework that operationalises the law's core consent architecture is expected to go live within weeks. A comprehensive EY India survey published earlier this year, now being cited widely as companies scramble, lays out a compliance picture that is more alarming than most boardrooms appear to have registered.
The numbers land at a deeply inconvenient moment. The DPDP Act's Consent Manager framework becomes operational on November 13, 2026 — less than four months away. Full enforcement, including the Data Protection Board's penalty powers, begins May 13, 2027. For 83% of Indian enterprises that have not yet begun end-to-end DPDP implementation, the window is closing faster than their compliance timelines acknowledge.
#What the EY Survey Actually Found
The EY India report, based on responses from approximately 150 professionals across eight sectors, is one of the most data-rich assessments of DPDP readiness conducted to date. The headline figure — 71% of enterprises have limited understanding of the Act and its Rules — is striking enough. The supporting statistics are worse.
- 83% of surveyed organisations have not begun end-to-end DPDP system implementation
- 80% have not updated privacy policies or governance frameworks aligned with the Act
- Only 48% have completed gap assessments to identify areas of non-compliance
- Only 44% have documented their data processing procedures
- Only 38% have categorised the personal data they hold or identified relevant third-party vendors
These are preparation metrics. They measure whether organisations have done the groundwork that compliance requires — not whether they have achieved compliance. The fact that fewer than half have finished a gap assessment with 10 months to the enforcement deadline suggests the execution curve ahead is extremely steep.
The barriers respondents cited track the shape of India's broader digital economy. 77% cannot adopt privacy technology in their legacy systems — a significant constraint for sectors like banking, insurance, and manufacturing that run core operations on infrastructure built before the concept of data subject rights existed. 76.4% lack access to subject-matter expertise in data protection. 58.8% are struggling specifically with cross-border data transfer complexities — an area where MeitY's pending notification on Significant Data Fiduciary restrictions is likely to make things more complicated, not less.
Murali Rao, EY India's Cybersecurity Leader, stated that organisations must move "beyond assessments and embed privacy into governance, systems and culture" rather than treating compliance as a regulatory obligation to check off. That framing — privacy as operating infrastructure rather than legal paperwork — is precisely the shift the Act demands, and precisely the shift most Indian enterprises have not yet made.
#The Sector Breakdown Is Not Uniform
Aggregate percentages obscure the fact that India's DPDP compliance gap is not evenly distributed. The EY data breaks down sector-wise initiation rates — the percentage of firms in each sector that have at least begun their DPDP compliance journey — and the spread is significant.
| Sector | Compliance Journey Initiated |
|---|---|
| Consumer, Retail & E-commerce | 50% |
| Technology Services | 38.8% |
| Financial Services | 34.7% |
| Metals, Mining & Energy | 20% |
| Healthcare & Life Sciences | 9.9% |
The healthcare figure deserves particular attention. At 9.9%, healthcare and life sciences is the worst-performing sector in the survey — less than one in ten firms has begun preparing. This is not a peripheral industry under the DPDP Act. Healthcare data falls within the Act's most sensitive category of personal data, where penalties for violations involving improper handling reach ₹200 crore. Hospitals, diagnostic chains, health insurance providers, and clinical research organisations processing the medical records of Indian citizens face among the heaviest compliance obligations in the entire Act — and the sector is functionally still asleep.
Financial services, at 34.7%, might appear better positioned, but given that the sector will almost certainly be among the first wave of Significant Data Fiduciary (SDF) designations — due any time from MeitY — it sits in a peculiar combination of elevated exposure and incomplete readiness.
Consumer internet and e-commerce, leading at 50%, is itself a sobering figure: the best-performing sector is still only at the halfway mark, and "initiated the journey" is not the same as ready to comply.
#November 13 Is Not a Distant Deadline
Part of what is generating urgency now is the concrete sequencing of what comes in the next four months.
By November 13, 2026, the Consent Manager framework under Rule 4 of the DPDP Rules becomes operational. This means the infrastructure through which Indian data principals can manage, review, and withdraw consent across multiple digital services — the DPDP Act's signature mechanism for giving individuals genuine control over their data — will go live. Organisations that want to operate as registered Consent Managers must complete their application with the Data Protection Board before this date.
The implications extend well beyond the consent management industry. Any data fiduciary that relies on third-party consent infrastructure to meet its obligations under the Act needs to have integrated with these systems before November 13. That means API-level development work that cannot start the week before the deadline. It means testing, security review, and user experience validation. For large enterprises managing consent at scale across millions of users, this is months of engineering — and the clock for that work is already running short.
Critically, the government is expected to operationalise the Consent Manager framework in the June–August 2026 window, meaning the registration portal may open imminently if it has not already. Organisations that plan to apply as Consent Managers — and there are at least eight platforms actively positioning for this status — need to be ready to file. The DPDP Rules restrict Consent Manager registration to India-incorporated entities with a minimum net worth of ₹2 crore, which by design excludes foreign platforms. This creates a compliance infrastructure market that is distinctly Indian, with early movers likely to capture a disproportionate share.
#The Supreme Court Dimension Businesses Are Ignoring
While corporate compliance teams focus on the implementation clock, a parallel process in the Supreme Court carries the potential to reshape the legal landscape without warning. A bench led by Chief Justice Surya Kant, with Justices Joymalya Bagchi and V.M. Pancholi, is currently hearing at least five consolidated writ petitions challenging the constitutionality of the DPDP Act and Rules. The next hearing is scheduled for August 3, 2026.
The core challenge before the bench targets Section 44(3) of the Act, which amended Section 8(1)(j) of the Right to Information Act 2005. The petitioners — including The Reporters Collective Trust, journalist Geeta Seshu, the Software Freedom Law Centre, and, in a more recently admitted petition, the Editors Guild of India and a coalition of state information commissions — argue that the amendment converts a calibrated public-interest balancing test into a blanket privacy exemption that effectively weaponises data protection against transparency and press freedom.
The Supreme Court has declined to stay the Act, meaning the DPDP Rules remain fully operative and the Data Protection Board can continue to function. But the constitutional challenge extends beyond the RTI amendment. Petitioners have raised concerns about the breadth of government exemption powers under Section 17(2), the vagueness of several statutory definitions, and the adequacy of oversight mechanisms for state surveillance activities.
For businesses, the practical implication is not that compliance should be delayed — it should not be. The Act is in force; penalties apply. But the August 3 hearing introduces a non-zero probability of amendments or clarifications that could affect how specific provisions are interpreted and enforced. Compliance strategies that treat the Act as completely settled law are, technically, working from an incomplete picture. The sensible approach is to build systems around the Act's requirements as currently notified while monitoring the constitutional proceedings — not to wait for the court's conclusion before beginning implementation.
#What MeitY's SDF Notification Will Change
One missing piece in the current compliance landscape is the formal notification of Significant Data Fiduciary criteria and the initial SDF list. MeitY proposed in January 2026 — after a stakeholder consultation — to accelerate this notification and simultaneously impose cross-border transfer restrictions on SDFs at the moment of designation. Industry feedback is being processed.
When the SDF notification lands, it will not come with a grace period. For entities designated as SDFs, the compliance burden immediately increases: mandatory Data Protection Impact Assessments every 12 months, appointment of a Data Protection Officer and an independent Data Auditor, prohibition on transferring certain categories of data outside India, and reporting obligations to the Data Protection Board. Likely SDF candidates based on the Act's stated criteria include social media platforms, major e-commerce marketplaces, health data processors, AI system operators, search engines, and entities processing data of national security significance.
The cross-border transfer restriction component is particularly complex. Rule 13(4) of the DPDP Rules already prohibits SDFs from transferring traffic data related to personal information flows outside India. Additional restrictions will be notified by the Central Government based on recommendations from a committee it constitutes. For multinational companies that currently process Indian user data on global infrastructure and assume GDPR compliance provides adequate cover, this assumption is wrong on multiple dimensions.
GDPR and the DPDP Act are structurally different frameworks. GDPR compliance does not equal DPDP compliance. The legal bases for processing differ; the consent architecture differs; the penalties are calculated differently. GDPR's proportionality-based fines contrast with DPDP's fixed penalty tiers — which means a startup faces the same maximum penalty as a global platform for the same category of violation. For smaller organisations currently relying on GDPR frameworks as their Indian compliance strategy, this is an exposure that requires active remediation.
#The Four Things That Cannot Wait
Given the convergence of deadlines, the EY survey's findings, and the regulatory trajectory, the organisations most at risk are those treating the May 2027 enforcement date as the starting point for urgency. It is not. The sequencing of obligations means that work required to meet November 2026 must begin now, and work required for the SDF notification must begin before the notification arrives.
Four actions are not optional in the current window:
1. Complete the gap assessment. Only 48% of firms have finished this step. Without knowing where data lives, what it is used for, and which third parties touch it, consent and notice architecture cannot be designed. The gap assessment is the foundation. Everything else depends on it.
2. Update privacy notices. The Act requires a notice to data principals that specifies the personal data being collected, its purpose, the grounds for processing, and the data principal's rights. Approximately 80% of Indian enterprises have not done this. For consumer-facing businesses, this notice must be live on every platform where data is collected — before consent is obtained.
3. Build or integrate consent mechanisms. The DPDP Act's consent standard requires free, specific, informed, unconditional, and unambiguous consent obtained through an affirmative action. Legacy consent flows — pre-ticked boxes, bundled permissions, buried terms-of-service — are non-compliant by design. These need to be rebuilt, not patched.
4. Appoint a grievance officer. The Act requires every data fiduciary to designate a contact for handling data principal complaints. This is one of the Act's lower-complexity requirements — and yet it feeds directly into the Data Protection Board's complaint intake process. Having no grievance mechanism is exposure on the easiest compliance item to resolve.
#The Competitive Argument for Acting Now
The EY data, while alarming in aggregate, also describes a first-mover opportunity that is still available. In every sector measured, the majority of competitors have not yet begun. Consumer and retail leads the pack at 50% initiation — meaning half the sector is still inactive. For a company that builds genuine, auditable consent infrastructure now, the competitive differentiation it creates extends beyond regulatory risk avoidance.
India's DPDP Act compliance will, over the next two years, become a procurement criterion for B2B services, a due diligence item for investors and acquirers, and an increasingly visible signal to consumers in a market where data trust is becoming a brand attribute. The organisations that build for compliance now are building for a market position that non-compliant competitors will eventually have to purchase at higher cost under more urgent conditions.
The consent manager market, the data auditing market, and the privacy technology market in India are all being created in real time. That opportunity window is finite. Unlike the EU's post-GDPR ecosystem, which matured over several years of enforcement activity, India's equivalent is forming now — before enforcement, before the first major penalties, before most of the market understands what these tools do.
Seventy-one percent of Indian enterprises struggling to interpret the DPDP Act is a problem for their compliance function. For the organisations that have already interpreted it, it is also a market.
For practical guidance on consent architecture and DPDP compliance tooling, see our /resources section. If you are evaluating a consent manager for your organisation ahead of the November 13 deadline, our /consent-manager comparison covers the platforms currently positioning for government registration.

