Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook →

116 Days to India's Consent Manager Deadline — and the Regulator Still Isn't There

India's DPDP Act Consent Manager framework activates November 13, 2026. The Data Protection Board has no Chairperson. What that means for every business in India.

D
DPDPBot Research Team
🕐 9 min read
An empty boardroom chair beneath a falling digital countdown hologram
An empty boardroom chair beneath a falling digital countdown hologram

#116 Days to India's Consent Manager Deadline — and the Regulator Still Isn't There

India's Digital Personal Data Protection Act has a hard, immovable deadline: on November 13, 2026, the Consent Manager framework activates. Every business that collects personal data from Indian users will need to work with registered intermediaries that let those users manage, review, and withdraw consent across multiple platforms. The problem is that the Data Protection Board of India — the body that must register those Consent Managers, adjudicate complaints, and impose penalties — still has no Chairperson and no Members seated, more than eight months after its legal formation.

The Ministry of Electronics and Information Technology opened applications for the Chairperson and four Members in May 2026. It is now July 20. No appointments have been announced.


Rule 4 of the Digital Personal Data Protection Rules, 2025 — notified by MeitY on November 13, 2025 — establishes a new category of regulated entity: the Consent Manager. These are companies that must register with the Data Protection Board and serve as centralised platforms through which a data principal (any Indian person whose data is processed) can give, review, and withdraw consent across multiple data fiduciaries simultaneously.

The concept is modelled loosely on similar frameworks in the EU and Singapore, but the Indian version is notably specific in its eligibility criteria. A Consent Manager must:

  • Be a company incorporated in India under the Companies Act
  • Maintain a minimum net worth of ₹2 crore
  • Demonstrate technical and organisational capacity to operate consent management at scale
  • Register with the Data Protection Board before beginning operations

The critical phrase is "register with the Data Protection Board." That registration process does not exist until the Board is operational. And the Board cannot be operational until it has leadership.


#The Board That Law Built But Government Hasn't Staffed

Under Section 18 of the DPDP Act, the Data Protection Board of India is constituted as an independent adjudicatory body with powers to inquire into data breaches, issue directions for remediation, and impose financial penalties up to ₹250 crore per violation. Sections 18 to 26, establishing the Board and defining its powers, came into effect on November 13, 2025.

What came into effect on that date was a legal shell. The actual human beings required to make it work are still missing.

The selection process requires a high-powered search-cum-selection committee chaired by the Cabinet Secretary, with the Secretary of the Department of Legal Affairs and the Secretary of MeitY, plus two independent experts. This committee must identify candidates, conduct due diligence, and recommend appointments to the Central Government, which then formally notifies them.

MeitY issued public notification F. No. 2(1)/2026-Pers.I on May 6, 2026, inviting applications. As of today, the committee has not announced a shortlist, a preferred candidate, or a timeline for appointment.

This is not a minor administrative delay. Mondaq's analysis from April 2026 catalogued the cascading consequences: breach notification protocols have no receiving authority, judicial referrals to the Board cannot be actioned, and the entire Consent Manager ecosystem has no regulator to register with or report to.

Courts are already feeling the friction. In at least one case before the Madhya Pradesh High Court, the bench directed a petitioner to take their data protection grievance to the Data Protection Board. The petitioner has nowhere to go.


#Why the Deadline Doesn't Move Even If the Board Doesn't Arrive

Here is the structural tension that should concern every Indian business processing personal data: the November 13, 2026 deadline for the Consent Manager framework is fixed in Rule 4 of the notified Rules. Changing it requires either a further amendment to the Rules or an explicit government notification extending the timeline. Neither has been signalled.

The government has previously shown willingness to compress timelines. In January 2026, MeitY held stakeholder consultations and proposed cutting the overall compliance period from 18 months to 12 months — a proposal that prompted the Internet and Mobile Association of India to publicly urge restraint in a Hindustan Times story in February 2026. But acceleration, not extension, has been the government's posture throughout.

This means businesses are in a peculiar bind. They are required to interact with a Consent Manager framework that requires a functional regulator, while that regulator has not been constituted in practice. The clock counts down regardless.


#What 71% Unprepared Looks Like in Practice

The governance gap arrives against a backdrop of deep unreadiness in Indian industry. EY's India's Data Privacy Shift report, published in mid-2026, found that nearly 70% of Indian professionals working in technology and compliance functions admitted they were not very familiar with the DPDP Act and its Rules. A separate estimate suggests that 83% of organisations subject to the Act have not begun comprehensive implementation.

For a law with penalties that reach ₹250 crore for failure to implement reasonable security safeguards — and ₹200 crore for failing to notify users and the Board of a data breach — that gap is not a minor compliance lag. It is a systemic exposure.

The Consent Manager deadline adds a specific operational dimension. Businesses that want to operate as Consent Managers need to begin technical build-out now: the net worth threshold of ₹2 crore must be met, the incorporation requirements satisfied, and the infrastructure to handle consent signals at scale designed and tested before registration opens. Registration cannot open until the Board has a Chairperson to chair the registration process.

Even for businesses that intend only to use Consent Manager services (rather than register as one), the absence of registered Consent Managers in the market means there is no third-party infrastructure to integrate with before the deadline.


#The Budget Signal That Makes the Silence Louder

One data point stands out in the Union Budget 2026: the Data Protection Board's budget allocation was increased fivefold, from INR 20 million to INR 100 million. The government committed meaningfully more money to an institution it has not yet fully constituted. That is a signal of intent — it says the government expects this body to operate at scale in the near term.

The budget increase was noted by IAPP's Asia-Pacific coverage as part of a broader "regulatory heat wave" across India's digital governance landscape in early-to-mid 2026. Alongside RBI's dark pattern ban (effective July 1), SEBI's AI cybersecurity advisory naming specific vendors, and IRDAI's three-day compliance deadline for insurers, the picture is of a state moving rapidly to regulate its digital economy. The DPDP Board is the centrepiece of that picture, and it is currently blank.


#Independence Was Always the Question

It is worth noting that structural criticism of the Board predates the current appointment delay. The Software Freedom Law Centre has argued since early 2025 that the appointment mechanism — with the Cabinet Secretary chairing the selection committee and Government retaining sole discretion over final appointments — creates a body that can never be truly independent of the state, which is itself India's largest data processor.

The Justice Srikrishna Committee, which produced the 2018 report that eventually led to the DPDP Act, had recommended including the Chief Justice of India in the selection process and establishing a separate expert-led panel. Those recommendations were not adopted in the final Act.

Whether the Board would be genuinely independent if constituted is a structural question that persists regardless of when appointments are made. The more immediate concern is simply that it needs to exist before November 13.


#What Businesses Should Do Right Now

The leadership vacuum does not change what the law requires of data fiduciaries. It does change what is practically achievable before November. Here is a realistic read on where to focus:

Audit your consent architecture today. The Consent Manager framework requires that consent be specific, informed, and easy to withdraw. Businesses that rely on pre-ticked boxes, vague "by using this service" language, or bundled consents that lump together multiple processing purposes will need to rebuild their user-facing consent flows regardless of whether the Board is operational.

Watch for rapid Board appointments. Given the political priority the government has signalled through budget allocations and public commitments, appointments may come quickly once the selection committee concludes its work. When they do, the registration window for Consent Managers could open with very little lead time.

Plan for the May 2027 full-compliance deadline in parallel. The November Consent Manager deadline is the first hard milestone, but the May 2027 deadline covers every substantive obligation: breach notification, individual rights handling, data retention and deletion, and security safeguards. Building toward May means the November work becomes a subset of a larger programme, not a standalone sprint.

Consider your SDF exposure. Organisations that process large volumes of sensitive personal data — healthcare providers, fintech platforms, large e-commerce players, social media — may be designated as Significant Data Fiduciaries once the Board is constituted and begins making such determinations. SDF designation triggers the most demanding obligations, including Data Protection Officer appointments, independent Data Auditor engagement, annual Data Protection Impact Assessments, and cross-border data transfer restrictions. Organisations in high-risk sectors should assess their exposure and begin governance work now.


#Conclusion

India's DPDP Act exists. The Rules exist. The deadlines exist. The budget exists. What does not exist, eight months after the Board was legally constituted and 116 days before its first major operational deadline, is the leadership of the institution required to make enforcement real.

The government will almost certainly fill these positions before November. The selection process is moving, even if it is moving slowly. But the window for businesses to treat the Board's absence as a reason to delay their own preparation has already closed. The rules are clear, the penalties are severe, and the deadline is fixed.

When the Chairperson finally sits down at the Data Protection Board for the first time, the first item on the agenda should not be a backlog of enforcement actions against businesses that read the vacancy as an invitation to wait.


For guidance on building DPDP-compliant consent infrastructure ahead of the November deadline, see our resources page. If your organisation is evaluating consent management solutions, the DPDP consent manager guide covers registration requirements, technical specifications, and vendor considerations.

Automate your DPDP compliance

Capture consent, honour data principal rights, and stay audit-ready — all in one platform.

Start free trial