Home/Blog/Data Privacy
Data Privacy9 min read

The Consent Manager Framework Commences 13 November 2026: Your Design Window Under the DPDP Rules

The DPDP Rules, 2025 introduce the Consent Manager — a regulated intermediary that gives individuals a single dashboard to control their consents. The framework commences on 13 November 2026. Here is why that date is a design window for every data fiduciary.

Rohit Lalwani
Rohit Lalwani
Associate Partner & Lead Global Partnership
25 July 2026
The Consent Manager Framework Commences 13 November 2026: Your Design Window Under the DPDP Rules

A New Institution in India's Privacy Architecture

The Digital Personal Data Protection Rules, 2025, notified on 13 November 2025, do more than operationalise the Digital Personal Data Protection Act, 2023. They introduce a genuinely new institution into the Indian privacy ecosystem: the Consent Manager. For the first time, the law contemplates a regulated intermediary whose entire purpose is to sit between data principals and data fiduciaries, giving individuals a single, auditable point of control over the consents they grant.

The framework for Consent Managers commences on 13 November 2026 — a full year after the Rules were notified. That gap is deliberate. It gives the ecosystem time to build, register, and test the infrastructure before individuals begin routing their consent through it. For businesses, that year is not a waiting period. It is a design window.

What a Consent Manager Actually Is

A Consent Manager is a data fiduciary of a special kind, registered with the Data Protection Board, that enables a data principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform. In plain terms, it is meant to be the dashboard for an individual's digital consent — a place where a person can see who holds permission to process their data, for what purpose, and can revoke that permission as easily as they granted it.

The Rules place real obligations on Consent Managers: registration criteria, minimum technical and operational standards, obligations of interoperability, and duties to act on the data principal's instructions without themselves reading into or exploiting the personal data flowing through the platform. The design philosophy is fiduciary in the truest sense — the Consent Manager holds a position of trust and must act in the interest of the individual, not the businesses that rely on it.

Why 13 November 2026 Is a Planning Date, Not a Deadline

It is tempting to file the commencement date away as someone else's problem — a matter for the entities that will register as Consent Managers. That would be a mistake. Ordinary data fiduciaries have a direct stake in this framework because the consent architecture they build today will need to interoperate with Consent Managers tomorrow.

Consider the sequence. Substantive duties under the DPDP framework become enforceable on 13 May 2027. The Consent Manager framework commences on 13 November 2026. A business that designs its consent capture, storage, and withdrawal mechanisms without anticipating the Consent Manager layer risks building infrastructure it will have to rebuild. The organisations that will move smoothly into the enforceable regime are those that treat 13 November 2026 as the date by which their systems should already be able to speak the language of Consent Managers.

The Interoperability Imperative

The single most important design consequence of the Consent Manager framework is interoperability. A data fiduciary can no longer treat consent as a private record locked inside its own systems. Consent must become portable — capable of being surfaced, referenced, and withdrawn through an external platform the individual controls.

This has concrete implications for system design:

  • Granular consent records. Consent must be captured and stored purpose-by-purpose, in a structure that can be mapped to an external dashboard rather than buried in a monolithic terms-of-service acceptance.
  • Machine-readable consent artefacts. The record of what was consented to, when, and for what purpose must be expressible in a form that a Consent Manager can ingest and display.
  • Real-time withdrawal handling. When a data principal withdraws consent through a Consent Manager, the fiduciary's systems must be able to receive that instruction and act on it — ceasing processing and, where required, initiating erasure.

What Businesses Should Do in the Design Window

The year between notification and commencement is best used to close the gap between current consent practices and the interoperable future the Rules envisage. Four steps are foundational:

  • Map every consent-based processing activity. Know exactly what personal data is processed on the basis of consent, for what purpose, and where the consent record lives.
  • Re-architect consent capture for granularity. Replace bundled, all-or-nothing consent with purpose-specific, independently revocable consent.
  • Build the withdrawal pathway. Ensure that a withdrawal instruction — whether received directly or through a Consent Manager — propagates through every downstream system that touches the relevant data.
  • Design for audit. Maintain a defensible, timestamped trail of consents granted and withdrawn, because the ability to demonstrate compliance will matter as much as compliance itself.

The Larger Shift

The Consent Manager framework signals a philosophical shift in how Indian law conceives of personal data. Consent is no longer a box ticked at the start of a relationship and forgotten. It becomes a living, revocable, individually controlled permission — and the infrastructure of the digital economy must be rebuilt to honour that. The businesses that internalise this now, in the design window before 13 November 2026, will not merely comply. They will have earned the trust that the entire framework is designed to protect.

This article is intended as general commentary and does not constitute legal advice. For advice specific to your circumstances, please contact our data privacy team at [email protected].