Rushikesh Mahajan logo

Rushikesh Mahajan

Archives
Log in
Subscribe
August 23, 2026

81 days to register. Who exactly receives the application?

TL;DR

India now has two data-and-AI regimes running at once, and they fail in opposite directions. One has a named regulator with nobody in the chair. The other has, by deliberate policy choice, no regulator at all. For a client the practical result is identical: the obligation is live and there is no counterparty to discharge it to.

  • The deep dive: Rule 4 of the DPDP Rules makes Consent-Manager registration the Data Protection Board's exclusive function, and that window opens in 81 days — but as at 1 August 2026 the Board had no appointed Chairperson and no appointed Members.
  • India desk: the RBI's draft data-governance guidance closed for comment on 17 August and no final instrument has issued; and India's AI Governance Guidelines are, by design, voluntary.
  • Global: the EU AI Act's only Article 50 grace period expires in 100 days.

THE DEEP DIVE — A registration deadline needs someone to register with

Every compliance conversation about the DPDP framework runs on dates. This one runs on a question that the dates do not answer: when the window opens on 13 November 2026, who receives the application?

What the Rule actually says. Rule 4 of the Digital Personal Data Protection Rules, 2025 is short and it is specific. A person who fulfils the conditions in Part A of the First Schedule "may apply to the Board for registration as a Consent Manager." On receiving that application the Board may make such inquiry as it thinks fit to satisfy itself that the Part A conditions are met, and then either register the applicant, or reject the application and communicate the reasons for the rejection.

Read that again for what it does not contain. There is no alternative route. No ministry counter, no self-declaration, no deemed registration on lapse of time, no interim authority. The Board is not one path to Consent-Manager status — it is the only one. Rule 4 commences on 13 November 2026, one year from notification of the Rules on 13 November 2025. That is 81 days from today.

What the Board currently is. The Data Protection Board of India is established by the Act, its composition governed by Section 19 — which requires, among other things, that at least one Member have expertise in law, alongside domain knowledge in data governance, dispute resolution, technology or the digital economy. The appointment machinery is real and it has been moving: a Search-cum-Selection Committee chaired by the Cabinet Secretary, joined by the Secretaries of the Department of Legal Affairs and of MeitY together with two domain experts. The terms are settled — ₹4.5 lakh per month for the Chairperson, ₹4 lakh for Members, with no housing, car, pension, gratuity, sitting fees or sumptuary allowance.

What the machinery has not yet produced is people in the chairs. MeitY issued a communication on 6 May 2026 seeking nominations for the Chairperson and Member posts, and a further notification on 6 June 2026 concerning the same process. Writing on 1 August 2026, LiveLaw put it flatly: "as of this month, the Board has no appointed Chairperson and no appointed Members." An April 2026 analysis had already recorded that the Chairperson and Members "have not yet all been appointed and assumed office."

I have looked for a later announcement and found none. That is a statement about what is publicly reported, not a claim of certainty about this week — if an appointment has been made since 1 August it had not been announced through the channels I can check as at 24 August 2026. Practitioners should verify status at the moment of advising rather than rely on this paragraph in October.

Why this is more than a curiosity. The gap is not confined to Rule 4. Section 8(6) obliges a Data Fiduciary to notify the Board of a personal data breach — a duty owed to a body that cannot currently receive it. Section 27 gives the Board its investigative function and Section 33 its power to impose penalties, which run under the Act's schedule to ₹250 crore for a failure of reasonable security safeguards and ₹200 crore for breach-notification and children's-data failures. Every one of those provisions is drafted around an institution that has to exist for the provision to operate at all.

The mirror image, in the same jurisdiction. Now hold that against India's approach to artificial intelligence. On 5 November 2025 MeitY released the India AI Governance Guidelines under the IndiaAI Mission — a four-part framework of principles, recommendations, an action plan and practical guidance. They are expressly not a compliance requirement. They are "envisioned as a foundational reference for policymakers, researchers, and industry." And the policy behind them was stated plainly by the MeitY Secretary: "Our focus remains on using existing legislation wherever possible." No dedicated AI statute, no dedicated AI regulator.

So the two regimes arrive at the same place from opposite directions. DPDP is hard law with a designated enforcer that is not yet seated. AI governance is soft law with no enforcer by design. In both cases a client asking "who do I deal with?" gets an unsatisfying answer — and in both cases the underlying obligation is unaffected by that answer.

What follows for advice given this quarter. Three things, and none of them is "wait".

First, an unseated regulator does not suspend a duty. Obligations under the Act run from their commencement dates whether or not the Board is constituted; the absence of an enforcer is a gap in enforcement, not a defence to non-compliance, and it can close without notice. A client who paced their build to the regulator's vacancy will be caught by its filling.

Second, for anyone contemplating the Consent-Manager route, the lead-time arithmetic has changed shape. It was already true — as this publication set out a fortnight ago — that the registrant bar is high. It is now also true that the counter is not open and there is no published, testable certification pathway to prepare against. If a consent architecture depends on a registered Consent Manager existing, that dependency now carries an institutional risk on top of a commercial one. The honest question for most mid-size fiduciaries remains whether they need the dependency at all.

Third, for AI deployment, voluntary does not mean unregulated. The Guidelines' choice to lean on existing law means the exposure sits where it always sat: in the IT Act and Rules, in contract, in consumer law, in sectoral regulation, and — for anyone whose output reaches the Union — in the EU AI Act. "There is no Indian AI law" is a true sentence that has misled a great many product decisions.


INDIA DESK

The RBI's data-governance guidance closed for comment a week ago, and nothing final has issued. The Reserve Bank published its Draft Guidance on Regulatory Expectations for Data Governance on 15 July 2026, with comments invited until 17 August 2026. The scope is unusually wide for a data instrument: commercial banks including foreign banks, small finance banks, payments banks, local area banks, regional rural banks, urban and rural co-operative banks, NBFCs across the Base, Middle, Upper and Top layers, all-India financial institutions, asset reconstruction companies and credit information companies. The draft addresses governance structures and named roles, data architecture, metadata and lineage, data quality, and third-party data-sharing arrangements. As at 24 August 2026 no final circular appears to have been issued. Regulated entities in scope have a short and useful window: the direction of travel is now public, and the final instrument is not. [Source: Business Standard · Cyril Amarchand — FIG Paper No. 61]

The AI Governance Guidelines are voluntary, and that is the point rather than an oversight. Released 5 November 2025, they set out guiding principles, recommendations across the pillars of AI governance, and an action plan on short, medium and long horizons. They are a reference framework, not a rulebook, and they were published alongside a stated preference for using existing legislation rather than enacting a new AI statute. For an adviser the practical consequence is that AI-related risk in India is presently distributed across instruments that were not written for AI — which makes the mapping exercise harder, not easier. [Source: IAPP · PIB]


GLOBAL — DATA PROTECTION & AI GOVERNANCE

The EU AI Act's only Article 50 grace period expires in 100 days. Article 50 became applicable on 2 August 2026. The single transitional carve-out is narrow: it exists only for AI systems placed on the market before that date, and only as regards the marking and machine-readable detection obligation in Article 50(2). Providers of those systems must comply from 2 December 2026 — 100 days from today. Content generated before 2 August 2026 does not require retroactive labelling. Everything else in Article 50 has applied since 2 August. As this publication set out last issue, the obligation reaches providers established outside the Union wherever their system's output is used inside it, so an Indian company with no European entity can be squarely within it. [Source: EU AI Act — Article 50]


RUNNING CLOCK — verified for this issue, computed 24 August 2026

Date What it is Distance
13 Nov 2025 DPDP Rules, 2025 notified 284 days ago
5 Nov 2025 India AI Governance Guidelines released 292 days ago
13 Nov 2026 Rule 4 — Consent-Manager registration commences 81 days
2 Dec 2026 EU AI Act Art 50(2) transitional relief expires 100 days
13 May 2027 DPDP substantive compliance 262 days

PRACTITIONER'S VERDICT

What to tell a client this fortnight. If their plan depends on a registered Consent Manager existing by November, that plan now carries an institutional risk as well as a commercial one — and the first question is still whether the dependency is necessary at all. If they have been reassured that "there is no AI law in India", correct it: there is no AI statute, which is a different thing, and their exposure sits in instruments that already bind them. And if anyone has read the regulator's vacancy as breathing room, say the obvious thing out loud — a duty that nobody is currently enforcing is still a duty, and the vacancy can close in a single gazette notification.


FOOTER

This publication is informational and educational only. It is not legal advice and creates no advocate–client relationship. Authored from India; readers in other jurisdictions should map terms to local law.

Every statutory reference and every date in this issue was checked against at least two sources before it went out. Where a claim could not be verified to that standard it does not appear — including in this issue, where I set aside a widely-repeated assertion about who chairs the Board, because it could not be traced to any government record. The archive, and everything else I have been building, is at wolfgangrush.github.io.


Don't miss what's next. Subscribe to Rushikesh Mahajan:
← Newer No country is restricted. Your data still cannot leave. Older → No EU office? Article 50 still applies from 2 August
Powered by Buttondown, the easiest way to start and grow your newsletter.