Rushikesh Mahajan logo

Rushikesh Mahajan

Archives
Log in
Subscribe
August 4, 2026

DPDP Alert: the Consent-Manager deadline is real

TL;DR

India's nearer DPDP deadline is not May 2027 — it is 13 November 2026, roughly 100 days out, and it forces two decisions now. Meanwhile the EU's AI transparency duties went live on 2 August.

  • The 13 Nov 2026 Consent-Manager clock is the one to scope first — registered, India-incorporated, ₹2-crore-net-worth intermediaries, with a hard independence bar. Decide whether you even need one.
  • The same date starts the Significant Data Fiduciary duties — an India-based DPO, independent audit, DPIA. Designation is the Government's call, not yours; scope for it now.
  • EU AI Act Article 50 transparency duties took effect on 2 August 2026 — and the Digital Omnibus deferral did not touch them.

THE DEEP DIVE — India's Consent-Manager clock: 13 November 2026

The nearer DPDP deadline forces two decisions now — and the machinery to comply is not fully built yet.

Issue-01 set the DPDP timeline: the Digital Personal Data Protection Rules, 2025 (notified 13 November 2025) run a phased schedule, with the bulk of substantive duties commencing 13 May 2027. But the date that should be on a data-fiduciary's desk this quarter is the nearer one — 13 November 2026, roughly 100 days out — when the registration regime for Consent Managers commences, and with it the first hard operational choices for every India-facing processor.

Why it matters now

A Consent Manager is a DPDP-specific creature: a registered, India-incorporated intermediary through which a Data Principal can give, manage, review and withdraw consent across multiple Data Fiduciaries from a single, interoperable interface. It sits between principal and fiduciary. That architecture cannot be improvised on 12 May 2027 — if a fiduciary's consent design assumes a Consent Manager, that entity must already exist, be registered, and be integrated. The lead time, not the deadline, is the problem.

The same 13 November 2026 milestone carries a duty that has nothing to do with Consent Managers: a Significant Data Fiduciary (SDF), once designated, must have an India-based Data Protection Officer in place, alongside an independent data auditor and periodic DPIAs. Designation is a Central-Government determination on volume, sensitivity and risk — not a self-certification — so the prudent posture for any high-volume processor is to assume it might be designated and to scope the DPO, audit and DPIA load now rather than after the notice arrives.

What changed — the registrant bar is now visible

The eligibility standard for a Consent Manager is deliberately high, and the detail is now on the table: a company incorporated in India; a minimum net worth of ₹2 crore; acting in a fiduciary capacity toward the Data Principal; keeping the personal data it routes unreadable to itself; retaining consent records for at least seven years; and demonstrating interoperability plus independent certification of its technical and organisational measures.

Structural independence is built in. A Consent Manager must avoid conflicts of interest with the fiduciaries it serves — including through the directorships held by its directors, key managerial personnel and senior management. That deliberately closes the obvious loophole of a large fiduciary standing up a captive, in-house Consent Manager to tick the box.

The children's-data line hardened in the same rulebook, and it is a design decision that cannot wait for 2027: verifiable parental consent before processing any under-18's data; age and identity verification (the Rules point to a DigiLocker-based route); and an outright ban on behavioural tracking and targeted advertising directed at children — a prohibition that parental consent cannot buy back. Any platform with under-18 users should treat this as a build item that needs architecture decisions now.

Open questions

Here is the awkward gap the bar should be watching: a 13 November 2026 registration deadline exists, but the registration and certification machinery is not yet fully operational. The Data Protection Board of India is being staffed; the certification pathway that would let a would-be Consent Manager prove interoperability is not yet a published, testable standard. Fiduciaries betting on a Consent-Manager route are therefore asked to plan around a market of registered intermediaries that does not yet exist. The single most useful thing to track over the next fortnight is any movement on that registration/certification pipeline.

Bottom line

We are advising India-facing clients to treat 13 November 2026 as a scoping deadline, not a distant one, and to take two decisions this quarter: (1) decide whether their consent architecture will depend on a Consent Manager at all — many mid-size fiduciaries can discharge DPDP consent duties directly and are better off avoiding the dependency; and (2) if they are plausibly an SDF, begin the India-DPO and independent-audit scoping now, because that clock also stops on 13 November 2026. The penalties sharpen the point: the Act's schedule runs to ₹250 crore per instance for a security-safeguards failure, with ₹200 crore exposure for breach-notification and children's-data failures — payable from the day after the relevant deadline lapses.


INDIA DESK

RBI's board-level data-governance framework is out for comment. The Reserve Bank's draft (15 July 2026) would require banks, NBFCs, cooperative banks, ARCs and credit information companies to run a board-approved data-governance framework — named data owners, stewards and custodians, a single source of truth, and DPDP-aligned safeguards for third-party data sharing. Still a draft — comments close 17 August 2026, so any bank, NBFC or CIC with a view has under two weeks to file it. [Source: https://www.business-standard.com/finance/news/rbi-issues-draft-data-governance-norms-for-banks-nbfcs-126071501296_1.html]

The Supreme Court's AI-in-Courts regulations remain unnotified. The draft Regulations for Use of AI in Courts, 2026 — which would make AI-use disclosure mandatory for advocates in pleadings and submissions — closed public consultation on 20 June 2026 and has not yet been finalised or notified. The disclosure duty is coming; it is not yet law. [Source: https://lawbeat.in/top-stories/supreme-court-releases-draft-ai-rules-for-courts-lawyers-must-disclose-use-of-ai-in-pleadings-1598628]

DPDP's hard line on children's data is a design decision, not a policy one. Rule 10 requires verifiable parental consent for anyone under 18, DigiLocker-based age/identity verification, and bans behavioural tracking and child-targeted advertising outright — regardless of consent. There are no graduated age bands. [Source: https://www.dpdpa.com/dpdparules/rule10.html]


GLOBAL — DATA PROTECTION & AI GOVERNANCE

EU AI Act Article 50 transparency duties took effect on 2 August 2026. Providers and deployers must now disclose when a user is interacting with AI, machine-mark AI-generated content, and flag deep fakes and emotion-recognition/biometric-categorisation systems. National market-surveillance authorities can enforce from that date, with fines up to €15 million or 3% of worldwide turnover. [Source: https://artificialintelligenceact.eu/transparency-rules-article-50/]

The Digital Omnibus deferral did not rescue Article 50. The Omnibus package pushed the Annex III high-risk timeline back to 2 December 2027 — but the Article 50 transparency duties were left out of that deferral and applied on schedule. "The AI Act got delayed" is only half true, and the half that bit is the half most India-facing GenAI deployers touch. [Source: https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-article-50-transparency-20260729/]

The EU Commission has published transparency guidelines and a voluntary Code of Practice to operationalise Article 50. The guidelines and the Code of Practice on marking AI-generated content give providers a concrete standard for the labelling duty that just went live — the reference point counsel should point clients to when the question is "how do we mark it." [Source: https://digital-strategy.ec.europa.eu/en/policies/guidelines-transparency-ai-generated-content]


PRACTITIONER'S VERDICT

What to tell your clients this fortnight: For India-facing clients, 13 November 2026 is closer than 13 May 2027 and carries two decisions — whether you need a Consent Manager at all, and whether you must staff an India-based DPO. Take both this quarter, not next year. For anyone running generative AI that touches the EU: as of 2 August, "we didn't label it" is now an enforceable failing, not a best-practice gap.


This publication is informational and educational only. It is not legal advice and creates no attorney-client relationship. Authored from India; readers in other jurisdictions should map terms to local law.

Found this useful? Forward it to one colleague who bills to data-protection or AI work. — wolfgang_rush · The India Data & AI Governance Desk

Don't miss what's next. Subscribe to Rushikesh Mahajan:
← Newer No EU office? Article 50 still applies from 2 August
Powered by Buttondown, the easiest way to start and grow your newsletter.