top of page

How to Comply with DPDPA Rules Before the November 2026 Phase 2 Deadline

  • Writer: Kaustav Chowdhury
    Kaustav Chowdhury
  • 1 day ago
  • 4 min read

India's Digital Personal Data Protection Act, 2023 (DPDPA) entered a critical phase when the Digital Personal Data Protection Rules, 2025 were notified on November 13, 2025. With the provisions rolling out in three distinct phases, 2026 is the "build and test" year for businesses across India. Phase 2, which introduces the Consent Manager Framework, takes effect on November 13, 2026. This guide explains each phase, identifies the compliance steps you must take before the deadline, and clarifies the enforcement architecture now in place.


Understanding the Three-Phase Implementation Timeline


The DPDPA and its rules are being implemented in a phased manner to give businesses adequate time to prepare. Each phase introduces specific obligations, with the full regime coming into force by May 2027. Understanding these phases is essential for planning your compliance roadmap.


Phase 1 (November 13, 2025): Foundation and the Data Protection Board


The first phase established the administrative and institutional foundation for data protection in India. The Data Protection Board of India (DPBI) was constituted as the adjudicatory body responsible for enforcing the DPDPA. This phase also brought into force the Act's definitions, rule-making powers, provisions relating to the Board's composition and procedures, and the mechanism for appeals through the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).


While Phase 1 does not impose substantive compliance obligations on data fiduciaries, it signals that the enforcement machinery is operational. Businesses should take note that the Board can receive complaints and initiate inquiries even at this stage. Organisations dealing with de-indexing of court records from Google will find that DPDPA principles around data minimisation and purpose limitation are becoming increasingly relevant.


Phase 2 (November 13, 2026): The Consent Manager Framework


Phase 2 is the most operationally significant phase for 2026. Effective November 13, 2026, it introduces the Consent Manager registration framework under Rule 4 of the DPDP Rules. Consent Managers are entities that act as intermediaries, enabling data principals (individuals) to give, manage, review, and withdraw consent through a single accessible platform.


Consent Managers must register with the DPBI and meet stringent registration conditions, including technical standards for interoperability, security, and transparency. Any organisation intending to operate as a Consent Manager must apply for registration well before the November 2026 deadline. For businesses that are data fiduciaries, Phase 2 means preparing your consent collection mechanisms to integrate with registered Consent Managers once they become operational.


Phase 3 (May 13, 2027): Full Compliance and Penalties


All remaining substantive provisions of the DPDPA come into force on May 13, 2027. This includes the full set of obligations for data fiduciaries: lawful processing, purpose limitation, data minimisation, storage limitation, accuracy, and security safeguards. It also activates the penalty framework, with fines reaching up to Rs 250 crore per breach category. Penalties can stack per violation, meaning a single breach could create cumulative exposure of Rs 650 crore or more.


This phase also triggers the obligations of Significant Data Fiduciaries (SDFs), who must appoint a Data Protection Officer, conduct periodic audits, and perform Data Protection Impact Assessments. The concept of "deemed consent" for certain categories of processing will also take full effect. Businesses should understand that the Supreme Court has already shown willingness to engage with technology governance issues, making judicial scrutiny of data protection compliance a practical reality.


What Businesses Must Do in 2026


The year 2026 is your compliance preparation window. First, conduct a data mapping exercise to identify all personal data you collect, store, and process, including the legal basis for each processing activity. Second, review and update your privacy notices and consent collection mechanisms to comply with the DPDPA's requirements for clear, specific, and informed consent.


Third, evaluate whether your organisation needs to integrate with Consent Managers once the framework is operational in November 2026. Fourth, implement technical and organisational security measures, including encryption, access controls, and breach notification procedures. Fifth, train your staff on data protection obligations and establish internal governance structures. Organisations that handle Aadhaar data for identity correction should pay particular attention to processing limitations around government-issued identifiers.


Sixth, if your organisation qualifies as a Significant Data Fiduciary, begin the process of appointing a Data Protection Officer and engaging auditors. Seventh, review cross-border data transfer arrangements in light of the government's expected notification of restricted jurisdictions. Those considering filing an appeal before NCLAT in corporate matters should be aware that the appellate structure for data protection matters runs through TDSAT, not the NCLT/NCLAT system.


The Data Protection Board of India and Enforcement


The DPBI is a digital-by-default body, meaning proceedings will be conducted through a digital office. It has the power to inquire into complaints, issue directions, and impose penalties. Appeals from DPBI orders go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), and further appeals on questions of law can be taken to the Supreme Court.


The Board can take cognisance of complaints from data principals, government referrals, and suo motu inquiries. Organisations registering entities such as Section 8 companies or SEZ units should ensure that their data processing practices are compliant from inception, as the Board can investigate both current and historical processing activities once the full provisions come into force.


Key Takeaways


The DPDPA is being implemented in three phases: Phase 1 (November 13, 2025) established the Data Protection Board of India; Phase 2 (November 13, 2026) introduces the Consent Manager Framework; Phase 3 (May 13, 2027) activates all substantive obligations and penalties. The year 2026 is the critical "build and test" year for businesses to prepare their compliance infrastructure. Penalties under the DPDPA can reach up to Rs 250 crore per breach category, with cumulative exposure potentially exceeding Rs 650 crore. All businesses that process personal data must conduct data mapping, update privacy notices, implement security measures, and prepare for Consent Manager integration. Appeals from the Data Protection Board of India go to TDSAT, not the NCLT/NCLAT system.

Comments


bottom of page