On 13 November 2026 — eleven weeks from now — the Data Protection Board of India acquires the power to conduct inquiries and levy penalties under the Digital Personal Data Protection Act. On the same date, Consent Manager registration opens under Rule 4 of the DPDP Rules. Full compliance for all covered obligations follows on 13 May 2027.

The maximum penalty is ₹250 crore per instance — roughly $30 million — for failure to take reasonable security safeguards.

India has over a billion internet users. When this law becomes operational, it will be, by population covered, the largest data protection regime on earth. It also does several things differently from the GDPR, and those differences are the interesting part.

The Timeline

The DPDP Act passed in August 2023 and then sat, unenforceable, waiting for implementing rules. The DPDP Rules were notified on 14 November 2025, starting a phased clock:

  • 14 November 2025 — Rules notified. Definitions and the Board’s constitution take effect.
  • 13 November 2026 — The Board can inquire and impose penalties. Consent Manager registration opens.
  • 13 May 2027 — Full compliance deadline. All Data Fiduciary obligations apply.

The gap between the second and third dates is unusual and deliberate. Enforcement powers arrive six months before the substantive obligations bite. Through 2026 the expectation is “soft enforcement” — guidance, warnings, and inquiries that establish how the Board reads the statute — with 13–14 May 2027 as the hard date everyone is actually planning around.

For anyone building compliance programmes, that means November is not a deadline so much as the moment the regulator becomes real and starts telling you what it thinks.

What Makes DPDP Different

Consent Managers are a registered, regulated intermediary. This is the most genuinely novel thing in the law and it has no GDPR equivalent. A Consent Manager is an entity registered with the Board that gives individuals a single interface to grant, review, manage and withdraw consent across all the Data Fiduciaries they deal with. Registration opens 13 November.

Think about what that is. Instead of every person managing consent separately with every company through every company’s own bespoke, deliberately awkward interface, India is mandating an intermediary layer where an individual sees their consents in one place and can revoke from one place. Europe never built this; the GDPR’s consent regime is administered by the same parties who benefit from confusion about it. If Consent Managers work in practice, they are the most consumer-favourable structural idea in modern privacy law.

If. The design questions — who funds them, whether Fiduciaries can degrade service for users who route through them, whether the interface is genuinely neutral — are all unresolved, and they determine whether this becomes real infrastructure or a registry nobody uses.

Consent is the dominant basis, with narrow alternatives. The GDPR offers six lawful bases and “legitimate interests” absorbs an enormous amount of real-world processing. DPDP is far more consent-centric, with a limited set of “legitimate uses” — largely state functions, employment, medical emergencies, and specified public interest purposes. That is stricter in theory and creates a familiar risk in practice: when consent is the only door, everything becomes a consent wall, and consent walls train people to click.

Notice must be plain and available in Indian languages. The Rules require notice in clear, plain language, accessible in English and the languages listed in the Eighth Schedule of the Constitution — 22 languages. This is a serious, expensive, and correct obligation that most global privacy laws quietly skip.

There is no general right to portability, and no explicit right against automated decision-making. Two significant GDPR rights are absent. There is no DPDP analogue to Article 22. In a country deploying algorithmic systems across welfare delivery, credit, and identity at enormous scale, that omission will be felt.

Children get a hard rule, not a balancing test. Processing children’s data requires verifiable parental consent, and tracking, behavioural monitoring, and targeted advertising directed at children are prohibited outright. No age-appropriate design balancing, no “reasonably likely to be accessed” analysis — a prohibition. Compare the New Jersey Kids Code Act, which achieves something similar through design mandates, or COPPA, which the TikTok settlement showed can take years to enforce once.

Government exemptions are broad. The State and its instrumentalities can be exempted from significant portions of the Act by notification, and the Act’s provisions on state processing are considerably more permissive than its provisions on companies. This is the criticism Indian privacy advocates have pressed hardest since 2023, and it is the most substantial gap in the regime.

Why This Matters If You Are Not in India

Three reasons.

Volume. India’s IT and business process services industry processes personal data for a very large share of the world’s banks, insurers, telecoms, and retailers. Obligations that attach to Data Processors in India propagate outward through contracts to controllers everywhere.

Cross-border transfers work by blacklist, not whitelist. The DPDP Act permits transfers to any country except those the government specifically restricts. This is the inverse of the GDPR’s adequacy model, where transfer is prohibited unless permitted. It is more permissive by default, and more politically volatile — a restriction can appear by notification without the multi-year adequacy process Brussels requires.

It confirms the direction of travel. 172 countries — 79% of the world — now have data protection laws. The story of 2026 is no longer enactment; it is the shift from statute books to enforcement machinery. India crossing from “passed” to “enforceable” is the single largest instance of that shift, and it lands in the same season as Vietnam’s first national law, Brazil’s EU adequacy, and China’s completed cross-border certification framework.

What To Do

  1. If you are in India: watch for Consent Managers and use one when they appear. Registration opens 13 November. A single interface for reviewing and withdrawing every consent you have granted is a genuinely powerful tool, and it only becomes powerful if people use it.

  2. Exercise access rights from May 2027, and note them now. The DPDP gives you rights to access, correction, erasure, and grievance redressal. Fiduciaries must publish a grievance officer’s contact details — start by finding out whether the companies you use have one.

  3. If you run a business touching Indian users or Indian processors, the November date is your planning trigger, not May. Data inventory, consent architecture, notice translation into Eighth Schedule languages, breach notification process, and grievance officer appointment are all long-lead items.

  4. Read the children’s provisions carefully if you operate any consumer service. A flat prohibition on behavioural advertising to children, with verifiable parental consent as a precondition to processing, is stricter than what most global platforms currently do anywhere.

  5. Watch the government exemption notifications. They are the mechanism by which this law’s real scope will be determined, and they will not be announced with a press conference.