Alastor InfoSec
← Back to Blog
Compliance

July 27, 2026 · Alastor InfoSec Team

India's Data Protection Board Is Now Live: What DPBI Enforcement Means for Businesses in H2 2026

For the past two years, India's Digital Personal Data Protection Act has existed as a law without a functioning regulator. That changes now. The Data Protection Board of India (DPBI) is actively being staffed as of July 2026, and the Consent Manager framework — one of the Act's most operationally significant provisions — is being operationalised between June and August of this year. For Indian businesses that have been treating DPDPA compliance as a future problem, that future has arrived.

This post breaks down exactly what these July 2026 milestones mean, what your obligations are before November, and how to start closing the gap if you haven't already.

What Just Changed: The DPBI Is No Longer a Paper Tiger

The DPDP Act was notified in November 2025 when the Rules were gazetted. But a statute without a regulator to enforce it carries limited practical weight. July 2026 marks a structural shift: the DPBI is now being staffed with adjudicating officers, and the government has moved to operationalise the Consent Manager registration process.

This matters because the DPBI has real enforcement powers. The Board can investigate complaints from Data Principals, issue notices to Data Fiduciaries, conduct inquiries, and levy penalties of up to ₹250 crore per violation. There is no indication of a grace period or a soft-launch enforcement posture. Once the Board is operational, it is operational.

Indian businesses that are not compliant by the time the DPBI begins active enforcement — expected to coincide with Phase 2 in November 2026 — will face a regulator with both the mandate and the mechanism to act.

The Consent Manager is the DPDP Act's answer to fragmented, unverifiable consent. Under Rule 4, organisations wishing to act as Consent Managers must register with the DPBI. For Data Fiduciaries who rely on a Consent Manager to collect and manage consent on behalf of Data Principals, this creates two urgent obligations: understanding whether your current consent collection model requires a Consent Manager intermediary, and if so, ensuring that intermediary is registered and technically integrated before November 13.

The Consent Manager must maintain an interoperable platform that allows Data Principals to grant, review, and withdraw consent across multiple services. The withdrawal propagation requirement is technically demanding — when a Data Principal revokes consent through the Consent Manager, that revocation must flow through to every downstream system that was processing data under that consent, in near-real time.

For most mid-market and enterprise organisations in India, this is not a small engineering task. It requires APIs to a registered Consent Manager, backend data flow mapping to understand what data was collected under which consent, and an audit trail that the DPBI can request at any time.

While the Consent Manager gets the most attention, Phase 2 — effective November 13, 2026 — brings several other obligations into force:

Breach Notification to DPBI: Data Fiduciaries must notify the Board of personal data breaches. The notification must be in a prescribed format and must be made promptly, without undue delay. CERT-In's parallel 6-hour incident reporting mandate for cyber incidents compounds this — a data breach that is also a security incident triggers reporting obligations to two separate regulators on overlapping (and extremely tight) timelines.

Data Principal Rights: The rights to access information about processed data, correction, erasure, and grievance redressal all become enforceable. This means Data Fiduciaries must have a functioning Rights Management process — not just a policy document, but an operational workflow that can respond to individual requests within the timelines prescribed by the Rules.

Data Minimisation and Purpose Limitation: These principles have been in the statute since enactment, but with the DPBI now staffed and enforcement imminent, organisations can no longer treat them as aspirational. Purpose-based data collection must be documented, enforced at the system level, and verifiable by auditors.

What Significant Data Fiduciaries Face in Q1 2027

Organisations that are classified as Significant Data Fiduciaries (SDFs) — based on volume of data processed, sensitivity, and risk to national security — face a further layer of obligations. SDFs must appoint a Data Protection Officer, conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities, and submit to periodic independent audits. The audit cycle for SDFs begins Q1 2027, meaning organisations that believe they may meet the SDF threshold need to be running DPIAs and building their DPO function now, not in December.

The government has not yet published the formal SDF notification list, but the criteria in the Rules are clear enough that organisations processing personal data of more than a few million Data Principals — particularly in fintech, healthtech, e-commerce, and enterprise SaaS — should conduct an internal threshold assessment immediately.

Where Most Indian Businesses Stand Right Now

Industry assessments consistently put the share of Indian organisations that are substantively compliant with DPDPA at somewhere between 17% and 25%. That means three in four Indian businesses are operating with significant exposure. The most common gaps we encounter are:

No data inventory: Organisations cannot demonstrate purpose-based data collection because they have never comprehensively mapped what personal data they collect, where it flows, and what system processes it for what stated purpose.

Legacy consent flows: Many organisations rely on omnibus consent buried in terms and conditions — the kind of consent the DPDP Act explicitly prohibits. Migrating to the granular, specific, informed-and-in-plain-language consent the Act requires takes time to engineer.

No breach response playbook: The 6-hour CERT-In window and the DPBI's breach notification requirement will not be met by an organisation whose incident response plan was last tested in 2024 and whose SIEM alerts go to a shared mailbox.

Third-party processor gaps: The Act holds Data Fiduciaries responsible for how their processors handle personal data. Most organisations lack binding contractual protections, let alone technical controls, over their SaaS vendors and cloud infrastructure providers.

How Alastor InfoSec Helps

Alastor Shield is built to close exactly these gaps. The platform maps your existing controls and findings directly to DPDPA obligations — consent management requirements, breach notification workflows, Data Principal rights management, and processor oversight. For organisations that need to close the gap between where they are today and where they need to be by November 13, we run a structured DPDPA readiness assessment that delivers a gap report, a prioritised remediation plan, and continuous compliance monitoring once remediation is underway.

Reach out to our team at [email protected] or visit our DPDPA compliance page to understand what the enforcement timeline means for your specific organisation.

The DPBI being staffed is not a formality — it is the moment enforcement becomes real. Indian businesses that start their compliance work this week are 16 weeks ahead of the November deadline; those that wait until October will be building the plane while flying it.

We use cookies to keep the platform secure and understand how our site is used. See our Security & Data policy for details.