July 10, 2026 · Alastor InfoSec Team
DPDPA Phase 2 Is Closer Than You Think: What the November 2026 Consent Manager Deadline Means for Your Business
India's Data Protection Board is operational. The DPDPA Rules are finalised. And Phase 2 of enforcement — the Consent Manager Framework — goes live in just four months, on November 13, 2026. If your compliance roadmap has "DPDPA" on it as a 2027 problem, it's time to revisit that assumption.
What the three-phase enforcement timeline actually looks like
The DPDP Act follows a staged rollout:
Phase 1 (live since November 2025) — The Data Protection Board of India (DPBI) is constituted and active. Data Principals can already file grievances. The Board is already conducting inquiries. This isn't future tense — it's running now.
Phase 2 (November 13, 2026) — The Consent Manager Framework becomes operational. Organisations can register as third-party intermediaries to manage user consent on behalf of Data Fiduciaries. If you process personal data for Indian users at any scale, your consent architecture needs to be ready for this.
Phase 3 (May 13, 2027) — Full enforcement. Every obligation under the Act — purpose limitation, breach notification, data minimisation, Significant Data Fiduciary requirements — becomes enforceable. Penalties up to INR 250 crore (approximately $26 million USD) can be levied for serious violations.
The message from regulators has been consistent: soft enforcement through 2026, hard enforcement from May 2027. But "soft enforcement" doesn't mean zero enforcement — the Board is taking complaints and conducting inquiries today.
What's actually changing in November
The Consent Manager Framework introduces a new category of registered intermediary specifically designed to handle consent on behalf of users. For businesses that rely on third-party consent layers or operate across multiple data processing contexts, this has real architectural implications:
- Consent records need to be structured in a way that can be passed to and interpreted by registered Consent Managers.
- Withdrawal of consent has to be as easy as giving it — which means your existing "settings buried three menus deep" approach likely doesn't pass muster.
- Consent logs need to be auditable, time-stamped, and retained for the duration of the processing relationship.
Where most organisations are getting caught out
The breach notification clock under the DPDP Act is one of the tightest in the world. Notification to the Data Protection Board and affected individuals is required promptly upon detection — not after investigation, not after legal review, upon detection.
Organisations that pentest once a year and otherwise rely on passive controls are routinely discovering breaches weeks or months after they began. That gap between a misconfigured S3 bucket or an exposed API and the moment your team finds out is the gap the DPDPA notification requirement is designed to close — and close fast.
Continuous monitoring and ongoing penetration testing are not just a security posture decision at this point. They're a compliance risk mitigation tool.
The Significant Data Fiduciary classification
The DPDP Rules empower the central government to classify certain Data Fiduciaries as "Significant Data Fiduciaries" based on volume, sensitivity, and risk profile. Businesses processing large volumes of sensitive data — fintech, healthtech, edtech, e-commerce platforms with millions of Indian users — should assume this classification is coming and begin preparing additional obligations now: Data Protection Impact Assessments, periodic audits, and appointment of a Data Protection Officer.
Practical steps before November 2026
The organisations that will get through Phase 2 and Phase 3 without a scramble are the ones already doing this work:
- Map your data flows. You cannot consent-manage data you haven't inventoried. Know what personal data you collect, where it goes, and who processes it.
- Audit your consent journeys. Every consent capture point — sign-up forms, cookie banners, marketing opt-ins — needs to meet the specific and granular standard the Act requires.
- Review your breach detection posture. Notification obligations are only meaningful if you detect incidents quickly. Continuous scanning closes the gap between a breach starting and your team finding out.
- Document your purpose limitation rationale. For each processing activity, make sure the purpose is recorded and that data use doesn't drift beyond it.
- Check your vendor contracts. Data processors acting on your behalf have obligations too — ensure your agreements reflect the Act's requirements.
How Alastor InfoSec maps to DPDPA compliance
Our platform maps continuous scan and pentest findings directly to DPDP Act control requirements, so your evidence trail exists when auditors — or the Board — come looking. Alastor Shield continuously monitors your controls against DPDPA obligations and surfaces gaps before they become enforcement issues. Enforster AI's dark web monitoring catches leaked data before a data breach notification situation develops.
If you want to understand your current DPDPA posture before November, book a walkthrough and we'll show you the coverage dashboard against your specific stack.
The DPDPA Consent Manager deadline is November 13, 2026. Full enforcement begins May 13, 2027. The time to build the evidence trail is now, not the week before an audit.