What Changed
The Consent Manager registration regime under India's DPDP Rules becomes operational on 13 November 2026, twelve months after the Rules were notified. Full substantive compliance covering notice, consent, security safeguards, data principal rights and breach notification is due 13 May 2027, with penalties attaching from that date.
Through 2026 the Data Protection Board is expected to focus on guidance rather than active enforcement. Pre-ticked boxes, bundled consent and blanket “I agree” patterns do not meet the standard: consent must be free, specific, informed, unconditional and unambiguous, with each purpose consented to separately.
Source pending: replace with the MeitY notification before publishing.
Why It Matters
Nothing bites until May 2027, which is exactly why this gets deprioritised and then becomes a scramble. 2026 is the build year, and the parts that touch marketing are not small.
Every lead capture form, checkout flow, newsletter opt-in and analytics tracker needs reworking against a standard that most Indian D2C sites currently fail. Bundled consent does not qualify. A single tickbox covering marketing, analytics and personalisation does not qualify. Each purpose needs its own standalone, unbundled consent, and withdrawal has to be as straightforward as giving it.
The practical consequence people miss: consent-gated pixel firing shrinks remarketing pools and degrades conversion signal into Smart Bidding and Advantage+. Brands that leave this to 2027 will take a performance hit and a compliance risk in the same quarter. Scope the work now, sequence it across the next three quarters, and treat the audience shrinkage as a forecastable event rather than a surprise.
This is not legal advice — clients should take their own counsel on scope and obligations.