MeitY opens consent manager registration and clarifies the DPDP phase-in
Registration for consent managers opens with a ₹12 crore net worth requirement, and MeitY confirms that notice, consent and breach obligations become enforceable from 13 May 2027.
MeitY has opened the registration window for consent managers under the Digital Personal Data Protection Rules and issued a clarificatory note confirming the phase-in schedule for the substantive obligations.
What is now settled
Three things that were genuinely uncertain are now not.
- The enforceable date. Notice, consent, data principal rights and breach intimation obligations apply from 13 May 2027, eighteen months from the notification of the Rules. Significant Data Fiduciary obligations follow the same date.
- Consent manager eligibility. Registration requires a net worth of ₹12 crore, incorporation in India, and an obligation to maintain an interoperable platform. This is a small market by design.
- Retrospective notice. MeitY has confirmed that data fiduciaries must give notice to data principals whose personal data was collected before the Act commenced, as soon as reasonably practicable after the obligations apply.
The part organisations keep under-estimating
That last point is the programme, not the policy.
If you hold personal data on forty million customers collected over fifteen years, you have to reach them with a compliant notice. Not a banner on the website — an itemised notice describing the personal data and the purpose, available in English and each of the twenty-two Eighth Schedule languages at the data principal's option.
Doing that requires knowing what personal data you actually hold, for what purpose, collected under what basis. Most organisations cannot answer that today, which is why the data inventory work needs to start now rather than in Q4 2026.
What DPDP does not have, and why it matters
Two absences from the Indian law regularly catch teams who ported a GDPR-shaped programme:
There is no sensitive personal data category. Health data, financial data and biometrics are treated the same as any other personal data. Programmes that built tiered controls around a special category have built something the Act does not ask for, and may have left the general population under-protected.
There is no materiality threshold for breach. Every personal data breach requires intimation to every affected data principal and to the Data Protection Board. GDPR's "unlikely to result in a risk" carve-out has no equivalent here. Organisations running a risk-assessed breach process will systematically under-report.
What to do in the next two quarters
- Complete a personal data inventory that maps data, purpose, source and retention
- Determine your position on Significant Data Fiduciary designation and prepare for the DPO, audit and DPIA obligations if you expect to be notified
- Design the retrospective notice programme, including the language obligation
- Rebuild breach response on an intimate-everything basis rather than a materiality basis
- Reconcile against CERT-In: the six-hour reporting clock is a separate obligation with a separate trigger list
What Regulens customers see
The Rules have been decomposed into 214 obligations mapped against entity, function and data domain. Customers who completed a DPDP impact assessment in 2025 have had it carried forward with eleven obligations flagged for re-review against the clarified phase-in.
A law with no materiality threshold for breach is not a stricter version of GDPR. It is a differently shaped obligation, and it needs a differently shaped process.
How Regulens customers received this
This item was scoped against every customer footprint within 15 minutes of publication. Customers to whom it applies received it routed to the named owner for the relevant theme, with the obligations decomposed, the affected entities identified and any prior assessment carried forward with the delta highlighted. Customers to whom it does not apply saw nothing — with the suppression reason recorded and auditable.
This analysis is provided for information only and does not constitute legal advice. Read it alongside the primary source it cites. Where a source reference is given (G.S.R. 612(E)), that is the authoritative text.