DPDP Rule 4 Goes Live 13 November 2026: What Actually Commences, and What Your Team Must Build

DPDP Rule 4 commences 13 November 2026 — but it binds Consent Managers, not ordinary Data Fiduciaries. What the Gazette says, and the work to start for 13 May 2027.

Saurabh Pande
Saurabh Pande
Aug 19, 202622 min read
DPDPConsent ManagerData ProtectionComplianceIAMSIEM
DPDP Rules 2025 commencement timeline showing Rule 4 Consent Manager registration on 13 November 2026 and substantive Data Fiduciary obligations on 13 May 2027

The date everyone is quoting is real. What it obliges most companies to do is not what they think.


Executive Summary

On 13 November 2025, MeitY notified the Digital Personal Data Protection Rules, 2025 through Gazette notification G.S.R. 846(E), finalising a draft that had been published as G.S.R. 02(E) on 3 January 2025. The Rules did not all commence at once. Rule 1 sets three separate commencement dates, and the middle one — 13 November 2026, now 86 days away — is the one being widely misreported.

Rule 1(3) says: "Rule 4 shall come into force one year after the date of publication of this Gazette." Rule 4 is titled "Registration and obligations of Consent Manager." That is the whole of what commences in November. It is a licensing regime for a new category of intermediary. It is not a compliance deadline for banks, insurers, hospitals, e-commerce platforms or SaaS companies.

The deadline that binds those organisations is Rule 1(4): Rules 3 and 5 to 16, plus 22 and 23, commence eighteen months after publication — 13 May 2027, 267 days away. That is where notice requirements, reasonable security safeguards, breach intimation, erasure timelines, Significant Data Fiduciary duties and cross-border restrictions live.

Two consequences follow, and they pull in opposite directions. You have more legal runway than the November headlines suggest — nothing substantive lands on you in 2026 unless you are becoming a Consent Manager. And you have less engineering runway than 267 days implies, because the Rule 6 and Rule 8 obligations are log-coverage and retention obligations: procurement, storage and pipeline decisions with lead times measured in budget cycles, which must be in place on day one rather than started on day one.

This post separates the two, works through the First Schedule a prospective Consent Manager has to clear, and lays out the Data Fiduciary engineering programme that has to start now.


1. What the Gazette Actually Says About Commencement

There are two commencement instruments and they are easy to conflate. The Act's provisions were brought into force by G.S.R. 843(E), and the Rules by G.S.R. 846(E), both dated 13 November 2025. The India Code text of the Act records the Act-side schedule in its commencement footnote.

Effective dateAct provisions (G.S.R. 843(E))Rules provisions (Rule 1)
13 Nov 2025Ss. 2, 18–26, 35–43, s. 44(1) and (3) — definitions, the Board's establishment and composition, miscellaneous powersRules 1, 2, 17–21 — commencement, definitions, Board appointments, salaries, meeting procedure, digital office, Board staff
13 Nov 2026S. 6(9) — every Consent Manager shall be registered with the Board; s. 27(1)(d) — Board's power to inquire into breach of a registration conditionRule 4 — Consent Manager registration and obligations
13 May 2027Ss. 3–5, s. 6(1)–(8) and (10), ss. 7–17, s. 27 except (1)(d), ss. 28–34, 36, 37, s. 44(2)Rules 3, 5–16, 22, 23

Read the middle row carefully. Section 6(9) — "Every Consent Manager shall be registered with the Board in such manner and subject to such technical, operational, financial and other conditions as may be prescribed" — commences in November 2026 alongside Rule 4, which prescribes those conditions, and Section 27(1)(d) commences with it so the Board can police them. The licensing regime and its enforcement hook were switched on together; everything else was left for eighteen months.

Note what did not move to November. Sections 6(7) and 6(8), which establish that a Data Principal may route consent through a Consent Manager and that the Consent Manager is accountable to her, sit in the 6(1)–(8) block and commence in May 2027. The enabling rights that give Consent Managers their commercial reason to exist arrive six months after the registration window opens.

The practical reading

If you are a Data Fiduciary, your November 2026 obligation is zero. Your May 2027 obligation is substantial. Anyone selling you a "November 2026 DPDP compliance deadline" is either selling to Consent Managers or has not read Rule 1.


2. The Registration Bar: First Schedule, Part A

If you are considering registering — a live strategic question for Indian BFSI groups, data-sharing intermediaries and identity platform vendors — Part A of the First Schedule sets nine conditions. They are stiffer than most commentary suggests.

#ConditionPractical implication
1Applicant is a company incorporated in IndiaRules out LLPs, partnerships and foreign entities operating through branches
2Sufficient technical, operational and financial capacityAssessed by the Board on inquiry under Rule 4(2)
3Sound financial condition and general character of managementSubjective, Board-assessed
4Net worth not less than two crore rupeesDefined in the Schedule note as total assets less liabilities per the books of accounts
5Adequate likely business volume, capital structure and earning prospectsA viability test, not just a solvency test
6Directors, KMP and senior management of general reputation and record of fairness and integrityFit-and-proper style screening
7MoA and AoA must embed the conflict-of-interest obligations (Part B items 9 and 10), and may be amended only with prior Board approvalA constitutional-document change, with a permanent Board veto over amendments
8Proposed operations are in the interests of Data PrincipalsBoard discretion
9Independent certification that the interoperable consent platform is consistent with such data protection standards and assurance framework as may be published by the Board on its website, and that technical and organisational measures ensure observance of Part B item 11Depends on a framework the Board has to publish first

Condition 7 deserves attention from anyone modelling this as a normal product launch. You are not agreeing to a policy; you are writing the conflict-of-interest regime into your articles of association and handing the regulator a standing veto over amendments. For a bank- or platform-affiliated applicant that is a governance decision, not a compliance one.

Condition 9 carries an external dependency. Rule 4(1) also has applicants apply "by furnishing such particulars and such other information and documents as the Board may publish in this behalf on its website." Both the assurance framework and the application particulars are Board deliverables, and the Rules attach no deadline to either.


3. Obligations of a Registered Consent Manager: Part B

Part B lists thirteen obligations. Four of them shape the architecture decisively.

Item 2 — the zero-knowledge requirement. "The Consent Manager shall ensure that the manner of making available the personal data or its sharing is such that the contents thereof are not readable by it." This is the most important sentence in the Schedule. It rules out the obvious implementation in which the Consent Manager proxies and inspects payloads, leaving a consent-artefact and routing model: the platform holds the signed consent record and the instruction, and data moves between Data Fiduciaries under that instruction unread. The Schedule's own illustration is concrete — X routes her consent through bank B2 to bank B1, and B2 sends the statement to B1 directly.

Items 3 and 4 — the record. Per Data Principal: consents given, denied or withdrawn; the notices preceding or accompanying each request; and the sharing of her data with transferee Data Fiduciaries. She must have access to it, obtain it in machine-readable form on request, and it must be retained for at least seven years.

Item 6 — no sub-contracting. "The Consent Manager shall not sub-contract or assign the performance of any of its obligations under the Act and these rules." Read alongside the seven-year record and the zero-knowledge requirement, this significantly constrains how much of the stack can be outsourced.

Items 11 to 13 — transparency and supervision. Public disclosure of promoters, directors, KMP and senior management, every shareholder above two per cent, and every body corporate in which any of those people hold more than two per cent as on the first day of the preceding calendar month — a monthly refresh, not a one-time filing. Plus effective audit mechanisms covering controls, continued fulfilment of registration conditions and adherence to obligations, reported to the Board periodically and whenever directed. Control of the company cannot be transferred by sale, merger or otherwise without prior Board approval.


4. The Enforcement Gap Nobody Has Solved

Rule 4 requires applicants to register with the Data Protection Board of India. The Board was established under Section 18, and Sections 18 to 26 commenced on 13 November 2025. Its composition is a Chairperson and four other Members.

On 6 May 2026, MeitY issued circular F. No. 2(1)/2026-Pers.I inviting applications for exactly those posts — one Chairperson and four Members — at consolidated monthly salaries of ₹4,50,000 and ₹4,00,000, matching the Fifth Schedule of the Rules, with a minimum applicant age of 55 and a tenure capped at two years or age 65. Under Rule 17 the Chairperson is recommended by a Search-cum-Selection Committee chaired by the Cabinet Secretary; Members by one chaired by the Secretary, MeitY. Commentary through 2026 has described the resulting gap bluntly — one analysis, published in April 2026, noted a High Court referring a petitioner to a Board not yet in a position to hear them. We could not locate any public announcement of appointments as of this writing.

For a prospective Consent Manager that is a concrete planning problem. The registration channel under Rule 4(1) is defined by particulars the Board publishes on its website; the Part A item 9 certification is against a framework the Board publishes; and Rule 19(9) gives the Board six months to complete an inquiry, extendable by three months at a time.

The honest planning assumption is that 13 November 2026 is when the legal ability to register begins, and that the operational date is unknown. Build to the Schedule regardless — the item 9 engineering is largely the same whether or not the framework has been published, and being certification-ready when it lands is the only lever you control.


5. If You Are a Data Fiduciary, This Is Your Actual Scope

Set the Consent Manager question aside. Here is what commences on 13 May 2027 and what each item costs to build.

Rule 3 — notice

The notice must be understandable independently of any other information the Data Fiduciary has made available. At minimum it must give an itemised description of the personal data plus the specific purposes and description of goods or services, and the communication link and other means by which she can withdraw consent "with the ease of doing so being comparable to that with which such consent was given," exercise her rights, and complain to the Board.

"Itemised description" is an engineering requirement disguised as a drafting one. You cannot itemise what you have not inventoried, which makes data discovery and mapping the gating task for the whole programme — and the one most often deferred, because it produces no visible control. Our comparison of DPDP compliance tooling covers the discovery and consent-management categories.

Rule 6 — reasonable security safeguards

Rule 6(1) is unusually specific for an Indian security rule. The minimum set is:

ClauseRequirementWhere it lands
6(1)(a)Encryption, obfuscation, masking, or virtual tokens mapped to the dataDatabase and application layer; tokenisation programme
6(1)(b)Access control over the computer resources used by the Fiduciary or its ProcessorIAM and PAM; entitlement review
6(1)(c)Visibility on the accessing of personal data through appropriate logs, monitoring and review, to enable detection of unauthorised access, investigation and remediationSIEM, database activity monitoring
6(1)(d)Reasonable measures for continued processing after a confidentiality, integrity or availability compromise, such as backupsBCP/DR
6(1)(e)Retain such logs and personal data for one year for that purpose, unless another law requires otherwiseSIEM storage tier and licensing
6(1)(f)Contractual flow-down of safeguards to Data ProcessorsVendor contracts
6(1)(g)Appropriate technical and organisational measures for effective observanceGovernance

Clause (c) quietly determines whether the rest is provable. "Visibility on the accessing of such personal data" means access to the data itself, not to the systems holding it — authentication logs from your identity provider do not satisfy it. You need read-level visibility at the data store, which for most Indian enterprises means database activity monitoring plus a correlation domain where identity and data-access events sit together. Same architectural problem as the SIEM and IAM integration playbook, different regulator.

Rule 7 — breach intimation, and the clock problem

Rule 7 creates three obligations from a single event:

  1. To each affected Data Principal, without delay: nature, extent and timing of the breach; the consequences relevant to her; mitigation measures implemented and in progress; safety measures she should take; and business contact information of someone who can answer her.
  2. To the Board, without delay: description including nature, extent, timing, location and likely impact.
  3. To the Board, within seventy-two hours of becoming aware (extendable only on written request): updated detail, the broad facts and circumstances, mitigation measures, findings on who caused it, remedial measures to prevent recurrence, and a report on the intimations given to affected Data Principals.

Now overlay the CERT-In Directions of 28 April 2022, which are already binding today:

ObligationTriggerDeadlineRecipient
CERT-In Direction (ii)Noticing a listed cyber incident, or it being brought to notice6 hoursCERT-In
DPDP Rule 7(1)Becoming aware of a personal data breachWithout delayEach affected Data Principal
DPDP Rule 7(2)(a)Becoming aware of a personal data breachWithout delayData Protection Board
DPDP Rule 7(2)(b)Becoming aware of a personal data breach72 hoursData Protection Board

The operational trap is the "extent" of the breach. Within 72 hours you must tell the Board how much personal data was affected and, under Rule 7(1), tell each affected individual the consequences relevant to her. Neither comes out of a firewall alert; both require the data-access telemetry Rule 6(1)(c) demands, which is why the two rules should be funded as one programme.

Note also CERT-In's separate requirement to enable logs of all ICT systems and maintain them securely for a rolling period of 180 days within Indian jurisdiction, against the one year in Rule 6(1)(e) and Rule 8(3). Design to the longest obligation that applies to you, not to each separately.

Rule 8 — erasure and the one-year floor

Rule 8(1) requires erasure after a fixed period of Data Principal inactivity for classes listed in the Third Schedule:

Class of Data FiduciaryThresholdErasure period
E-commerce entityNot less than two crore registered users in IndiaThree years from last approach or exercise of rights, or the commencement of the Rules, whichever is latest
Online gaming intermediaryNot less than fifty lakh registered users in IndiaThree years, same basis
Social media intermediaryNot less than two crore registered users in IndiaThree years, same basis

Two things practitioners miss. Rule 8(2) requires the Data Fiduciary to inform the Data Principal at least forty-eight hours before erasure completes, so she can log in and stop it — a scheduled-job-plus-notification pipeline, not a delete script. And Rule 8(3) applies to every Data Fiduciary, not just the Third Schedule classes: personal data, associated traffic data and processing logs must be kept for a minimum of one year from the date of processing for the Seventh Schedule purposes, then erased unless another law requires longer.

Rules 8(1) and 8(3) point in opposite directions, and the Rules' own illustration resolves it: an e-book platform must retain order, payment and delivery records for at least a year even if the customer deletes her account. Your retention engine has to encode both a floor and a ceiling, per data category. Most do not.

Rule 13 — if you are notified as a Significant Data Fiduciary

An SDF must, once every twelve months from notification, undertake a Data Protection Impact Assessment and an audit, and cause the person carrying them out to furnish a report of significant observations to the Board. It must also observe due diligence that its algorithmic software does not pose a risk to Data Principals' rights, and comply with any localisation restriction the Central Government specifies on a committee's recommendation.

That is a recurring external-assurance obligation with a regulator-facing deliverable. If you are a plausible SDF candidate, rehearse the first cycle before it is mandatory — the core of our DPDP audit and readiness service.


6. What Non-Compliance Costs

The Schedule to the Act, read with Section 33(1):

BreachMaximum penalty
Failure to take reasonable security safeguards under s. 8(5)₹250 crore
Failure to give the Board or affected Data Principal notice of a breach under s. 8(6)₹200 crore
Breach of additional obligations in relation to children under s. 9₹200 crore
Breach of Significant Data Fiduciary obligations under s. 10₹150 crore
Breach of Data Principal duties under s. 15₹10,000
Breach of a voluntary undertaking accepted under s. 32Up to the extent applicable to the underlying breach
Breach of any other provision of the Act or rules₹50 crore

The residual ₹50 crore tier in row 7 is where an unregistered Consent Manager lands after 13 November 2026, since Section 6(9) has no dedicated row — and where most Rule 3, Rule 7 procedural and Rule 8 retention failures land. The headline ₹250 crore attaches specifically to the security-safeguards obligation: to Rule 6. Section 33(1) also constrains the Board — penalties follow an inquiry, a determination that the breach is significant, and an opportunity of being heard.


7. A 267-Day Programme

Working back from 13 May 2027, on the quarters Indian enterprise budget cycles actually use:

WindowWorkRule driving it
Now – Q3 FY27Data discovery and mapping across every system holding personal data, including Processor-held copies. Log coverage audit — generated, shipped, parsed, retained, searchable — for data access events, not authentication events. Establish whether you are plausibly an SDF.Rule 3 itemised description; Rule 6(1)(c); Rule 13
Q4 FY27Size one-year retention against current SIEM licensing and storage tiers. Decide tokenisation and masking scope. Start Data Processor contract amendments — you do not control the counterparty's calendar.Rules 6(1)(a), 6(1)(e), 6(1)(f), 8(3)
Q1 FY28Consent capture, withdrawal propagation to downstream systems and Processors, and the evidentiary trail.Ss. 6(6), 6(10); Rule 3
Q2 FY28Breach simulation against the four clocks above.Rule 7; CERT-In Direction (ii)

Three notes on that plan. Section 6(10) puts the burden on the Data Fiduciary to prove notice was given and consent obtained, so consent must be stored as timestamped evidence linked to the exact notice version served — not as a boolean flag. The Q2 failure mode is never the notification template; it is the inability to state extent and affected-individual scope within 72 hours, and that gap is telemetry, which takes a quarter to close. And none of this is a product purchase: Rule 6(1)(c) visibility, Rule 7 extent determination and Rule 8 retention logic are integration and detection-engineering work on platforms you already own, which is why organisations treating DPDP as GRC-tool procurement arrive at May 2027 with a policy library and no evidence.

If you are SEBI-regulated you are running this alongside CSCRF audit cycles, where the log-coverage and access-visibility work is largely shared and should be scoped once. Our SEBI CSCRF checklist sets out that overlap; the CERT-In Digital Threat Report analysis covers the detection-engineering side.


FAQ

Do we need to appoint a Data Protection Officer?

Only Significant Data Fiduciaries must appoint one, under Section 10(2)(a). But Rule 9 obliges every Data Fiduciary to prominently publish on its website or app — and mention in every response to a rights request — the business contact information of the DPO if applicable, or of a person who can answer Data Principal questions about processing. So every organisation needs a named, reachable person; only SDFs need the statutory role.

Can we keep using a foreign cloud region?

Rule 15 permits transfer outside India subject to requirements the Central Government may specify by general or special order regarding making personal data available to a foreign State or an entity under its control. Rule 13(4) separately lets the Government restrict specified personal data and its traffic data from leaving India, for Significant Data Fiduciaries. Neither is a blanket localisation mandate today; both are enabling powers.

Does consent withdrawal have to propagate to our processors?

Yes. Section 6(6) requires the Data Fiduciary, within a reasonable time, to cease and cause its Data Processors to cease processing after withdrawal. Section 8(7)(b) similarly requires the Fiduciary to cause its Processor to erase data made available to it. If your consent state lives only in your CRM and never reaches the analytics warehouse, the vendor's model-training pipeline or the marketing platform, you have a technical gap that maps directly onto a statutory one.

What happens if the Board is still not constituted in May 2027?

The obligations commence regardless — commencement follows the Gazette notification, not the regulator's staffing. What would be affected is enforcement and the breach-intimation channel under Rule 7(2). Build the reporting capability and evidence trail on the statutory timeline anyway: a limitation on the Board's ability to act is not a defence, and it can end at any time.

Are the DPDP Rules the same as CSCRF or the CERT-In Directions?

No — they stack rather than substitute. The CERT-In Directions of 28 April 2022 apply to service providers, intermediaries, data centres, body corporates and Government organisations, and bind you today. CSCRF applies to SEBI-regulated entities. DPDP applies to processing of digital personal data. A single Indian BFSI organisation is typically subject to all three, with different clocks, different recipients and overlapping but non-identical log requirements.

We are a mid-size NBFC with a lean team. Where do we start?

With the log coverage audit. It is required evidence under the CERT-In Direction you are already subject to, so it is not speculative spend — and it is the diagnostic that tells you whether Rule 6(1)(c) and Rule 7's 72-hour extent determination are achievable on your current stack.


Where Cyberaube Fits

The programme above is mostly security engineering and only partly legal drafting, and most organisations resource it the other way round.

Cyberaube works on the engineering side. We run DPDP readiness and gap assessments that produce an evidence-backed control map rather than a policy pack; SIEM detection engineering and log-coverage work on QRadar and Splunk, including retention architecture sized to the Rule 6(1)(e) and Rule 8(3) one-year floors; IAM and PAM implementation across CyberArk, Okta and SailPoint for the Rule 6(1)(b) obligation; and 24/7 managed security operations that can sustain a six-hour CERT-In and 72-hour DPDP reporting tempo. Where you would rather build the capability inside your own team, we place certified specialists on contract and permanent terms.

Book a DPDP readiness and log coverage assessment


Conclusion

Rule 1 of the DPDP Rules is unambiguous. One rule commences in November 2026, and it is a licensing regime for Consent Managers. Everything that binds an ordinary Data Fiduciary commences on 13 May 2027.

That is not relief. The May 2027 obligations are dominated by two requirements — visibility on personal data access, and one-year retention of that visibility — that cannot be procured late. They have the longest lead times and the least visible outputs in a security programme, which is exactly why they get deferred.

For a prospective Consent Manager the constraint is harder: a ₹2 crore net worth floor, a constitutional-document amendment with a permanent regulator veto, a no-sub-contracting rule, a seven-year record obligation, and an independent certification against a framework that only the Board can publish — while its own appointments remain unannounced.

Either way the work starts with the same question, and it is about your logs rather than your policies: when someone reads a customer's personal data in your environment, does anything record it?

Talk to our team about DPDP readiness


About the Author

Saurabh Pande is Co-Founder of Cyberaube Technologies with 13+ years of experience across enterprise security platforms including IBM Security, CyberArk, and QRadar. He has interviewed and placed 2,500+ cybersecurity professionals across SIEM, PAM, and IAM disciplines, and advises BFSI organizations on security operations strategy and compliance readiness.


About Cyberaube

Cyberaube provides cybersecurity staffing, 24/7 managed security services, and expert consulting for SIEM, IAM, and data protection platforms. Our certified specialists implement and operate QRadar, Splunk, ArcSight, CyberArk, Okta, SailPoint, and integrated security stacks for enterprises across India and globally.

Contact Cyberaube for DPDP readiness and SOC support

💬Need Support Now?