Compliance team reviewing consent management documentation in an Indian office meeting room

Consent management under DPDP: what changes in November 2026

Consent management under DPDP: what changes in November 2026

Consent management under DPDP is the requirement most companies think they already handled, because a cookie banner has been sitting on the website since 2019. That banner and a consent record are two different documents, and the gap between them is where this story starts.

I am Priya. I work on DPDP readiness for Indian mid-market companies, mostly BFSI and retail. This is what November 2026 actually changes, told through one Pune brand that learned the hard way what their banner was not doing.

08:40 AM. Karan, the ops head at a 240-person D2C skincare brand in Pune, was on a call with a hospital chain that wanted to stock the brand in its gift shops. Legal had one question before anyone signed anything. Can you show us your consent architecture for customer data collected on the website. Karan said yes. He had not actually opened that folder in three years.

The banner that was never a record

Arre, this is the part nearly every mid-size company gets wrong. A cookie banner tells a visitor that cookies exist. It does not record what a specific person consented to, when, for which purpose, or whether they later withdrew it. A real consent record under DPDP is itemised by purpose, marketing separate from order processing separate from analytics, timestamped, as easy to withdraw as to give, and readable by a Consent Manager if the customer routes permissions through one.

That last part is the November 2026 change. MeitY opened the registration window for Consent Managers roughly a year after the DPDP Rules 2025 were notified. A Consent Manager works the way an Account Aggregator does for financial data, a licensed intermediary a customer can use to control every consent they have given, across every company. It does not force every business to act immediately. It changes what “ready” means for any company that wants an enterprise client, or a hospital chain, to trust its consent trail.

Rs 250 crore. That is the ceiling penalty under Section 33 of the DPDP Act 2023. The substantive compliance date, per the DPDP Rules 2025, is 13 May 2027. The Data Protection Board does not need a breach to act. A consent record it cannot verify is a finding by itself.

Get my free DPDP readiness check
200+ Indian businesses. Response within 24 working hours. No card, no contract.

What the audit actually found

I want to be honest about a mistake here. I walked in assuming the fix was mostly technical, a plugin update, a new banner vendor, a week of work. It was not. The website banner was the smallest problem in the building.

The marketing team had roughly 40,000 contacts collected across four years, from a 2022 giveaway form, a referral programme, in-store QR codes at a mall kiosk, and a webinar sign-up sheet typed into a spreadsheet by hand. None of it was purpose-tagged. A person who scanned a QR code for a ten percent discount sat on the same list as someone who had opted into a monthly newsletter, and both got the same WhatsApp broadcasts. Nobody could say, for any single contact, what they had actually agreed to.

Yaar, the founder’s first reaction was that this felt like an overreaction to a cookie law. It is not a cookie law. It is a question about whether the company can show, for any one of those 40,000 people, exactly what they said yes to and whether they still mean it.

The consent inventory, once we counted it

By the end of week two we had the real picture, and it is the table that made the founder go quiet.

What the banner gave youWhat a DPDP consent record needs
One yes covers the whole siteSeparate consent per purpose: marketing, analytics, order processing
No timestamp, no versionTimestamped, tied to the notice version shown at that moment
No withdrawal pathWithdrawal as easy as consent, honoured across every system it touched
Lives only in a cookie plugin dashboardExportable, Consent Manager readable, survives a vendor switch

What we built, and what it cost

Six weeks, end to end. Week one was the inventory above. Weeks two and three rebuilt the capture forms, three checkboxes instead of one, each tied to a named purpose, none pre-ticked. Week four built the withdrawal flow into the same account page customers already used for orders, because a withdrawal buried in a support queue is not really a withdrawal path. Week five was the sync layer, so a withdrawal on the website switched off WhatsApp and email the same day, not eventually. Week six was documentation, because an auditor reads the paperwork, not the code.

Total cost, roughly Rs 9 lakh, split across a developer, a privacy consultant’s review, and the tooling. “DPDP isn’t even being enforced yet, we’ll deal with it later” was the line the founder used in week one. Achha, enforcement timing is genuinely a gamble, but the hospital chain’s legal team was not waiting for enforcement, they asked the question before signing. The companies scrambling after the first big penalty will pay a premium and move badly. The ones who built this quietly now just tick the box when asked.

Karan sent the hospital chain’s legal team the consent architecture document in week seven. They signed the stockist agreement nine days later. He told me afterwards that the deal would probably have stalled on that one question if the folder had stayed unopened.

Start my consent audit now
We have run this rebuild for 40+ Indian D2C and retail brands. Response within 24 working hours. WhatsApp +91 91375 93228, 10 to 7 IST.

If you are building this yourself

Bas, here is the shortlist, in the order we actually did it. Inventory every place you collect personal data, including the ones nobody remembers, mall kiosks, old giveaway forms, referral links. Tag every existing contact by the purpose it was collected for, even retroactively, even if that means emailing people to re-confirm. Split consent capture into named purposes instead of one blanket checkbox, none pre-ticked. Timestamp every consent event against the exact notice text shown that day. Build withdrawal into the account page customers already use, not a hidden support form. Sync withdrawal across every downstream system the same day. Keep the record exportable, so a Consent Manager or an auditor can read it without calling your developer.

Where to start if no letter or client question has landed yet: the DPDP readiness assessment maps this before it becomes urgent. If a deadline has already landed on your desk, the 8-week audit response plan we ran for a Mumbai bank walks through the same triage discipline. The plain-English guide to who counts as a Data Fiduciary is worth reading first if you are still unsure whether this applies to you, and it does. For the penalty math itself, see what the Rs 250 crore ceiling really means for a company your size, and for the fuller pre-deadline checklist, 10 things to fix before May 2027. CERT-In’s directions overlap the breach-notification side of this once a consent gap turns into an incident.

FAQ

What actually changes in November 2026?
MeitY’s window for Consent Manager registration opens roughly a year after the DPDP Rules 2025 notification. It does not force every company to act that month, but it is the point from which a serious client or partner can reasonably expect your consent trail to be Consent Manager compatible.

Is a cookie consent plugin enough on its own?
No. A plugin can display a banner and log a single yes or no. It rarely separates consent by purpose, timestamps against a specific notice version, or syncs a withdrawal across your marketing and CRM systems on the same day, all of which the Act expects.

Do we need to fix this before 13 May 2027 or before November 2026?
The Act’s substantive duties apply from 13 May 2027. November 2026 matters earlier than that for any company being asked the question by a client, an investor, or a partner before that date, the way Karan’s brand was.

How long does a rebuild like this actually take?
Six weeks is realistic for a company between 100 and 300 employees with one or two marketing channels. Larger, multi-brand companies with legacy contact lists across several systems should budget ten to twelve weeks.

P.S. Priya here. Karan called me back a month after the stockist deal closed, not about consent this time, just to say the hospital chain’s procurement team had asked two other vendors the same question and both had stalled. If your consent folder has not been opened in a while, that is usually the actual reason to open it. Reach me on WhatsApp +91 91375 93228 if you want a second pair of eyes on yours.

Get my free consent audit
200+ Indian businesses. 24 working hours response. No card, no contract.


Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *