Most organisations are aware of the 13 May 2027 DPDPA compliance deadline.

But waiting until 2027 to begin implementation could leave businesses with too much to complete in too little time.

Before the final deadline, there is another important milestone: 13 November 2026.

This is when the Consent Manager registration phase begins. It marks a clear shift from understanding the Digital Personal Data Protection Act to preparing systems, records and business processes that can support it.

For Indian organisations, this date should be treated as a readiness checkpoint.

The DPDPA timeline businesses should understand

The Digital Personal Data Protection framework is being implemented in phases.

13 November 2025: The DPDP Rules were notified

The DPDP Rules, 2025 were notified, the Data Protection Board framework became operational, and the phased implementation period began.

This gave organisations time to understand the requirements, identify responsible teams and start preparing for compliance.

13 November 2026: Consent Manager registration begins

This is the next major milestone.

The Consent Manager framework is intended to give individuals a structured way to give, manage, review and withdraw consent.

Not every organisation needs to register as a Consent Manager. However, businesses that collect and process personal data need to examine whether their consent records and connected systems can support this more structured environment.

13 May 2027: Wider DPDPA obligations take effect

The wider obligations relating to privacy notices, consent, individual rights, security safeguards, breach reporting and organisational accountability are scheduled to take effect from this date.

The important point is simple. 13 November 2026 is not the final DPDPA deadline, but it significantly reduces the remaining implementation window.

What changes on 13 November 2026 under DPDPA?

The immediate change is the start of the Consent Manager registration phase.

The larger business impact is that organisations will need better visibility and control over how consent is captured, stored, updated and withdrawn.

Today, consent may be collected through:

  • Website forms
  • Mobile applications
  • Customer onboarding documents
  • CRM systems
  • Marketing campaigns
  • Recruitment portals
  • Email communication
  • WhatsApp conversations
  • Physical forms later converted into digital records

In many businesses, these channels work separately.

A customer may withdraw consent through one channel, while their data continues to be used in another system. Marketing tools, CRM platforms, service applications and third-party vendors may all hold separate copies.

Before the Consent Manager phase begins, organisations should understand how consent moves across these systems.

Consent will need to be supported by evidence

A consent checkbox alone may not provide the complete picture.

An organisation should be able to establish:

  • Who provided consent
  • When the consent was provided
  • What personal data it covered
  • Why the data was required
  • What information was shown to the individual
  • Whether the data is being used for the stated purpose
  • How the individual can withdraw consent
  • What happens after consent is withdrawn

This requires more than updating the wording on a website.

The consent process must connect with actual business operations. If an individual withdraws consent, the relevant teams and systems should know what processing must stop and whether connected vendors need to take action.

Historical data could become a major compliance gap

Most organisations hold personal data collected over several years.

This may include old customer records, former employee documents, inactive prospect lists, event databases, recruitment information, identity documents and files stored in shared folders.

The challenge is not simply that this data exists.

The organisation needs to know:

  • Why the data is still being retained
  • Whether the original purpose still applies
  • Whether the available consent is adequate
  • Who can currently access the data
  • Whether copies exist in other systems
  • When and how the data should be deleted

Legacy data is often spread across email, Excel files, cloud folders and business applications. This makes it difficult to manage without first conducting proper data discovery and mapping.

Vendors do not remove your responsibility

Payroll providers, CRM vendors, marketing agencies, cloud platforms, payment partners, recruitment firms and IT service providers may process personal data on behalf of an organisation.

However, outsourcing a business activity does not automatically outsource accountability.

Organisations should have visibility into:

  • Which vendors receive personal data
  • What information they receive
  • Why they need it
  • How they protect it
  • How long they retain it
  • Whether they share it with other parties
  • How they report a data breach
  • What happens to the data when the contract ends

Vendor agreements should also address processing responsibilities, security safeguards, retention, deletion and breach reporting.

Vendor and processor management is therefore an important part of DPDPA readiness, not only a procurement or legal exercise.

A privacy policy alone will not be enough

Many organisations begin their DPDPA journey by updating their website privacy policy.

That is useful, but it is only one part of compliance.

The policy should reflect what the business actually does. Teams also need working processes for:

  • Giving clear privacy notices
  • Capturing and recording consent
  • Managing consent withdrawal
  • Responding to access, correction and erasure requests
  • Handling grievances
  • Reviewing data retention
  • Managing vendors
  • Protecting personal data
  • Responding to a personal data breach

These activities usually involve Legal, HR, IT, Information Security, Marketing, Procurement and business teams.

DPDPA readiness is therefore an organisation-wide responsibility. It cannot sit with one department while the rest of the business continues handling data in the same way.

Why organisations should not wait until May 2027

Most compliance gaps cannot be fixed through one policy or one technology purchase.

Identifying personal data may require reviews across email, cloud storage, CRM systems, shared folders, employee devices and third-party platforms.

Improving consent may require changes to customer journeys, websites, applications and marketing systems.

Vendor remediation may require contract reviews and coordination with several service providers.

Breach readiness may require a defined response process, communication templates, decision ownership and practical testing.

Even organisations with ISO 27001 certification may still need separate privacy processes. Information security controls can provide a useful foundation, but they do not automatically cover consent, notices, purpose limitation, retention and Data Principal rights.

The earlier an organisation identifies its gaps, the more effectively it can prioritise people, process, policy and technology changes.

What should businesses have in place by 13 November 2026?

By this milestone, organisations should at least have clear visibility into:

Personal data

Know what personal data is collected, where it is stored, why it is required and who can access it.

Consent

Identify every channel where consent is captured and check whether it can be demonstrated, updated and withdrawn.

Historical records

Review old customer, employee and prospect data to determine whether it should still be retained.

Vendors

Maintain visibility into every third party that processes personal data and review the agreements in place.

Accountability

Assign clear responsibility for privacy, grievances, security incidents and compliance decisions.

Implementation gaps

Document the most important gaps, their business impact, responsible owners and remediation priorities.

This baseline helps the organisation move towards compliance in a structured way instead of implementing isolated changes without knowing whether they address the highest-priority risks.

How a DPDPA Readiness Assessment helps

A DPDPA Readiness Assessment gives management a clear view of the organisation’s current position.

The assessment is designed to identify gaps and produce a prioritised compliance roadmap based on the organisation’s systems and processing activities.

Rather than starting with assumptions, the business gets an evidence-based view of what is already working, what is missing and what should be addressed first.

Conclusion: Make 13 November 2026 your readiness checkpoint

The biggest change on 13 November 2026 is the beginning of the Consent Manager registration phase.

For businesses, its wider importance lies in what it represents. The preparation period is moving forward, and the time available before full compliance on 13 May 2027 is becoming shorter.

By November, organisations should know where their personal data is stored, how consent is managed, which vendors process data, who owns compliance and which gaps need immediate attention.

Businesses that establish this visibility early can approach implementation in a planned and practical way. Those that wait may have to make changes across systems, contracts and departments at the same time.

Book a DPDPA Readiness Assessment with Matrix3D to identify your current gaps and build a prioritised roadmap for compliance.