Update
On 12 August 2026, Minister of State for Electronics and Information Technology Jitin Prasada told the Lok Sabha that implementation of the Digital Personal Data Protection (DPDP) Act, 2023 is proceeding in three phases. The first phase, covering establishment of the Data Protection Board of India, is already in effect; the DPDP Rules bringing the Board into being were notified on 13 November 2025. The second phase, opening registration for Consent Managers, is expected around November 2026. The third phase, bringing the Act's substantive obligations into force, including consent requirements, notice obligations, security safeguards, breach reporting, provisions on children's data, and penalties of up to ₹250 crore, is scheduled for 13 May 2027.
Prasada told Parliament that the Data Protection Board will have a chairperson and four members. Recruitment advertisements for these positions were issued in June 2026, roughly seven months after the Board's establishment provisions came into force. The government also clarified in its parliamentary reply that Common Service Centre Village Level Entrepreneurs are not classified as data fiduciaries under the Act, since they do not determine the purpose of data processing carried out through the centres they operate.
Analysis
The staggered rollout has drawn mixed reactions. MeitY officials, including Secretary S. Krishnan, have described the phased approach as giving both the regulator and regulated entities time to prepare, consistent with the government's broader description of the DPDP framework as principles-based rather than prescriptive. Industry compliance advisors have generally welcomed the extended runway to May 2027, while noting that the framework leaves companies to interpret many of their own obligations without detailed rules to follow.
Some commentary has focused on the gap between the Board's formal establishment in November 2025 and the start of recruitment for its members in June 2026. During that period, the Board existed as a legal entity capable of receiving filings but without appointed members to adjudicate them. MeitY has not issued a public statement addressing this specific gap or indicating when the Board is expected to be fully staffed and operational for adjudicatory purposes.
The Consent Manager framework, due to open for registration around November 2026, has no close precedent in other major data protection regimes. The European Union's General Data Protection Regulation relies on data controllers and processors rather than a licensed intermediary consent layer, and India's own account aggregator framework in financial services, sometimes cited as a loose analogue, operates in a narrower, sector-specific context. Whether Consent Managers will reduce friction for users navigating multiple consent requests, or add a further layer on top of existing consent flows, is not yet established, and MeitY has not published detailed operational guidance on how the two systems will interact ahead of the November timeline.
Comments
0 commentsNo comments yet — be the first.