DPDP Three-Phase Rollout Confirmed in Parliament
12 August 2026
I. Sequencing as a Political Instrument
The three phase structure Jitin Prasada described in Parliament is not merely an implementation convenience. It allows the government to claim the DPDP Act is fully operative, since the Board exists and can already receive complaints, while deferring the two obligations that actually bind ordinary businesses, Consent Manager registration and the substantive Chapter II duties, by twelve and eighteen months respectively. This sequencing lets the executive point to "operational" status in press briefings while giving industry a genuine multi year runway. Both claims are true simultaneously, which is precisely what makes the phased structure politically useful and analytically slippery. Practitioners advising boards should be explicit that current DPDP "compliance" activity is preparatory, not yet legally mandatory in its substantive form, so that governance committees do not overstate readiness to auditors or investors.
II. The Institutional Lag Behind Phase One
Phase one's claim to completeness rests entirely on the Data Protection Board's existence. That existence is thinner than it appears. The Board's establishment provisions came into force with the Rules in November 2025, but the recruitment advertisement for its chairperson and four members appeared only in June 2026, seven months later. A Board without appointed members can receive filings under the Rules' digital first design, but it cannot meaningfully adjudicate them. This is the recurring pattern across Indian digital regulation: the institutional shell precedes the institutional capacity by a wide margin, and the government's public messaging elides the difference. Clients should not assume that a functioning appellate or adjudicatory backstop exists merely because the Board is described as operational.
III. Consent Managers Face a November Deadline Against an Unclear Regulator
Phase two, opening Consent Manager registration around November 2026, depends on the same under-resourced Board to actually process registrations. Industry commentary published closer to the deadline has noted that the Board may not be fully constituted even as the registration window opens, creating a scenario where the intermediary layer meant to operationalise consent management launches before its regulator can meaningfully oversee it. Businesses planning to integrate with registered Consent Managers, rather than build first party consent infrastructure, should build contingency plans assuming registration delays, not treat the November date as a hard technical milestone others will have cleared by then.
IV. The CSC Clarification Is a Narrow Carve-Out, Not a Trend
The government's confirmation that Common Service Centre Village Level Entrepreneurs are not data fiduciaries, because they do not determine the purpose of processing, is doctrinally unremarkable. It restates the existing definition of data fiduciary under the Act rather than creating a new exemption category. Advisors should resist reading this as evidence of a broader government appetite for carving exemptions into the fiduciary definition; it is a single, fact specific clarification limited to intermediated public service delivery, not a template applicable to commercial assisted access models.
V. Comparative Note: Consent Managers Have No Clean Precedent
Unlike most DPDP architecture, which borrows recognisably from the GDPR's data controller and processor framework, the Consent Manager is a genuinely India specific institution with no close European or American analogue. The closest comparator is the account aggregator framework in Indian financial regulation, itself a novel construct rather than an imported one. This absence of precedent means the usual practice of importing compliance playbooks from GDPR readiness programmes will not work for the Consent Manager obligations specifically. Firms that have built DPDP compliance purely by adapting existing GDPR documentation should treat the consent architecture as requiring bespoke design work, not a translation exercise. The account aggregator comparison is also imperfect in one important respect: account aggregators mediate a narrow, well-defined category of financial data flows between regulated entities, whereas Consent Managers under the DPDP framework are meant eventually to mediate consent across the entire economy's personal data processing, a scope of ambition with no working model anywhere to validate against before the November 2026 launch.
VI. Practitioner Guidance
Clients should calendar the May 2027 substantive compliance date as fixed and non negotiable, given Secretary Krishnan's public statements ruling out extension, while treating the November 2026 Consent Manager milestone as directionally correct but operationally uncertain. Data mapping and consent architecture work should begin now regardless of Consent Manager registration timing, since first party consent capture mechanisms will be required either way and cannot be built in the compressed window between a delayed Consent Manager rollout and the fixed May 2027 deadline. Boards reviewing DPDP readiness reports should specifically ask whether reported "compliance" refers to phase one preparatory activity or phase three substantive readiness, since the two are being conflated in much of the current market commentary and the distinction carries real governance and disclosure consequences.