Thursday, September 3, 2026

India's Consent Manager Deadline Arrives With No Regulator To Register

You open a food delivery app you last used in 2019. It still holds your home address, your office address, a card you cancelled two years ago, and every order you placed during a lockdown you would rather not revisit. No button in that app takes any of it back.

India's Consent Manager Deadline Arrives With No Regulator To Register

TL;DR: From 13 November 2026, Indian users are supposed to manage every app consent from one interoperable dashboard run by a registered consent manager. The regulator that registers them, the Data Protection Board of India, still has no chairperson and no members. The right arrives; the plumbing does not.

Why It Matters

A consent manager is not another privacy policy. Under the Digital Personal Data Protection Rules notified in November 2025, it is a licensed intermediary sitting between you and every company that holds your data, and its duty runs to you rather than to them. Consent given through it can be reviewed and pulled back in one place, and the withdrawal is meant to travel to the company on its own. One screen instead of forty settings pages.

The conventional read is that India is copying Europe, late. That gets it backwards. GDPR handed Europeans a right to withdraw and left them to exercise it one company at a time, which is precisely why almost nobody does. India's version is the more ambitious of the two, because it puts a registered institution in the middle whose entire job is to make a withdrawal actually propagate. Ambitious is not the same as working.

And here is the part nobody planned around. A LiveLaw analysis published in August 2026 found that the Data Protection Board of India, the body that must register consent managers and hear complaints against companies, had no appointed chairperson and no appointed members roughly ten months after the rules took effect. Nominations went out. No seat was filled. The shape of this will be familiar to anyone who followed India's AI labelling rules at their six month mark, where the rule existed, the enforcement did not, and a High Court ended up doing the regulator's work for it.

Court-Set Decision Window

15 Days

ordered of an empty bench

Maximum Penalty

₹250 Crore

available on paper, unused

MeitY Nomination Calls

2 Rounds

May and June, both open

Board Seats Filled

0%

chairperson and members alike

Take that court-ordered decision window. A High Court bench in Madhya Pradesh sent a petitioner to file before the Board and told the Board to decide inside a fortnight, which reads as ordinary case management right up until you remember there is nobody at the other end to open the envelope. That is what a vacant regulator does to everything downstream of it. It does not collapse in public. It quietly converts a right into a queue.

"

Ten months of rules in force, and not one seat on the board that enforces them has been filled. That is not a delay any more. That is a decision.

The framework itself is not vague. It is unusually precise about what a consent manager has to be, which makes the missing registrar more conspicuous rather than less.

Category Detail What It Decides
Deadline Twelve months after the rules were notified Legacy consents must be revalidated by then
Entry Bar ₹2 crore minimum net worth, Indian incorporation Prices out the small privacy startups
Data Blindness Cannot read the personal data it routes A broker of permission, never of data
Retention Seven years of consent records held Your refusal outlives the app itself
Registrar Data Protection Board, zero members seated No desk accepts an application today
Breach Route Section 8(6) notifications land nowhere Reporting duty exists, recipient does not
Full Powers Adjudication expected around May 2027 Enforcement lands well after the deadline

Read down that middle column and the shape is obvious. Every line is a barrier to entry, and every barrier assumes a working gate behind it. What exists is a wall with no gate cut into it, and a date circled on a calendar.

12 months 6 months rules in force · board empty deadline passed · powers pending notification full powers

The eighteen month runway from notification to full enforcement powers, split at the point where the consent obligations bite.

Friction Points

The gap between the deadline and real enforcement is where the damage sits. From November, companies are supposed to have revalidated every legacy consent sitting in their databases. Nothing checks whether they did. Nothing, in the sense that no one holding statutory authority is currently in a position to look.

There is a second problem the industry does not much enjoy discussing. A consent manager is a new intermediary, and new intermediaries have to earn a living somewhere. The rules say it must be blind to the data it carries, which is the right instinct. But blindness is a technical property, not a revenue model, and India has watched the same gap open before: India's draft phone security standards ran into an industry with every reason to comply slowly and none to fund the work early.

Before you trust anything that calls itself a consent manager, check the following.

  • Registration is mandatory, and until the Board is seated, no operator in India holds it.
  • Withdrawal stops future processing. It does not erase an inference a company already drew from data it held lawfully.
  • Interoperability is a requirement on paper. Ask which fiduciaries a platform actually connects to today, by name.
  • The record of your refusal is kept about you too, long after you have stopped using the service.

Key takeaways

  • The duty of a consent manager runs to you, not to the company holding your data. That reversal is the entire design idea, and it is genuinely rare in Indian regulation.
  • Interoperability is what separates this from a cookie banner. One withdrawal is meant to reach every fiduciary you have linked, without you chasing any of them.
  • A dashboard is only as strong as the body that licenses it. Until seats are filled, the honest label for what exists is a well drafted intention.

Do not wait for the dashboard. Open the five apps you actually use, go into their existing privacy settings this week, and delete what you can while the deleting is still manual. The consent manager is a better answer than doing it by hand. It just is not an answer yet.

Thursday, August 20, 2026

India's AI Labelling Rules Six Months On: Courts Still Needed

A video of a Union Minister pocketing money lands in your family WhatsApp group. It looks right. The voice is his, the office is his, the lighting is ordinary enough to pass. Nothing on the screen tells you a machine built it, and by the time anyone official says so, your uncle has forwarded it twice.

India's AI Labelling Rules Six Months On: Courts Still Needed
TL;DR: India's IT Amendment Rules 2026 have required visible labels on AI-generated media and fast takedowns since 20 February. Six months on, a Union Minister still needed a Bombay High Court order to get deepfakes of himself pulled down. The label arrived. The enforcement did not.

Why It Matters

The rules were notified on 10 February 2026 and came into force ten days later. They do two things worth caring about. Synthetically generated information, meaning audio or video created or altered by a machine so it reads as authentic, now has to carry a label an ordinary person can actually see. And platforms have to embed permanent provenance markers into that content wherever it is technically feasible, then stop anyone from stripping them out. It is the same regulatory instinct that produced 83 security standards aimed at the handset in your pocket: fix it at the device or the platform, because chasing individual bad actors across the open internet has never scaled.

The draft wanted something blunter. A watermark covering ten percent of the frame, fixed, non-negotiable. That died before notification and was replaced by a principle: the label must be clear and prominent. Good. A hard percentage would have been unreadable on a phone and ridiculous on a television, and every design team in the country would have spent a year gaming the geometry instead of improving the disclosure. But turn it around and the change reads as an admission. Nobody could describe what a good label looks like, so the rule now describes a feeling and leaves the rest to whoever ships the app.

Then there is the clock, and the clock is where the framework quietly hands the work back to you. Platforms now face a hard deadline to pull flagged unlawful synthetic content once a lawful notice reaches them, cut sharply from the old window. Cross the significant intermediary threshold and a second duty lands: ask uploaders whether their material is machine-made, then verify that answer with technical measures instead of taking it on trust. On paper, aggressive. In practice, none of it moves until somebody notices, reports, and is believed. McAfee's State of the Scamiverse survey, published in February 2026, found Indians now spend 102 hours a year working out whether the messages hitting their phones are genuine. That is the real bill, and a shortened takedown window does nothing to it.

Takedown deadline

3 hours

Down from thirty six

Average scam loss

₹93,915

Per affected Indian respondent

Strict-tier threshold

50 lakh users

Registered accounts inside India

Cannot spot a fake

1 in 3

Indians surveyed, November 2025

The tier threshold is the number to watch, because it is a cliff rather than a slope. Cross it and you inherit the declaration-and-verification duty, which in engineering terms means building a classifier that guesses whether an upload is synthetic and then owning every case it gets wrong. Stay under it and you inherit almost nothing. Every mid-sized Indian app now has a live commercial reason to keep its registered account count comfortably short of the line, and no regulator has said a word about what happens when they do. TRAI has spent years watching this exact arithmetic play out in telecom without moving on it.

"

A three hour takedown clock means nothing to the person it was written for, because the clock only starts once she has already found the video, reported it, and been believed.

August gave the framework its first properly public test, and it is worth setting the written rule beside what actually happened in a courtroom.

Category Detail Insight
Legal basis An amendment to the existing intermediary guidelines, not a standalone AI statute Existing framework extended, not rewritten
Scope Audio, visual and audio-visual material altered to appear authentic Text-only output sits outside the rule
Label test Clear and prominent, with the draft's fixed frame percentage dropped Flexibility bought at the cost of certainty
Provenance Permanent markers embedded where feasible, with removal blocked by design Traceability outlasts any visible badge
Exemptions Routine editing, good-faith technical correction, accessibility work Ordinary photo cleanup stays untouched
Verification Uploader declares, platform checks the declaration with technical measures Platforms now own the classification mistakes
Trigger A lawful order or notice from a court or an authorised government agency Nothing moves without an external complaint
August test Bombay High Court, 5 August 2026, before Justice Arif Doctor Meta and Google agreed after court intervention

Read down that Trigger row again. The entire machine is reactive. Provenance markers, declaration duties, a stopwatch on removals, and every one of them waits for a complaint to arrive from outside. Which is why the story of the last six months is not the rule failing. It is the rule working exactly as drafted, on a schedule set by whoever has the time and standing to complain.

More wary than a year ago · 82% Social account compromised · 70% Lost money to a scam · 51% Hit by a voice-clone scam · 20% 0% 100%

The same McAfee fieldwork, run across seven countries, puts the Indian exposure picture in one frame: most people have already been hit, and most of them know it.

Friction Points

Earlier this month the Bombay High Court heard Nitin Gadkari's application against Meta Platforms over face-swapped videos and fabricated quotes tying him to the E20 ethanol controversy. Justice Arif Doctor called the material absolutely vile and abusive and said it should have no place on a public platform accessible to everyone, including the young. Meta and Google agreed in court to remove the listed content and were directed to hand over basic subscriber information for the accounts behind it. The next hearing sits roughly four weeks out. Note what that sequence required: a sitting Union Minister, senior counsel, and a High Court listing, half a year after the deadline took effect. If that is the cost of entry, the rule is not built for the woman whose face was pasted into something at two in the morning.

Here is the part nobody in the drafting room seems to have answered, and I would put it as opinion rather than fact: a labelling regime binds the people who were already going to behave. The model that stamps provenance into its output and the platform that surfaces the badge are both following rules that a deliberate faker simply routes around, using an offshore tool, a screen recording, a re-encode. So the label ends up certifying the harmless half of the internet while the harmful half stays unmarked, and no one has told readers what they are supposed to conclude from a video that carries no label at all. Absence of a badge is not evidence of authenticity. It might just mean the rule was ignored.

And there is a cost on the other side that gets less attention than it deserves. Compressing removal into hours, with safe harbour hanging on compliance, pushes platforms toward automated over-removal, because deleting a borderline clip is cheaper than defending it. Satire, political commentary, parody accounts (and yes, that includes the stuff you actually wanted to see) all sit in the blast radius. The Internet Freedom Foundation has argued the shortened windows leave no room for meaningful human review, and on that narrow point the criticism looks right to me even if the underlying goal does not.

  • An unlabelled video proves nothing either way. Treat missing provenance as unknown, not clean.
  • The clock starts at the notice, not at the upload. Reporting fast matters more than knowing the law.
  • Text is out of scope, so machine-written fake quotes and fake screenshots carry no labelling duty at all.
  • Smaller apps sit below the strict tier and owe you far less, which is where a lot of this content will migrate.
  • Provenance markers survive the label. If a clip matters, the metadata is the thing worth preserving before you forward it.
Check · Report · Hold Look for provenance data, not a corner watermark. Screenshots strip it out. Use the in-app report flow, not a comment. Only a notice starts it. Do not forward while you are still checking. Reach beats correction.

Three habits, none of which require you to read a gazette notification.

The rules are a real improvement over having nothing, and they are nowhere near what the marketing around them implied. India moved faster than most countries here, which counts for something, in the same way moving first on credit through UPI counted for something before the fine print landed. If you want a version of this that protects your household rather than a minister, the move is not legal. Go into the settings on every account your family uses, turn on whatever synthetic-media reporting the platform already offers, and use it the first time rather than the fifth, the same discipline that makes switching off Shorts on the living room television actually stick. The label is not going to save you. The report button might.

Saturday, August 1, 2026

India Wants 83 Security Rules Baked Into Your Next Phone

Your phone finished installing a security patch last night while you slept. Under a draft rule India is still arguing over, that patch would have stopped at a government body for review before it ever reached you, and the code behind it would sit in a testing lab somewhere in India. Same phone, same update, one extra reader.

India Wants 83 Security Rules Baked Into Your Next Phone
TL;DR: India's draft ITSAR package bundles 83 security standards into one rulebook for every handset sold here. Source-code review, pre-release patch vetting, and a year of system logs stored on your device. Nothing is notified yet, and the real fight is over who gets to look.

Why It Matters

Start with what already happened, because it sets the pattern. India's Ministry of Communications gave handset makers 90 days to preinstall its Sanchar Saathi app in a December 2025 order, told them to make sure users could not disable it, and withdrew the whole thing two days later after the backlash. The app survived. The mandate did not. That sequence, order first and consultation afterwards, is the thing worth watching, not any single rule inside it.

The ITSAR package is a bigger version of the same instinct. Reuters reported in January 2026 that the draft would require device makers to open source code for review at designated labs in India, submit updates and security patches to a government body before public release, run periodic on-device malware scans, and keep system logs on the handset. India's IT ministry publicly refuted the source-code characterisation the next day. Both things are on the record, and neither has been resolved since.

And here is where I part company with most of the coverage. The patch-vetting clause worries me more than the source-code clause does. Source code review is a one-time exposure that vendors can negotiate, sandbox, and lawyer around. A standing approval queue between a security fix and your handset is different: it inserts a delay into the exact process that exists to remove delay. Every hour a patch waits in a review inbox is an hour the bug it fixes is still live on 750 million devices. That is not a privacy argument. It is an arithmetic one. The same tension showed up when credit lines quietly attached themselves to ordinary UPI payments, and again when EV charging fragmented into a hundred incompatible apps: the rulebook arrives after the behaviour, and consumers absorb the gap.

Draft Standards

83

Rules in one package

Log Retention

12 months

Kept on your handset

Average Phone Price

$282

Record India price, 2025

Yearly Price Rise

8%

Counterpoint's 2025 increase

Those price figures come from Counterpoint Research's 2025 India numbers, and they belong in this conversation for a plain reason. Compliance is never free. Testing, lab submissions, and a separate India build all land somewhere in the bill of materials, and in a market where the average handset already costs more than it did a year ago, the cheapest phones are where that cost shows up first. The people most likely to buy a device with a locked-down India-specific security build are also the people least able to pay another few hundred rupees for it.

"

A year of system logs sitting on your handset is not a security feature. It is an evidence locker, and you are holding the key on someone else's behalf.

What The Draft Actually Contains

Strip away the legal briefings and the exam-prep summaries, and the package resolves into a handful of concrete changes to the device in your pocket. Some of them are things privacy advocates have wanted for a decade. Others are the opposite.

Category Detail Why It Matters
Framework ITSAR, drafted in 2023, now weighed as binding Old text, brand new legal force
Source Code Reviewed and tested at designated Indian labs Vendors call it precedent-free globally
Update Path Patches submitted for review before public release A queue sits between fix and phone
Bloatware Every pre-installed app becomes removable The one clean consumer win here
Permissions Limits on what apps may run in background Fewer apps listening while idle
Scanning Periodic malware scans running on the handset Battery and performance cost falls on you
Status Consultations open, no rules notified so far Still a draft, not yet law

Read down that table and the split is obvious. Two rows help you. Four rows help someone else and bill you for the privilege. The removable-bloatware clause alone would do more for the average budget handset in India than anything a manufacturer has shipped voluntarily in five years, which is exactly why it should not be traded away as a sweetener for the rest.

1 Dec 2025 · 3 Dec 2025 · 11 Jan 2026 · Aug 2026 Preinstall order · Order withdrawn · ITSAR draft reported · Still unnotified

The timeline above tracks four moves in eight months: a preinstall order on 1 December 2025, its withdrawal on 3 December 2025, the ITSAR draft surfacing on 11 January 2026, and no notified rule as of August 2026.

The Friction Points Nobody Has Solved

Nobody has answered the question that actually matters: who audits the auditor. A state that can read source code and clear patches before release gains real defensive capability and real surveillance capability from the identical access, and the draft says nothing about which one it is buying. That is not a conspiracy claim. It is a design gap, and it is the kind of gap that gets filled quietly by whoever holds the keys, in whichever direction is convenient at the time. My position is that access this broad needs an independent oversight body named in the rule itself, before the rule exists, not bolted on after the first misuse.

There is a fair counter-argument and it deserves stating properly. India absorbs enormous volumes of device-level fraud, and regulators have limited leverage over handset makers headquartered elsewhere. Sitting on your hands is also a choice with a body count. The complaint here is not that India is regulating phones. It is that the sequencing keeps running backwards, the same way telecom oversight arrived years after market concentration had already set.

  • Patch latency compounds: a review queue that adds even days to an emergency fix hands attackers a window that scales with every device in the country.
  • Storage and battery are finite: continuous scanning plus a year of retained logs consumes exactly the resources that budget handsets have least of.
  • Log access is undefined: the draft says logs must exist, not who may request them, under what process, or how long a request stays secret.
  • Fragmentation risk: an India-specific build that diverges from the global one tends to receive updates last, which is the reverse of the stated goal.
  • Enforcement is untested: the same withdrawal that killed the preinstall order shows how fast a mandate can move, in both directions, without warning.

Key Takeaways

India shipped 152 million smartphones in 2025 on IDC's count, roughly flat year on year, so any device rule here lands on a market that is large but no longer growing.

Nothing in the package is enforceable today. Consultations are open and no standard has been notified, which means public comment still counts for something.

The removable pre-installed apps clause is worth defending on its own merits, separately from the surveillance-adjacent clauses it currently travels with.

Read the consultation notices when they appear and say something specific about the clause you object to, because a draft with no notified rule is the only stage at which any of this is still negotiable. Once 83 standards ship as one package, nobody gets to keep the two good ones and drop the rest.