Thursday, September 3, 2026

India's Consent Manager Deadline Arrives With No Regulator To Register

You open a food delivery app you last used in 2019. It still holds your home address, your office address, a card you cancelled two years ago, and every order you placed during a lockdown you would rather not revisit. No button in that app takes any of it back.

India's Consent Manager Deadline Arrives With No Regulator To Register

TL;DR: From 13 November 2026, Indian users are supposed to manage every app consent from one interoperable dashboard run by a registered consent manager. The regulator that registers them, the Data Protection Board of India, still has no chairperson and no members. The right arrives; the plumbing does not.

Why It Matters

A consent manager is not another privacy policy. Under the Digital Personal Data Protection Rules notified in November 2025, it is a licensed intermediary sitting between you and every company that holds your data, and its duty runs to you rather than to them. Consent given through it can be reviewed and pulled back in one place, and the withdrawal is meant to travel to the company on its own. One screen instead of forty settings pages.

The conventional read is that India is copying Europe, late. That gets it backwards. GDPR handed Europeans a right to withdraw and left them to exercise it one company at a time, which is precisely why almost nobody does. India's version is the more ambitious of the two, because it puts a registered institution in the middle whose entire job is to make a withdrawal actually propagate. Ambitious is not the same as working.

And here is the part nobody planned around. A LiveLaw analysis published in August 2026 found that the Data Protection Board of India, the body that must register consent managers and hear complaints against companies, had no appointed chairperson and no appointed members roughly ten months after the rules took effect. Nominations went out. No seat was filled. The shape of this will be familiar to anyone who followed India's AI labelling rules at their six month mark, where the rule existed, the enforcement did not, and a High Court ended up doing the regulator's work for it.

Court-Set Decision Window

15 Days

ordered of an empty bench

Maximum Penalty

₹250 Crore

available on paper, unused

MeitY Nomination Calls

2 Rounds

May and June, both open

Board Seats Filled

0%

chairperson and members alike

Take that court-ordered decision window. A High Court bench in Madhya Pradesh sent a petitioner to file before the Board and told the Board to decide inside a fortnight, which reads as ordinary case management right up until you remember there is nobody at the other end to open the envelope. That is what a vacant regulator does to everything downstream of it. It does not collapse in public. It quietly converts a right into a queue.

"

Ten months of rules in force, and not one seat on the board that enforces them has been filled. That is not a delay any more. That is a decision.

The framework itself is not vague. It is unusually precise about what a consent manager has to be, which makes the missing registrar more conspicuous rather than less.

Category Detail What It Decides
Deadline Twelve months after the rules were notified Legacy consents must be revalidated by then
Entry Bar ₹2 crore minimum net worth, Indian incorporation Prices out the small privacy startups
Data Blindness Cannot read the personal data it routes A broker of permission, never of data
Retention Seven years of consent records held Your refusal outlives the app itself
Registrar Data Protection Board, zero members seated No desk accepts an application today
Breach Route Section 8(6) notifications land nowhere Reporting duty exists, recipient does not
Full Powers Adjudication expected around May 2027 Enforcement lands well after the deadline

Read down that middle column and the shape is obvious. Every line is a barrier to entry, and every barrier assumes a working gate behind it. What exists is a wall with no gate cut into it, and a date circled on a calendar.

12 months 6 months rules in force · board empty deadline passed · powers pending notification full powers

The eighteen month runway from notification to full enforcement powers, split at the point where the consent obligations bite.

Friction Points

The gap between the deadline and real enforcement is where the damage sits. From November, companies are supposed to have revalidated every legacy consent sitting in their databases. Nothing checks whether they did. Nothing, in the sense that no one holding statutory authority is currently in a position to look.

There is a second problem the industry does not much enjoy discussing. A consent manager is a new intermediary, and new intermediaries have to earn a living somewhere. The rules say it must be blind to the data it carries, which is the right instinct. But blindness is a technical property, not a revenue model, and India has watched the same gap open before: India's draft phone security standards ran into an industry with every reason to comply slowly and none to fund the work early.

Before you trust anything that calls itself a consent manager, check the following.

  • Registration is mandatory, and until the Board is seated, no operator in India holds it.
  • Withdrawal stops future processing. It does not erase an inference a company already drew from data it held lawfully.
  • Interoperability is a requirement on paper. Ask which fiduciaries a platform actually connects to today, by name.
  • The record of your refusal is kept about you too, long after you have stopped using the service.

Key takeaways

  • The duty of a consent manager runs to you, not to the company holding your data. That reversal is the entire design idea, and it is genuinely rare in Indian regulation.
  • Interoperability is what separates this from a cookie banner. One withdrawal is meant to reach every fiduciary you have linked, without you chasing any of them.
  • A dashboard is only as strong as the body that licenses it. Until seats are filled, the honest label for what exists is a well drafted intention.

Do not wait for the dashboard. Open the five apps you actually use, go into their existing privacy settings this week, and delete what you can while the deleting is still manual. The consent manager is a better answer than doing it by hand. It just is not an answer yet.