All articles
Regulatory Update 7 min read 20 September 2026 Primitra

The DPDP Act's Quiet Deadline: What Changes on 14 November 2026 for Indian SMEs

14 November 2026 marks one year since the DPDP Rules were notified, and it is when the Data Protection Board is expected to shift from awareness-building to active supervision. Here is what actually changes, what doesn't, and how Indian SMEs should use the eight weeks that are left.

There is a date that keeps getting misread in compliance discussions right now: 14 November 2026. Ask around and you will hear two versions. One says everything under the DPDP Act 2026 becomes enforceable that day. The other says nothing happens until May 2027, so there is no rush. Both are wrong, and for Indian SMEs the gap between them is where the risk sits.

The Digital Personal Data Protection Rules were notified in November 2025. That started an 18-month clock. November 2026 is the one-year mark, and it is not a soft, symbolic date. It is the point at which the Data Protection Board of India (DPBI) is widely expected to move out of its awareness-building posture and into active supervision. With roughly eight weeks left until then, it is worth being precise about what the day actually brings.

What actually changes in November 2026

Two concrete things happen around 13-14 November 2026, and they are narrower than the panic suggests.

First, the Consent Manager registration framework goes live. From 13 November 2026, an entity that wants to operate as a Consent Manager can register with the Board, and any entity operating as one without registration is in breach of Section 6(9). That penalty sits in the residual tier of the Act's Schedule, up to ₹50 crore per instance. For most SMEs this is a non-event, because you are a Data Fiduciary collecting consent, not a Consent Manager building a platform to broker it. The distinction matters and gets blurred constantly.

Second, and this is the part that affects almost everyone, the DPBI is expected to stop being purely a guidance body. The first phase after notification has effectively been a grace window: the Board being constituted, MeitY inviting applications for the Chairperson and four Members earlier in 2026, companies being told to prepare. That posture is expected to harden into supervision once the year is up. A regulator that can hold inquiries and impose penalties behaves differently from one that is still publishing FAQs.

What does not change until May 2027

Here is the part the "nothing happens yet" camp gets partly right. The bulk of the substantive obligations, the notice requirements under Rule 3, the mechanics of consent, data-principal rights handling, breach notification, and the extra duties placed on Significant Data Fiduciaries, are set to take full effect around 13 May 2027. So if you are reading November 2026 as the day your privacy notice must be perfect, that is a misread.

The trap is treating May 2027 as the start line rather than the finish line. The obligations that land in May are not switches you flip in a weekend. A consent flow that captures purpose properly, a working process to answer a data-principal request within a sensible window, a retention policy that actually deletes data instead of hoarding it, all of these take months of quiet work across product, legal, and engineering. Firms that wait for the deadline to become real will be building their compliance program in the same weeks the Board starts asking questions.

Why the global signal matters here

If you think a regulator only acts after a headline breach, look at what happened in France this month. On 9 September 2026 the CNIL fined the consultancy EXTIA €300,000, not for a leak, but for failing to respect individual rights, the process obligations around how people's data requests are handled. Days earlier it fined a private hospital €500,000 over a health-data breach. The pattern across GDPR enforcement, which has now crossed €7.1 billion in cumulative fines, is that authorities go after weak process as readily as they go after incidents.

The DPDP Act is built on the same logic. Section-level penalties run up to ₹250 crore per instance for serious failures, with a separate tier up to ₹200 crore for failing to notify a breach. The Board does not need you to have lost data to open an inquiry. A complaint that your consent was never valid, or that you ignored a correction request, is enough.

What to do with the eight weeks that are left

The useful way to treat November 2026 is as a readiness checkpoint, not a deadline. A short, honest list:

Map what you hold. Most SMEs cannot answer "what personal data do we have, where, and why" in a single sitting. That inventory is the foundation for everything the Act asks and the thing that takes longest.

Sort out consent going forward. You do not need a registered Consent Manager. You do need consent that is specific, purpose-linked, and withdrawable, captured in a way you can produce later. Fixing new collection now is cheaper than re-papering old data in 2027.

Stand up a request process, even a manual one. Decide today who receives a data-principal request, who answers it, and in how many days. A named owner and a logged workflow beats a policy nobody has run.

Check whether you are a Significant Data Fiduciary. If your data volumes or sensitivity are high, the extra duties are not optional, and you want to know before the Board tells you. Our note on how to self-assess SDF status walks through the signals.

Read the fine print on breach timing. The expectation is notification within 72 hours. That is an operational muscle, not a document, and it only works if you have rehearsed it.

None of this requires waiting for the Board to be fully seated. If you want a structured starting point, our DPDP compliance checklist covers the sequence in order, and you can talk to us if you would rather have a second pair of eyes on where your gaps actually are.

November 2026 will not fine you. It changes who is watching. The companies that treat the next eight weeks as build time, rather than the start of a countdown to May, are the ones that will not be improvising when the Board's first inquiries land.

This article is general guidance for Indian businesses, not legal advice. DPDP compliance depends on your specific data practices, so for a plan tailored to your situation, start with our free checklist or get in touch.

Get help implementing this

Turn this reading into a compliance plan.

Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.

Book a free 30-minute consultation