Skip to content

DPDP Act · Statute mapping

What the Rules require, what we record, and what you can produce.

Consentry mapped to India's DPDP Act and the 2025 Rules. Not legal advice, but the boardroom scan of dates, duties, and the decision record you keep against each one.

Last verified 16 July 2026

Regulatory content is informational, not legal advice. Verify against the gazette before relying on any date or citation.

Phase table

Gazetted dates from the DPDP Rules.

Treat only what appears in the gazette as enacted.

DPDP Rules phase dates
PhaseDateWhat takes effect
113 Nov 2025DPDP Rules notified (G.S.R. 846(E)). Data Protection Board of India established (ss. 18–26). Section 2 definitions operative. Rules 1, 2, 17–21.
213 Nov 2026Rule 4: Consent Manager registration and oversight. Penalties and appeals.
313 May 2027Rules 3, 5–16, 22, 23: core operational obligations.

Proposed, not gazetted

MeitY proposed in January 2026 compressing the compliance window from 18 to 12 months, which would move the core deadline from 13 May 2027 to 13 Nov 2026. As of this page that compression appears proposed, not gazetted. Sources into mid-2026 still cite May 2027. Do not treat a compressed date as enacted.

Statute mapping

Law requires → Consentry records → what you produce.

Rule 3

Rule 3: standalone consent notices

Law requires

Consent notices must be standalone, plain-language, and purpose-specific.

Consentry records

Purpose, decision state, notice facts that matter to proof, and which systems later enforce that decision.

✓ Evidence

Decision record tied to notice version, not a banner tick screenshot.

Rule 6 / 8

Rule 6 / Rule 8: retention of processing logs

Law requires

Minimum one-year retention of processing logs (longer for Third Schedule entities).

Consentry records

Decision records retained for seven years, a product choice above the floor, because proof that expires is not proof.

✓ Evidence

Ledger artifact: what was permitted, for what purpose, when, and which systems obeyed it.

90-day clock

The 90-day rights-request clock

Law requires

Data principals can demand answers about how their personal data is used within the statutory clock.

Consentry records

The decision that governed a use and which systems enforced it: the same record that runs production checks.

✓ Evidence

Retrievable decision id, purpose, timestamp, systems affected, and audit export.

Erasure

Erasure on withdrawal

Law requires

When consent is withdrawn and the purpose is served, personal data governed by that decision is erased on the schedule the Act requires.

Consentry records

Withdrawal state, enforcement fan-out, and the surviving decision record without retaining the governed personal data.

✓ Evidence

Decision record survives; the data it permitted does not.

Consent Managers

Consentry and Consent Managers

Law requires

A Consent Manager is a regulated intermediary for the data principal and cannot also act as Data Fiduciary or Processor for the same person.

Consentry records

Consentry is not a registered Consent Manager, by design. It sits on the Data Fiduciary side and interoperates with registered managers.

✓ Evidence

Published fiduciary-side boundary; Consent Manager registration opens 13 November 2026.

Cross-border

Cross-border transfers

Law requires

Negative-list model: personal data may be transferred abroad unless the Central Government restricts the destination.

Consentry records

Single India region residency posture as a product choice, not a statutory checkbox.

✓ Evidence

Security and DPDPA pages state residency factually without inventing a localisation duty.

Honest boundaries

What we don't do

  • We are not a registered Consent Manager.
  • We do not sell or share customer decision records for advertising.
  • We do not train models on customer data.
  • We do not claim SOC 2 certification today.
  • We do not invent compliance dates. If a proposal is not gazetted, we say so.

Load-bearing facts

Dates and duties you should recite without opening the gazette.

  1. 01

    Standalone, plain-language consent notices stating the specific purpose (Rule 3)

  2. 02

    Minimum 1-year retention of processing logs; 3 years for Third Schedule entities

  3. 03

    90-day maximum for data-principal rights requests

  4. 04

    Cross-border: negative-list model. Transfer permitted unless the country is restricted

  5. 05

    Penalties up to ₹250 crore; Board is fully digital; appeals to TDSAT

  6. 06

    Consent Manager: India-incorporated company, ≥ ₹2 crore net worth, 7-year consent record retention, cannot be fiduciary/processor for the same principal

Frequently asked questions

Answers about Consentry and the DPDP Rules

Direct answers to the questions compliance and engineering teams ask before evaluating consent infrastructure.

What is Consentry?
Consentry is a consent decision and enforcement layer for Data Fiduciaries operating under India's DPDP Act. It carries a person's consent decision across named systems and retains an auditable record of what was permitted, when, and why.
Is Consentry a registered Consent Manager?
No. Consentry is not a registered Consent Manager. It operates on the Data Fiduciary side and is designed to interoperate with registered Consent Managers rather than compete with them.
When do the DPDP Rules phases take effect?
The DPDP Rules were notified on 13 November 2025. Consent Manager registration and oversight take effect on 13 November 2026. The core operational obligations in Rules 3, 5–16, 22, and 23 take effect on 13 May 2027.
How long does Consentry retain decision records?
Consentry retains consent decision records for seven years. Each record captures what was permitted, for which purpose, when the decision applied, and which systems obeyed it.
Does Consentry retain personal data for seven years?
No. The seven-year period applies to the consent decision record, not the personal data governed by that decision. When consent is withdrawn and the purpose is served, the governed personal data is erased on the schedule required by the Act.
Where is Consentry customer data stored?
Consentry keeps customer data in a single India region and does not replicate it outside India. This is a product choice; the DPDP Rules use a negative-list model for cross-border transfers rather than requiring India-only storage by default.
Who is Consentry built for?
Consentry is built for compliance, DPO, platform, and privacy engineering teams that need to enforce consent decisions across analytics, processors, personalization, warehouses, and customer data platforms.

Guides

Dated explainers on the same calendar

Short notes on Consent Manager registration, phase dates, and Rule 3 notices, written to be cited, not marketed.

Map notices, retention, and rights to a record

Early access for teams mapping notices, retention, and rights work to a decision record under the DPDP Rules.