The 13 November DPDP Consent Manager Deadline Is Not Your Deadline
Rule 4 of the DPDP Rules starts on 13 November 2026, but it regulates who may register as a consent manager. Your own obligations begin on 13 May 2027.
Tag
Rule 4 of the DPDP Rules starts on 13 November 2026, but it regulates who may register as a consent manager. Your own obligations begin on 13 May 2027.
Two regulatory deadlines are converging on Indian fintech engineering teams this quarter. Neither is a UI change. Both attack the same assumption: that a UPI ID can be parsed back into a customer's identity.
Most DPDP guides are written for DPOs, not engineers. Here are the six technical obligations the DPDP Rules 2025 create — what each one requires from your backend, which phase it activates in, and where to start.
The DPDP Rules were notified in November 2025 and most Indian SaaS teams are treating May 2027 as comfortable. It isn't. Here is what the Rules actually require you to build, in priority order.
The DPDP Act has three engineering implications: a consent layer, a deletion pipeline, and breach notification. Most teams build all three before checking which exemptions already apply to their use case.
The DPDP Rules 2025 went live in November. Full compliance is due May 2027. Here's what Indian SaaS teams need to build — consent records, erasure workflows, breach pipelines, and Consent Manager integration.
Most DPDP guidance is written for compliance officers. This is the engineering version: schema migrations, consent state machines, retention jobs, and audit patterns for a defensible Indian SaaS codebase.
Most DPDP coverage is written for legal teams. This piece maps the Act's obligations to concrete engineering work: consent tables, data rights endpoints, deletion flows, and breach notification infrastructure.
DPDP Rules 2025 are in force. Most guides target compliance officers. This one targets the engineer assigned the ticket: four code changes that cover every engineering obligation in the Act.
The DPDP Rules 2025 specify six engineering obligations for Indian SaaS products. Here is what consent, erasure, security safeguards, and the rights API look like in code, with a priority order for compliance.
Most compliance teams file their eSign vendor assessment and move on. SOC 2 auditors who understand signing stacks don't. Five control areas they specifically test, with the evidence needed for each.
Practical guides, product updates, and compliance notes — straight to your inbox. No fluff.
Newsletter is opening soon. We'll switch this on once we've got our first issue ready.