Latest
Webinar: Release days shouldn't be stressful — solving the blast-radius problem Register Now →·
Webinar: Release days shouldn't be stressful — solving the blast-radius problem Register Now →·
Webinar: Release days shouldn't be stressful — solving the blast-radius problem Register Now →·
Webinar: Release days shouldn't be stressful — solving the blast-radius problem Register Now →·
Secure & Comply

November 14 Is the Consent Manager Deadline. Are You Ready?

Close to 70% of Indian professionals surveyed are not very familiar with the DPDP Act and its Rules, according to EY's 2025 readiness survey. Even if the deadline moves, the gap won't close itself. Fines can reach ₹250 crore per violation, and unmapped, unprotected personal data without a consent trail is exactly what puts you at risk.

The Reality

Can You Prove How You Handle Personal Data?

Most organizations can't locate their personal data, let alone prove how it's handled. The Consent Manager deadline doesn't move.

Personal data is unmapped

Scattered across systems with no single record of where it lives.

Consent can't be proven

Collected but not tracked, so it can't be produced on request.

Data principal rights run on email

Access, correction and deletion requests are handled manually.

Sensitive data sits unprotected

No vaulting or tokenization means one breach exposes raw PII everywhere.

The deadline is fixed

Consent Manager compliance is due on November 14, 2026.

The penalty is not theoretical

Up to ₹250 crore per violation under Section 33.

Key Benefits

Privacy Architecture Is Now an Operating Requirement, Not Only a Legal One

Rule 3

Consent Made Provable

Consent needs to be specific, informed, purpose-based, withdrawable and traceable. Build a clear record of what was consented to, when, and how it was withdrawn.

Rule 6

Data Protection Made Operational

Put strong controls around personal data with encryption, tokenization, access controls and auditability across the systems that handle it.

Rule 14

Data Principal Rights, Built Into Workflows

Make access, correction, deletion and grievance handling defined processes, not requests managed through scattered emails and spreadsheets.

Rule 7

Breach Response Before the Breach

Have the processes, ownership and evidence ready to respond within the required timelines when a breach occurs.

The Numbers You Need to Know
₹250 CrMaximum penalty per violation under Section 33
72 hrsBreach response window once an incident is discovered
~70%Of surveyed Indian professionals not very familiar with the DPDP Act and Rules (EY, 2025)
How It Works

A Phased Path From Gap Analysis to Managed Operations

An ideal phased rollout for an estate of 50+ applications, scoped up or down based on your actual footprint.

  1. 1

    Assess (Weeks 1–6)

    DPDP Gap Analysis, PII Discovery & Data Mapping, and a consent and breach readiness review.

  2. 2

    Build (Weeks 6–20)

    Vault and tokenization rollout, consent enforcement integration, data migration and backfill.

  3. 3

    Govern (Weeks 20–24)

    PBAC tuning, Data Principal rights workflows in production, and audit evidence in place.

  4. 4

    Operate (Ongoing)

    Managed services on the privacy stack, quarterly business reviews, and continuous control improvement.

Technology Stack

The Stack Behind the Rollout

GoTrust: Consent & Privacy Operations

The DPO Co-Pilot is the control plane: cookie consent, consent and preference management, DSAR/DSR workflows, breach management, RoPA registry, DPIA/TIA/LIA automation and vendor risk, each mapped to a DPDPA section and rule. ISO 27001:2022, ISO 20000-1:2018 and ISO 9001:2015 certified; incubated by DSCI, a Nasscom initiative.

Learn more about GoTrust

Skyflow: Data Privacy Vault

Personal data is isolated in a purpose-built vault using polymorphic tokenization and encryption. A leaked or stolen token is worthless without the vault, while search, joins and analytics keep working on the tokenized data, so nothing downstream has to be rebuilt around encrypted blobs.

Learn more about Skyflow

AWS: The Infrastructure Layer

KMS-backed key management, Security Hub and GuardDuty for continuous posture monitoring, and the landing zone the vault and consent layers run inside, delivered under Flentas's AWS Advanced Consulting Partner and Managed Service Provider status.

Learn more about Flentas and AWS
Case Studies

Where DPDP Compliance Makes a Difference

View all client success stories

BFSI / NBFC / Lending

Core banking and lending platforms holding KYC, financial, and credit data across dozens of systems. Consent Manager integration and vaulting before the Nov 14, 2026 deadline.

Program Delivery
24 wksAssess → Build → Govern, Phased Rollout

A phased engagement model takes an estate from DPDP gap analysis through vault and tokenization rollout to production-ready Data Principal rights workflows in roughly 24 weeks, scoped to your actual application footprint.

Healthcare & Insurance

Sensitive health and policy data spread across claims, underwriting, and provider systems. Tokenization and access governance built for Section 8 fiduciary duties.

E-Commerce & Consumer Platforms

High-volume consumer PII across checkout, support, and marketing stacks. Consent artifacts and rights fulfillment built to handle scale.

Platform Delivery
50+Applications, Ideal Phased-Rollout Scope

The phased model is built for an estate of 50+ applications, integrating a governed data vault and a MeitY/NeGD-aligned consent management platform rather than building either from scratch.

SaaS & Enterprise Platforms With Children's Data or Cross-Border Transfers

Section 9 and Section 16 obligations for platforms serving minors or moving data across borders. Vault residency and consent enforcement mapped to the rule.

Risk Reduction
₹250 CrMaximum Penalty Exposure Addressed

Tokenization shrinks the breach blast radius, documented control evidence reduces audit findings, and automated Data Principal rights fulfillment replaces a manual queue.

We knew the Consent Manager deadline was coming, but nobody could tell us where our personal data actually lived across forty-plus systems. Flentas ran the gap analysis and PII discovery in six weeks and came back with an exposure heatmap and a phased roadmap our board could actually approve. We're not guessing anymore.

Chief Privacy OfficerLeading Indian NBFC

What's Next

Where This Fits in Your Journey

One engagement is one stage. Here is what usually comes before and after, so the next step is always clear.

You are here

DPDP

Consent, data protection and Data Principal rights ahead of the deadline.

Get Started

The Gap Analysis Is the Fastest Way to Know Where You Actually Stand

With the Consent Manager deadline landing in a matter of months, the organizations in the best position are the ones who already have a baseline. Book a DPDP gap analysis and get a compliance heatmap, a gap register, and a phased roadmap.

  • AWS Advanced Consulting Partner
  • AWS Managed Service Provider
  • 96.5% Client Retention