Data protection

DPDP Rules phase 2: what to fix in your contracts before November 2026

Aakash ChaudharyLast updated 22 September 20266 min read

The Consent Manager framework under Rule 4 of the Digital Personal Data Protection Rules, 2025 comes into force in November 2026, and the substantive obligations on notice, consent, security safeguards, breach intimation and data principal rights follow in May 2027. In-house legal teams should use the gap to fix six things in their contract estate, starting with knowing which contracts involve personal data at all.

Why November 2026 matters even if you never register as a Consent Manager

When the Digital Personal Data Protection Rules, 2025 were notified in November 2025, most companies read the eighteen-month runway as breathing room. The first milestone after notification lands in November 2026, when the Consent Manager framework under Rule 4 comes into force. The substantive obligations — notice, consent, security safeguards, breach intimation and data principal rights — follow in May 2027.

Consent Managers are a platform question, and most companies will not register as one. But the November date is a useful forcing function for a quieter, less glamorous task that sits squarely with in-house legal: the contract estate. Every obligation that arrives in May 2027 will be tested against agreements negotiated years ago, for a law that did not yet exist. Six months is not a lot of time to renegotiate hundreds of vendor, processor and partner contracts.

1. Find every contract where someone else touches your personal data

Section 8(2) of the DPDP Act allows a Data Fiduciary to engage a Data Processor only under a valid contract, and the Data Fiduciary stays responsible for what the processor does. The first job is simply knowing which contracts those are: payroll and HR platforms, cloud and SaaS providers, collection agencies, call centres, marketing agencies, background verification vendors, logistics partners holding customer addresses.

In most companies this list does not exist in one place. It lives in procurement files, business-unit shared drives and email. Build it before anything else, and tag each agreement with the categories of personal data involved. You cannot prioritise what you cannot see.

2. Rewrite processor clauses around the Rules, not generic data-protection language

Many existing agreements carry a boilerplate "comply with applicable data protection laws" clause. That is not enough when the fiduciary carries the liability. Processor terms should at least:

  • restrict processing to your documented purpose and instructions;
  • require reasonable security safeguards equivalent to your own, including access controls, encryption or masking where appropriate, and logging;
  • require processing logs to be retained, since the Rules expect logs to be kept for at least one year;
  • oblige the processor to delete data when the purpose ends or the contract terminates, and to certify deletion;
  • flow the same obligations down to sub-processors, with your right to know who they are.

3. Align breach clauses with the 72-hour window

Rule 7 requires a Data Fiduciary to intimate the Data Protection Board without delay on becoming aware of a personal data breach, and to follow up within seventy-two hours with detailed information on the facts, the mitigation, the cause and the remedial steps, as well as intimating affected individuals. A vendor contract that allows "notification within a reasonable time" — or even "within 72 hours" — leaves you with no time to investigate before your own clock runs out.

Push processor notification to a much shorter window, specify what the first notice must contain, and require continuing cooperation: logs, forensic reports and a named contact. Check that indemnities and liability caps reflect the scale of penalties the Act allows, which run into hundreds of crores for security and breach-notification failures.

4. Treat consent records as contract evidence

Where consent is your legal basis, the obligation to show it sits with you. If a partner, aggregator or agency collects personal data on your behalf, the contract should specify the notice they must give, how consent is captured, how withdrawal is handled and how quickly records are passed back to you. When Consent Managers become operational, agreements with them will need the same discipline.

5. Build retention and erasure into the contract lifecycle

The Rules tie retention to purpose and, for certain large platforms, prescribe erasure after inactivity with at least 48 hours' notice to the individual. For most in-house teams the practical point is simpler: termination and expiry clauses must say what happens to personal data, and someone must actually act on them. That means tracking contract end dates, renewals and post-termination obligations as live tasks, not clauses buried in a PDF.

6. Re-run vendor due diligence with DPDP questions

Existing onboarding questionnaires were usually written for information security or anti-bribery. Add DPDP-specific questions: where data is stored and processed, sub-processor lists, breach history, logging and retention practices, and whether the vendor has mapped its own obligations under the Rules. Record the answers against the vendor and the contract, so they can be revisited at renewal.

Make it a register, not a one-time project

The companies that come through May 2027 comfortably will be the ones that treat DPDP as an ongoing register of obligations: which contracts carry which duties, who owns them, when they fall due and what evidence shows they were met. That register is equally useful for the next amendment, the next sector regulator circular and the next audit.

November 2026 is a good date to have the inventory done. May 2027 is when someone will ask to see it.

On dates: the Press Information Bureau states the Rules were notified on 14 November 2025, while law-firm analyses based on the Gazette give 13 November 2025 — which would put phase 2 on 13 November 2026. This article says "November 2026" throughout. Confirm against the Gazette if you need a specific day.

Aakash Chaudhary is the founder and CEO of IntelloSync, which builds contract, compliance and vendor management software for enterprises in India. The views expressed are his own.

FAQ

Frequently asked questions

When do the DPDP Rules actually take effect?

The Digital Personal Data Protection Rules, 2025 were notified in November 2025 with phased commencement. The Consent Manager framework under Rule 4 comes into force in November 2026, and the principal substantive provisions — notice, consent, security safeguards, breach intimation and data principal rights — follow in May 2027.

What must a contract with a Data Processor contain under the DPDP Act?

Section 8(2) permits engaging a processor only under a valid contract, and the Data Fiduciary remains responsible for the processor's acts. In practice the contract should restrict processing to documented instructions, require equivalent security safeguards and logging, require deletion and certification at the end of purpose, and flow the same obligations down to sub-processors.

How quickly must a personal data breach be reported under the DPDP Rules?

Rule 7 requires intimation to the Data Protection Board without delay on becoming aware of a breach, followed within 72 hours by detailed information covering the facts, mitigation, cause and remedial steps, along with intimation to affected data principals. Vendor notification windows must be materially shorter so there is time to investigate.

Do existing vendor contracts need to be renegotiated for DPDP compliance?

Usually yes, where they carry only generic "applicable data protection laws" wording. Those clauses do not give the fiduciary the instruction control, security standards, log retention, deletion certification, sub-processor visibility or breach timelines the Rules assume, and the liability sits with the fiduciary regardless.

How long must processing logs be retained under the DPDP Rules?

The Rules expect logs to be retained for at least one year. Because processing frequently happens on a vendor's systems rather than your own, the retention period should be written into the processor contract along with a right of access to those logs during a breach investigation.

What is a Consent Manager under the DPDP Rules?

A Consent Manager is a registered platform through which a data principal can give, manage, review and withdraw consent. The framework under Rule 4 commences in November 2026. Most companies will not register as one, but agreements with a Consent Manager need the same evidentiary discipline as any other party handling consent records.

See your contracts run themselves.

A 30-minute walkthrough with our team, on your use cases — then a 30-day free trial on every product.