India's DPDP Act: Protean Launches Consent Platform
India’s Digital Personal Data Protection (DPDP) Act enters enforcement in 2027. Discover why buying a consent manager like Protean’s new platform is critical for your product strategy.

Enterprise-grade tooling for India's new Digital Personal Data Protection (DPDP) Act is hitting the market, fundamentally standardizing how applications collect, store, and govern user data. For non-technical founders and SME owners building consumer-facing software this quarter, the landscape has entirely shifted. If your product roadmap includes user data collection, instruct your developers to buy an off-the-shelf DPDP compliance software rather than building one from scratch.
This shift was cemented in September 2026 at the Global Fintech Fest (GFF) in Mumbai, where Protean eGov Technologies officially launched its Enterprise DPDP Governance & Consent Platform. Launched at the Protean pavilion with an address by Shri Suvendu Pati, Chief General Manager at the Reserve Bank of India (RBI), the release of this centralized consent stack signals that India's privacy infrastructure has matured from regulatory theory into plug-and-play architecture.
Building consumer tech in India now requires strict adherence to this architecture. Here is what non-technical founders need to understand about the compliance clock, the tools hitting the market, and why writing custom code for privacy management is now a critical business risk.
The DPDP Compliance Clock: What Founders Need to Know in 2026
The enforcement timeline for data protection in India is no longer a moving target. India's DPDP Act was officially passed in August 2023 following years of legislative drafts stemming from the landmark Puttaswamy judgment. However, the substantive technical obligations for businesses remained largely dormant until the Ministry of Electronics and Information Technology (MeitY) officially notified the DPDP Rules on November 13, 2025.
According to compliance phase roadmaps published by Deloitte and KPMG, the notification of the rules triggered a strict 18-month operational countdown. The phased implementation works as follows:
- Phase 1 (Active): Immediate establishment of the Data Protection Board of India and operationalization of statutory definitions.
- Phase 2 (November 13, 2026): Registration and oversight officially open for "Consent Managers"—a newly regulated class of intermediaries.
- Phase 3 (May 13, 2027): Full operational compliance becomes mandatory. The grace period ends for itemized notices, verifiable consent architecture, 72-hour breach reporting, automated data erasure, and data principal rights management.
With maximum penalties for non-compliance reaching up to INR 250 crore (specifically for failing to take reasonable security safeguards to prevent a personal data breach), data protection compliance India is no longer a secondary feature ticket to be pushed to next quarter's Jira backlog. It requires foundational system architecture.
Enter Protean: Enterprise-Grade DPDP Compliance Software Hits the Market
Protean (formerly NSDL e-Governance Infrastructure) is not a standard SaaS startup. This is the institution that built India's Tax Information Network (TIN), manages the PAN card database, and serves as the central record-keeping agency for the National Pension System (NPS). When Protean launches an India DPDP consent manager, the market pays attention because they understand population-scale digital public infrastructure.
Their new Enterprise DPDP Governance & Consent Platform provides a template for how data collection will operate going forward. Instead of relying on fragmented privacy tools, the platform brings the statutory obligations of a Data Fiduciary into a single operating system, organized across distinct governance pillars:
- The Consent Stack: This embeds directly into an enterprise's web and mobile channels. Instead of users leaving a checkout or onboarding flow to manage permissions, the governance journey happens natively.
- The Immutable Consent Vault: When a user grants, updates, or withdraws consent, the policy engine propagates that request to mapped internal applications and third-party processors. Crucially, it writes an immutable artifact to a consent vault. If the Data Protection Board investigates a complaint, this vault produces regulator-ready evidence generated directly by the user's action, timestamped and securely hashed.
- Processor Risk Governance: The platform maintains a central processor registry, tracking third-party risk assessments to ensure that the vendors you share data with are also compliant.
This level of comprehensive infrastructure highlights exactly why internal engineering teams should not attempt to replicate these systems.
Build vs. Buy: The Engineering Trade-Offs for Privacy Tools
For a non-technical founder, the "build vs. buy" conversation with an engineering team can be difficult. Developers naturally want to write code. The internal pitch usually sounds like this: "It’s just a boolean flag in the database. True for opted-in, False for opted-out. We can build a consent manager in two weeks."
This is a fundamental misunderstanding of the DPDP Act.
Under the new 2025 Rules as analyzed by EY India, consent is not a binary state. It is purpose-linked, time-bound, verifiable, and freely revocable. If you choose to build a custom build vs buy privacy tool, you are signing up to build, maintain, and bear the legal liability for the following complexities:
- Itemized Multilingual Notices: DPDP mandates plain-language notices detailing exactly what data is collected and why. Because India is highly multilingual, compliance platforms offer dynamic, localized notices in up to 22 scheduled languages. Building this localization engine in-house is a massive undertaking.
- Granular Revocation Workflows: If a user revokes consent for promotional emails but maintains consent for billing, your custom database must untangle those data flows across your CRM, email provider, and analytics dashboards in real-time.
- Erasure Timelines (Rule 8): The rules enforce specific retention periods, demanding automated deletion across all your databases when the original purpose is served.
- Breach Reporting (Rule 7): In the event of a breach, organizations have a 72-hour detailed reporting window. Automated compliance software triages these alerts and formats the required reports for the Data Protection Board. Manual systems rely on panicked spreadsheet compilation.
Comparison: Building Custom vs. Buying Off-The-Shelf
| Feature / Requirement | Custom Built In-House | Off-The-Shelf DPDP Platform (e.g., Protean) |
|---|---|---|
| Time to Market | 3 to 6 months of dedicated engineering time. | Plug-and-play APIs, deployed in weeks. |
| Audit & Evidence | Tainted if DB admins have write-access. You must prove your own tool hasn't been altered. | Cryptographically hashed, immutable consent vaults trusted by regulators. |
| Vendor Integrations | Requires custom API wrappers for every third-party tool you use (CRM, analytics, hosting). | Native integration ecosystems. Propagates consent revocation automatically. |
| Regulatory Updates | Requires continuous code updates every time the Data Protection Board issues new guidance. | Managed by the vendor. The platform updates to reflect current laws. |
| Total Cost of Ownership | High. Consumes ongoing payroll, maintenance bandwidth, and hidden technical debt. | Predictable SaaS licensing fee. Frees up engineers to build core features. |
The "Consent Manager" Under DPDP: It’s Not Just a Tool, It’s a Regulated Entity
It is also critical to understand that the phrase "Consent Manager" has a specific legal definition under Section 6(9) of the DPDP Act. As Deloitte notes in its DPDP roadmap, a Consent Manager in India is not merely a software widget—it is a distinct, registered intermediary entity officially overseen by the Data Protection Board.
Similar to Account Aggregators in the Indian financial sector, Consent Managers provide an accessible, interoperable platform for Data Principals to manage their preferences across multiple Data Fiduciaries (businesses).
While you are not strictly mandated to use an official Consent Manager (you can still collect consent directly provided you meet all stringent notice requirements), plugging into a compliant, registered platform offloads an immense regulatory burden. Building an internal tool means you bear 100% of the compliance liability. Buying access to a standardized Protean DPDP platform aligns your product with the national ecosystem layer, creating immediate trust with your end-users.
Product Strategy in a Regulated Era (The Ganakys BOT Perspective)
At Ganakys, our mandate is to derisk software development for non-technical founders and domain experts. In a Build-Operate-Transfer engagement, our primary focus is on building the core intellectual property that differentiates your business in the market.
Regulatory compliance is mandatory, but it is not a competitive differentiator. Nobody buys your SaaS product or downloads your consumer app because your consent logs are well-structured; they buy it because your core features solve their problem. Allocating hundreds of expensive engineering hours to build custom DPDP compliance workflows is a misallocation of capital.
When we architect applications for our clients, our policy is strict: integrate enterprise-grade compliance suites from day one. During the "Build" phase, we wire the product into platforms like Protean or similar specialized compliance software. During the "Operate" phase, we run the real-time monitoring and reporting. By utilizing off-the-shelf software, we ensure that when we execute the "Transfer" phase to your in-house team, you aren't inheriting a fragile, custom-built compliance module that requires a dedicated legal engineering team to maintain.
If you are comparing engagement models with development partners, demand that they use established third-party privacy platforms. A software partner offering to build a consent management module from scratch is exposing you to regulatory fines in 2027. If you are ready to build your product securely, efficiently, and compliantly, request a BOT engagement to discuss how we architect enterprise-grade products for the Indian market.
Navigating DPDP Compliance Software (FAQ)
Is appointing a Consent Manager mandatory under the DPDP Act?
No. Utilizing a registered Consent Manager is optional for businesses. However, maintaining verifiable, purpose-linked consent architecture is absolutely mandatory. Off-the-shelf DPDP compliance software provides this architecture securely, whether or not the vendor acts as the official intermediary for the user.
When do the DPDP Rules 2025 become fully enforceable?
The phased implementation provides an 18-month window from the November 2025 notification. The hard deadline for full operational compliance—including data erasure, notice workflows, and breach reporting—is May 13, 2027. After this date, failure to comply can result in severe financial penalties.
Can I use a standard GDPR cookie banner to comply with Indian law?
No. The DPDP Act differs significantly from the European GDPR. It mandates verifiable consent for specific purposes, explicit rules for processing children's data (including verifiable parental consent without behavioral monitoring), and strict itemized notices tailored to the Indian context. A simple European cookie plugin will fail an Indian regulatory audit.
Does compliance software solve past data collection issues?
Compliance software governs data flowing forward and helps discover historical data silos, but it does not retroactively make illegally gathered data compliant. You will need to run a re-permissioning campaign through your new consent platform before the May 2027 deadline to ensure your existing database remains legally usable.