Now Reading
The DPDP Act, One Year On: How Compliance Is Actually Playing Out in Indian AdTech

The DPDP Act, One Year On: How Compliance Is Actually Playing Out in Indian AdTech

The Digital Personal Data Protection Rules have been on the books for close to a year. Enforcement hasn’t started, but the industry is already reorganising around it — unevenly, and with a lot more happening in slide decks than in ad servers.

Ask five people in Indian adtech where DPDP compliance actually stands right now, and there is a fair chance you get five different answers, each delivered with total confidence. A legal head will tell you the organisation is “enforcement-ready.” A media planner two floors down will tell you nothing about how programmatic buying actually runs has changed. A publisher’s ad ops lead will tell you they’re still waiting on their DSP partners to tell them what’s expected of them. All three can be true at once, and that contradiction is, in many ways, the most accurate one-line summary available of how the DPDP Act’s first year has actually played out inside the country’s advertising ecosystem.

The headline facts are not in dispute. The Digital Personal Data Protection Rules, 2025 were notified in mid-November 2025, converting a law that had sat dormant since its 2023 passage into an operational compliance regime with a defined runway. The implementation is phased across roughly eighteen months, with the Data Protection Board of India already constituted, a Consent Manager registration framework opening in mid-November 2026, and full simultaneous enforcement landing by mid-May 2027, with penalties running as high as ₹250 crore per violation and no grace period once that date arrives. On paper, the industry has known exactly what is coming and exactly when, for the better part of a year now. What the last several months have revealed is that knowing the dates and actually restructuring a data supply chain built for a decade of frictionless third-party targeting are two very different exercises — and Indian adtech, broadly, has done a great deal more of the former than the latter.

Where the Real Work Has Actually Started

To be fair to the industry, it is not standing still. The organisations moving fastest are, unsurprisingly, the ones with the most first-party data and the most to lose. Large advertisers with direct, high-frequency customer relationships — FMCG majors, BFSI players, e-commerce platforms — have generally been ahead of their agencies and vendor ecosystems, not behind them, because their existing customer data operations gave them a natural head start on the kind of granular data mapping DPDP now formally requires. Dabur’s media leadership has spoken publicly about commissioning a full audit of its data practices early, mapping every collection touchpoint and assessing consent validity across the business — the kind of exercise that takes multiple quarters, not a single compliance sprint, and one most mid-sized advertisers have not yet begun.

That asymmetry is the first real story of DPDP’s first year: it is quietly reshuffling who has structural advantage inside Indian marketing, and the reshuffle runs almost exactly along the first-party versus third-party data line that industry analysts flagged early. Brands and platforms sitting on deep, consent-linked purchase histories are simply better positioned to keep operating normally through the transition. Adtech intermediaries whose entire business model depends on aggregating and activating third-party signal — the exchanges, the data management platforms, the identity resolution vendors sitting between publishers and demand — are the ones facing the sharpest structural disruption, because their inventory of usable signal is the thing DPDP’s consent architecture is specifically designed to constrain.

The Consent Manager Problem Nobody Can Fully Solve Yet

If there is one piece of the DPDP architecture that captures the gap between regulatory intent and operational readiness, it’s the Consent Manager framework. Registration opens in mid-November 2026 — a deadline the entire compliance industry has spent the past several months treating as the year’s central milestone, with countless gap-assessment offers and readiness checklists built around it. The mechanic itself is straightforward in principle: a registered, neutral intermediary sitting between individuals and the many businesses processing their data, letting a person manage, review or withdraw consent across services through one interoperable layer, rather than negotiating separately with every fiduciary that touches their information.

Knowing the dates and actually restructuring a data supply chain built for a decade of frictionless third-party targeting are two very different exercises.

The complication, which several legal analysts have been candid about in recent months, is that the regulator meant to operationalise this framework has itself been in a state of partial readiness. The Data Protection Board came into formal existence alongside the Rules, but the specific technical standards, and the appointment of the Board’s full leadership needed to actually process and approve Consent Manager registrations, have lagged behind the statutory deadline sitting on the calendar. That leaves adtech businesses in an unusual position: legally obligated to be integration-ready for a framework whose regulator has not yet finished specifying exactly what that integration should look like. The practical response from most serious compliance teams has been to build toward the framework’s publicly known architecture anyway — consent captured and enforced at the authorisation layer in real time rather than in batch, since batch-synchronised consent systems create a direct compliance gap against DPDP’s withdrawal standard — on the reasonable bet that waiting for perfect regulatory clarity before building anything guarantees falling behind the timeline regardless.

Where Compliance Is Still Mostly a Slide Deck

Step outside the compliance and legal function, into the parts of adtech that actually move media day to day, and the picture gets noticeably less advanced. Programmatic buying in India still runs substantially through global demand-side and supply-side platforms whose consent architecture, cookie deprecation posture, and data-sharing defaults are set at a level far removed from the India-based teams actually transacting on those platforms daily. A media planner can commission a DPDP gap assessment for their own organisation’s owned data, and many now have, but they have comparatively little practical leverage over whether the programmatic auction their brand is buying into tomorrow morning is running on inventory backed by DPDP-compliant consent capture at the publisher level, several layers upstream.

This is the gap industry commentary has started calling the era of “privacy-by-slide-deck” coming to an end — the recognition that a compliance narrative built for board presentations and client pitches has, in a great many organisations, run well ahead of the actual product, media activation, measurement and vendor-contract changes DPDP requires. For an industry whose competitive edge has been built on scale, speed and granular signal, that’s not a comfortable adjustment to make quickly, and the honest read of the last several months is that most of the ecosystem has treated 2026 the way it was explicitly designed to be treated — a build year rather than an enforcement year — and has built at roughly the pace that framing implies: real progress in pockets, considerable distance still to cover everywhere else.

The Publisher Side of the Equation

Publishers occupy a particularly uncomfortable middle position in all of this. They sit closest to the actual point of consent — the reader landing on a page, the app user opening a screen — which means the operational burden of capturing and honouring valid consent falls on them first, even as the demand-side platforms and data brokers further downstream in the value chain are the ones actually monetising the resulting signal most aggressively. Many mid-sized Indian publishers, running lean ad ops teams without dedicated legal or compliance functions, are effectively waiting for their programmatic partners and consent management platform vendors to hand them a plug-and-play solution rather than building bespoke consent infrastructure themselves — a rational response to limited resources, but one that leaves their compliance posture almost entirely dependent on vendors whose own readiness varies considerably.

That dependency chain — publisher relying on CMP vendor, CMP vendor building toward a Consent Manager framework the regulator hasn’t fully specified, demand-side platform waiting on both — is where a great deal of the industry’s actual first-year progress has quietly stalled, not from lack of intent but from the ordinary friction of a multi-party ecosystem trying to move in sync toward a standard that itself is still being finalised in real time.

What the Next Year Actually Requires

The honest assessment, one year into a law that will not fully bite for another nine months, is that Indian adtech’s DPDP story so far is a story of triage rather than transformation. The organisations with the most exposure and the most first-party data have moved first and moved furthest, because they had both the incentive and the existing data infrastructure to do so. Everyone downstream of them — the mid-tier agencies, the smaller publishers, the third-party data vendors whose entire commercial model DPDP is most directly reshaping — is largely still waiting: for the Consent Manager framework to be technically finalised, for their platform partners to ship compliant tooling, for a genuinely persuasive commercial reason to prioritise this over the next quarter’s revenue targets.

That waiting posture has a shelf life, and it is shorter than it currently feels. November 2026’s Consent Manager registration deadline is a real statutory date regardless of how ready the surrounding ecosystem is, and May 2027’s full enforcement deadline arrives with no grace period built in, which means the organisations still in “we’ll get to it” mode as 2026 closes are choosing, whether they frame it this way or not, to build under pressure rather than with runway. The lesson of the Act’s first year isn’t that Indian adtech has failed to take DPDP seriously. It’s that taking a regulation seriously in principle and rebuilding a decade of third-party-data-dependent infrastructure in practice are running on very different clocks — and the gap between those two clocks is exactly what the next nine months are going to force the entire ecosystem to close, publicly and possibly expensively, whether it’s ready or not.

• • •

© 2026 Hemito Media Pvt Ltd
All Rights Reserved

Scroll To Top