Is 13 November 2026 a DPDP Deadline for Your Business? What Actually Changes for SMB Chatbots
On 13 November 2026 the DPDP Rules on Consent Managers take effect. For most small businesses that is not the deadline it sounds like. Here is what actually changes, and what your WhatsApp bot or website chatbot needs before May 2027.
For most small businesses, 13 November 2026 is not a DPDP deadline. That date brings in Rule 4, which sets up Consent Managers, a regulated role for a few specialist platforms. The duties on an ordinary business, including notice, consent, security, breach reporting, and data rights, start on 13 May 2027. That is the real deadline for SMB chatbots.
- Most SMBs will never register as a Consent Manager, and there is no blanket duty to use one.
- A customer's phone number is personal data the moment they message your WhatsApp number.
- Penalties run up to 250 crore rupees per instance, a ceiling rather than a typical fine.
- Map every system a conversation touches, then shorten retention and make deletion reach every copy.
- This is an operational reading of the timeline, not legal advice.
Summary written with AI from this post.
Short answer: For most small businesses, no. 13 November 2026 is when Rule 4 of the DPDP Rules takes effect, which sets up the registration and functioning of Consent Managers, the platforms people will be able to use to give and withdraw consent across many businesses. The obligations that land on an ordinary business, including notices, consent, security safeguards, breach reporting, and responding to people’s rights, start on 13 May 2027. That is the real deadline for an SMB running a WhatsApp bot or a website chatbot, and it is closer than it looks.
What happens on 13 November 2026 under the DPDP Rules?
Rule 4, covering Consent Managers, comes into force. The DPDP Rules were notified on 13 November 2025 in three phases: the Data Protection Board and institutional framework first, the Consent Manager framework one year later, and the substantive compliance obligations on 13 May 2027 (Mondaq). November is phase two, and its subject is the Consent Manager system itself.
What is a Consent Manager?
A Consent Manager is a company registered with the Data Protection Board that gives a person one place to give, review, and withdraw consent across the many organisations they deal with, instead of managing it separately on every app and form (Mondaq). Being one is a regulated business in its own right, a role for a few specialist platforms rather than a duty for everyone.
Does my small business have to register or connect to a Consent Manager?
Almost certainly not register, and probably not connect yet. Most businesses will never become Consent Managers, and there is no blanket requirement for every business to use one; what each organisation has to judge is whether its consent systems will need to interact with that ecosystem (Mondaq). Larger consumer businesses may need to accept consent signals from Consent Managers, so if you sell through a big platform or partner, expect their requirements to reach you. For a typical SMB, 13 November is a date to note, not a deadline to panic over.
Then what is the deadline that matters for SMBs?
13 May 2027. From that date the core duties apply: clear notice of what personal data you collect and why, valid consent where consent is your basis, reasonable security safeguards, reporting personal data breaches, handling children’s data carefully, and honouring people’s rights to access, correct, and erase their data (Mondaq). Penalties under the Act run up to 250 crore rupees per instance, which is a ceiling rather than a typical fine, but it explains why larger partners will start asking you questions well before May.
What counts as personal data in a chatbot conversation?
More than most businesses assume, because the conversation itself is full of it. The customer’s phone number is personal data the moment they message your WhatsApp number, before they type a word. So are their name, address, order history, and anything they volunteer, which on a support channel can include photos of documents, voice notes, and details about their health or finances that you never asked for. If a chat can be tied back to a person, treat everything in it as personal data.
That matters because AI agents tend to keep more than people do. A human agent forgets a conversation; a bot logs it, may send it to a model provider, and may copy it into a CRM, a spreadsheet, and a backup. Every one of those copies is a place the May 2027 duties apply to, and a place a deletion request has to reach.
What does this mean for a WhatsApp bot or website chatbot?
Chatbots collect personal data by design, so they are where an SMB’s DPDP exposure concentrates. A WhatsApp agent that captures names, phone numbers, addresses, and order details, or a website chatbot that asks for an email to send a quote, is collecting personal data, and from May 2027 it needs to tell people what it is collecting and why, keep only what it needs, and be able to find and delete a person’s data on request. We cover the consent question for AI agents in depth in India’s DPDP Act for SMBs.
- A short notice at the start of the conversation, with a link to your privacy policy.
- Collect only what the task needs; do not ask for an address to answer an opening-hours question.
- A way to find every record for one phone number or email, across the bot, your CRM, and backups.
- A plain way for someone to withdraw consent or ask for deletion, and a person who acts on it.
What should I do between now and May 2027?
Map where your chatbot sends data, then fix the gaps in order of risk. Start by listing every system a conversation touches: the messaging platform, the AI model provider, your CRM, spreadsheets, and any automation in between. For each, note what personal data lands there and how long it stays. Most of the work that follows is unglamorous: shorter retention, tighter access, a deletion process that reaches every copy, and a notice that says what the bot actually does. Seven months is enough time if you start now, and not enough if you start in April.
Is this legal advice?
No. This is an operator’s reading of the published timeline, written to help you prioritise, and you should confirm your specific obligations with a lawyer, especially if you handle children’s data or sensitive categories such as health or finance. What we can help with is the engineering side: making your bots and automations collect less, log what they do, and delete on request. If you want that reviewed, book a free 15-minute call. We build these controls into every WhatsApp AI agent we run.
Want this running in your business?
We build and run automations like this for Indian SMBs, first one live in 72 hours, then we operate it for you. Tell us the workflow you want handled.
How we build this for clients: WhatsApp AI agent →
About Shera
Co-Founder & Operations at ClosedChats AI. Owns commercial conversations and ROI modeling. Translates "we want this automated" into a project plan that pencils out.