Your Old Data Is the Problem, Not Your New Consent Screens : Your Old Data Is the Problem, Not Your New Consent Screens
The data collected over the last ten or fifteen years — sitting in customer databases, loyalty systems, old call-centre recordings, paper forms scanned into a document store — is the part nobody has a plan for
The short version
Most organisations are building consent screens for new customers. That work is visible, fundable, and mostly on track. The data collected over the last ten or fifteen years — sitting in customer databases, loyalty systems, old call-centre recordings, paper forms scanned into a document store — is the part nobody has a plan for. That is where the exposure sits, and it cannot be fixed by a screen.
Where the law actually stands
The Rules were notified on 13 November 2025. Provisions relating to the Data Protection Board took effect immediately. Consent-manager provisions take effect on 13 November 2026. The substantive compliance provisions take effect on 13 May 2027.
Date | What changes |
|---|---|
Nov 2025 | Rules notified; Board and definitions in force |
13 Nov 2026 | Consent-manager provisions operational |
13 May 2027 | Notice, consent, safeguards, breach reporting, rights — all enforceable |
Early 2027 | Audit obligations for significant data fiduciaries |
A common mistake is reading November 2026 as the deadline. It is not. November 2026 does not represent a universal compliance deadline for every Data Fiduciary; it is an important milestone in the implementation of the framework. The date that matters for most organisations is May 2027.
What does change in November is the regulator's posture. November 2026 is widely expected to signify the end of the initial implementation or "soft enforcement" phase, with the Board expected to transition from awareness-building toward more active regulatory supervision.
How far behind is everyone, really
An EY survey of more than 150 professionals across sectors found close to 70% were not very familiar with the Act and Rules. More than 81% had not updated or drafted aligned privacy policies. Over 83% had not begun comprehensive implementation.
So if your programme is not finished, you are in the overwhelming majority. That is not comfort — it means the market for remediation help will be badly congested in the first half of 2027.
Why legacy data is the hard part
A key compliance focus during this period is legacy data management. Organisations are expected to ensure that personal data collected before this framework is supported by valid notice and consent mechanisms consistent with the Act and Rules. Those unable to demonstrate lawful consent or valid processing grounds for historical datasets may face increased regulatory exposure.
Two features of the law make this sharper than people expect:
Consent must be free, specific, informed, unconditional and unambiguous. A checkbox on a 2016 sign-up form that bundled everything together does not meet that bar.
Unlike GDPR, legitimate interest is not available as a basis for processing. Consent is the primary basis. So the fallback many global programmes rely on is not there.
The practical difficulty is that legacy consent capture systems — sign-up forms, cookie banners, IVR scripts, paper-based onboarding — were never designed to talk to an external registry.
Pre-consent versus post-consent data: the only split that matters
Pre-consent data | Post-consent data | |
|---|---|---|
What it is | Collected before you had compliant notice and consent | Collected under a compliant notice and consent |
Can you prove it? | Usually no record of what was shown or agreed | Yes, with a timestamped record |
Can you keep using it? | Only if you can re-establish a lawful basis | Yes, within the stated purpose |
Your realistic options | Re-consent, restrict, or delete | Maintain the record |
Where it usually lives | Old CRM, loyalty systems, call recordings, scanned forms, spreadsheets on shared drives | Current customer platform |
The line between them is not a date. It is the point at which your organisation started keeping evidence of what the person was told and what they agreed to. Most organisations do not know where that line falls, and finding it is the first piece of real work.
Which industries carry the most exposure
Sector | Why the legacy problem is severe | What usually hurts |
|---|---|---|
Consumer internet, e-commerce | Years of free sign-ups, bundled terms, no consent records | Volume; data copied into many systems |
Retail and hospitality | Loyalty programmes built on paper and point-of-sale | Purpose creep — collected for billing, used for marketing |
Telecom | Enormous subscriber histories, heavy outsourcing | Third-party processors holding copies |
Insurance | Long policy lifetimes, health and family details | Sensitive data, long retention |
Healthcare and diagnostics | Patient records across clinics and labs | Sensitivity plus paper origins |
Banking and financial services | Large estates, but existing regulatory discipline | Less severe than assumed — consent regimes already exist |
Manufacturing and B2B | Employee and vendor data rather than consumer | Often overlooked entirely because "we have no customers" |
The common misreading is that this is a consumer-facing problem. Employee data is personal data. A manufacturer with 20,000 employees and thirty years of HR records has a real legacy estate.
A triage method that works
Do not start with a full data inventory. It takes months and produces a spreadsheet nobody acts on. Start by sorting what you have into four boxes.
Box 1 — Delete. Data you no longer use for anything. Old campaign lists, dormant accounts, duplicate extracts sitting in analytics environments. This is usually 20–40% of the estate and it is pure cost and pure risk. Deleting it is the cheapest compliance win available.
Box 2 — Re-consent. Data you actively use and cannot afford to lose. Active customers, live loyalty members. Plan a re-consent campaign, and accept that response rates will be poor — build the plan assuming you keep only a fraction.
Box 3 — Restrict. Data you must retain for another legal reason (tax, sectoral regulation) but are no longer free to use for marketing or analytics. Lock it down, narrow the access, stop feeding it to downstream systems.
Box 4 — Investigate. Where you genuinely cannot tell what was collected or agreed. This box is the real work, and it should shrink as the others fill.
Heuristics for sorting quickly
The five-year rule. If nobody has touched the dataset in five years, it belongs in Delete until someone argues otherwise. Make them argue.
Follow the copies, not the source. The system of record is usually the easy part. The risk is the six downstream copies in analytics, testing environments, vendor systems, and someone's exported file.
Purpose drift is the giveaway. If data collected for one reason is now used for another, treat it as pre-consent regardless of the date.
Paper origin means no proof. Anything that started as a physical form has no retrievable record of what the person was shown. Assume the worst.
Third parties hold your problem. Processors, agencies and call centres holding copies are your exposure, not theirs.
Employee data counts. Every time.
What a first assessment looks like
A useful first pass takes one to two days, not six weeks.
Day one: map where personal data physically sits — systems, vendors, and the informal places (shared drives, exports, test environments). Identify roughly when compliant consent capture began. Sort the top ten datasets by volume into the four boxes.
Day two: size the Delete box (the quick win), size the Re-consent box (the expensive one), and list what cannot be answered without deeper work. Produce a one-page view for the board: how much can be cleared immediately, what needs budget, what the timeline to May 2027 looks like.
The output is not a compliance document. It is a decision: what to stop keeping, what to pay to keep, and what to escalate.
Frequently asked questions
Is 13 November 2026 our deadline?
No. Consent-manager provisions take effect then; substantive compliance provisions take effect 13 May 2027. That is the date to plan against.What are the penalties?
Up to ₹250 crore for failing to maintain reasonable security safeguards, ₹200 crore each for breach-notification and children's-data failures, ₹150 crore for significant data fiduciary failures, and ₹50 crore for general non-compliance — per violation, and they can stack.We already comply with GDPR. Are we covered?
Mostly, but not entirely. Enterprises with GDPR programmes already have most of the controls; the work is the local overlay, not a rebuild. The gap that catches people is the absence of legitimate interest as a lawful basis.Do we have to use a consent manager?
No. Organisations that intend to use Consent Managers, or whose consent infrastructure may interact with that ecosystem, should assess readiness before the rule takes effect. It is an option, not an obligation for every organisation.Can we just keep old data if we stop marketing to it?
Only if you have another lawful reason to hold it. Retention still requires a basis. Stopping use reduces risk but does not remove the obligation.What should be done first?
Delete what nobody uses. It is the fastest reduction in exposure, needs no legal interpretation, and usually needs no budget.Who owns this — the CISO, the technology leader, or legal?
Legal owns the interpretation. The technology leader owns the estate. In practice the decisions that matter — what to delete, what to migrate, what to re-consent — are estate decisions, and they cannot be delegated to a compliance function alone.Is this only a consumer-business problem?
No. Employee, contractor, and vendor-contact data is personal data. Business-to-business organisations frequently discover their largest legacy estate is in HR.
The bottom line
The organisations that will handle 2027 calmly are not the ones with the best consent screens. They are the ones that spent the first half of 2027's runway deciding what to stop keeping. That decision is available to you now, costs almost nothing, and gets harder every month you defer it.