Why marketers should care
Marketing runs on personal data: email addresses and phone numbers for campaigns, WhatsApp opt-ins, CRM records, website behaviour, customer lists uploaded to ad platforms, lead forms from partners. The Digital Personal Data Protection Act, 2023 changes the terms on which all of that may be collected and used in India, and applies to processing of digital personal data within India as well as certain processing outside India connected with offering goods or services to people in India.
For many Indian businesses this is the first comprehensive privacy law they have had to design around. The temptation is to treat it as a legal team's problem. It is not. Most of the practices it affects (forms, banners, lists, messages, vendors) are owned by marketing.
Consent is no longer a checkbox on the way to the data. It is the terms of the relationship.
The key roles and terms
| Term in the Act | Plain meaning | Marketing example |
|---|---|---|
| Data Principal | The individual the personal data relates to (for a child, including the parent or lawful guardian) | A customer, subscriber or lead |
| Data Fiduciary | The organisation that decides why and how personal data is processed | Your brand, running its CRM and campaigns |
| Data Processor | An entity processing data on behalf of a fiduciary | An email platform, CRM vendor, agency or call centre acting on your instructions |
| Consent Manager | A registered entity through which individuals can give, manage and withdraw consent | A platform for managing consent across services, under the rules |
| Data Protection Board of India | The body that oversees compliance and handles complaints | The authority that can inquire into breaches and impose penalties |
The Act also allows the government to designate certain organisations as Significant Data Fiduciaries, based on factors such as the volume and sensitivity of data processed, with additional obligations. Large consumer brands should check whether this could apply to them.
Consent: the centre of the Act
For most marketing processing, the lawful basis will be consent. The Act requires consent to be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the personal data necessary for the specified purpose. In practice that points away from pre-ticked boxes, bundled consents and buried terms.
Fig. 01 · Process
Tap to explore
A consent journey shaped by the Act's principles
The Act also recognises certain legitimate uses where consent is not required, such as where an individual voluntarily provides data for a specified purpose and has not indicated objection, and various legal and employment situations. These are defined narrowly; marketers should not assume their activity fits them without legal advice.
Notice: telling people plainly
A consent request must be accompanied or preceded by a notice explaining the personal data to be processed and the purpose, how the individual can withdraw consent and exercise their rights, and how to complain to the Board. The Act provides for notice to be available in English or any language in the Eighth Schedule to the Constitution, which matters for brands serving audiences in regional languages.
Good notice is short, specific and placed where the decision is made: next to the form field, inside the WhatsApp opt-in, on the banner. A long privacy policy linked in the footer is necessary but rarely sufficient as the only notice.
Rights that affect marketing operations
- Withdrawal of consent: individuals can withdraw at any time, with ease comparable to giving it. After withdrawal, processing for that purpose should stop within a reasonable time, including by your processors.
- Access to information: individuals can ask for a summary of their personal data being processed and the processing activities.
- Correction and erasure: individuals can ask for data to be corrected, completed, updated or erased, subject to legal requirements to retain it.
- Grievance redressal: you must provide a readily available means for individuals to raise grievances, and respond.
- Nomination: individuals can nominate another person to exercise their rights in the event of death or incapacity.
For marketing, withdrawal is the most operationally demanding. An unsubscribe in one system must flow to every other system and vendor holding that person's data for that purpose: the email tool, the WhatsApp provider, the CRM, audience lists uploaded to ad platforms. Suppression lists and connected systems become compliance infrastructure.
Children's data
The Act defines a child as an individual under eighteen. Processing a child's personal data requires verifiable consent of a parent or lawful guardian, and the Act prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, subject to exemptions that may be prescribed. Brands in education, gaming, entertainment, food and fashion that reach younger audiences should review targeting, age assurance and data practices carefully with legal advice.
Obligations beyond consent
Data fiduciaries must take reasonable security safeguards to prevent personal data breaches, notify the Board and affected individuals of breaches in the manner prescribed, ensure accuracy where data is used for decisions or disclosed, and erase personal data when the purpose is no longer served and consent is withdrawn, unless retention is legally required. They remain responsible for processing done by their processors, which makes vendor contracts and oversight important.
The Act provides for significant financial penalties for breaches of its obligations, set out in its schedule. Beyond penalties, the reputational cost of a breach or a public complaint can exceed any fine for a consumer brand.
Fig. 02 · Stack
Tap to explore
Where DPDP touches the marketing stack
Collection points
Forms, banners, WhatsApp opt-ins, events, partner lead sources
Systems of record
CRM, ecommerce platform, customer data platform
Engagement tools
Email, SMS, WhatsApp Business providers, call centres
Advertising
Customer list uploads, pixels, conversion APIs
Analytics
Web and app analytics, data warehouse, dashboards
Practical steps for marketing teams
Checklist
0/10A DPDP review for marketing
Turning compliance into advantage
The Act pushes marketing towards practices that work better anyway: smaller, consented, engaged audiences instead of large, cold lists; clear value exchanges; data collected for a purpose and used for it. Brands that adopt these willingly tend to see healthier engagement and fewer complaints, and they build the kind of first-party data asset that remains useful as cookie-based tracking declines.
Myth vs reality
DPDP misconceptions
Technical implementation matters too: a consent-aware tag setup, as described in our explainer on Google Consent Mode, and careful use of server-side tracking help ensure analytics and advertising tags respect the choices people make. For WhatsApp-specific practice, see WhatsApp marketing.
Key takeaways
- 01The DPDP Act makes consent, given freely and specifically after clear notice, the basis for most marketing use of personal data in India.
- 02Withdrawal must be as easy as giving consent and must flow to every system and vendor holding the data.
- 03Children's data requires verifiable parental consent, and tracking and targeted advertising directed at children are prohibited, subject to prescribed exemptions.
- 04Organisations remain responsible for processing by their vendors, so map data flows and review contracts.
- 05Check the current rules and commencement dates and take legal advice; the Act's application is developing.
Frequently asked
- Does the DPDP Act apply to email and WhatsApp marketing?
- Yes, where it involves processing digital personal data such as email addresses and phone numbers. Marketing messages will generally need consent obtained after clear notice, for a specific purpose, with easy withdrawal. Messaging platforms may have their own opt-in rules too. Take legal advice on your specific practices.
- When does the DPDP Act come into force?
- The Act was passed in 2023, and its provisions take effect through rules notified by the government, with different provisions commencing at different times. Because timelines are set by notification, check the current official rules and commencement dates rather than relying on secondary sources.
- Can I still use purchased email or phone lists?
- Lists bought from third parties carry significant risk, because you may be unable to show that the individuals gave valid consent to you for your purpose. Under the DPDP Act's consent model, using such lists for marketing is difficult to justify. Seek legal advice before using any list of uncertain origin.
- Do cookie banners need to change because of the DPDP Act?
- The Act does not mention cookies specifically, but cookies and similar technologies often process personal data. Where they do, consent and notice principles are likely to be relevant. How this applies to analytics and advertising cookies is a question for legal advice in light of the rules and any guidance issued.
- What are the penalties under the DPDP Act?
- The Act sets out financial penalties in a schedule, varying by the type of breach, with the highest for serious failures such as inadequate security safeguards leading to a breach. The Data Protection Board determines penalties. Consult the official text for current amounts and seek legal advice on exposure.
Published by Fabulous.Media, a network of specialist marketing agencies. Updated 9 October 2026. Platform features change often; check current official documentation before acting on platform-specific detail.






