Marketing Compliance

The DPDP Act and What It Means for Marketing Teams in India

By Vikas Goyal  ·  August 2026  ·  8 min read

I am not a lawyer, and nothing here is legal advice — every company should get its own counsel to interpret the Digital Personal Data Protection Act against its specific data flows. What I can offer is the operator's view: what this law actually changes about how a marketing team in India should collect, store, and use customer data day to day, because I have spent the last two years getting our own data practices ready for it, and most marketing teams I talk to still treat it as a legal department problem rather than something that touches campaign design, form fields, and vendor contracts directly.

Why This Is a Marketing Problem, Not Just a Legal One

The DPDP Act regulates how personal data is collected, processed, and stored, and marketing teams are usually the single largest generator of personal data collection points in a B2B company — website forms, WhatsApp opt-ins, event registrations, gated content downloads, cold outbound lists, retargeting pixels. Legal can write a policy. Only marketing can actually change how a form is built, what a consent checkbox says, or whether a purchased contact list gets used at all. Treating this purely as a legal sign-off misses that the actual compliance work happens in the tools and workflows marketing owns.

The Core Concepts That Change How You Operate

Consent has to be specific, not bundled

The old pattern of a single checkbox at the bottom of a form — "I agree to the terms and privacy policy" — covering everything from lead follow-up to newsletter sends to third-party data sharing, does not meet the specificity standard the Act expects. Consent needs to be clear about what it is for. In practice, this means separating "contact me about my enquiry" from "add me to your newsletter" from "share my data with partners," as distinct, genuinely optional choices rather than one bundled tick-box that is functionally impossible to decline without abandoning the form.

Purpose limitation is now an operating constraint, not a principle

Data collected for one purpose — say, a webinar registration — cannot be freely repurposed for an unrelated purpose, like adding someone to a general outbound prospecting list, without fresh, specific consent for that new use. This directly affects a common Indian B2B growth tactic: harvesting event or webinar attendee lists for broader sales outreach. That practice needs a compliant consent basis now, not an assumption that "they gave us their email, so it is fair game."

The right to withdraw consent and be forgotten needs an operational answer

A prospect who withdraws consent needs to actually be removed from active marketing systems, not just marked in one tool while five other systems — your ad platform's custom audience, your outbound sequencing tool, your WhatsApp broadcast list — keep using their data because nobody built a process to propagate deletion requests across the full stack. This is where the martech-salestech integration discipline I have written about elsewhere becomes a compliance requirement, not just an efficiency one: if your systems are not connected, you cannot honour a deletion request completely, and partial compliance is not compliance.

The audit question I ask every team: if a customer emailed us today asking exactly what personal data we hold on them and asked us to delete all of it, could we answer completely within a reasonable timeframe, across every tool in our martech and salestech stack, not just the primary CRM? Most Indian B2B marketing teams I have asked this question of could not answer yes with confidence, and that gap, not the headline fines, is the practical risk worth fixing first.

What This Means for Specific Marketing Practices

A Practical First Ninety Days

  1. Map every point where your marketing function collects personal data — forms, WhatsApp, events, purchased lists, chatbots — and document the consent basis for each.
  2. Rebuild consent language on your top three highest-volume collection points to be specific and unbundled, rather than a single blanket checkbox.
  3. Confirm your CRM can execute a full deletion or data export request across connected systems, not just within itself, and time how long that actually takes today.
  4. Audit any purchased or third-party contact lists currently in active use, and either re-consent that data or retire it from active campaigns.
  5. Add a standard data processing clause review to every new martech or agency vendor contract going forward.

None of this needs to slow marketing down as dramatically as some teams fear. Companies that build clean, specific consent practices in usually find their engaged-audience quality improves, because the people who opt in deliberately convert better than the people swept in by a vague, bundled checkbox. Compliance and marketing effectiveness are not as opposed here as the initial anxiety suggests. Get the operational plumbing right once, and this becomes a background discipline rather than a recurring fire drill every time a campaign launches.

Back to all posts