I am not a lawyer, and nothing here is legal advice — every company should get its own counsel to interpret the Digital Personal Data Protection Act against its specific data flows. What I can offer is the operator's view: what this law actually changes about how a marketing team in India should collect, store, and use customer data day to day, because I have spent the last two years getting our own data practices ready for it, and most marketing teams I talk to still treat it as a legal department problem rather than something that touches campaign design, form fields, and vendor contracts directly.
The DPDP Act regulates how personal data is collected, processed, and stored, and marketing teams are usually the single largest generator of personal data collection points in a B2B company — website forms, WhatsApp opt-ins, event registrations, gated content downloads, cold outbound lists, retargeting pixels. Legal can write a policy. Only marketing can actually change how a form is built, what a consent checkbox says, or whether a purchased contact list gets used at all. Treating this purely as a legal sign-off misses that the actual compliance work happens in the tools and workflows marketing owns.
The old pattern of a single checkbox at the bottom of a form — "I agree to the terms and privacy policy" — covering everything from lead follow-up to newsletter sends to third-party data sharing, does not meet the specificity standard the Act expects. Consent needs to be clear about what it is for. In practice, this means separating "contact me about my enquiry" from "add me to your newsletter" from "share my data with partners," as distinct, genuinely optional choices rather than one bundled tick-box that is functionally impossible to decline without abandoning the form.
Data collected for one purpose — say, a webinar registration — cannot be freely repurposed for an unrelated purpose, like adding someone to a general outbound prospecting list, without fresh, specific consent for that new use. This directly affects a common Indian B2B growth tactic: harvesting event or webinar attendee lists for broader sales outreach. That practice needs a compliant consent basis now, not an assumption that "they gave us their email, so it is fair game."
A prospect who withdraws consent needs to actually be removed from active marketing systems, not just marked in one tool while five other systems — your ad platform's custom audience, your outbound sequencing tool, your WhatsApp broadcast list — keep using their data because nobody built a process to propagate deletion requests across the full stack. This is where the martech-salestech integration discipline I have written about elsewhere becomes a compliance requirement, not just an efficiency one: if your systems are not connected, you cannot honour a deletion request completely, and partial compliance is not compliance.
The audit question I ask every team: if a customer emailed us today asking exactly what personal data we hold on them and asked us to delete all of it, could we answer completely within a reasonable timeframe, across every tool in our martech and salestech stack, not just the primary CRM? Most Indian B2B marketing teams I have asked this question of could not answer yes with confidence, and that gap, not the headline fines, is the practical risk worth fixing first.
None of this needs to slow marketing down as dramatically as some teams fear. Companies that build clean, specific consent practices in usually find their engaged-audience quality improves, because the people who opt in deliberately convert better than the people swept in by a vague, bundled checkbox. Compliance and marketing effectiveness are not as opposed here as the initial anxiety suggests. Get the operational plumbing right once, and this becomes a background discipline rather than a recurring fire drill every time a campaign launches.
Back to all posts