DPDP Act for Marketing: A Practical Checklist for Indian Sales and Marketing Teams
What the DPDP Act for marketing and sales teams means in plain language: the key terms, notice and consent, withdrawal, security, breaches, children's data and people's rights, with a checklist for handling leads. General information from the official texts, not legal advice.
By DigiPix Flow team

In this guide
This article explains general principles from the official texts and is not legal advice. For advice on your situation, speak to a qualified lawyer.
Sales and marketing teams handle more personal data than almost anyone else in an Indian business: names, mobile numbers, emails, WhatsApp chats, budgets, addresses and site-visit notes, often spread across a CRM, spreadsheets and personal phones. The DPDP Act for marketing teams matters because it sets the rules for how that data is collected, used, protected and deleted. This guide walks through what the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 say, quoting and linking the official texts, then turns it into a checklist you can work through.
The DPDP Act and Rules in brief
The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) received the President's assent on 11 August 2023. Section 3 applies it to the processing of digital personal data in India, whether the data was collected in digital form or collected on paper and digitised later. It does not apply to data processed by an individual for a personal or domestic purpose, or to personal data that the person has made publicly available themselves. For a plain-English overview, see our glossary entry on the DPDP Act.
The Digital Personal Data Protection Rules, 2025 were published in the Gazette under a notification dated 13 November 2025 (G.S.R. 846(E)). Rule 1 phases them in: some rules took effect on publication, rule 4 (on consent managers) one year after publication, and rules 3, 5 to 16, 22 and 23, which hold most of the duties discussed below, eighteen months after publication. The Act itself also comes into force on dates the government notifies. Before you rely on any date, check the current position on MeitY's data protection framework page, including any later amendment.
Key terms for a sales team
| Term in the Act | What it means for you |
|---|---|
| Data Principal | The individual the data is about: your lead, customer or contact |
| Data Fiduciary | Your business, which decides why and how the data is processed |
| Data Processor | Anyone processing data on your behalf, such as a CRM, messaging provider or agency |
| Personal data | Any data about an individual who is identifiable by or in relation to it |
| Personal data breach | Any unauthorised processing, or accidental disclosure, sharing, alteration, destruction or loss of access, that compromises the data |
| Child | An individual who has not completed eighteen years of age |
Consent, notice and legitimate uses
Section 4 allows personal data to be processed for a lawful purpose either with the person's consent or for certain legitimate uses. Section 6(1) describes valid consent as "free, specific, informed, unconditional and unambiguous with a clear affirmative action", limited to the data necessary for the specified purpose. Under section 6(10), if consent is questioned in a proceeding, the business must prove that notice was given and consent was obtained. That makes record-keeping a core marketing task, not an afterthought.
Section 5 requires a notice with every consent request, and rule 3 adds detail: it must be understandable on its own, in clear and plain language, with an itemised description of the personal data, the specific purpose, and a link or other means to withdraw consent, exercise rights and complain to the Board. Section 5(3) adds that people must be able to read the notice in English or any language in the Eighth Schedule to the Constitution.
One legitimate use is especially relevant to enquiries. Section 7(a) covers a purpose for which the person has voluntarily provided their data and has not said they object. The Act's own illustration is a person who messages a real estate broker asking for help finding a rental: the broker may use the data to share available properties, and must stop once the person says they no longer need help. Note how narrow it is: it covers answering what the person asked about, not adding them to unrelated promotions.
Withdrawal, erasure and retention
Section 6(4) gives people the right to withdraw consent at any time, with "the ease of doing so being comparable to the ease with which such consent was given". Under section 6(6), the business must then stop processing within a reasonable time, and make its processors stop too, unless the law requires otherwise. A one-click form opt-in followed by a phone-only opt-out would not sit well with that.
Section 8(7) requires erasing personal data when consent is withdrawn or as soon as it is reasonable to assume the purpose is no longer being served, unless retention is necessary under another law, and making processors erase it too. Separately, rule 8(3) requires keeping personal data, associated traffic data and logs of processing for at least one year for the purposes in the Rules' Seventh Schedule. Agree with your lawyer how these fit your retention schedule.
Security safeguards and breaches
Section 8(5) requires reasonable security safeguards to prevent a personal data breach, including for processing done by your vendors. Rule 6 lists minimum measures, among them encryption, obfuscation or masking; controlling access to computer resources; visibility of access through logs, monitoring and review; backups for continuity; keeping such logs for a year; and security terms in contracts with processors.
If a breach happens, section 8(6) and rule 7 require telling each affected person without delay, in plain language, what happened, the likely consequences, what you are doing and what they can do. The Data Protection Board must also be told without delay, followed by a detailed report within seventy-two hours of becoming aware, unless the Board allows longer on a written request.
The stakes are significant. The Act's Schedule sets penalties that may extend to ₹250 crore for failing to take reasonable security safeguards, ₹200 crore for failing to notify a breach, ₹200 crore for breaching the obligations on children's data, and ₹50 crore for breaches of other provisions.
Children's data
Section 9 requires verifiable consent from a parent or lawful guardian before processing a child's personal data, bans processing likely to harm a child's well-being, and bans "tracking or behavioural monitoring of children or targeted advertising directed at children". Rule 10 sets out how verifiable parental consent works, and rule 12 exempts some classes of businesses and purposes from parts of section 9. Since a child is anyone under eighteen, this matters to coaching institutes, schools and admissions teams whose enquiries often come from or about students.
People's rights, and how fast you must respond
- Access (section 11): a summary of the personal data you process and the processing activities, and the identities of others you have shared it with.
- Correction and erasure (section 12): correct, complete or update data, and erase it on request unless it is needed for the purpose or required by law.
- Grievance redressal (section 13): a readily available way to complain to you, which people must use before approaching the Board. Rule 14 caps the response period at ninety days and requires the means of making requests to be published prominently.
- Nomination (section 14): a person can nominate someone to exercise their rights on death or incapacity.
Section 8(9) and rule 9 also require publishing the business contact details of a Data Protection Officer, where applicable, or of a person who can answer questions about your processing.
The DPDP checklist for sales and marketing teams
- Map where lead data lives: CRM, spreadsheets, inboxes, WhatsApp on company and personal phones, ad platforms, agencies and partners.
- Write a clear notice for every form and ad: what you collect, why, and how to withdraw, exercise rights and complain.
- Separate purposes. Replying to an enquiry and sending promotions are different purposes; ask for marketing separately, with an unticked box.
- Record consent evidence: wording and version shown, time, channel, and how the person agreed.
- Make withdrawal as easy as opt-in, and apply it on every channel and to every future import.
- Collect only what you use. Remove form fields and CRM columns nobody acts on.
- Set retention periods for leads that never converted, and erase or anonymise on schedule, checking what other laws require you to keep.
- Restrict access and exports by role, and keep logs of who viewed, changed or exported data.
- Review processors' contracts for security and erasure terms.
- Prepare a breach plan: who investigates, and who informs the Board and affected people, within the required time.
- Handle children's data with extra care, including verifiable parental consent and no targeted advertising at children.
- Publish a contact and a rights process, and train the team on forwarding sheets, personal WhatsApp groups and old lists.
Example: consent wording on an enquiry form
An illustration to discuss with your lawyer, not approved legal wording; the business name is invented. Above the submit button: "We'll use your name, mobile number and email to reply to this enquiry. Read our privacy notice to see how to withdraw consent, use your rights or complain." Below it, an optional, unticked box: "☐ Also send me offers from Verma Academy by WhatsApp and email. I can opt out at any time." Record which box each person ticked, when, and under which version of the wording.
The DPDP Act is not the only rule that applies to outreach: commercial SMS has its own registration and template system, explained in our guide to DLT registration for SMS.
Where DigiPix Flow fits
No software makes a business compliant on its own, and DigiPix Flow doesn't claim to. What it does is keep the records that make good practice easier. Consent is kept per channel (email, SMS, WhatsApp) and per purpose (marketing, sales outreach) with where it came from and the notice version, and website form consent boxes are never pre-ticked. Opt-outs, STOP replies and bounces join a do-not-contact list that is checked before messages go, as described on the consent and opt-outs page.
For people's rights, DigiPix Flow handles access, erasure and anonymise requests with an approval step and a due date. Roles, data scope, multi-factor sign-in, a separate export permission and an append-only audit log control who sees and takes data, and the service is hosted in the Mumbai region; see security and access.
This article is general information from the official texts linked above and does not constitute legal advice.
Want consent records and access control built into your lead handling? Talk to an expert and we'll walk through how your team captures, uses and deletes customer data today.
Frequently asked questions
What is the DPDP Act, 2023?
The Digital Personal Data Protection Act, 2023 is India's law on processing digital personal data. It gives individuals rights over their data, requires a lawful basis such as consent or a listed legitimate use, and places duties on businesses to give notice, protect data, report breaches and erase data when it is no longer needed. The DPDP Rules, 2025 set out how many of these duties work.
Does the DPDP Act apply to leads in my CRM?
Generally, yes. Names, phone numbers and emails of identifiable people stored digitally are personal data, and the Act also covers data collected on paper and digitised later. Data a person has made publicly available themselves is excluded. Ask a lawyer how it applies to your business.
What does valid consent mean under the DPDP Act?
Section 6(1) says consent must be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and limited to the data needed for the stated purpose. It must come with a clear notice, and withdrawing it must be comparable in ease to giving it.
Can I still send marketing messages under the DPDP Act?
Marketing isn't banned, but you need a lawful basis for it, usually consent for that purpose, and you must honour withdrawals on every channel. SMS also has its own registration and template rules, and WhatsApp's policies require opt-in before you message people.
When do the DPDP Rules take effect?
The Rules phase in. As published, some rules took effect on publication, the consent manager rule one year after publication, and most duties, including notice, security, breach intimation and rights, eighteen months after publication. Check MeitY's website for the current position and any amendment, and take legal advice rather than relying on summaries.
Is a CRM a Data Processor under the DPDP Act?
Typically, a CRM provider that processes lead and customer data on your behalf acts as a Data Processor, while your business remains the Data Fiduciary responsible for compliance. Section 8(2) requires a valid contract with any processor, and rule 6 expects that contract to cover security safeguards.
Put this guide into practice
See qualification questions, lead scoring and follow-up built into one workspace, using your own lead sources.


