DPDP Consent (Marketing Data)

The standard of consent India's Digital Personal Data Protection Act, 2023 requires before a business may process personal data for marketing: free, specific, informed, unambiguous, and as easy to withdraw as it was to give.

India's Digital Personal Data Protection Act, 2023 sets out how organisations may handle the personal data of individuals in India. For a marketing team, almost every routine activity falls inside its scope: a newsletter list, a lead form, a remarketing audience built from customer emails, a CRM, a WhatsApp broadcast.

The Act's vocabulary is worth learning, because obligations attach to the roles:

  • Data Principal — the individual the data is about.
  • Data Fiduciary — whoever determines the purpose and means of processing. If you decide what to collect and why, this is you, and the duties are yours. They do not transfer to your agency or your tooling.
  • Data Processor — a party processing on the Fiduciary's behalf, under contract.

The consent standard

Consent under the Act must be free, specific, informed, unconditional and unambiguous, and given by a clear affirmative action. Each of those words removes a common practice:

  • Clear affirmative action rules out pre-ticked boxes and consent inferred from continued use of a site.
  • Specific rules out one blanket permission covering every future purpose. Consent is tied to the purposes you named.
  • Unconditional rules out demanding data you do not need in order to provide the service — you may collect what is necessary for the stated purpose, not everything you would find useful.
  • Informed requires an accompanying notice, in plain language, saying what you are collecting, for what purpose, and how the person can exercise their rights. The Act contemplates that notice being available in English and in the languages listed in the Eighth Schedule to the Constitution.

Withdrawal is the operational test

A Data Principal may withdraw consent at any time, and withdrawing must be about as easy as giving it was. This is where most marketing stacks fail, because consent is usually captured in one system and acted on in five: an email platform, an SMS gateway, a WhatsApp provider, a CRM, and an ad platform holding an uploaded custom audience.

An unsubscribe link that stops the newsletter but leaves the person in a remarketing audience has not honoured the withdrawal. Designing for that — one authoritative consent record, propagated outward — is considerably easier before the stack is built than after.

What this means in practice

Record consent as evidence rather than as a checkbox: what was shown, which purposes were named, when, and through what interface. Keep purposes narrow and named. Give withdrawal a real path that reaches every downstream system. And treat data you cannot show a lawful basis for as a liability rather than an asset — the Act's penalty schedule runs to figures large enough that quietly retained lists are a poor trade.

Note on currency: the Act was passed in 2023 and its detailed operational rules and compliance timelines have been phasing in since. Treat this entry as an explanation of the consent architecture, not as legal advice, and confirm the current position with counsel before relying on it.

Worked example

A lead form asks for name, email, phone and company, with a single checkbox reading "I agree to the terms".

That does not meet the standard. It bundles unrelated purposes into one permission, it does not name what the data will be used for, and it makes contact permission a condition of the enquiry.

A compliant version separates the two: the enquiry itself proceeds on the data needed to answer it, and a distinct, unticked option says in plain words — "Send me occasional offers and updates by email and WhatsApp" — with a link to a notice explaining the purposes, retention and how to withdraw. The withdrawal, when it comes, has to reach the email platform, the WhatsApp provider and any uploaded ad audience, not just the newsletter tool.

Common mistakes

  • Pre-ticked consent boxes, or treating continued browsing as agreement. Neither is a clear affirmative action.
  • Bundling purposes. One checkbox covering service messages, marketing and third-party sharing is not specific consent.
  • Making marketing consent a condition of the enquiry, which fails the unconditional requirement.
  • Honouring withdrawal in one system only. Unsubscribing from email while the person remains in an uploaded ad audience is not withdrawal.
  • Assuming the agency carries the obligation. If you decide the purpose and means, you are the Data Fiduciary; a vendor contract does not move that.
  • Keeping old lists "just in case" with no record of how consent was obtained or for what.

Need this handled properly? See how we run it →