Skip to content
Free SEO Audit

India Market

The DPDP Act and What Marketers Must Change

What the DPDP Act actually requires from Indian marketers on consent, tracking minors, and breach notification, plus the penalties for getting it wrong.

A magnifying glass over financial and accounting documents, representing close review of compliance records under a data protection law

The Digital Personal Data Protection Act, 2023 (DPDP Act) changes how Indian businesses can collect, use, and store customer data for marketing. The short version: consent has to be specific and opt-in rather than assumed, you can no longer run behavioural tracking or targeted ads against anyone identified as under 18, and the penalties for getting security and consent wrong run into hundreds of crores. The DPDP Rules, 2025 were notified by the Ministry of Electronics and Information Technology on 14 November 2025, which is what actually made the Act operational after two years of waiting. If your marketing stack still runs on pre-ticked newsletter boxes and silent data collection, that stack needs work.

This is general information to help you understand what changed, not legal advice. DPDP compliance touches contracts, IT systems, and sector-specific rules that vary by business, so confirm your specific obligations with a lawyer or compliance professional before you rely on anything below.

What the DPDP Act actually is

The DPDP Act received presidential assent on 11 August 2023, making it India’s first comprehensive, standalone personal data protection law. Before this, India relied on a patchwork of IT Act provisions and sector-specific rules that never really addressed how modern marketing tools collect, segment, and target people using their personal data. The Act sat unenforced for two years while the government worked out the operational rules. Those rules, the DPDP Rules 2025, were finally notified in November 2025, and they’re what turns the Act’s broad principles into specific, checkable obligations.

For marketers, the Act treats you as a “data fiduciary” the moment you collect a name, phone number, email address, or any other personal data tied to an identifiable person, whether that’s through a lead form, a WhatsApp opt-in, a loyalty programme, or a pixel on your website. The person whose data it is, the “data principal” in the Act’s language, gets a defined set of rights over that data. Marketing teams sit right at the point where most of that data enters a business, which is why this law lands on marketing operations harder than most other departments realise.

What actually changes for marketing teams

Strip away the legal language and four things change in practice.

Consent has to be genuine opt-in, not implied

Continuing to email someone because they didn’t unsubscribe, or collecting data through a form with a pre-ticked “yes, send me offers” box, doesn’t meet the bar. The Act requires clear, specific, informed consent given before you process the data, communicated through a notice that states what you’re collecting and why in plain language. Consent bundled into a vague terms-and-conditions checkbox is exactly the pattern the Act was written to stop.

Withdrawal has to be as easy as giving consent

If a customer can opt in with one click, they need to be able to opt out with comparable ease, and once they withdraw consent, continuing to send marketing messages becomes a violation with real penalty exposure. Marketing automation platforms that make unsubscribing a five-step process, or that keep contacts “warm” after opt-out for retargeting, are a direct compliance risk under this framework.

Targeting minors is now flatly restricted

Section 9 of the Act prohibits tracking, behavioural monitoring, and targeted advertising directed at anyone under 18, regardless of consent, unless the government specifically exempts a class of processing. That covers cookie-based tracking, device fingerprinting, retargeting, and lookalike-audience advertising aimed at users identified as children. India’s 18-year age threshold for this protection is stricter than most comparable data protection laws globally, which typically draw the line at 13 or 16. If any part of your funnel touches an audience that might include under-18s, education and edtech being the obvious example, this needs a specific review.

Data breaches carry mandatory notification and steep penalties

Fiduciaries have to notify the Data Protection Board of India and affected individuals when a personal data breach occurs, within timelines set out in the Rules. The financial exposure here is real: the Data Protection Board can impose penalties up to ₹250 crore per instance for the most serious failures, such as not taking reasonable security safeguards to prevent a breach, with penalties assessed per violation and per inquiry. A single incident touching several obligations at once (a security failure plus a missed notification plus a consent violation) can stack multiple penalties from one event.

Marketing activities and their DPDP exposure

Marketing activityWhat DPDP requiresCommon gap in current practice
Email / SMS / WhatsApp campaignsExplicit opt-in per channel, clear notice, one-step withdrawalSingle “marketing consent” checkbox covering all channels indefinitely
Website retargeting and pixelsConsent before tracking begins, no tracking of under-18sPixels fire before a cookie banner is interacted with
Lead forms and gated contentPurpose-specific notice at point of collectionGeneric privacy policy link instead of an in-context notice
CRM and email list purchases or rentalsConsent has to travel with the data or be re-obtainedThird-party lists used without verifying original consent basis
Loyalty programmes and referral schemesClear notice on how referred contacts’ data will be usedReferral data added to marketing lists without the referred person’s consent

There’s no single template the Act mandates, but the pieces a defensible flow needs are consistent across most compliance guidance published since the Rules dropped:

  1. A notice, in plain language, shown before or at the point of data collection, stating what’s collected and why.
  2. A genuine opt-in action (an unticked checkbox, a clicked “agree” button) rather than a default-on state.
  3. Separate consent per purpose where purposes are meaningfully different, rather than one blanket checkbox for “marketing.”
  4. A visible, low-friction way to withdraw consent that takes effect promptly, not after a support ticket.
  5. A record of when and how consent was given, since the burden of proving valid consent sits with the fiduciary, not the individual.
  6. Age-appropriate handling that excludes anyone identified as under 18 from behavioural tracking and targeted ads.
Fast compliance check for your current marketing stack

Can you show, for any contact in your CRM, exactly when and how they consented to marketing? Does your unsubscribe link actually stop all channels, not just email? Do your pixels and retargeting tags fire before or after consent is captured? Is there any part of your funnel that could reach under-18 users with targeted ads? If you answered “not sure” to more than one of these, that’s the starting list for your next compliance review, not a reason to panic, but a reason to move it up the priority list.

Timeline: when this actually has to be in place

The DPDP Rules 2025 were notified on 14 November 2025, and implementation is rolling out in phases rather than all at once. Some provisions, including the constitution of the Data Protection Board and core definitions, took effect immediately. Enforcement powers, the penalty framework, and Consent Manager registration are reported to phase in on a longer runway, with full compliance across consent, notice, security, and data-principal rights expected over the following one to two years as businesses adjust systems and processes. That phased runway is useful, but it’s not a reason to wait. Consent flows, CRM audit trails, and tracking configuration take real engineering and process time to fix, and starting once enforcement is already active is the expensive way to do this.

Why this matters beyond avoiding a fine

There’s a commercial argument here too, separate from penalty risk. Customers who gave real, informed consent are more likely to open, click, and buy than contacts sitting on a list they never knowingly agreed to be on. Clean, consented lists tend to perform better on every marketing metric that matters, deliverability, open rate, complaint rate, because you’re only marketing to people who actually said yes. Treating DPDP compliance purely as a legal cost misses that a well-built consent flow is also a better-performing one.

If you’re weighing how this fits into a broader Indian go-to-market plan, it’s worth reading alongside how advertising and marketing compliance in India works more broadly, since DPDP is one of several regulatory layers Indian marketers now operate under. It also connects to how businesses build trust with Indian buyers online, because visible, honest data practices are increasingly part of that trust equation, not separate from it.

Where to start if you haven’t touched this yet

Don’t try to fix everything simultaneously. Start with an inventory: list every place your business collects personal data for marketing purposes, email forms, WhatsApp opt-ins, event sign-up sheets, cookie-based tracking, third-party data purchases. For each one, check whether consent is genuinely opt-in, whether withdrawal actually works, and whether under-18 users could be caught in the net. That inventory alone usually surfaces the highest-risk gaps within a day or two of honest review.

Getting this right takes coordination between marketing, legal, and whoever manages your website and CRM, which is exactly the kind of cross-functional gap an outside team can help close quickly. Our marketing services include reviewing how campaigns, tracking, and consent flows fit together, so reach out if you want a second set of eyes on where your current setup stands. If you’re also working through the tax side of hiring an agency or freelancer, our piece on GST on digital marketing services covers the other compliance question that tends to come up around the same time as a data protection review.

Frequently asked questions

Does the DPDP Act apply to small businesses, or only large companies?

The Act applies to any entity processing personal data of individuals in India, regardless of size, with some obligations scaled differently for entities the government designates as Significant Data Fiduciaries. A small business collecting customer emails for a newsletter is still a data fiduciary under the Act.

Can I still use Google Analytics and Meta Pixel for marketing?

Yes, but consent needs to be captured before tracking scripts fire, and tracking or targeted advertising aimed at anyone under 18 is restricted regardless of consent. Review your cookie consent implementation to confirm scripts don’t load before a user has actively agreed.

What counts as “consent” under the DPDP Act for marketing emails?

A clear, specific, informed, and freely given affirmative action, such as an unticked checkbox a user actively selects after seeing a plain-language notice of what they’re agreeing to. Pre-checked boxes, bundled consent inside broad terms and conditions, or continued use interpreted as consent don’t meet this bar.

What happens if a customer withdraws consent but we keep emailing them?

Continuing to process or market to someone after they’ve withdrawn consent is a violation that can trigger penalties and mandatory corrective action from the Data Protection Board. Withdrawal needs to take effect promptly across every channel it applies to, not just the one the request came through.

Do we need a Consent Manager to be compliant?

Not necessarily. A Consent Manager is a registered intermediary that can manage consent on a data principal’s behalf, but most businesses can build compliant, direct consent flows without routing through one. It becomes more relevant at scale or in specific sectors. Confirm your specific situation with a compliance professional.

Get the audit.
Keep the findings.

Free, no payment details, yours to act on either way.

Get Your Free SEO Audit WhatsApp Us

What you get back

A 12-point audit of your actual site: technical issues blocking indexation, on-page gaps, speed findings, and the three to five fixes we’d make first.

  • 2 daysDelivery
  • 225Checks run
  • ₹0Cost, always