DPDP Act compliance checklist for Indian marketers

Almost every DPDP obligation lands on work marketing owns. The dates, the classification question, and nine things to fix before May 2027.

Most Indian marketing teams have filed the Digital Personal Data Protection Act under “legal will handle it”. Almost every obligation in it lands on work marketing owns: list building, lead forms, retargeting pixels, WhatsApp broadcasts, CRM enrichment, and every vendor you hand customer data to.

The dates that matter: the DPDP Rules were notified in November 2025. The Data Protection Board of India became operational on 13 November 2025. Consent Manager registration opens 13 November 2026. Full compliance with the penalty regime live arrives 13 May 2027. The maximum penalty for failing to take reasonable security safeguards is 250 crore rupees.

Work out what you are first

The Act splits organisations into Data Fiduciaries, who decide why and how personal data gets processed, and Data Processors, who process it on instruction. Run a brand and collect customer emails, you are a Fiduciary. Run an agency executing on a client list, you are usually a Processor for that work and a Fiduciary for your own leads. Plenty of agencies are both at once on different datasets.

Get this wrong and you build the wrong compliance programme. Fiduciaries owe notice, consent, breach reporting and grievance redressal directly to the individual. Processors owe their obligations to the Fiduciary through contract.

The checklist

  • Map every collection point. Website forms, gated content, webinar registrations, WhatsApp opt-ins, event badge scans, chatbot transcripts, in-store sign-ups. Teams routinely find two to three times more than they expected.
  • Rewrite your notices. The DPDP notice has to be standalone and specific about purpose. A link to a 4,000-word privacy policy at the bottom of a form does not clear the bar. It also has to be available in the languages listed in the Eighth Schedule, which is translation work nobody has budgeted for.
  • Make consent granular. One checkbox covering marketing, analytics and partner sharing will not survive scrutiny. Each purpose needs its own consent, and someone has to be able to say yes to one and no to another.
  • Build a consent log. You need to show what a named person agreed to, when, and against which version of the notice. If your consent record is a boolean column in the CRM, you cannot answer that. This is the most common gap.
  • Make withdrawal as easy as signup. If joining takes one click and leaving takes an email to support, you have a problem. Withdrawal also has to reach every downstream vendor, not just your email tool.
  • Audit purchased data. Bought lists, scraped contacts and third-party enrichment have no lawful basis here. There is no legitimate interest ground to fall back on the way there is under GDPR.
  • Fix vendor contracts. Every processor touching customer data needs terms covering purpose limitation, security, breach notification and deletion. Count your martech stack. For most mid-sized Indian teams it is somewhere between fifteen and forty tools.
  • Set retention periods and automate deletion. Keeping data forever because storage is cheap is now an exposure.
  • Name a grievance officer and publish the contact.

If you only have time for two

Do the collection map and the consent log. Everything else depends on knowing where data enters and being able to prove what was agreed. A team with those two can fix notices and contracts steadily. A team without them is guessing.

General information, not legal advice. Rules current as of July 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *