DPDP Act marketing compliance comes down to a few principles that are genuinely simple to state and genuinely inconvenient to implement: consent must be free, specific, informed and unambiguous, tied to a stated purpose, and as easy to withdraw as it was to give. In practice that means you cannot reuse a webinar registration list to promote an unrelated course, pre-ticked boxes are not consent, and "reply STOP" needs to actually work. This is the marketer's version of the conversation, because every existing guide is written for data protection officers.
This is general information, not legal advice. I'm a marketing practitioner, not a lawyer. India's Digital Personal Data Protection framework has statutory text and subordinate rules whose details and timelines have evolved, and how they apply to your specific business is a legal question. Read the official sources, the Ministry of Electronics and Information Technology at meity.gov.in, and get advice from qualified counsel before making compliance decisions.
Key Takeaways
- Consent must be free, specific, informed and unambiguous, and given by a clear affirmative action. Pre-ticked boxes and bundled consent fail all four tests.
- Notice is a requirement, not a nicety. At the point of collection, tell people what you're collecting, what for, and how to withdraw and complain.
- Purpose limitation is the rule marketers most often break. Data collected for one stated purpose cannot be repurposed for an unrelated one.
- Withdrawal must be as easy as consent. If opting in took one tap, opting out cannot take an email to support and a three-day wait.
- Your existing lists need an honest audit: what did you tell people at capture, and can you evidence it?
- Build a consent record: timestamp, source, exact wording shown, purposes agreed. Without it you cannot demonstrate anything.
Why marketers need their own version of this
Search "DPDP Act marketing compliance" and you'll find law-firm explainers, compliance-software vendors and DPO-oriented breakdowns. All useful. None of them tell you what to put on your form, what to do with the 40,000 emails you already have, or whether you can message a webinar list about a new course.
Those are the questions marketing teams actually have. Let's take them one at a time: with the standing caveat that where the answer has legal consequence, you confirm it with counsel.
The principles, in marketer's language
Consent must be free
Free means unbundled and non-coercive. You cannot make marketing consent a condition of receiving something unrelated. "Tick this to receive promotional messages" cannot be the price of downloading the syllabus PDF the person came for.
The practical test: could the person get what they came for while declining marketing? If no, your consent probably isn't free.
Consent must be specific
Specific means tied to stated purposes. One blanket "I agree to the terms" covering account creation, marketing, analytics and third-party sharing is the opposite of specific.
Practically: list the purposes. If you want to send WhatsApp marketing and share data with a hiring partner, those are two purposes and arguably two decisions.
Consent must be informed
Informed means the person knew what they were agreeing to, in language they can understand. A 4,000-word privacy policy behind a link is not, on its own, informing anyone.
Practically: put the essential facts in plain language at the point of capture, with the full policy linked for detail.
Consent must be unambiguous, by clear affirmative action
Unambiguous means an active choice. Pre-ticked checkboxes fail this. So does "by submitting this form you agree to receive marketing communications" buried in grey 10px text under the button.
Practically: an unticked checkbox the user ticks themselves, or an equally explicit affirmative action.
Notice at collection
Alongside consent, people are entitled to notice: broadly, what personal data you're collecting, the purposes, how they can exercise their rights including withdrawal, and how to complain. Official material on the framework and its rules is published by MeitY.
What a compliant consent notice actually looks like
Here is a form block I'd be comfortable shipping, subject to your counsel's review.
Bad, what most Indian sites still do:
☑ I agree to receive updates and promotional offers from Brand and its partners via email, SMS, WhatsApp and phone. (Pre-ticked. Bundled. Vague purposes. Undefined "partners". No withdrawal information.)
Better:
Your details Name · Email · Phone ☐ Send me course updates, cohort dates and admissions information on WhatsApp and email. ☐ Send me promotional offers and content from Brand. We'll use your details to process your application and contact you about it. You can withdraw either consent any time: reply STOP on WhatsApp, click unsubscribe in any email, or write to [email protected]. Full details in our [Privacy Notice].
What changed: nothing pre-ticked, purposes separated and named, channels named, withdrawal stated in-line with three concrete mechanisms, and the transactional processing of the application distinguished from marketing.
Design notes that matter in practice
- Don't hide the checkbox. Same font size as the labels. If it needs to be hidden to convert, you have a bigger problem.
- Name the channels. "Updates" is not consent to WhatsApp specifically.
- Don't say "and our partners" unless you name them or a defined category.
- Keep the wording versioned. When you change the notice text, keep the old version, your consent records need to point to what was actually shown.
Yes, this costs you some form conversion. In my experience it costs less than people fear, and the list you get responds better because everyone on it chose to be there.
Purpose limitation: the rule that breaks campaign calendars
This is the one that will change how your team works.
The principle: personal data collected for a specified purpose should be processed for that purpose. Data collected for purpose A is not automatically available for unrelated purpose B.
The webinar scenario
You run a free webinar on "Career Options After B.Tech." 3,000 people register, giving name, email and phone so you can send them the joining link and recording.
Reasonably within the stated purpose: the joining link, a reminder, the recording, a follow-up on that webinar's subject matter, if that's what you told them at registration.
A problem: three weeks later, adding all 3,000 to a promotional campaign for an unrelated Digital Marketing course, on the theory that they're "in the funnel."
They consented to attend a webinar. They did not consent to a promotional relationship about a different product. If you want that, ask for it at registration as a separate, clearly-worded option, or ask later in a message that is itself within the original purpose.
How to fix this without killing your pipeline
- Ask upfront. Add a second, unticked box at registration: "Also send me information about Brand's courses and programmes." A meaningful share will tick it.
- Segment on it. Your CRM needs a field for what each contact consented to, per channel, with a date.
- Design a consented bridge. During the webinar and in the follow-up, both within purpose, invite people to opt in to more. A live CTA converts far better than a cold email later.
- Stop treating "in the CRM" as "marketable." Being in your database is not consent. This is the mental shift.
Withdrawal mechanics
The rule that catches teams out: withdrawal should be as easy as giving consent.
If someone opted in with one tap on a mobile form, they should be able to opt out with comparable ease. Not by emailing an address that bounces. Not by logging into an account they never created. Not by "allow 7 working days."
What good looks like
- Email: a working one-click unsubscribe in every marketing email. Honoured immediately, not on the next sync.
- WhatsApp: an opt-out button on marketing templates, plus keyword handling for STOP, BAND KARO, UNSUBSCRIBE and reasonable variants. Processed automatically.
- SMS: a working opt-out path in the message.
- A preference centre, so people can turn off promotions without losing transactional messages they want.
The suppression discipline
Withdrawal only works if it propagates. Most leaks I've seen come from:
- An exported CSV that predates the opt-out, re-uploaded months later
- A second ESP or BSP that never received the suppression
- A "re-engagement campaign" deliberately targeting people who unsubscribed
That last one is not a grey area. Don't.
Maintain one authoritative suppression list, sync it to every sending system, and check it before every send.
WhatsApp opt-in specifically
WhatsApp deserves its own section because it sits under two sets of rules simultaneously: India's data protection framework and Meta's own platform policies, which have their own opt-in requirements documented at business.whatsapp.com and in the WhatsApp Business Platform docs.
Practical requirements
- Name WhatsApp explicitly at capture. Consent to "updates" is not consent to WhatsApp.
- Record where and when the opt-in happened, and what wording was shown.
- Keep marketing and utility separate. Someone who gave you their number to receive an application status update has not necessarily agreed to promotional broadcasts.
- Honour opt-outs instantly and permanently. Platform-level blocks damage your quality rating; regulatory exposure is the bigger risk.
- Don't buy or scrape numbers. It fails consent requirements, it fails platform policy, and it destroys your sender quality.
If your BSP dashboard lets you upload a CSV and broadcast to it, that capability is not permission. The system will let you do it. That doesn't make it compliant.
What changes about your existing list
The honest audit, in five steps.
1. Inventory your sources
Every list, every source: website forms, lead ads, webinar registrations, event scans, purchased lists, partner lists, offline collection.
2. For each source, answer three questions
- What exactly were people told at the point of capture?
- Did they take a clear affirmative action?
- Can you produce evidence: a screenshot of the form as it was, a timestamped record?
3. Classify honestly
- Clean: explicit, specific, evidenced consent for the purposes you're using it for.
- Uncertain: collected legitimately but with vague or unrecorded consent wording.
- Bad: purchased, scraped, or scoped to a clearly different purpose.
4. Decide the treatment
Bad lists: stop using them. Uncertain lists: discuss a re-permission approach with counsel: typically a message within the original purpose that invites explicit opt-in going forward. Clean lists: keep, and make sure the record is retrievable.
5. Fix the intake before you fix the backlog
There's no point re-permissioning 40,000 contacts while your forms keep producing non-compliant ones. Fix capture first.
Data principal rights, in marketing terms
People whose data you hold have rights, and marketing teams are usually the ones who receive the requests.
- Access: what do you hold about me, and who did you share it with?
- Correction and erasure: fix it, or delete it.
- Grievance redressal: a route to complain to you, before escalating.
- Nomination, the ability to nominate someone to exercise rights in defined circumstances.
Practically, marketing needs: a monitored inbox, a documented internal process, an owner, and the ability to actually find and delete a person across every system, including that spreadsheet on someone's laptop.
A practical compliance checklist
At capture
- [ ] Unticked, clearly visible consent checkboxes
- [ ] Purposes listed separately and in plain language
- [ ] Channels named explicitly (email, WhatsApp, SMS, phone)
- [ ] Withdrawal method stated inline
- [ ] Privacy notice linked and actually readable
- [ ] Form wording versioned and archived
In storage
- [ ] Consent recorded per purpose and per channel, with timestamp and source
- [ ] The exact notice text shown is retrievable for each record
- [ ] Retention period defined and enforced
In sending
- [ ] Suppression list checked before every send, in every system
- [ ] Marketing and transactional streams separated
- [ ] Working one-click unsubscribe in every marketing email
- [ ] WhatsApp opt-out keywords handled automatically
In operations
- [ ] A named owner for data requests in the marketing team
- [ ] A documented process to find and delete a person across all systems
- [ ] Vendor list reviewed, every tool that touches personal data
- [ ] Reviewed with qualified counsel
Frequently Asked Questions
Does the DPDP framework apply to my small startup?
The framework applies broadly to the processing of digital personal data in India, and it isn't limited to large companies, though certain obligations scale with the nature and volume of processing. Whether and how specific obligations apply to your business is a legal question. Read the official material and ask counsel.
Can I email people who gave me their card at an event?
Depends entirely on what you told them and what they agreed to. A card handed over for a follow-up conversation is not obviously consent to a marketing newsletter. The safe practice: at the event, tell people explicitly what you'll send, and capture the opt-in there.
Is a pre-ticked checkbox ever acceptable?
For consent to marketing, treat it as not acceptable. Consent requires a clear affirmative action, and a box the user didn't tick isn't one.
Can I keep marketing to my existing list?
Audit it first. Where consent was explicit, specific and evidenced for the purposes you're using, you're in a much stronger position. Where it wasn't, discuss re-permissioning with counsel rather than assuming grandfathering.
Do transactional messages need marketing consent?
Messages necessary to deliver something the person asked for, order confirmations, application status, class reminders, payment receipts, sit in a different category from promotional messaging. The line gets blurred the moment you add promotional copy to a transactional message. Keep them clean and separate.
What counts as a valid consent record?
Broadly: who consented, when, through which form or interface, what wording they saw, which purposes and channels they agreed to, and any subsequent withdrawal with its timestamp. If you can't reconstruct the screen the person saw, your record is weak.
How does this affect lead-gen ads on Meta and Google?
The consent language in the platform's lead form is the notice your users see, so it needs the same care as your own forms. Configure the form's custom questions and consent text deliberately rather than accepting defaults, and sync the consent state into your CRM.
Can I share leads with a partner institution?
Only with consent that specifically covers that sharing, and the person should understand who is receiving their data. "And our partners" without definition is not specific.
What happens if we get it wrong?
The framework provides for financial penalties, and the specifics are set out in the statute. More immediately for marketers: platform-level consequences like WhatsApp quality-rating damage and email deliverability collapse arrive faster than any regulator does.
Where do I read the actual official sources?
Start with the Ministry of Electronics and Information Technology at meity.gov.in, which publishes the Act and the associated rules and consultation material. Then take the specific questions to counsel: this post is orientation, not advice.
I write about growth and lifecycle marketing for Indian edtech and startup brands, including the compliance-shaped parts nobody enjoys. If you're rebuilding your consent capture and list hygiene and want a practitioner's view alongside your legal advice, that's the kind of thing I write about at younusfardeen.com.