DPDP Compliance Checklist for Marketers (2026–27)

What India's DPDP Act and Rules mean for lead forms, email, WhatsApp, ads and CRM data, with the compliance timeline and a channel-by-channel checklist.

Published 26 September 2026 by Web Hippo in Strategy

Not legal advice This article explains the DPDP Act and Rules from a marketing operations point of view, based on the official texts published by MeitY. It is not legal advice. Have a lawyer review your specific notices, consent flows and contracts.

DPDP compliance is about to become a marketing problem, not just an IT problem. India's <strong>Digital Personal Data Protection Act, 2023</strong> governs every piece of personal data your marketing touches: the phone number on a lead form, the email list, the WhatsApp opt-ins, the retargeting audience built from website visitors. The DPDP Rules, 2025, notified in November 2025, set the timeline. Most obligations switch on in <strong>May 2027</strong>.

That sounds distant, but consent is collected when data is gathered. A lead captured today with a pre-ticked checkbox and no proper notice is a lead you may not be able to use once the rules apply. This guide explains what the law requires in plain language and turns it into a checklist for each marketing channel.

The DPDP Timeline: What Applies When

In January 2026, MeitY proposed bringing some deadlines forward. As of September 2026 we have not seen an amending notification, so the dates above stand. Watch MeitY for changes.

Five DPDP Terms Marketers Need to Know

  • <strong>Data Principal:</strong> the person the data is about, such as your lead, customer or subscriber. For a child, it includes their parent or guardian.
  • <strong>Data Fiduciary:</strong> whoever decides why and how the data is used. That is your business, even if an agency runs the campaigns.
  • <strong>Data Processor:</strong> anyone processing data on your behalf, such as your CRM, email platform, WhatsApp BSP or marketing agency.
  • <strong>Consent Manager:</strong> a registered platform that lets people give, review and withdraw consent across businesses. These must be Indian companies registered with the Board.
  • <strong>Significant Data Fiduciary:</strong> a business the government designates because of the volume or sensitivity of the data it handles. It carries extra duties: an India-based Data Protection Officer, independent audits and impact assessments.

What Valid Consent Looks Like Under DPDP

Section 6 of the DPDP Act says consent must be <strong>"free, specific, informed, unconditional and unambiguous with a clear affirmative action"</strong>, limited to the data needed for the stated purpose. Withdrawing it must be as easy as giving it. For marketing teams, that translates into a few concrete rules:

  • <strong>No pre-ticked boxes.</strong> The person must actively tick, tap or type.
  • <strong>Separate purposes, separate consent.</strong> "Contact me about my enquiry" and "send me offers on WhatsApp" are different purposes. Bundling them into one checkbox fails the "specific" test.
  • <strong>No forced consent.</strong> You cannot make marketing consent a condition of getting a quote or downloading a brochure, unless the marketing is genuinely necessary for that service.
  • <strong>One-tap withdrawal.</strong> If someone opted in with one tap, they must be able to opt out with roughly one tap: an unsubscribe link, a "STOP" reply, a toggle in their account.
  • <strong>Collect only what you need.</strong> A callback form needs a name and phone number. Asking for date of birth "just in case" is hard to justify.

The notice that must come with consent

Rule 3 requires a notice that stands on its own, in clear and plain language, available in English or any of the 22 languages in the Eighth Schedule of the Constitution. It must list the personal data you collect item by item, the specific purposes, and links to withdraw consent, exercise rights and complain to the Data Protection Board. A long privacy policy linked from the footer is not the same thing. The notice should appear where the data is collected.

When you don't need fresh consent

Section 7 lists "legitimate uses". The one most relevant to marketing covers data a person <em>voluntarily provides for a specified purpose</em> without objecting to its use. The Act's own example is a pharmacy sending a receipt to a customer who shared their phone number to receive it. This covers transactional use, such as sending the quote someone requested. It does <strong>not</strong> cover adding them to a promotional list.

Children's Data: The Biggest Change for Some Sectors

Under the DPDP Act a <strong>child is anyone under 18</strong>, not under 13 as in many other countries. Section 9 requires verifiable parental consent before processing a child's data. It also prohibits <strong>"tracking or behavioural monitoring of children or targeted advertising directed at children"</strong>, with limited exemptions for areas such as healthcare, education and safety.

This hits coaching institutes, ed-tech, schools, gaming, youth fashion and snack brands hardest. Retargeting a 16-year-old who visited your JEE coaching page is exactly the kind of processing the law restricts. Plan campaigns around parents, and review how your forms establish whether a lead is under 18. Our education marketing page covers how we approach admissions campaigns.

DPDP Checklist by Marketing Channel

Cookies: not named, still covered

Neither the Act nor the Rules use the word "cookie". But cookies and pixels that identify a person, or combine with other data to do so, collect personal data, so the general consent and notice rules apply. Law firms such as Khaitan & Co recommend purpose-specific cookie consent, no dark patterns, and records of consent and withdrawal. Strictly necessary cookies, such as those that keep a cart working, are a different matter from advertising pixels.

SMS and calls: TRAI rules apply as well

Commercial calls and SMS in India are also regulated by TRAI's TCCCPR regulations, which apply alongside DPDP. TRAI's July 2026 direction makes the <strong>140 number series mandatory for promotional calls</strong>, which people can block by category through DND. The 1600 series is reserved for service and transactional calls from RBI, SEBI, IRDAI and PFRDA-regulated entities and government. Promotional calls from ordinary 10-digit mobile numbers are not allowed.

Breaches, Rights Requests and Penalties

If lead data leaks, whether from a misconfigured form, a shared spreadsheet or a vendor's breach, Rule 7 requires you to inform affected people without delay and to notify the Data Protection Board, followed by a detailed report <strong>within 72 hours</strong>. People can also ask to access, correct or erase their data, and you must respond within 90 days. In practice, marketing teams need to know where every copy of a lead list lives.

These are ceilings. The Board decides actual penalties based on factors such as how serious the breach was and whether it recurred. Still, "any other breach", which covers things like invalid consent, carries up to ₹50 crore. That is well beyond the cost of fixing a form.

A Realistic Plan for the Next Eight Months

  • <strong>October–November 2026, map your data.</strong> List every place personal data enters (forms, ads, chats, events, walk-ins) and everywhere it is stored (CRM, sheets, email tool, BSP, agency drives).
  • <strong>December 2026–January 2027, fix collection.</strong> Rewrite notices, split consent checkboxes, update ad lead forms and add a proper cookie banner. New data collected from here on is clean.
  • <strong>February–March 2027, clean the past.</strong> Run a re-permission campaign for older contacts with unclear consent. Delete what you cannot justify keeping, and stop using bought lists.
  • <strong>April 2027, set up processes.</strong> Vendor contracts, a breach response plan, a way to handle rights requests, and a named person accountable for marketing data.
The upside nobody mentions A consented list is smaller and far more responsive. In our experience, removing contacts who never really opted in usually improves open rates, WhatsApp quality ratings and cost per lead. DPDP forces a clean-up most businesses should have done anyway.

If you need help rebuilding lead capture, consent flows and tracking so they are compliant and still convert, our web development and marketing strategy teams can audit your current setup. Our GA4 and attribution guide covers tracking in a consent-first setup, and the email marketing guide covers building opt-in lists properly.

Frequently Asked Questions

<em>Sources: DPDP Act, 2023 and DPDP Rules, 2025 (MeitY); TRAI press release 91/2026. Last checked 22 September 2026. This article is general information, not legal advice.</em>

This article was written by Web Hippo, a goal-based digital marketing agency in Hyderabad, India. Get in touch for a custom growth strategy.