Skip to content

ARKA // PrivéClient-ConfidentialNeed-to-know

Mumbai // HQ19.0330° N  73.0297° EIST

Back to Briefings

File 0001— DATA AND CONSENT

Unclassified // Cleared for release

The List Is a Liability: what the DPDP Rules change for a marketing and communications team

India's data protection law is coming into force in stages, its main duties apply from May 2027, and they reach the contact list a marketing team already holds.

File
PPR-004
Kind
paper
Date filed
Reading time
12 min

File 0002The paper

Key points

  • The main duties under the DPDP Act and Rules, including notice, consent, erasure, children's data and breach intimation, apply from May 2027; consent manager registration opens in November 2026.
  • Marketing has no legitimate-use ground of its own, so a list needs either a provable consent or a narrow section 7 basis such as replying to an enquiry.
  • Processing based on a consent given before commencement can continue once a notice is sent, but bought, scraped or unsourced contacts carry no consent to continue.
  • The brand stays responsible for what its agencies and software vendors do with the list, and needs a valid contract with each of them.
  • Maximum penalties reach ₹250 crore for failing to take reasonable security safeguards and ₹50 crore for notice, consent and erasure failures.

Prepared by ARKA's desk from public sources, not by lawyers. General information, not legal advice.

This paper sets out the timetable, what notice and consent will require, what to do with the list already held, and how the duties reach lead forms, WhatsApp opt-ins, agencies and overseas tools.

Where the law stands in October 2026

The Digital Personal Data Protection Act became law in August 2023 [1]. The Rules that make it workable were notified as G.S.R. 846(E), dated 13 November 2025 [2]. Commencement is staggered [2][3]:

  • On publication: definitions, the Data Protection Board and the rule-making powers.
  • One year on: registration of consent managers (section 6(9) and rule 4).
  • Eighteen months on: the duties a marketing team has to meet, including notice, consent, legitimate uses, erasure, children's data, individuals' rights, breach intimation, cross-border transfers and penalties (among them sections 3 to 17, other than section 6(9), and sections 28 to 34; rules 3 and 5 to 16).

The calendar dates are November 2026 and May 2027, on the 13th or the 14th: the Gazette is dated 13 November 2025, while its e-Gazette reference number and the government's press note carry 14 November [2][3][4]. Plan to the 13th.

In January 2026 the Financial Express reported that the ministry was considering a cut from eighteen months to twelve and had asked industry for comments by 4 February [5]. Legal commentary published in September 2026 still treats the notified timetable as the law [6][7], and the ministry's own page for the Rules, as we read it on 4 October 2026, listed nothing later than a December 2025 corrigendum [12]. Confirm the dates again before relying on them.

Notice and consent

Personal data may be processed only with consent or for one of the "certain legitimate uses" in section 7 [1].

A request for consent must come with a notice, given with the request or before it [1]. Rule 3 says the notice must be presented, and be understandable, independently of anything else the business has told the person, and must be in clear and plain language. It must itemise the personal data, state the specific purpose, describe the goods, services or uses involved, and give the link through which she can withdraw consent, exercise her rights and complain to the Board [2]. She must be able to read it in English or in a language listed in the Eighth Schedule to the Constitution [1].

Consent itself must be "free, specific, informed, unconditional and unambiguous", given by a clear affirmative action, and it covers only the data necessary for the stated purpose [1]. The Act's own illustration is a telemedicine app that asks for the phone's contact list: the consent does not extend to the contacts, because the service does not need them [1].

The ease of withdrawing consent must be comparable to the ease of giving it. After a withdrawal the business and its processors must stop within a reasonable time, unless a law requires or authorises the processing [1].

If consent is questioned in a proceeding, the business must prove that the notice was given and the consent obtained. [1]

The business must also publish contact details of a person who can answer questions about processing, and publish the period, of no more than ninety days, within which it will respond to grievances [2].

Legitimate uses

Section 7 is a closed list, and marketing is not on it [1]. The entry that matters to a campaign is the first: data a person has voluntarily given for a specified purpose, where she has not said she objects. The Act's example is a property broker, who may use an enquirer's details to send her rental options and must stop once she says she no longer needs help [1]. The other entries concern the State, legal obligations, court orders, emergencies and employment [1].

Erasure and retention

Unless another law requires retention, personal data must be erased when consent is withdrawn or when it is reasonable to assume the purpose is no longer served, whichever comes first. Processors must be made to erase it too [1].

The Rules fix a period for three classes of business only: e-commerce entities and social media intermediaries with two crore or more registered users in India, and online gaming intermediaries with fifty lakh or more. For them, most purposes are treated as spent three years after the user's last contact (or after the Rules commence, if later), and the user must be warned at least forty-eight hours before erasure [2]. Everyone else must choose a period it can defend under the general test.

Rule 8(3) sets a minimum in the other direction. Every data fiduciary must keep personal data, associated traffic data and processing logs for at least one year from the date of processing, for the government purposes listed in the Seventh Schedule, and then erase them unless another law or a government notification requires longer [2]. The rule's illustration says the record is kept even if the customer deletes her account [2]. Read together, a withdrawal ends marketing use within a reasonable time, while the record may have to be held, out of use, until the year is up. That reading is ours and is untested; take advice on it.

Children

A child is anyone under eighteen [1]. Before processing a child's data a business needs the verifiable consent of a parent or lawful guardian, and it may not track children, monitor their behaviour or direct targeted advertising at them [1]. Rule 10 describes how to check that the person consenting is an adult: against reliable identity and age details the business already holds, or against details she provides voluntarily, directly or as a virtual token issued by an authorised entity, including through a Digital Locker service [2]. The Fourth Schedule exempts some health, education and child-safety processing, and the processing needed to confirm that a user is not a child [2]. The Rules do not prescribe how a brand with a general audience should establish a user's age in the first place [2].

Consent managers and significant data fiduciaries

A consent manager is a company incorporated in India, with a net worth of at least two crore rupees, registered with the Board, that runs a platform through which people give, manage, review and withdraw consents. It must not be able to read the personal data shared through it, and it keeps the consent record for at least seven years [1][2]. Once the main duties commence, withdrawals may reach a marketing team through such a platform [1].

The government may notify a business, or a class of businesses, as a significant data fiduciary on factors that include the volume and sensitivity of the data it handles [1]. Those notified must appoint a data protection officer based in India and an independent data auditor, and carry out an impact assessment and an audit every twelve months [1][2]. In January 2026 none had been named [5], and we found no notification since.

Breach intimation and penalties

A personal data breach includes accidental disclosure or sharing that compromises confidentiality [1], so a lead sheet emailed to the wrong recipient is likely to count. On learning of a breach, the business must tell each affected person without delay, tell the Board without delay, and give the Board a fuller report within seventy-two hours or any longer period the Board allows on a written request [2]. The duty stays with the business when the breach happens at its agency or software vendor [1][8].

Duty What it means for a campaign Applies from Source
Notice and consent (ss. 5, 6; r. 3) A self-contained, itemised notice and a purpose-specific opt-in given by a clear affirmative action, with proof kept May 2027 [1][2]
Withdrawal and erasure (ss. 6, 8, 12; r. 8) An opt-out as easy as the opt-in, carried through to the CRM and every vendor May 2027 [1][2]
Children (s. 9; rr. 10, 12) Verifiable parental consent; no tracking or targeted advertising to under-18s May 2027 [1][2]
Security and processors (s. 8; r. 6) A valid contract with each agency and tool, with security terms; access logs kept for a year May 2027 [1][2]
Breach intimation (s. 8(6); r. 7) Tell affected people and the Board without delay; detailed report to the Board in 72 hours May 2027 [1][2]
Consent managers (s. 6(7) to (9); r. 4) Withdrawals may later arrive through a registered platform Registration November 2026; rest May 2027 [1][2][3]

The Schedule to the Act sets maximum penalties: ₹250 crore for failing to take reasonable security safeguards, ₹200 crore for failing to give notice of a breach, ₹200 crore for breaching the duties on children's data, ₹150 crore for a significant data fiduciary's additional duties, and ₹50 crore for a breach of any other provision, which is where notice, consent and erasure failures fall [1]. The Board may impose a penalty where it finds a breach significant, after hearing the business, and it weighs gravity, duration, repetition and mitigation, among other factors, in setting the amount [1].

The list you already hold

Section 5(2) deals with consent given before commencement. The business must send a notice "as soon as it is reasonably practicable" and may continue processing until the person withdraws [1]. Section 1(2) says a reference to commencement means the date the provision itself comes into force, so on its face this covers consents collected up to May 2027 [1]. The provision is not yet in force, and no ruling confirms that reading.

The provision assumes a consent exists. A purchased or scraped list carries no consent given to you, a visiting card typed into the CRM is not a recorded consent to marketing, and the burden of proving consent is yours [1]. Writing in August 2023, as the Bill went through Parliament, one Indian law firm warned that many of the broad consents then in use would fall short and that continued processing would need fresh consent [9]. The exclusion for publicly available data is narrow: it covers data the person herself made public, or data that someone else published under a legal duty [1].

Before May 2027, that means sorting the list into three piles. Contacts with a provable marketing consent get the section 5(2) notice. Customers with a real relationship and no marketing consent are asked for it, with a rule 3 notice. Contacts with no known source are taken out of use and deleted, unless a law requires the record to be kept.

Lead forms and WhatsApp opt-ins

A person who fills in an enquiry form has given her details for that enquiry, and section 7 allows a reply to it [1]. Adding her to a newsletter or a retargeting audience is a second purpose and needs its own consent. Ask only for the fields the purpose needs.

WhatsApp's Business Messaging Policy already requires that the person has given you her number or username and has opted in to receive your messages, and it makes the business responsible for an opt-in that complies with the law [10]. The Act adds a notice, a consent the business can prove, and an opt-out comparable in ease to the opt-in. SMS and voice campaigns also fall under TRAI's commercial communication regulations, amended in February 2025 to require an opt-out option in promotional messages and to bar a fresh consent request for ninety days after an opt-out [11]. The Act applies in addition to other laws [1].

Agencies as data processors

The brand that decides why and how data is used is the data fiduciary. An agency or platform that processes data on its behalf is a data processor [1]. The fiduciary remains responsible whatever the contract says, may engage a processor only under a valid contract, and must include security safeguards in that contract [1][2]. A LiveLaw analysis in September 2026 lists what else the contract should carry: processing only on documented instructions, prior approval or notice before sub-processors are engaged, breach notice fast enough to meet the seventy-two hours, audit rights, and deletion certified in writing at exit [8]. A vendor that keeps the right to use client data for its own analytics may be a fiduciary itself [8]. A person may ask for the identities of every processor her data has been shared with, so keep that list current [1].

Cross-border tools

A CRM or an email platform may keep its data outside India. From May 2027, section 16 allows transfers except to a country or territory the government restricts by notification, and rule 15 lets the government set requirements for making data available to a foreign State or a body it controls [1][2]. No restricted list had been published by September 2026 [6][7]. Other laws that restrict transfers more tightly continue to apply [1]. Record where each tool keeps its data, and write contracts that can change when a notification arrives [6][7].

ARKA's Signal Corp desk runs campaigns on consented data, for a stated purpose, and signs a data processing agreement where it handles a client's customer data. It does not give legal advice; how the Act applies to a particular list is a question for the client's counsel.

What to do with this

  • Diarise November 2026 and May 2027, and check for amendments each quarter.
  • Record the source, date and consent wording for every segment of the list.
  • Stop buying lists, and retire contacts whose source cannot be shown.
  • Rewrite each form notice to the rule 3 standard.
  • Separate the marketing opt-in from the enquiry and leave it unticked.
  • Make opting out one step on every channel, and carry it through to vendors.
  • Decide how under-18s are treated before any targeting is planned.
  • Sign a data processing agreement with every agency and tool that holds the list.
  • Write a breach drill that can meet the seventy-two hours.
  • Publish a contact for data questions and set a retention period.

Sources

  1. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Gazette of India, Extraordinary, Part II, Section 1, No. 25  (opens in a new tab)

    Ministry of Law and Justice; copy hosted by the Ministry of Electronics and Information Technology

    Dated 11 August 2023 // Read 2026-10-04

  2. Government notifies DPDP Rules to empower citizens and protect privacy  (opens in a new tab)

    Press Information Bureau, Government of India (Ministry of Electronics and IT)

    Dated 14 November 2025 // Read 2026-10-04

  3. DPDP compliance timeline may be cut to 12 months  (opens in a new tab)

    The Financial Express

    Dated 22 January 2026 // Read 2026-10-04

  4. Preparing for the DPDA  (opens in a new tab)

    Cyril Amarchand Mangaldas, India Corporate Law blog

    Dated 7 August 2023 // Read 2026-10-04

  5. WhatsApp Business Messaging Policy  (opens in a new tab)

    WhatsApp

    Dated Last updated 23 September 2026 // Read 2026-10-04

  6. TRAI Strengthens Consumer Protection with Amendments to TCCCPR, 2018  (opens in a new tab)

    Press Information Bureau, Government of India (Ministry of Communications)

    Dated 12 February 2025 // Read 2026-10-04

This note is general information as of the date it was filed. It is ARKA's reading of public sources, prepared by a communications and advisory firm and not by lawyers. It is not legal, tax or investment advice; take advice on your own facts from a qualified professional.

File 0003— Open a channel

Discuss this paper

Sending an enquiry does not bind you to anything. It opens a confidential conversation.

Status
  • SYSTEM STATUS: OPTIMAL
  • THREAT LEVEL: LOW
  • GLOBAL SENTIMENT: MONITORING
  • MUMBAI // HQ: ONLINE
  • OPEN-SOURCE SIGNALS: ELEVATED
  • MARKET SENTIMENT: STABLE
  • CHANNEL: TLS-ENCRYPTED
  • ARKA OPS: ONLINE
  • DISCRETION PROTOCOL: ACTIVE
  • EUROPE RELAY: CONNECTED