DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

Under the DPDP Act 2023, using personal data for direct marketing requires a valid lawful basis — usually consent that is free, specific, informed and unambiguous, with a clear affirmative opt-in. Pre-ticked boxes, bundled consent, or marketing to a purchased list without consent do not meet this standard. Every marketing contact must also be able to withdraw consent as easily as they gave it, and you must keep records proving when and how consent was obtained. This checker audits your email and SMS marketing consent against those requirements.

Email & SMS Marketing Consent Audit Checker

Direct marketing under DPDP needs valid, provable consent. Audit your email and SMS lists for opt-in quality, withdrawal, and record-keeping in three minutes.

Audit your marketing consent

Marketing consent audit — what to verify

What valid marketing consent looks like under DPDP

The DPDP Act 2023 treats direct marketing to identifiable individuals as processing of personal data, which needs a valid lawful basis — in most marketing contexts, that means consent. Valid consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action. That rules out several practices Indian marketers have long relied on: pre-ticked opt-in boxes, opt-out-by-default flows, marketing consent bundled into account sign-up, and above all sending to purchased or scraped lists where the contact never consented at all.

Just as important as obtaining consent is the ability to prove it and to honour its withdrawal. Marketers must keep timestamped records of when and how each contact opted in, and every message must carry a genuinely easy way to withdraw — withdrawal must be as easy as consent was to give. A blanket consent that quietly covers marketing plus profiling plus data sharing also fails the 'specific' test and should be broken into purpose-specific consents.

Turning a risky list into a compliant one

For most marketing teams, the practical work is a re-permissioning exercise: audit how your current list was built, remove or re-consent anyone who was never validly opted in, fix the sign-up flow so future consent is affirmative and purpose-specific, and put timestamped consent logging in place. This is uncomfortable in the short term because list size may shrink, but a smaller list of validly consented contacts is far more defensible — and usually more engaged — than a large one built on weak consent.

Niti Bharat helps Indian marketing and growth teams audit and rebuild consent across email, SMS and web forms as part of fixed-price DPDP engagements, putting in place the opt-in design, withdrawal mechanics and consent records that would stand up if a Data Principal complained to the Data Protection Board about unsolicited marketing.

Get the marketing consent audit toolkit (free)

A consent audit worksheet, a re-permissioning email template, and a compliant opt-in and withdrawal design checklist for email and SMS marketing under DPDP.

Frequently Asked Questions

Can we keep marketing to our existing list under DPDP?+
Only if that list was built on valid consent or another lawful basis. If contacts were added through pre-ticked boxes, bundled sign-ups, or a purchased list, you should re-permission them with a clear affirmative opt-in before continuing to market to them.
Is a purchased marketing list legal under DPDP?+
Marketing to a purchased or scraped list where the individuals never consented to hear from you is a serious risk under DPDP, because you cannot demonstrate valid consent. Re-permissioning or removing such contacts is the safer path.
Do we need to keep records of marketing consent?+
Yes, in practice. If a contact complains that they never consented, you must be able to show when and how they opted in. Timestamped consent records per contact are the standard way to demonstrate this.
Does an unsubscribe link satisfy the withdrawal requirement?+
A working, easy-to-find unsubscribe in every email helps, and an equivalent STOP mechanism for SMS. The key is that withdrawal must be as easy as giving consent, and that you actually stop sending once someone withdraws.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Employee Monitoring DPDP CheckerFeature Privacy Risk CheckerFintech Data Sharing Risk CheckerDPDP Compliance Certificate Generator IndiaSee all Calculators tools →📝 DPDP Compliance Pricing India📝 DPDP Compliance Deal Risk