Marketing teams using email lists, SMS campaigns, WhatsApp broadcasts, and digital advertising face significant DPDP Act exposure. Every contact in your database must have a valid, documented, purpose-specific consent. Purchased lists, inferred consent, and legacy opt-ins are not valid under DPDP Act 2023.
DPDP compliance for marketing — email/SMS/WhatsApp consent, CRM data protection, cookie framework, and marketing agency DPA.
Every person in your email marketing database must have given specific, documented consent to receive commercial communications from your organisation. Under DPDP Act 2023, consent must be: informed (they knew what they were signing up for), specific (for the specific type of communication, not blanket), freely given (not a condition of accessing a core service), and withdrawable (with a mechanism to unsubscribe without friction).
Valid Consent Sources: (a) Website sign-up forms with an explicit checkbox (pre-ticked checkboxes are not valid) and a clear description of what they will receive. (b) App onboarding with in-flow consent notification for marketing emails. (c) In-store POS sign-up with a written record. (d) Event registration with explicit marketing opt-in (separate from event confirmation).
Invalid Consent Sources: (a) Purchased or rented email lists — the original consent was not given to your organisation. (b) Business card collection at events without specific email marketing consent. (c) Existing customer emails added to marketing lists without separate marketing consent. (d) Emails collected through 'enter to win' promotions where marketing consent was not clearly stated.
Consent Record Requirements: For each email address in your database, maintain: (a) date consent was given, (b) the specific consent language shown to the user, (c) IP address (for digital sign-ups), (d) consent form version, (e) what marketing types were consented to (newsletter, promotional, event invites). This record must be producible in a DPB inquiry within 72 hours of request.
SMS and WhatsApp marketing require explicit, prior consent under both TRAI TCCCPR regulations and DPDP Act 2023. TRAI's Telecom Commercial Communications Customer Preference Regulations have been in force since 2019 — DPDP adds a consent documentation and purpose specificity overlay.
SMS Consent Requirements: (a) Prior written or digital opt-in from the recipient. (b) Sender ID registered with TRAI through your telecom operator. (c) Message templates registered with TRAI. (d) National Do Not Disturb (DND) scrubbing before each send. (e) Opt-out mechanism: STOP reply to the SMS must be processed within 5 working days. (f) Consent record with timestamp and opt-in source.
WhatsApp Business Consent: WhatsApp's Business Messaging Policy requires opt-in consent before sending marketing messages. DPDP adds: (a) consent must be explicit and separate from general terms of service, (b) the opt-in must describe the types of WhatsApp messages the user will receive, (c) opt-out (Reply STOP or block) must be immediately honoured, (d) opt-in records must be maintained with timestamp and opt-in channel.
Re-Consent Campaigns: For existing SMS and WhatsApp lists where you cannot confirm DPDP-compliant consent records, run a re-consent campaign before any further sends. Send a single message asking recipients to confirm their consent with a clear opt-in call to action. Remove all non-responders after 30 days. Yes — your list will shrink. But the remaining consented contacts are both legally compliant and genuinely interested.
Marketing teams typically have the largest databases of personal data in the organisation — email lists, CRM contacts, retargeting pixels, event attendee lists, and social media audiences. They are also the fastest-moving function, regularly acquiring new contacts and launching campaigns. This combination — large data volumes + fast-moving processes — creates the highest DPDP compliance risk in most organisations.
The first wave of DPDP enforcement actions globally has consistently targeted marketing practices: non-consensual email marketing, retargeting without consent, and cookie banners that do not actually give users a meaningful choice. Indian marketing teams should expect similar scrutiny from the DPB once enforcement begins in earnest.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.