Indian retail chains commonly capture customer phone numbers at the point of sale for billing, warranty or loyalty purposes, then feed that data into a CRM for WhatsApp and SMS marketing — each of these is a separate processing purpose under the DPDP Act 2023 and needs its own specific, informed consent, not an assumption based on the sale itself. Store staff collecting numbers verbally at checkout with no documented consent trail is a common and easily-flagged gap. This guide and checker maps the obligations across POS, CRM and marketing.
POS phone capture, CRM records, WhatsApp marketing — see exactly where your retail data flows need DPDP-compliant consent.
Omnichannel Indian retailers sit at the intersection of several high-volume data flows: point-of-sale phone capture for billing and warranty, CRM systems that consolidate purchase history across stores, and WhatsApp or SMS marketing tools that run campaigns off that CRM data. Each handoff — POS to CRM, CRM to marketing platform — is a separate use of personal data, and most retail chains have never mapped or documented consent across that chain. The most common gap is staff verbally asking for a phone number at checkout with no consent record at all.
This is a high-visibility risk because customers directly experience the downstream effect — an unwanted WhatsApp promotion is the kind of thing that generates a Data Protection Board complaint, unlike a backend security gap a customer would never notice. With enforcement fully active from May 2027, retail chains with multiple outlets and a large customer marketing list are a natural early scrutiny target given complaint volume potential.
The fix does not require ripping out existing POS or CRM systems — it requires adding a consent capture step at billing, tagging what each customer has consented to (warranty follow-up, marketing, loyalty), and honouring that tag consistently across CRM and marketing tools. Niti Bharat's Retail Privacy Policy Generator produces a compliant privacy notice covering both in-store and online data use, paired with practical guidance for billing-counter consent capture, so retail teams can close this gap without disrupting checkout speed.
A one-page PDF mapping consent requirements across POS, CRM and marketing, with sample billing-counter consent language.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.