How should sales teams handle consent for lead data under the DPDP Act? Under the DPDP Act 2023, sales teams should treat every lead source differently based on how the data was obtained and what the person agreed to. A first-party inbound lead who filled a form and agreed to be contacted has a clear consent basis; an event or webinar lead has consent scoped to what was disclosed at capture; a purchased or scraped list generally has none and is the highest risk. A sales data consent framework maps each lead source to its lawful basis, provides the exact consent-capture language for forms and calls, defines an opt-out and deletion workflow that actually removes the person from outreach, and specifies the CRM fields (source, consent status, timestamp, opt-out flag) that make the whole system auditable. This framework gives sales and marketing leaders that structure for both B2B and B2C selling, so consent is designed in rather than assumed.
A DPDP sales data consent framework that maps every lead source to its lawful basis, gives you the consent-capture language, an opt-out workflow and the CRM fields to make it auditable — built for both B2B and B2C selling.
The heart of the framework is a map that assigns every lead source a clear standing under the DPDP Act. Inbound web-form leads who submitted their details and agreed to be contacted have the strongest position — consent is explicit, scoped and time-stamped. Event and webinar leads have consent scoped to what was disclosed at the point of capture, so what the registration page said about follow-up matters. Referral and partner-shared leads depend on what the referring party was permitted to share and whether the individual was told. Purchased, scraped or third-party lists generally have no demonstrable consent and no clear source, placing them at the highest-risk end of the map. Enrichment-appended data sits in a grey zone that depends on the enrichment source's own basis.
For each source, the map states the standing (strong / conditional / high-risk), the specific question sales must be able to answer (what did this person agree to, and can we prove it), and the safer handling rule. This turns an abstract legal question into an operational lookup: a rep or a marketing manager can find any lead type on the map and immediately know how to treat it, rather than guessing. It is the foundation the rest of the framework builds on, because consent language, opt-out workflow and CRM design all follow from correctly classifying where a lead came from.
This section provides the actual wording to use at the point of capture, because consent under DPDP must be free, specific, informed and unambiguous — and vague, bundled or pre-ticked consent does not meet that bar. For web forms it gives clean opt-in language that names the specific purposes (for example, to respond to the enquiry, and separately, to send product updates), with the marketing purpose as a distinct, unticked option rather than bundled into a single 'I agree' box. For events and gated content it gives the disclosure line that scopes follow-up correctly. For phone and in-person capture it gives the short verbal script a rep uses to record what the prospect agreed to.
Critically, the language separates the two purposes sales tends to conflate: consent to respond to a specific enquiry versus consent to ongoing marketing. A prospect can want the first without the second, and bundling them is one of the most common consent defects in Indian sales funnels. The section also covers the informed element — a short, plain-language line telling the person who is collecting the data and why, with a link to the full privacy notice — so the consent captured is genuinely valid and not merely a checkbox that would not survive scrutiny.
Lead sources selected for your framework:
Sales and marketing run on personal data — lead lists, contact records, engagement history — and the DPDP Act 2023 makes how that data is collected and used a compliance question, not just a commercial one. The central concept is lawful basis: for most outreach and marketing, an organisation needs consent (or an equivalent basis) to hold and use a prospect's personal data, and that consent must be free, specific, informed and revocable. In practice this means the standing of every lead depends on where it came from and what the person agreed to — which is exactly what most sales operations never systematically track. A sales data consent framework fixes that by making source, purpose and consent status explicit for every lead.
Without a framework, consent is assumed rather than demonstrated, and assumption is what fails under scrutiny. If a prospect complains, or the Data Protection Board asks, the organisation needs to show a traceable source and a valid consent for the outreach — not a general belief that 'they were interested'. Designing consent into the funnel from capture to opt-out, and recording it in the CRM, is what turns an unauditable pile of leads into a defensible, well-governed sales operation.
Many companies sell to both businesses and consumers, and the consent expectations are not identical. B2B outreach to a professional contact in their business capacity generally has more latitude, while B2C marketing to individuals as consumers demands clearer, opt-in consent and easier opt-out. The mistake is to run one loose process for both, or to over-engineer B2B while under-protecting B2C. A good framework defines a single operational system — one lawful-basis map, one consent-capture standard, one opt-out workflow, one set of CRM fields — that flexes correctly between the two, so the team follows one process while still meeting the stricter B2C bar where it applies.
With DPDP enforcement expected around May 2027, building this framework now means new leads are captured correctly from the start rather than requiring a painful retrospective clean-up of a non-compliant database later. Niti Bharat runs fixed-price DPDP compliance engagements (Rs 75,000–Rs 3.2 lakh) that implement this consent framework alongside the privacy notices, vendor governance and breach-response programme it connects to, so the sales team's consent practice is part of a coherent, organisation-wide compliance posture.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.