India · Data Protection

The DPDP Act for Marketers: Consent Rules for SMS, WhatsApp, Email and Websites

India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 change how businesses collect and use customer data for marketing. Here is what marketers need to know and do before the main obligations apply.

By the DND Teams editorial team · Updated

For years, Indian businesses collected phone numbers and email addresses through forms, contests, walk-ins and purchased lists with little formal structure. The Digital Personal Data Protection Act, 2023 (DPDP Act) changes that. Together with the Digital Personal Data Protection Rules, 2025, notified by the Government of India in November 2025, it sets clear rules on notice, consent, security and individual rights.

For marketers, the most important change is that consent must be real: specific, informed and freely given, with an easy way to withdraw. This guide explains what that means for SMS, WhatsApp, email, ads and websites, and gives a practical checklist. It is general information, not legal advice; for complex data uses, speak to a lawyer.

Key terms in plain English

  • Data Principal: the individual whose personal data you process, such as a customer or lead.
  • Data Fiduciary: the business that decides why and how personal data is processed, which is usually you.
  • Data Processor: a company that processes data on your behalf, such as your SMS provider, CRM, email platform or marketing agency.
  • Consent Manager: a registered entity that lets people give, manage, review and withdraw consent through an interoperable platform.
  • Data Protection Board of India: the body that handles complaints, inquiries and penalties.

When do the obligations apply?

The DPDP Rules are being brought into force in phases. According to the commencement provisions in Rule 1 of the DPDP Rules, 2025 and the Government of India press note:

  • Provisions on definitions and the Data Protection Board took effect when the Rules were notified in November 2025.
  • Rules on registration and obligations of Consent Managers take effect one year after notification, in November 2026.
  • Most operational obligations, including the detailed notice requirements, security safeguards, breach intimation and rights handling, take effect eighteen months after notification, in May 2027.

That gives businesses a transition window, but changing forms, CRMs, vendor contracts and consent records takes time. Starting now avoids a rush later.

What valid consent looks like

Under the Act, consent must be free, specific, informed, unconditional and unambiguous, given with a clear affirmative action. It must be limited to the personal data needed for the specified purpose. In marketing terms:

  • No pre-ticked boxes. The customer must actively tick or tap to agree.
  • Separate purposes. Agreeing to order updates is not agreement to promotional messages. Ask separately for marketing.
  • No bundling. Do not make marketing consent a condition of buying a product or using a service unless it is genuinely needed.
  • Clear language. The request must be in clear and plain language, and the person should be able to read the notice in English or any of the languages listed in the Eighth Schedule of the Constitution.
  • Easy withdrawal. Withdrawing consent must be as easy as giving it. If someone opted in with a tick box, they should be able to opt out with one tap or reply.

The notice you must give

When you ask for consent, you must give a notice explaining, at minimum, what personal data you are collecting and for what purpose, how the person can withdraw consent and exercise their rights, and how they can complain to the Board. The Rules require the notice to be understandable on its own, and to give an itemised description of the data and a specific description of the purposes.

For a website enquiry form, this can be a short notice beside the form with a link to a fuller privacy notice. For WhatsApp opt-in, it can be a short message with a link. For in-store collection, it can be printed on the form or a QR-code page.

What this means for each channel

SMS

India's SMS rules already require DLT registration, correct categories and respect for DND preferences. The DPDP Act adds a data protection layer: collect consent properly, record it, and stop processing for marketing when someone withdraws. DLT consent templates for service explicit messages do not automatically satisfy all DPDP requirements, so keep your own records. See our guide to SMS categories.

WhatsApp

WhatsApp already requires opt-in before you message customers. Make sure your opt-in wording is specific (for example, "Send me offers and updates on WhatsApp"), recorded with date and source, and that a "Stop" option works across your systems. Our WhatsApp Business API setup guide covers opt-in collection.

Email

Use clear sign-up forms, separate marketing consent from account emails, and include a working unsubscribe link in every marketing email.

Websites, analytics and ads

Review the personal data your website collects: forms, chat widgets, call tracking, pixels and analytics. Explain this in your privacy notice and collect only what you need. Our website designing team builds forms with clear notices and consent checkboxes.

Purchased or rented lists

Lists bought from third parties are high risk. If you cannot show that each person consented to receive marketing from your business for this purpose, do not use the list.

Children's data

The Act defines a child as anyone under 18. Processing a child's personal data requires verifiable consent from a parent or lawful guardian, and the Act prohibits tracking, behavioural monitoring and targeted advertising directed at children, subject to exemptions in the Rules. Coaching institutes, schools, edtech platforms and youth brands should review their lead forms, ads and messaging carefully.

Rights you must support

Individuals have rights to obtain information about their data, to correction, completion and erasure, to grievance redressal, and to nominate someone to act for them. Practically, you need:

  • A contact point (email or form) for data requests and complaints
  • A process to find a person's data across your CRM, SMS, WhatsApp and email tools
  • A way to delete or correct data and confirm it to the person

Security and breaches

You must take reasonable security safeguards to prevent personal data breaches, and, once the relevant Rules apply, notify the Board and affected individuals of breaches. For marketing teams, this means limiting who can export contact lists, using strong passwords and two-factor authentication on marketing tools, and avoiding sharing spreadsheets of customer data over personal WhatsApp or email.

Penalties

The Act sets penalties in its Schedule, including up to ₹250 crore for failing to take reasonable security safeguards to prevent a breach, and up to ₹200 crore for failing to notify a breach or for breaching the obligations relating to children. Penalties are decided by the Board based on factors such as the nature and seriousness of the breach.

Your DPDP marketing checklist

  1. Map where you collect personal data: website, ads, WhatsApp, events, stores, partners.
  2. Rewrite forms with clear notices and separate, unticked marketing consent.
  3. Record consent with date, time, source, wording and purpose.
  4. Make withdrawal easy on every channel and sync opt-outs across tools.
  5. Review vendors (SMS, WhatsApp, CRM, agencies) and update contracts to cover processing on your behalf and security.
  6. Stop using purchased lists without provable consent.
  7. Review campaigns that might reach children.
  8. Set up a process for data requests and breach response.
  9. Train staff who handle customer data.

How DND Teams helps

DND Teams, based in Bhopal, helps businesses across India update websites, forms and messaging journeys so consent is collected clearly and recorded properly. We configure opt-in and opt-out flows for bulk SMS, WhatsApp and email, and build digital marketing campaigns that rely on consented data. For legal interpretation of complex cases, we recommend speaking with a qualified data protection lawyer.

Get a custom quote

Working with clients in India, the US, UK, Canada, Australia and the UAE, DND Teams replies with a short written review and a clear quote, with no obligation. Get a custom quote for making your forms, website and messaging DPDP-ready, or message us on WhatsApp at +91 88274 09728.

Not ready for a full project? Start with our Ads pilot (1 month) for US$199 (one-time, paid in advance). Price covers our setup and 4-week management work only. Ad spend is paid separately (directly to Google or Meta). Need more? Get a custom quote. See how our pricing works for what affects your price.

Prices shown are indicative ranges in US dollars and exclude taxes and third-party charges (such as Meta or carrier fees, billed at cost) unless stated. Your price depends on your requirements; get a custom quote for an exact figure. This article is general information, not legal advice, and reflects our understanding as of October 2026.

Get a free audit from DND Teams

Tell us about your business and we will send a short written review with clear next steps and a quote. No obligation.

Frequently Asked Questions

When does the DPDP Act apply to marketing?

The DPDP Rules were notified in November 2025 and apply in phases. Board provisions applied immediately, Consent Manager rules apply after one year, and most operational obligations such as notices, security and rights handling apply eighteen months after notification, in May 2027.

Do I need consent to send marketing SMS or WhatsApp messages under DPDP?

For most marketing, consent is the appropriate basis. It must be free, specific, informed and unambiguous with a clear affirmative action, separate from consent for order or service messages, and easy to withdraw.

Are pre-ticked consent boxes allowed under the DPDP Act?

No. Consent requires a clear affirmative action, so the person must actively tick or tap to agree. Pre-ticked boxes do not show clear, unambiguous consent.

Can I market to students under 18?

Processing a child's personal data requires verifiable consent from a parent or guardian, and the Act prohibits tracking, behavioural monitoring and targeted advertising directed at children, subject to limited exemptions in the Rules.

What are the penalties under the DPDP Act?

Penalties are set in the Act's Schedule, including up to ₹250 crore for failing to take reasonable security safeguards and up to ₹200 crore for failing to notify breaches or for breaching children's data obligations.

Request Your Free Audit

Tell us what you need and we will get back to you, usually within one working day.

  • Free requirement discussion
  • Clear written quotation, in USD on request
  • No long lock-in for most services

Prefer to talk? Call +91 88274 09728 or message us on WhatsApp.