Global Info Edge
Performance Marketing13 Aug 2026 11 min

The DPDP clock every Indian marketer should have in their calendar

Chandan KumarChandan KumarFounder · Performance Marketing Specialist

Listen to this article

The DPDP clock every Indian marketer should have in their calendar

The short answer

India's Digital Personal Data Protection framework now has dates attached. The Consent Manager registration rule comes into force on 13 November 2026, and the substantive obligations — notice, consent, breach notification, handling data-principal rights — are due in full by 13 May 2027, at the end of the phased implementation. Penalties reach ₹250 crore for security-safeguard failures and ₹50 crore for general non-compliance. For a marketing team the work is narrower than the headlines suggest: a plain-language notice at every point you collect data, an auditable record of who consented to what and when, a working way to withdraw, and a decision about legacy lists collected without any of that. Using a registered Consent Manager is optional.

On this page

Most compliance writing about DPDP is written for lawyers, which is why marketing teams read it, feel vaguely threatened, and change nothing. The practical truth is that the Act asks for things a well-run lead engine should already do: tell people plainly what you are collecting and why, keep proof they agreed, and stop when they ask you to. What it will not tolerate is the Indian default — a form with no notice, a list bought or scraped, and a WhatsApp blast to people who never opted in. Here are the dates, the obligations that touch marketing, and the order I would fix them in.

The two dates that matter

The Rules phase obligations in rather than switching everything on at once. The date doing the rounds is 13 November 2026, when the Consent Manager provisions become operative — that is the registration framework for licensed intermediaries who can manage consent on a person's behalf, and it carries real entry requirements including Indian incorporation and a ₹2 crore net worth. Note what it is not: a requirement that your business use one. It remains optional.

The date that actually governs your marketing is 13 May 2027, when the phased implementation ends and the substantive duties — notice and consent operations, breach notification, honouring rights requests — are enforceable in full. Eighteen months sounds generous until you remember it includes re-papering consent for the data you already hold.

India DPDP: the dates and what they mean for marketing
DateWhat comes into forceMarketing implication
13 Nov 2026Consent Manager registration frameworkOptional to use one; no action required of most businesses
13 May 2027Full compliance at end of phased implementationNotices, consent records, withdrawal and rights handling must all work
OngoingBreach notification dutiesYou need to know who to tell, how fast, and with what detail

This is orientation, not legal advice

I run marketing programmes, not a law practice. Use this to brief your team and scope the work, then have your counsel confirm how the Act applies to your specific data and sector.

What the Act asks of a marketing team, in plain words

Four things. Notice: at the moment you collect personal data, tell the person what you are collecting, why, and how to withdraw — in clear language, and with regard to accessibility in the languages your users actually read. Consent: it must be free, specific, informed and unambiguous, which rules out pre-ticked boxes and bundling marketing consent into terms of service. Records: you must be able to demonstrate that a specific person consented to a specific purpose at a specific time. Rights: people can access, correct, and withdraw, and you need a route that works rather than an inbox nobody reads.

Read that list against your own lead flow and the gaps become obvious fast. The typical Indian enquiry form fails on notice and records, not because anyone intended to cut corners, but because nobody ever asked the form to do that job.

The four obligations that touch every lead form

  1. 1Notice at collection — plain-language, specific to the purpose, not a link to a 4,000-word policy.
  2. 2Unbundled consent — separate, unticked, and never a condition of receiving the service you advertised.
  3. 3An auditable record — timestamp, purpose, the exact wording shown, and the version of the notice.
  4. 4A withdrawal route that works — and that actually stops the sends when used.

The legacy-list problem nobody wants to discuss

Every business has a spreadsheet. Contacts collected over years — trade shows, walk-ins, a purchased list somebody swears was opt-in, WhatsApp groups, an old CRM export. The expectation is that personal data collected before the framework still needs valid notice and consent to keep being used for marketing. That means for each legacy segment you have three honest choices: re-consent it, restrict it to purposes that do not need marketing consent, or delete it.

Re-consenting is uncomfortable because response rates are low and the list shrinks. It is also the single highest-return compliance action, because what remains is a list of people who want to hear from you — which performs better than the bloated version did. I have watched a 40,000-contact database re-consent down to 6,000 and produce more revenue in the next quarter than it had the previous one.

The uncomfortable arithmetic

A list that loses 80% of its contacts to re-consent usually loses close to 0% of its revenue — because the 20% who confirm are the ones who were ever going to buy.

What to fix, in order

Start where data enters. Every form, chat widget, WhatsApp opt-in, lead-ads form and offline capture sheet needs a notice and an unbundled consent, and your system needs to store the proof. Then fix the plumbing: where consent is recorded, how it propagates to your CRM and sending tools, and what happens when someone withdraws — the failure mode that gets businesses in trouble is honouring withdrawal in the email tool but not the WhatsApp tool.

Only then look at vendors. Every tool that touches personal data — CRM, email, WhatsApp provider, analytics, call tracking, ad platforms — is a processor you are responsible for, so you need to know what each holds, where, and under what terms. Do this as an inventory, once, and keep it current; it is also the document that makes a breach survivable.

Sequence that wastes the least effort

  1. 1Inventory — list every place personal data enters and every tool that stores it. One page, brutally honest.
  2. 2Fix collection points — notice plus unbundled consent on every form, chat, lead ad and offline sheet.
  3. 3Make consent auditable — store purpose, timestamp and notice version with the record, not in a screenshot folder.
  4. 4Wire withdrawal end to end — one action must suppress across CRM, email, WhatsApp and ad audiences.
  5. 5Decide on legacy data — re-consent, restrict, or delete. Pick one per segment and document why.
  6. 6Paper the vendors — processing terms, data location, retention and deletion commitments.

Why this is good for your marketing, not just your risk register

Consent hygiene and performance point the same way. Suppressing people who never asked lifts deliverability, protects your WhatsApp quality rating, cuts spend on audiences that would never convert, and makes every report more honest. First-party data collected with a clear purpose is also the asset that survives cookie deprecation and platform signal loss — the same work, serving two masters.

The businesses that will struggle in May 2027 are the ones whose growth depends on contacting people who did not ask. If that describes a meaningful share of your pipeline, the compliance deadline is not your real problem; it is just the date the real problem becomes visible.

₹250 crore

Maximum penalty under the DPDP framework for failing to maintain reasonable security safeguards; ₹50 crore for general non-compliance.

Key takeaways

  • Two dates: the Consent Manager framework is operative from 13 November 2026 (using one is optional), and full compliance is due 13 May 2027.
  • For marketing the work is four things — notice at collection, unbundled consent, an auditable record, and withdrawal that actually propagates everywhere.
  • Legacy lists are the real project: re-consent, restrict or delete each segment, and expect a smaller list that performs better.

Frequently asked questions

What is the DPDP compliance deadline for businesses in India?

The Rules phase obligations in: the Consent Manager registration framework becomes operative on 13 November 2026, and the substantive duties — notice and consent, breach notification, handling data-principal rights — are due in full by 13 May 2027 at the end of the phased implementation period.

Do I have to use a registered Consent Manager?

No. Consent Managers are licensed intermediaries that can manage consent on an individual's behalf, and the framework for registering them comes into force on 13 November 2026 — but using one is optional for businesses. You still need your own valid notice, consent and record-keeping either way.

Does DPDP apply to a small business or only large companies?

It applies to anyone processing digital personal data, with additional obligations for entities notified as Significant Data Fiduciaries. A small business running lead forms and WhatsApp marketing is in scope for notice, consent, records, withdrawal and breach notification.

Can I keep marketing to contacts I collected years ago?

Only if that data is supported by valid notice and consent consistent with the framework. In practice each legacy segment needs a decision: re-consent it, restrict it to purposes that do not require marketing consent, or delete it. Document which you chose and why.

What does a compliant lead form look like?

A short, plain-language notice at the point of collection saying what you collect, why, and how to withdraw; a separate, unticked consent for marketing that is not a condition of the service; and storage of the consent record with its timestamp, purpose and the notice version shown. Withdrawal must then suppress that contact across every tool, not just the one they replied to.

Written by

Chandan Kumar

Mr. Chandan Kumar

Founder & Performance Marketing Director, Global Info Edge

Founder of Global Info Edge and a performance-marketing specialist with 18+ years — Google & Meta ads, conversion funnels and measurable growth.

View full profile