DPDP Rules for marketing leaders: what changes on 14 November 2026 and 14 May 2027
The big consent and notice duties do not bite until May 2027, but the marketing stack takes months to fix. Here is a clear plan for leaders who own leads, data and ad spend.
Key takeaways
- Under Rule 1 of the DPDP Rules, Rule 4 (Consent Managers) starts one year after gazette publication, which is 14 November 2026. Most duties for businesses, including notice, security, breach and erasure, start 18 months after, on 14 May 2027.
- Every data collection point needs a standalone notice that lists the personal data and the specific purpose in plain language, plus an easy way to withdraw consent.
- Lead forms, WhatsApp opt-ins, retargeting audiences and bought lists are the highest risk parts of a marketing stack. Audit them first.
- The PIB explainer lists penalties of up to ₹250 crore for failing to keep reasonable security safeguards, and up to ₹200 crore each for breach notification and children’s data failures.
- Use the next six months as a 30/60/90 day project, not a May 2027 scramble.
What changes, and when
India’s Digital Personal Data Protection (DPDP) Rules, 2025 phase in over 18 months. Rule 4, which sets up registered Consent Managers, applies from 14 November 2026. The duties that hit marketing teams directly, such as notices, security safeguards, breach intimation and erasure, apply from 14 May 2027. The sensible plan is to fix your lead and data stack now.
The Government notified the Rules on 14 November 2025, as the PIB explainer DPDP Rules, 2025 Notified records. The commencement clause in the gazette text of the Rules is short:
| Rules | When they apply | What they cover |
|---|---|---|
| 1, 2 and 17 to 21 | 14 November 2025 | Short title, definitions and the Data Protection Board |
| 4 | 14 November 2026 | Registration and obligations of Consent Managers |
| 3, 5 to 16, 22 and 23 | 14 May 2027 | Notice, security safeguards, breach intimation, erasure, children, rights and more |
This is a summary for marketers, not legal advice. Your company lawyer or a privacy counsel should confirm how the Act applies to your sector, especially if you handle health, financial or children’s data.
Why this lands on the marketing P&L
Marketing is usually the largest collector of personal data in a business: lead forms, WhatsApp chats, call tracking, event badges, loyalty sign-ups, retargeting pixels and CRM imports. The PIB explainer sets out the penalty ceilings under the Act:
- Up to ₹250 crore for failure to maintain reasonable security safeguards.
- Up to ₹200 crore each for failing to notify the Board and affected individuals of a breach, and for breaching children’s data obligations.
- Up to ₹50 crore for any other violation of the Act or Rules by a Data Fiduciary.
Those are ceilings, not predictions. The real cost for most brands is slower lead capture, a re-permissioned list that shrinks, and rework in the stack. Better to pay that cost on your timeline than a regulator’s.
The notice and consent standard your forms must meet
Rule 3 describes what a notice to a customer must do. It must be presented and understandable independently of other information, use clear and plain language, give an itemised description of the personal data, and state the specified purposes and the specific goods or services enabled by the processing. It must also tell the person how to withdraw consent, with the ease of doing so comparable to how it was given, how to exercise their rights, and how to complain to the Board.
For a marketer, that translates into five practical tests for every form and opt-in:
- Standalone. The notice is not buried in a long privacy policy that nobody reads.
- Itemised. It names the data you collect (name, phone, email, city, budget) rather than saying “information you provide”.
- Specific purpose. “To call you about your enquiry” is a purpose. “For marketing purposes” bundled with everything else is not specific.
- Easy withdrawal. If it took one tap to opt in on WhatsApp, withdrawal should not need an email to a support inbox.
- Provable. Keep a record of what notice was shown, when, and what the person agreed to.
Where your marketing stack is most exposed
Lead forms and landing pages
Pre-ticked boxes, one checkbox covering calls, WhatsApp, email and partner offers, and notices hidden behind a footer link are all patterns to retire. Revisit your landing page templates and ask whether each field is necessary for the purpose you state. Fewer fields usually improve conversion as well.
Retargeting and custom audiences
Audiences should be built from data collected for a purpose that includes advertising. Uploading a purchased list, an old event database or a partner’s customers is the riskiest habit. Our guide to responsible retargeting covers the platform rules; add the consent question to your checklist.
WhatsApp and call follow-up
Conversations are personal data. Define who can see them, how long they are kept and how an individual can ask for them to be corrected or removed. Our piece on WhatsApp Business marketing shows a clean opt-in approach.
Agencies, freelancers and SaaS vendors
If an agency runs your ads or an automation tool holds your leads, they process data on your behalf. The PIB explainer describes the Data Fiduciary as the entity that decides why and how data is processed, and a Data Processor as one that processes on its behalf. Your contracts should say what the vendor may do, how data is secured, and what happens at the end of the engagement.
Breach, erasure and rights requests: the operational duties
Rule 7 requires a Data Fiduciary that becomes aware of a breach to tell each affected person without delay, in plain language, covering what happened, likely consequences, the mitigation steps and a business contact. It also requires a report to the Board, including a detailed report within 72 hours of becoming aware of the breach, or a longer period the Board allows. Rule 8 and its Third Schedule set erasure periods and a 48 hour advance warning to the person, but only for listed classes: large e-commerce entities, online gaming intermediaries and social media intermediaries above stated user thresholds. Most brands are not in those classes, though the principle of not keeping data without a purpose still applies.
The PIB explainer adds that Data Fiduciaries must respond to access, correction, update or erasure requests within a maximum of ninety days, and must publish contact details for queries, which can be a designated officer or a Data Protection Officer. Decide now who owns these requests in your company. Marketing, support and IT all touch the data, so name one accountable person and write a one page runbook.
Children’s data and sensitive campaigns
The PIB explainer states that processing a child’s personal data needs verifiable consent from a parent or guardian, unless it relates to essential services such as healthcare, education or real time safety. Education brands, toy and gaming brands and family apps should review sign-up flows, age gates and any audience targeting that might include minors. Our post on education marketing is a useful companion for admissions teams.
What Rule 4 means for your brand on 14 November 2026
A Consent Manager, in the PIB explainer’s words, is an entity that provides a single, transparent and interoperable platform through which a person can give, manage, review or withdraw consent. Rule 4 lets eligible companies apply to the Data Protection Board for registration, and the Board publishes the registered ones. The Rules also say Consent Managers must be companies based in India.
Brands do not have to register as a Consent Manager. The practical question is whether your systems could accept a consent change that arrives through a third party. If your consent records sit in a spreadsheet or inside a form plugin, that is hard. If they sit in a CRM with a timestamped history per contact, it is routine.
A 30/60/90 day plan for CMOs and founders
| Window | Actions | Owner |
|---|---|---|
| Days 1 to 30 | Map every place you collect personal data. List tools, vendors and audiences. Mark which have a clear purpose and consent record. | Marketing head with IT |
| Days 31 to 60 | Rewrite notices and forms to meet the Rule 3 tests. Remove unnecessary fields. Add a one step withdrawal link to WhatsApp and email flows. | Marketing and legal |
| Days 61 to 90 | Move consent and contact history into one system of record. Review vendor contracts. Write the breach and rights request runbook and run one drill. | CMO, CTO, legal |
After day 90 you still have well over six months before May 2027 to fix what the audit uncovers, retire risky audiences and test the runbook. That buffer is the point of starting in October.
Why a single system of record makes this easier
Most compliance pain is a data scatter problem: a lead lives in an ad platform, a spreadsheet, a WhatsApp export and a salesperson’s phone. When someone asks what you hold about them, nobody can answer. A CRM that stores every enquiry, call and chat against one contact, with source and consent notes, turns a multi week hunt into a lookup. Be12 CRM is built for exactly this: capture leads, calls and WhatsApp in one place. Our guide to choosing a CRM in India lists what to look for, including data export and user permissions.
The bottom line
Rule 4 arrives on 14 November 2026, and the duties that shape everyday marketing arrive on 14 May 2027. Treat the gap as a funded project: audit the stack, fix the notices, clean the audiences, contract your vendors properly and give one person ownership. Check the Rules themselves with your counsel, since sector specific provisions may apply to you.
Frequently asked questions
When do the DPDP Rules apply to businesses?
The Rules were notified on 14 November 2025. Rules 1, 2 and 17 to 21 applied immediately, Rule 4 on Consent Managers applies from 14 November 2026, and Rules 3, 5 to 16, 22 and 23 (notice, security, breach, erasure, children and others) apply from 14 May 2027.
Do small businesses and agencies need to comply with the DPDP Act?
The Act applies to any Data Fiduciary processing digital personal data in India, which includes brands that collect leads and agencies that handle that data as processors. Small businesses should read the Rules themselves or take legal advice, as some exemptions are limited to specific classes.
Do I need a consent manager?
No. Consent Managers are optional registered intermediaries that individuals can use to manage consent. Rule 4 sets how they register with the Data Protection Board. Your duty is to give a clear notice and honour consent and withdrawal.
What does a DPDP consent notice have to contain?
Under Rule 3, the notice must be understandable on its own, use clear and plain language, give an itemised description of the personal data and the specified purposes, and explain how the person can withdraw consent, exercise rights and complain to the Board.
Can I keep using retargeting and custom audiences?
Only if the data was collected with valid consent for that purpose. Treat any audience built from data without a clear, specific purpose as a risk, and check with your lawyer before May 2027.
Login
Get free audit