Services Industries Products Free Tools Insights About Contact Call +91 88006 74252 WhatsApp us Book a call →
Automation

DPDP Consent: Fixing Your Lead Forms Before 2027

A marketer’s reading of what the DPDP Rules mean for the checkbox at the bottom of your enquiry form, and the CRM behind it.

India’s Digital Personal Data Protection Rules were notified on 14 November 2025 with a phased runway, and the lead-capture patterns most Indian brands run today will not meet the standard the DPDP Act sets for consent. The Act requires consent given without coercion, specific, informed, unconditional and unambiguous, through a clear affirmative action. Pre-ticked boxes fail that. Bundled consent fails it. Silence fails it. The substantive notice and consent obligations commence on 14 May 2027, which sounds distant and is not, because the work is in your CRM rather than on your form.

In this article

What was notified, and whenThe phased dates, including one our sources disagree onWhat a compliant lead form actually looks likeWhy the patterns you are running now failThe notice: what goes in it and where it goesPurpose limitation, and the campaign your CRM wants to runWithdrawal, and what your CRM must actually supportThe children’s data problem, and who has itWhat the Consent Manager phase means for a brandA practical sequence, starting this quarter

What was notified, and when

The Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 on 14 November 2025. That date holds up. It is consistent across every source we checked, including a law-firm summary from Shardul Amarchand Mangaldas, the public encyclopaedic record, and a Press Information Bureau release carrying the title of the notification itself.

The Rules give operational shape to the Digital Personal Data Protection Act, 2023, which had been passed but largely un-commenced. The Act supplies the principles. The Rules supply the machinery: how consent is to be recorded, what a notice must contain, how breaches are reported, who counts as a Significant Data Fiduciary, and how Consent Managers are to be registered and supervised.

The translation for marketers is short. Every enquiry form, every WhatsApp opt-in, every newsletter signup and every downloadable brochure gate is a consent collection point, and each one now has a legal standard it either meets or does not.

One caveat before going further. This is a marketer’s reading written for people who run campaigns, not legal advice, and nothing here substitutes for counsel who has read the gazette notification against your own specific processing. We have flagged where our sources disagree rather than smoothing it over.

The phased dates, including one our sources disagree on

Enforcement is staged across three dates. The law-firm summary we relied on sets them out as 14 November 2025, 14 November 2026 and 14 May 2027, and the broader record agrees on those three.

From 14 November 2025: commencement provisions, the establishment of the Data Protection Board of India, and consequential amendments to the Right to Information Act, 2005 and the Telecom Regulatory Authority of India Act, 1997. The adjudicating body exists from that date.

From 14 November 2026, twelve months after notification: registration of Consent Managers, together with the Board’s powers to inquire into breaches of registration conditions and impose penalties in that context. That date is close.

Then the big one. From 14 May 2027, eighteen months after notification, come the substantive obligations that most marketers care about. Notice and consent requirements, breach reporting, security safeguards, verifiable consent for children and persons with disabilities, Significant Data Fiduciary obligations, and Data Principal rights.

Now the disagreement, stated plainly because a compliance page that hides a conflict is worse than useless. Our sources differ. The law-firm summary places restrictions on transfer of personal data outside India in the 14 May 2027 group alongside the other substantive obligations, while the encyclopaedic summary places cross-border transfer mechanisms in the 14 November 2026 phase alongside Consent Managers. We could not resolve that from the sources we fetched. Our reading, and we mark it as ours, is to plan against the earlier of the two dates, since preparing early costs you a quarter of effort and preparing late costs you a live obligation you have not met.

What a compliant lead form actually looks like

Start with a real example. Take a Gurugram real estate enquiry form, the sort that sits under a project microsite and feeds a sales CRM. Today it collects name, phone, email, budget band and preferred configuration, and it carries one checkbox, usually pre-ticked, that reads something like: I agree to the terms and privacy policy and consent to receive updates.

Here is the shape it needs instead. The fields stay largely as they are, because purpose limitation does not stop you asking for what you genuinely need to answer the enquiry, though it does mean you should stop collecting fields you cannot justify against a stated purpose.

Below the fields sits a notice, not a link. Short, in plain language, stating who is collecting the data, what personal data is being collected, the specific purpose it will be used for, how long it will be retained, and how the person can withdraw consent later. The public record of the Rules describes notices as needing to specify purpose of processing, categories of data collected, retention periods and the mechanisms available to withdraw. A link to a policy document is not a notice. It can sit alongside one.

Then separate, unticked checkboxes. One for the enquiry itself, which is the purpose the person came for. A second, distinct one for marketing communication, worded so it is obvious what it authorises. A third if you intend to share the lead with a channel partner, broker or co-developer, naming that category of recipient, because the person cannot consent specifically to a disclosure you have not described.

Every box starts empty. The person ticks what they want.

For a D2C brand the same structure applies at checkout and at newsletter signup, with the added wrinkle that a transactional order confirmation and a promotional campaign are different purposes and should not share a consent record. One delivers what was bought. The other is marketing, and it needs its own affirmative tick.

Why the patterns you are running now fail

Section 6 of the DPDP Act sets the standard. Take the adjectives one at a time. Consent must be given without coercion, specific, informed, unconditional and unambiguous, and it must be signified by a clear affirmative action, which is a longer list of conditions than any single checkbox on an Indian lead form has ever been asked to carry.

Unambiguous is the one that kills pre-ticked boxes. The Act’s own gloss, as reproduced in the bare-act sources we checked, is that unambiguous means expressed by way of any clear affirmative action and not by mere inaction or disengagement. A box that arrives already ticked records the absence of an action. So does a line saying that by continuing you agree. So does silence.

Specific is what kills bundling. One box, three things. A single checkbox covering terms of service, the privacy policy and marketing consent asks for one action to authorise three unrelated things, leaving a person who wants the product but not the promotional messages with no way at all to express that preference. Splitting the box is not a design flourish. It is the mechanism by which consent becomes specific.

Unconditional is the subtle one. It will also cause the most argument inside marketing teams. The Act’s gloss is that consent must not be made subject to any term or condition that is deceptive or manipulative, or that makes consent a precondition for the provision of a good or service. Read against a lead form, our understanding is that you cannot make marketing consent the price of a brochure download. The gate itself is the problem.

That point deserves a pause. Gated content is the load-bearing wall of most Indian B2C lead generation, and the honest position is that a mandatory marketing tick on a brochure gate looks difficult to defend under an unconditional standard. Take that one to counsel. It is not something to quietly keep doing.

The bare-act sources we checked state directly that pre-ticked boxes, silence and bundled consent do not meet the standard. That is the plainest formulation available.

The notice: what goes in it and where it goes

A notice is not your privacy policy. Your privacy policy is a long document written for completeness. A notice is short, sits at the point of collection, and tells the person what is happening to the data they are about to hand over.

Keep it plain. Per the record of the Rules, a notice needs to specify the purpose of processing, the categories of personal data being collected, retention periods, and the mechanisms available to withdraw consent. Write it in the language of the person filling the form, not the language of your legal team, because a notice nobody can parse fails the informed limb regardless of how accurate it is.

Then the language requirement, which is the one most brands have not costed. Notices must be available in English as well as the twenty-two languages of the Eighth Schedule to the Constitution. Two of our sources state this consistently.

That is a real cost. For a national D2C brand it is a translation project with a maintenance tail, since every time you change a purpose or a retention period you change twenty-three documents rather than one. Our practical advice is to write the notice once, keep it deliberately short so translation stays affordable, and treat notice text as a versioned asset with an owner rather than as copy that anyone in marketing can edit on a Friday.

Placement matters as much as content. The notice belongs where the consent is given, visible without expanding anything, above the checkboxes rather than behind a link beneath them.

Purpose limitation, and the campaign your CRM wants to run

This is where the Act stops being a form-design question. It becomes a data-operations question instead, because consent under Section 6 is limited to the specified purpose and to the personal data necessary for that purpose, which means the sentence you wrote on the form in March quietly defines what your CRM may lawfully do in August. The purpose you stated is the boundary.

Play out the scenario, offered as illustration. A developer collects leads for a residential project in Sector 79 through a campaign in March. The notice names one purpose: answering that enquiry. In August the same developer launches a commercial project and someone in marketing asks for the March list.

Our reading is that the March list was not collected for that purpose. It cannot simply be repurposed. If those leads ticked a distinct marketing box worded broadly enough to cover communications about the developer’s other projects, there may well be a basis for the August send, but if the only consent on record was an enquiry about one specific project, there is not.

So your CRM has to store purpose, not just permission. A single boolean field called opted_in is no longer sufficient, because it cannot answer the question of what the person actually agreed to, and when a Data Principal or the Board asks precisely that question, a boolean gives you nothing whatsoever to show. Permission without purpose is not a record. It is a guess.

What you need is a consent record per purpose, carrying the purpose itself, the notice version shown at the time, the timestamp, the capture source, and the current state. That is a data model change. It is not difficult, but it is not a plugin either, and it is the single item most likely to be underestimated in your remediation plan.

Start it now. May 2027 is nine months of engineering queue away.

Withdrawal, and what your CRM must actually support

The Act requires that withdrawing consent be as easy as giving it. Read that literally. The corollary in the sources we checked is that once consent is withdrawn, the Data Fiduciary must cease processing within a reasonable time unless some other law requires the processing to continue.

That is a demanding test. Consent was given by ticking a box on a mobile form in about one second. Withdrawal, in most Indian marketing stacks today, means finding an unsubscribe link in an email footer, or replying STOP to a WhatsApp message, or in the worst cases writing to a support address and waiting.

Build a symmetric route. A link in every communication that leads to a page listing the purposes that person has consented to, each with a toggle, requiring no login and no support ticket. That page is also where the person exercises the granularity you gave them at collection, switching off promotional messaging while keeping order updates.

Then make withdrawal propagate. This is where most stacks break, because the consent state lives in the CRM while the actual sending happens from an email platform, a WhatsApp BSP dashboard, an SMS gateway and whatever an agency is running on the side, each holding its own stale copy of the list.

A withdrawal that updates the CRM and not the BSP is not a withdrawal at all. It is merely a record of an intention that your systems then ignore, and the person keeps receiving messages, which is precisely the harm the provision addresses. So audit every downstream system holding a copy of a contactable list, and make sure suppression flows outward automatically rather than through a monthly export. Automatically. Not on somebody’s checklist.

The children’s data problem, and who has it

The Rules require verifiable parental or lawful guardian consent before processing the personal data of a child, meaning anyone under eighteen. Alongside that sits a prohibition. Platforms are not to track children, behaviourally monitor them, or serve them targeted advertising.

Verification is operationalised rather than left abstract. The law-firm summary describes verification that the consenting adult is an identifiable adult, potentially through a virtual token mapped to details of age and identity issued by an authorised entity, which is a meaningfully harder bar than a checkbox asserting adulthood.

Exemptions exist for certain fiduciaries and purposes, and the final Rules added tracking the real-time location of a child for her safety to the exempted list, which was not in the draft. Check whether you qualify. If you operate in education, paediatric healthcare or child safety, the exemption analysis is genuinely worth doing properly with counsel.

Most of our clients assume this does not apply to them. Real estate does not sell to minors. A furniture D2C brand does not either.

The exposure is not in who buys. It is in who the audience overlaps with, and any brand whose social advertising reaches an audience containing under-eighteens, or whose site is browsed by them, or whose contest entries and app installs pull in teenagers, has a children’s data question to answer even though no minor is a customer. Consider the D2C apparel brand running Instagram campaigns, where a substantial slice of engagement is realistically under eighteen, and behavioural retargeting is switched on by default across the whole audience.

So measure first. Our reading is that the honest opening step is measurement rather than policy: find out what your actual age distribution looks like in the platforms you already run, before deciding you sit outside scope.

This phase is new. Consent Managers are described in the public record of the Rules as registered, independent digital platforms that must maintain technical and security standards for interoperability. Registration commences 14 November 2026, together with the Board’s powers to inquire into breaches of registration conditions.

The concept is that a person can manage consents given to many organisations through one interface, giving, reviewing and withdrawing in a single place rather than chasing each brand separately. Portability, applied to permission.

Our reading, and it is only a reading, is that most brands in real estate, hospitality and D2C will not become Consent Managers. Most will be counterparties instead. That shapes what you should build now, because a consent record that exists only inside a proprietary CRM field with no clean way to be read, updated or withdrawn through an external interface is going to be awkward when that phase matures.

Not a big-bang integration. It argues instead for keeping your consent records structured, timestamped and addressable per purpose, so that when an interoperability requirement arrives you are exposing something that already exists rather than reconstructing consent history from campaign logs.

Watch the date. Do not build for it blind, because the registration framework commences in November 2026 and the operational picture will be considerably clearer once actual registered Consent Managers exist and brands can see what integrating with one really involves.

A practical sequence, starting this quarter

Order matters here. Do it in this sequence, because the dependencies run one way and starting with the form is the mistake almost everyone makes.

One: inventory. List every place your organisation collects personal data. Website forms and landing pages. Microsites run by agencies, WhatsApp opt-ins, offline event registrations digitised later, channel partner spreadsheets, contest entries. The list is always longer than the marketing team expects, and the forgotten microsite from a campaign two years ago is still collecting.

Two: map purposes. For each collection point, write the actual purpose in one sentence. Where you cannot state one, you have found something to stop collecting.

Three: the data model. Fix it before you touch the interface, adding per-purpose consent records with notice version, timestamp, source and state. This is the long pole and it belongs in an engineering sprint now, not in early 2027.

Four: rebuild the forms. Unticked separate boxes, notice at the point of collection, no bundling, no mandatory marketing tick as the price of access. This part is fast once the model behind it exists.

Five: the withdrawal route. Build the page and wire suppression outward to every downstream sender, then test it properly by withdrawing a real record and confirming that nothing at all sends from any system afterwards.

Six: notice translation. English plus the Eighth Schedule languages, with a named owner and a version history.

Seven: age exposure. Measure it, then decide.

Eight: take the whole thing to counsel. Everything above is a marketer’s reading of published summaries, offered so that you arrive at that conversation with your systems mapped rather than with a blank page, and it is not legal advice.

Key takeaways

  • India’s DPDP Rules were notified on 14 November 2025, with enforcement phased across 14 November 2025, 14 November 2026 and 14 May 2027.
  • Consent must be given without coercion, specific, informed, unconditional and unambiguous, signified by a clear affirmative action.
  • Pre-ticked boxes, bundled single checkboxes and silence-as-consent do not meet the standard, per the bare-act sources we checked.
  • Purpose limitation means a lead collected for one project cannot simply be reused for another campaign, so your CRM must store purpose and not a single opt-in flag.
  • Withdrawal must be as easy as giving consent and must propagate to every downstream sender, not only to the CRM record.
  • Notices must be available in English and the twenty-two Eighth Schedule languages, so keep the notice short and version it properly.
FAQ

DPDP consent and lead forms — questions, answered.

When do the DPDP obligations actually apply to my marketing? +

The Rules were notified on 14 November 2025. Data Protection Board provisions commenced immediately, Consent Manager registration commences 14 November 2026, and the substantive notice and consent obligations commence 14 May 2027. Our sources disagree on whether the cross-border transfer framework falls in the 2026 or the 2027 group, so we suggest planning against the earlier date.

Is a pre-ticked consent checkbox really not allowed? +

The DPDP Act requires consent to be unambiguous, expressed by a clear affirmative action and not by mere inaction or disengagement. A pre-ticked box records the absence of an action rather than the presence of one. The bare-act sources we checked state directly that pre-ticked boxes, silence and bundled consent do not meet the standard. Start every box empty.

Can I keep one checkbox covering terms, privacy policy and marketing? +

Our reading is no, because consent has to be specific. One action authorising three unrelated things gives a person who wants your product but not your promotional messages no way to say so. Split them: one for the enquiry or transaction, a separate one for marketing communication, and another if you intend to share the lead with partners.

Can I reuse an old lead list for a new campaign? +

Only if the consent on record covers that purpose. Consent is limited to the specified purpose, so a lead who enquired about one residential project has not thereby agreed to marketing for a different commercial launch. If your consent record is a single opt-in flag with no purpose attached, you cannot demonstrate what was agreed, which is itself the problem to fix.

What does my CRM need to support? +

A consent record per purpose rather than one boolean field, each carrying the purpose, the notice version displayed, the timestamp, the capture source and current state. It also needs a withdrawal route as easy as the original opt-in, and automatic suppression propagating to every downstream sender including your email platform, WhatsApp BSP and SMS gateway.

Do the children’s data provisions apply if I do not sell to minors? +

Possibly, because exposure comes from audience overlap rather than from who buys. The Rules require verifiable parental consent for under-eighteens and prohibit tracking, behavioural monitoring and targeted advertising directed at children. A brand whose social advertising or website reaches teenagers has a question to answer. Measure your actual age distribution before concluding you are out of scope.

What language do our privacy notices need to be in? +

Two of our sources state that notices must be available in English as well as the twenty-two languages of the Eighth Schedule to the Constitution. That makes notice text a translation programme with an ongoing maintenance cost, so write it short, assign it an owner, and version it rather than letting anyone edit the copy without a change record.

Is this article legal advice? +

No. It is a marketer’s reading of published summaries of the DPDP Act and Rules, written so that campaign and CRM owners can map their own systems before speaking to counsel. We have flagged where our sources conflict and where a statement is our inference. Any decision about your specific processing should be taken with a qualified lawyer.

HR
Written by
Himanshu Ranjan · Founder & Lead Engineer, Pantheraa

Ready to replace guesswork with a growth engine?

Book a 30-minute strategy call. We’ll show you exactly where your funnel is leaking, before you spend a dollar.

A senior strategist replies within 4 business hours. Prefer the full brief? Use the contact form.

Call WhatsApp
Chat with Co-Founder