⚙️ CRM & Automation

DPDP Act & Your CRM: The 2026 Consent Checklist for Indian D2C Brands

Your customer list is a growth asset and, from 2026, a compliance liability. India's DPDP Rules were notified in November 2025 with deadlines through 2027 and penalties up to ₹250 crore. Here's how to make your CRM and marketing consent-first before the clock runs out.

DDigistex4u Team7 min read
DPDP Act & Your CRM: The 2026 Consent Checklist for Indian D2C Brands

Your customer database is probably your most valuable growth asset. In 2026 it also became a liability with a price tag. India's Digital Personal Data Protection Rules were formally notified on 14 November 2025, and they change the rules of the game for how a D2C brand collects, stores and markets to customer data. This isn't a distant policy debate. There are dates on the calendar, obligations that touch every opt-in form and win-back flow you run, and penalties large enough to matter to a founder.

The good news is that consent-first marketing isn't only about avoiding fines — done well, it builds a cleaner, more engaged list that performs better. The brands treating DPDP as a forcing function to fix their data hygiene will come out ahead of the ones scrambling at the deadline. Here's what the rules require, the timeline you're working against, and a practical checklist to make your CRM consent-first. (This is general information, not legal advice — run your specifics past a qualified lawyer.)

The timeline you're working against

Per India Briefing, the DPDP Rules 2025 were notified on 14 November 2025, and they phase in rather than landing all at once. Scrut.io's practical guide breaks the runway into two parts worth marking on a wall. Consent Manager registration provisions carry roughly a twelve-month window, pointing to around 14 November 2026. The substantive obligations — consent notices, purpose limitation, retention and erasure, security safeguards and children's data — carry roughly an eighteen-month window, pointing to around 14 May 2027.

That sounds like breathing room. It isn't, if you consider what has to change: every collection point, your retention logic, your unsubscribe flow, and how you handle data requests. Those touch product, marketing and engineering, and they take months to ship properly.

The number that makes this a board issue

The reason this can't stay in the legal team's drawer is the penalty. India Briefing and Scrut.io both note the maximum can reach up to ₹250 crore per instance of non-compliance. Whatever your view on how enforcement will play out, a ceiling that high turns consent from a checkbox into a line item leadership pays attention to.

The heart of the rules is a stricter definition of consent. Per Scrut.io and the rules themselves, consent must be free, specific, informed, unambiguous and given by a clear affirmative action. In plain terms, the customer has to actively choose — a pre-ticked box doesn't count, and neither does burying permission inside a wall-of-text privacy policy that nobody reads.

The notice you show also has to change. It must be standalone and itemised: an explicit list of the exact data you're collecting, the specific purpose you'll use it for, a dedicated way to withdraw, and a contact for questions. "We may use your data to improve your experience" is the kind of vague catch-all the rules are built to end.

Withdrawal has to be as easy as opt-in

One requirement quietly reshapes a lot of marketing plumbing: withdrawing consent must be as simple as giving it. If someone can join your WhatsApp list with one tap, they must be able to leave with one tap. That makes a working, low-friction opt-out non-negotiable across every channel — email, SMS and WhatsApp alike.

How this rewires your CRM flows

The retention rules are where compliance meets everyday marketing. Per India Briefing, you may keep personal data only as long as the stated purpose is served, and for inactive users you must erase the data after the retention period — with advance notice reported as 48 hours before deletion. Certain system logs carry a minimum retention of their own, but the direction for marketing data is clear: you can't hoard a dormant list indefinitely.

That collides head-on with the classic win-back playbook, where brands sit on a cold list and re-blast it every festival season. Under the new regime, win-back has to live inside a defined window, and the smarter move is to build a consent-refresh step — a clear, honest message asking a lapsing customer whether they want to stay, before their data ages out. A shorter, permission-fresh list will out-convert a bloated one anyway.

CRM practice Old habit Consent-first 2026
Opt-in Pre-ticked box, bundled policy Active, specific, itemised consent
Unsubscribe Buried, multi-step One-tap, as easy as opt-in
Dormant list Kept forever, re-blasted Erased after retention, with notice
Win-back Blast the cold list Consent-refresh inside a window
Data requests Ad hoc, slow Answered within the required window
Minors' data Treated like any adult Verifiable parental consent, no ad targeting

The obligations behind the scenes

Two more duties sit behind your CRM and are easy to miss. First, per Scrut.io, you have a maximum window — reported as 90 days — to respond to access, correction and erasure requests, so you need a process to find and act on a person's data quickly, not a frantic manual hunt. Second, per India Briefing, a personal data breach means notifying affected individuals without delay and reporting to the Data Protection Board within 72 hours. That's a runbook you write before you need it, not during a crisis.

Children's data is a hard line

The rules treat anyone under 18 as a child, and per Scrut.io and India Briefing, targeted advertising, tracking and behavioural profiling of children is prohibited, with verifiable parental or guardian consent required to process their data at all. If your brand's audience skews young, this isn't a nuance — it's a redesign of how you collect and use those profiles.

A practical starting checklist

You don't fix all of this at once, but you can start where the risk and the payoff are highest. Audit every place you collect data — website forms, checkout, WhatsApp opt-ins, lead ads — and rewrite each to itemise the data, state the purpose, and capture an active choice. Then fix the exits: make unsubscribe and opt-out genuinely one step on every channel.

Move consent capture into a system that timestamps and stores what each customer agreed to, so you can prove it and honour withdrawals cleanly. Then define retention windows by data type and build the erasure and notice steps into your CRM rather than deleting by hand. This is the kind of operational rebuild — consent capture, retention logic, clean opt-outs — our CRM team sets up for D2C brands so marketing and compliance stop fighting each other.

Don't forget email deliverability

The consent shift lines up neatly with a global change already in force: Gmail and Yahoo's bulk-sender requirements. Per Chronos Agency, senders above 5,000 messages a day must keep spam complaints below 0.10% (with 0.30% a hard failure line), authenticate with SPF, DKIM and DMARC, and offer one-click unsubscribe. A consent-first, permission-fresh list is exactly what keeps complaint rates low and your email landing in the inbox — so compliance and deliverability reward the same behaviour.

The takeaway

DPDP turns your customer list from a thing you accumulate into a thing you steward. The rules were notified in November 2025, the deadlines run through 2026 and 2027, and the penalties are large enough to demand a plan now rather than a panic later. But the work — active consent, honest notices, easy opt-outs, disciplined retention — also builds the cleaner, more engaged list that every good CRM strategy wants anyway. Start with your collection points and your exits, get consent on the record, and let compliance make your marketing better instead of slower. This topic sits at the intersection of law and marketing, so pair this checklist with proper legal advice for your business.

Sources: India Briefing (Dezan Shira), "DPDP Rules 2025 Notified" (notification on 14 November 2025; phased runways; retention and 48-hour erasure notice; 72-hour breach reporting to the Data Protection Board; maximum penalty up to ₹250 crore; Consent Manager requirements). Scrut.io, "India's DPDP Rules 2025: A practical guide" (consent must be free, specific, informed, unambiguous and by clear affirmative action; standalone itemised notices; withdrawal as easy as consent; 90-day window for data-subject requests; prohibition on targeted advertising and profiling of children). Digital Personal Data Protection Rules, 2025 (consent standards; children's data). Chronos Agency, "Gmail & Yahoo Sender Requirements 2026" (5,000-per-day threshold; spam-rate limits of 0.10% and 0.30%; SPF/DKIM/DMARC; one-click unsubscribe). This article is general information and not legal advice.

Frequently asked questions

What is the DPDP Act and when do the rules take effect?
The Digital Personal Data Protection Act is India's data protection law, and its implementing rules — the DPDP Rules 2025 — were notified on 14 November 2025 per India Briefing. The rules phase in: Consent Manager registration provisions carry roughly a 12-month runway (around 14 November 2026), and the core substantive obligations — consent notices, purpose limitation, retention and erasure, security safeguards, children's data — carry roughly an 18-month runway (around 14 May 2027), per Scrut.io. This is general information, not legal advice; confirm specifics with a qualified lawyer.
Does DPDP apply to a small D2C brand, or only big companies?
It applies to any business that processes the personal data of people in India — which includes your customer list, your WhatsApp opt-ins, your email database and your ad audiences. Size doesn't exempt you. Larger or higher-risk processors may face extra obligations, but the core duties around consent, purpose and erasure apply broadly. If you run a CRM, you're in scope.
What counts as valid consent under the new rules?
Per Scrut.io and the rules, consent must be free, specific, informed, unambiguous and given by a clear affirmative action — an active choice, not a pre-ticked box or a checkbox bundled into a long privacy policy. The notice has to be standalone and itemised: exactly what data you collect, the specific purpose, a way to withdraw, and a contact. And withdrawing consent must be as easy as giving it, so a one-tap unsubscribe or opt-out is effectively required.
How does this change my win-back and re-engagement campaigns?
Significantly. The rules require you to erase personal data once the purpose it was collected for has ended, and to give inactive users notice — reported as 48 hours in advance — before deletion. That means you can't legally sit on a dormant list forever and blast it every quarter. Win-back has to run inside a defined retention window and, ideally, include a consent-refresh step that gives lapsed customers a clear reason and a clear choice to stay on your list.

Ready to put this into action?

Digistex4u runs performance, CRM, CRO and growth as one engine for D2C brands. Book a free 20-minute call and we'll map your fastest path to scale.

✉️

Get the D2C growth playbook

One practical teardown a week — the Meta, Google, SEO, CRM and retention tactics we run on real D2C brands. No fluff, no spam.

Join D2C founders getting our weekly growth playbooks. Unsubscribe anytime.