Performance Marketing

DPDP Act 2026: What Indian Marketers Must Fix Before Enforcement

You have a Meta Pixel on your website, a Google tag firing on every page, a lead form that asks for a phone number, and a WhatsApp list you have been broadcasting offers to for two years. Almost none of it was built with consent in mind. That was survivable until now. India’s Digital Personal Data Protection Rules were notified on 14 November 2025, and the clock is running. The marketing stack most Indian businesses run today would not survive an audit.

What does the DPDP Act actually require from marketers?

It requires you to collect personal data only after clear, itemised, freely given consent, to state exactly what you will use it for, and to let people withdraw that consent as easily as they gave it. Marketing data is personal data.

Under the DPDP Rules, 2025, privacy notices must be standalone and plain, not buried in terms and conditions, and must spell out the specific purpose of each processing activity. EY India’s guide to the notified Rules stresses itemised notice, purpose-based retention timelines and documented security safeguards. Data principals – your customers and leads – get rights of access, correction, erasure and withdrawal. And this is not a tech-company law. As Dr Pavan Duggal, Advocate at the Supreme Court of India, put it, the Act applies to all data fiduciaries, and non-compliance can pose an existential threat to organisations. Retailers, clinics, coaching centres, real estate firms and D2C brands are all in scope.

How ready are Indian businesses right now?

Barely ready at all. A February 2026 study of more than 6,000 Indian websites found that 95.9% deploy tracking cookies with no consent mechanism whatsoever. Only 4.1% show any consent notice.

The research, “The State of Cookie Compliance in India, 2026” by ComplyZero Research, analysed over 84,000 tracking cookies across 24 industry sectors. The findings:

  • Only 249 of the 6,000-plus websites displayed any form of user consent mechanism.

  • Nearly 80% of sites begin tracking users before consent is granted.

  • Around 82% of tracking technologies serve marketing or advertising, not essential site function – which means they need consent.

  • Media sites were the heaviest trackers at an average of 30 tracking technologies per page; e-commerce sites averaged 24 cookies per visit.

Awareness is just as thin. A PwC India survey of 3,233 consumers and 186 organisations found that only 16% of Indian consumers understand the DPDP Act, and just 9% of organisations report a comprehensive grasp of its provisions. If you are reading this, you are already ahead of nine in ten Indian businesses.

What deadlines do you need in your calendar?

Three. The Rules were notified on 14 November 2025 with an 18-month phased rollout. The Consent Manager framework lands in November 2026. Full enforcement, with financial penalties, begins on 14 May 2027.

  1. 14 November 2025 – MeitY notifies the DPDP Rules, 2025. The phased 18-month implementation window opens.

  2. November 2026 – Rule 4 takes effect. Consent Managers registered with the Data Protection Board of India give users one interface to give, review and withdraw consent across every business they deal with. Expect withdrawal rates to rise the moment this goes live.

  3. 14 May 2027 – full enforcement. Penalties reach ₹250 crore per violation. The Data Protection Board of India is already operational.

What happens to your Meta and Google ad tracking?

You will observe fewer conversions, because tags that used to fire on every visitor will now fire only on consenting ones. Modelling fills part of the gap, but only if your account clears a volume threshold. Smaller Indian accounts often do not.

Google’s own documentation sets a minimum for conversion modelling under consent mode: roughly 700 ad clicks over a seven-day period per country and domain grouping. Below that, you simply lose the data. Google states that consent mode recovers a large share of lost ad-click-to-conversion links through modelling, but recovery is never guaranteed and it scales with your consented traffic.

The response is not to rip out the pixel. It is to implement consent mode v2 and Meta’s consent signals properly, so the platforms know a user declined rather than seeing nothing at all, and to build a first-party data asset. Consented email addresses and phone numbers in your CRM outlast every cookie and platform identifier. They power enhanced conversions, offline conversion imports and lookalike seeding – all of which keep working when browser signals do not.

Do WhatsApp broadcasts and bought lists still work?

Broadcasts work only where you can evidence consent for each recipient. Bought and scraped lists do not survive the Act at all, because you cannot produce a consent record you never collected.

  • Every recipient of a marketing broadcast must have affirmatively consented, and you must hold a timestamped consent record for each one.

  • Consent is purpose-bound. Someone who gave a number to book a site visit has not consented to festive offers on an unrelated product line.

  • Withdrawal must be as easy as opting in. A working STOP or unsubscribe path in every channel is not a courtesy any more.

  • Anyone under 18 is a child under the Act. Verifiable parental consent is required before processing their data, with Rule 10 setting the verification methods including DigiLocker-based checks – and tracking, behavioural profiling and targeted advertising to children are prohibited outright. Edtech, coaching, toys, kidswear and gaming brands should read that twice.

What can you fix this week?

Most of this is a week of work, not a year. As ComplyZero founder Virat Shah noted, the tools already exist; what is missing is the awareness that consent is now a legal requirement rather than a best practice. Work through this list in order.

  1. Run a cookie scan on your website and list every tag that fires before a user clicks anything.

  2. Install a consent banner that genuinely blocks marketing and analytics tags until opt-in. No pre-ticked boxes, no “by continuing you agree”.

  3. Rewrite your privacy notice as a standalone, plain-language document with an itemised purpose for each type of data you collect.

  4. Add a purpose-specific consent checkbox to every lead form, and store the timestamp, source and exact wording version alongside the lead.

  5. Audit your WhatsApp and email lists. Split contacts you can evidence consent for from those you cannot, and stop marketing to the second group.

  6. Wire Google consent mode v2 and Meta’s consent signals correctly, then check that modelled conversions are actually appearing in your accounts.

  7. Move budget towards first-party data capture – gated content, loyalty sign-ups, offline conversion uploads and enhanced conversions.

  8. Name one person accountable for data protection, publish a contact point, and write down what you would do in the first 72 hours of a breach.

There is an upside here that most people miss. A consented list converts better than a scraped one, and a business that can prove where every contact came from can invest in retention without fear. Compliance and performance are pulling in the same direction for once.

Make your marketing DPDP-ready with AdiAnsh Media

AdiAnsh Media is a Pune-based digital marketing agency working with Indian and international brands across Google and Meta ads, SEO and AI search visibility, social media management, AI Reels and UGC content, Wix Studio web design, Shopify development and branding. We rebuild consent-safe tracking, fix lead forms and tag setups, and keep performance campaigns running on first-party data instead of borrowed cookies. If your pixels, forms or WhatsApp lists need an honest audit before the deadlines land, get in touch with us.

Chat with us