DPDP Compliance Mistakes Indian Businesses Should Avoid: 14 Operational Gaps to Fix
Learn the DPDP compliance mistakes Indian businesses should avoid, from consent and employee data to vendors and erasure, with practical fixes for each gap.

DPDP compliance gaps tend to appear where personal data moves across the business. Customer data travels from websites and stores into CRM and CDP platforms, and from there to marketing tools and agencies. Employee data flows from HR systems to payroll and verification partners. Older records stay in downstream systems long after the purpose for collecting them has ended.
The Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025 govern how organisations handle digital personal data from collection to erasure. Responsibility rests with the Data Fiduciary, the organisation that decides why and how personal data is processed. A Data Processor handles data on the fiduciary's behalf, such as a cloud provider or a marketing agency.
The Rules were notified in November 2025 with a phased timeline. Consent Manager provisions follow a one-year timeline. Most operational obligations follow an 18-month timeline widely computed to end in May 2027.
The 14 mistakes below are grouped into five business areas. Each section explains what the law permits, where its limits lie and how your teams can close the gap.
Customer Data and Consent
1. Treating the Privacy Policy as the Compliance Programme
The Act links the notice duty to consent. Every request for consent must come with a notice, and Rule 3 sets out what that notice contains. The notice should be understandable on its own and describe the personal data and the purpose. Your notice should also explain how people can withdraw consent and exercise their rights, including the route to complain to the Data Protection Board.
Reconcile your notice against actual data flows every quarter, comparing it with collection forms and vendor lists. A named owner for the reconciliation keeps the notice aligned as new campaigns launch.
2. Capturing Consent Once and Treating It as Permanent
Consent under the Act must be specific and informed. Valid consent also requires a clear affirmative action and covers only the data needed for the stated purpose. A pre-ticked box does not meet that standard.
Customer preferences change, so a checkbox captured at registration records a single moment. Where consent is the applicable ground, your teams can maintain it as a living record that captures:
The date and time consent was given
The purpose and the notice version shown
The channel or touchpoint used
Every later change, including withdrawal
3. Bundling Several Purposes Into a Single Consent Request
The Act recognises two grounds for processing. Consent is the first. Section 7 adds a set of legitimate uses, which permit processing without consent in defined situations.
For customer-facing businesses, the most relevant legitimate use covers data a person provides voluntarily for a specified purpose, where they have not objected to its use. An illustration in the Act describes a pharmacy customer who shares a mobile number to receive a payment receipt, and the pharmacy may use the number to send that receipt. Promotional offers to the same number fall outside the specified purpose and need a separate ground, which for most marketing activity is consent.
Map each processing activity to its applicable ground before designing consent journeys. A customer can then accept delivery updates and decline promotional messages, and your systems hold both choices accurately.
4. Leaving Store, POS and Call-Centre Journeys Outside the Consent Framework
The Act applies to personal data collected digitally, and to data collected offline once that data is digitised. A paper form held only on paper remains outside scope, and the same form enters scope when a store associate keys it into a POS or CRM.
Build a consent framework that follows the customer across touchpoints:
Store → POS → Loyalty → CRM → Campaign Platform
Consent captured at the counter should carry the same purpose structure as consent captured online. OTP-based confirmation is one implementation option for store journeys. The Act does not prescribe a specific method.
5. Making Withdrawal Harder Than Opting In
Under the Act, withdrawing consent should be as easy as giving it. Once a person withdraws, the Data Fiduciary must stop processing within a reasonable time and cause its processors to stop as well. Processing carried out before the withdrawal remains lawful, so historical campaign records keep their validity.
Offer withdrawal in the same channel where consent was given, then test the flow on a test profile. Confirm that the CRM and marketing automation tool reflect the change, along with any agency platform.
Employee and HR Data
6. Leaving Recruitment and Employee Data Outside the Programme
HR data has its own ground for processing. Section 7(i) permits processing for the purposes of employment. The same clause covers safeguarding the employer from loss or liability, with examples such as preventing corporate espionage and protecting trade secrets. Benefits or services an employee requests also fall within it.
For employees, the ground generally supports core HR activity:
Payroll, attendance and leave records
Statutory filings and benefits administration
Performance management, security and misconduct investigations
Recruitment needs more care. The Act does not state whether shortlisting, interviews and background checks count as purposes of employment. A common approach is to rely on the voluntary-provision ground for CVs a candidate submits for a role. Background verification through third-party agencies is usually handled with the candidate's consent until regulators clarify the position.
Consent becomes the appropriate ground once employee data is used outside employment. Sharing employee details with partners for their own offers is one example. Using staff photographs in external marketing is another.
The notice duty in the Act attaches to consent requests. An employee privacy notice remains good practice, since it sets expectations and supports grievance handling. Security safeguards and breach intimation apply to HR data on every ground. Unsuccessful candidate records need a defined erasure period, and exit records follow the periods labour and tax laws require.
Vendors, Processors and B2B Data
7. Assuming Vendors Carry the Compliance Responsibility
A Data Fiduciary may engage a Data Processor under a valid contract, and the processor may handle personal data only on the fiduciary's behalf. Accountability for that processing stays with your organisation. The Rules also expect contracts to require processors to maintain appropriate security safeguards.
Review each vendor relationship against six questions:
What personal data is shared, and for what purpose?
Which processors and sub-processors receive it?
Which security controls apply?
How are incidents escalated to your team?
How does the vendor support rights requests and erasure?
What happens to the data when the contract ends?
8. Overlooking Data Processed on Behalf of B2B Clients
Technology providers in the SaaS and loyalty space often hold two roles at once. A software company acts as a Data Fiduciary for its own employee and marketing data. For personal data its enterprise clients send for processing, the same company acts as a Data Processor and may use that data only on the client's instructions.
Document the role for each processing activity and agree written instructions with clients on use and security. Cooperation terms for rights requests and breach response help your clients meet their own obligations.
Data Lifecycle and Governance
9. Retaining Data Indefinitely in Case It Becomes Useful
The Act permits retention for as long as the specified purpose is served. Once consent is withdrawn or the purpose ends, the data should be erased, unless another law requires the organisation to keep it. A bank keeping identity records for the period banking regulations prescribe is an example the Act itself gives.
The Rules add two specific provisions. Large e-commerce, online gaming and social media platforms above set user thresholds follow a three-year inactivity timeline, with notice to the user at least 48 hours before erasure. The Rules also set minimum one-year retention for certain logs and associated personal data.
Your retention schedule can link each data category to its purpose and to sector requirements such as RBI KYC rules. Ask your Legal team to confirm how the one-year floors apply to each system, since they affect when erasure can begin.
10. Deleting From the CRM While Copies Remain Elsewhere
A deletion in the primary CRM leaves copies in every system that received the record. The Act asks the Data Fiduciary to ensure that its processors also erase personal data when the conditions for erasure are met.
Map every downstream copy before designing the erasure workflow:
CDP and marketing automation platforms
Analytics tools and data warehouses
Customer support systems and cloud storage
Agency and vendor platforms
Close each erasure request once every system confirms completion, subject to applicable retention requirements. An erasure log gives your Compliance team evidence of what was removed and when.
11. Losing Track of Where Data Lives and Why It Was Collected
Spreadsheet exports and shared drives hold personal data that formal inventories often miss. Purposes also drift, as data collected for service delivery finds its way into analytics or profiling. Any new use needs its own ground under the Act.
A working data inventory connects six elements for every data category:
The personal data collected
The purpose of collection
The applicable ground for processing
The system holding the data
The internal users and external recipients
The retention period
GDPR teams may know a similar document as a Record of Processing Activities. The DPDP Act does not name it formally, and an inventory remains a practical way to evidence purpose limitation.
Data Principal Rights, Security and Governance
12. Handling Data Principal Requests Through Inboxes and Spreadsheets
Rights to access, correction and erasure apply to data processed on consent and to data a person provided voluntarily for a specified purpose. Grievance redressal and nomination apply more widely. An erasure request can be declined where the data is still needed for the specified purpose or where a law requires retention.
Rule 14 asks organisations to publish how these rights can be exercised and how grievances will be handled. Legal teams are still assessing the exact operation of the response period wording in Rule 14, so organisations should take advice on the period they publish.
A defined workflow gives every request the same treatment:
Receive the request through a published channel
Verify the identity of the requester
Route the request to each system owner
Track progress against the published response period
Close the request and record the outcome
13. Treating Security as an IT-Only Responsibility
The Act requires reasonable security safeguards. Minimum measures in the Rules include encryption and masking, along with access controls and logging. Breach intimation to affected Data Principals and reporting to the Board are also prescribed, and the Rules set no minimum severity threshold for a breach to be reported. Other cyber incident reporting requirements may apply depending on the organisation and the incident.
A joint incident playbook brings your Marketing and HR teams together with key vendors. Role-based access to customer data in campaign tools deserves the same scrutiny as access to production databases.
14. Treating DPDP Compliance as a One-Time Project
New tools and new vendors change your data picture every month. Set governance triggers that prompt a review:
A new product, channel or campaign purpose
A new vendor, integration or AI tool
A change in consent or preference structure
A change in retention requirements
A scheduled quarterly review
Questions Leadership Teams Should Ask
Five questions help CXOs assess readiness without a full audit:
When a customer withdraws marketing consent, how long does each downstream system take to reflect the change?
Can we retrieve the notice version and purpose attached to any customer's consent?
Which vendors hold our customer or employee data today, and under which contracts?
Which data categories have a documented retention period?
Who owns the end-to-end workflow for Data Principal requests?
Connecting Consent Decisions to the Systems That Act on Them
A customer makes a consent or preference decision in one channel, and many other systems need to respect it. OneConsent is a DPDPA consent management platform designed to connect those decisions with the systems that act on them. The platform supports three core outcomes:
Capture and maintain consent records at purpose level across digital and physical touchpoints
Propagate withdrawal and preference changes to connected CRM, CDP and marketing systems
Check consent eligibility before connected customer engagement systems send communications
Related reading: Consent Management Platform in India: Complete Buyer's Guide
Preparing Your Organisation for the DPDP Compliance Timeline
The 14 DPDP compliance mistakes in this guide have practical fixes, and most begin with visibility of how consent and personal data move through the organisation. OneConsent helps customer-facing enterprises connect consent capture and preference changes to the systems your Marketing and Technology teams already use, with records your Legal and Compliance teams can review. You can explore the OneConsent platform to see how purpose-level consent and cross-system enforcement work in practice. To review your own customer journeys with a specialist, book a guided demo with the OneConsent team.
Frequently Asked Questions
Have more questions?
Search our full DPDP knowledge base for more answers.