DPDP Compliance for OTT and Digital Media Platforms: Viewer Data and Ad Consent

    A practical guide to managing viewer data, advertising consent, children’s profiles and consent withdrawal across OTT and digital media platforms.

    OneConsentBlog
    9 min read
    Thursday, 8 October 2026
    OneConsent banner showing a streaming TV with privacy controls for personalised ads, content recommendations, analytics and third-party sharing.

    DPDP compliance for OTT and digital media platforms requires a clear connection between viewer data, its permitted uses and the systems receiving it. For CTOs, privacy heads and advertising leaders, this means reviewing how streaming subscriber consent governs recommendations, advertising and analytics across TVs, mobile apps and web browsers.

    According to the 2026 study by Ormax Media, the connected TV audience base in India stands at 206.9 million, an increase of 60% from 2025 figures. With streaming growing in households, there will be a need to distinguish between subscribers, viewer profiles and users of the same device.

    The starting point of this review should be the journey of a viewing event: why the data is being collected, whether it affects recommendations, and which advertising partners receive the data.

    What does DPDP compliance for OTT cover?

    This applies to the processing of personal data of individuals in India that is processed digitally and to the processing of personal data outside India in connection with offering goods or services to individuals in India, except where exceptions are specified under law. For OTT platforms, this could include account data, device IDs, viewing histories and preferences that can be attributed to a specific individual.

    A profile ID or hashed email can still connect activity to an individual or identify an individual. Your data inventory should therefore extend to recommendation systems, audience segments and advertising identifiers.

    The final DPDP Rules were notified in November 2025. Many core business obligations are scheduled to commence after the 18-month transition, in May 2027. The requirements discussed below should guide implementation planning during this transition.

    OTT data privacy in India involves several distinct activities. Subscription administration, playback support, personalised discovery and advertising should each have a documented purpose and processing basis. For digital publishers, the same review covers newsletters, embedded video players and advertiser audience segments.

    For OTT platforms, DPDP compliance software can bring consent, preferences, notices and connected systems into one operational workflow, making it easier to apply the same privacy decisions across the viewer journey.

    Do ads and recommendations need separate consent?

    Different purposes need sufficiently specific consent where consent is the processing basis. Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, with a clear affirmative action for the specified purpose and limited to the personal data necessary for that specified purpose.

    For adult viewers, using watch history to recommend a movie and using that watch history to market movies are two different business decisions altogether. The suggested design would be to offer options separately for recommending, marketing and analysing the audience.

    The legislation sets the standards of consent, while the platform can design its interface within those requirements. Separate controls can be used to explain the purposes and design the interface accordingly.

    Analytics also needs closer classification. Playback error reporting, individual engagement scoring and advertiser measurement use data differently. Your teams should assess each activity separately.

    Where Section 7 is relevant, document the particular legitimate use and its conditions. A subscription contract should not automatically be treated as justification for every subsequent use of viewer data.

    How should streaming apps collect ad consent?

    Seek consent for ads via a notice and affirmative action before engaging in any activity that requires consent. Rule 3 states that the notice must be independently understandable, providing clear and plain-language details regarding the personal data being processed and the specified purposes, as well as the means to withdraw consent, exercise rights and make complaints.

    When it comes to adtech consent as per DPDP, here is what the workflow looks like:

    1. Explain the advertising use. Describe whether watch history, device identifiers or inferred interests will support personalised ads, audience matching or measurement.

    2. Record a meaningful choice. Make the advertising purpose understandable alongside other preferences. Keep the notice version, purpose, timestamp and relevant account or profile reference with the consent record.

    3. Apply the choice before data moves. Configure advertising software and server-side transfers to check the relevant permission before sending data for that purpose.

    4. Carry changes across connected services. Update the preference record and the systems that act on it when consent changes.

    For example, an adult viewer might enable film recommendations and decline advertising personalisation. The recommended implementation would permit the agreed recommendation use while excluding that viewer’s history from advertising audiences.

    If your platform offers contextual advertising, assess the entire delivery flow. Selecting an ad by programme genre may avoid behavioural targeting, while measurement tools can still collect personal data requiring their own assessment.

    OneConsent’s guide to implementing a consent management system provides a broader foundation for purpose mapping and consent records.

    How should streaming apps handle kids profiles?

    Children’s profiles require verifiable parental consent and controls addressing the separate restrictions on tracking, behavioural monitoring and targeted advertising. Under the Act, a child is anyone who has not completed 18 years of age. Parental consent does not by itself remove those restrictions, subject to applicable statutory exemptions.

    An ordinary entertainment service should assess any claimed exemption against its specific conditions.

    Rule 10 requires due diligence to establish that the person identifying themselves as the parent is an identifiable adult. It permits reference to reliable identity and age details or identity and age details voluntarily provided by the individual or through an authorised virtual token. An OTP alone proves access to a contact channel; the verification design still needs to establish adulthood in accordance with the requirements of the Rules.

    For kids profiles, recommended operational controls include:

    • Link the child’s profile to the verified parental consent record.

    • Exclude children’s viewing activity from behavioural advertising audiences.

    • Review recommendation features that depend on persistent behavioural monitoring.

    • Assess editorial or contextual content discovery that avoids behavioural tracking.

    • Test whether switching from an adult profile to a child profile updates advertising and analytics behaviour.

    Your review should include shared-device identifiers. A child’s activity can enter household audience segments even when the visible profile has restricted settings.

    How should consent work across TV, app and web?

    Associate each preference with the person or profile it governs and define how it applies on connected devices. A television account can contain several viewers, making identity and profile handling central to streaming subscriber consent.

    For connected TV, remote-friendly controls or an authenticated QR journey can help viewers read notices and manage choices. These are implementation options. The chosen approach should make the relevant preference accessible and preserve the context in which consent was given.

    Avoid treating a household device identifier as evidence that every viewer agreed to the same uses. For your acceptance testing, include profile switching, logout, app reinstalls and a withdrawal made on mobile while a TV session remains active.

    The test should inspect actual data transfers. A changed setting on screen provides only part of the evidence that the underlying systems applied the viewer’s choice.

    A DPDP compliance platform becomes particularly useful when viewer preferences need to remain consistent across TV, mobile, web and the downstream systems connected to them.

    Who is liable if an adtech partner misuses viewer data?

    Under Section 8, the platform remains responsible for processing performed by it or on its behalf by a Data Processor. Engaging a processor requires a valid contract. A partner that determines its own purposes and means may itself be a Data Fiduciary. Responsibility therefore depends on the actual arrangement and conduct of each party.

    Before entering into a relationship with a marketing or measurement partner, make sure that you know what data will be shared with the partner, how it may be used and transferred, and how it is to be stored.

    A practical vendor test is to withdraw a test profile’s advertising consent and trace what happens to future data transfers and existing audience membership. Ask the partner to demonstrate its response, including any downstream services acting on its behalf.

    This gives Legal, Engineering and Ad Operations a shared basis for assessing adtech consent under DPDP.

    For adtech-heavy OTT environments, DPDP compliance management software can help maintain consent propagation and provide evidence that viewer choices are being enforced across processor integrations.

    What should happen when a viewer withdraws consent?

    Section 6 requires comparable ease for giving and withdrawing consent. Moreover, the Data Fiduciary must cease processing personal data based on consent within a reasonable time after withdrawal, unless continued processing is otherwise authorised under the Act.

    Consent withdrawal should be treated separately from account closure and incorporated into your workflow. Changes to advertising consent should be propagated to the systems using data for advertising, including the implications of those changes for the viewer.

    As far as profiling of viewers is concerned, you need to perform an audit of stored audience segments, scheduled exports, future refreshes and any additional data collection. You should determine the systems where the change was applied and look into why it was not implemented on some systems.

    Retention of information is a separate activity. Rule 8(3) provides for a minimum one-year retention period for personal data, traffic data and associated processing logs in the specific circumstances and for the purposes covered by the Seventh Schedule. This should not be treated as a general one-year retention requirement for all OTT viewer data.

    A DPDP consent management platform can help connect the viewer’s consent record with preference changes, withdrawal actions and downstream systems, giving teams a clearer view of how those decisions are being applied.

    Turning DPDP compliance for OTT into an operating workflow

    The execution strategy involves connecting each use case with a specific owner, a viewer preference when it applies, and a test demonstrating the effect in the recipient system.

    Start with the flows crossing the largest number of systems: creation of a new account, personalised viewing experience, ad serving, child profile creation and withdrawing of consent. In addition, include access requests, data corrections, erasure requests and complaints in the same analysis.

    OneConsent helps you collect consent, manage preferences, withdraw consent, and manage notices. The publicly available implementation guidelines describe how to handle consent and withdrawals in connected systems.

    When evaluating the capabilities, find out how these features will be integrated with your TV applications, recommendation service and advertising partners. Ask for a demo covering the adult profile, child profile and withdrawal flows relevant to your platform.

    DPDP compliance of OTT is easier to evaluate when each team is able to explain which data it uses, why, and how the viewer’s decision influences that use.

    For OTT platforms operating across multiple viewer touchpoints, a consent management platform in India can provide a central way to manage the consent lifecycle across profiles, connected devices and downstream systems.

    OneConsent helps you collect consent, manage preferences, withdraw consent, and manage notices. The publicly available implementation guidelines describe how to handle consent and withdrawals in connected systems.

    Book a OneConsent demo to discuss the consent flows and integration of your streaming or digital media platform.

    Frequently Asked Questions

    Have more questions?

    Search our full DPDP knowledge base for more answers.

    See it live

    See OneConsent in action

    Get a personalised walkthrough of how OneConsent helps your teams stay DPDPA compliant.

    • 30-minute walkthrough
    • DPDPA-ready by design
    • Tailored to your stack