DPDPA for Telemarketing: What Section 6 Means for Your Outbound Calling Operations

    Telemarketing in India has long operated in a grey zone of customer data use. The DPDPA draws a clear line — and most outbound calling operations currently sit on the wrong side of it.

    OneConsentBlog
    6 min read
    Sunday, 28 June 2026
    Explained section 6 and DPDPA for telemarketing

    Telemarketing in India has long operated in a grey zone of customer data use. The DPDPA draws a clear line, and most outbound calling operations currently sit on the wrong side of it.

    Here's the uncomfortable part. Most telemarketing teams I've seen think they are already covered because they scrub against the DND registry before every campaign. They aren't. DND scrubbing answers a completely different question than the one the DPDPA asks. And the gap between those two questions is where the compliance risk now lives.

    India's telemarketing and SMS marketing industry processes the personal data of hundreds of millions of individuals. Phone numbers, purchase histories, financial profiles, demographic segments, all of it feeding dialler queues and campaign lists every single day. The TRAI DND framework governs some of this activity. But the DPDPA 2023 adds a layer that goes far deeper: it requires affirmative consent for processing personal data for marketing purposes, regardless of whether the person is on a DND list.

    That single sentence changes the economics of outbound marketing in India. Let me explain why.

    What Section 6 actually requires from a telemarketing operation

    DPDPA Section 6 sets the conditions for valid consent. It must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, for a specified purpose. Every word in that list does work, but two matter most for outbound calling.

    First, "specific". A customer who agreed to your terms of service while buying a product has consented to processing for that purchase. They have not consented to receiving promotional calls. Consent given for service delivery does not carry over to marketing. These are separate purposes under the Act, and each needs its own consent record.

    Second, "clear affirmative action". Silence is not consent. A pre-ticked box is not consent. A customer who simply never registered on DND has done nothing affirmative at all. Which means the absence of a DND registration is legally worthless as a basis for marketing calls under the DPDPA.

    Alongside Section 6 sits the notice obligation under Section 5. Before or at the time of seeking consent, you must tell the person, in plain language, that their data will be used for outbound marketing communications, and how they can withdraw. And withdrawal is not a formality. Withdrawing consent must be as easy as giving it, and once withdrawn, the calls and messages have to stop.

    Run your current contact lists through this test

    Now take an honest look at where your campaign data actually comes from. In most operations it is some mix of these four sources:

    CRM records where customers consented to service terms but never specifically to marketing. Purchased lead lists where nobody can tell you what the original consent said, or whether it existed. Partner data-sharing arrangements with unclear consent provenance. And historical campaign databases built over a decade, where consent records were never kept because nobody asked for them.

    Under the DPDPA, none of these sources is automatically compliant for marketing use. Not one. Each contact in your database needs a verifiable consent record tied to the marketing purpose specifically. A list of ten lakh numbers with no consent trail is not an asset anymore. It is documented exposure.

    Retail and D2C brands are confronting the same provenance problem at the point of checkout, which are covered in detail in DPDPA for E-Commerce: Customer Data, Marketing Consent and Checkout Compliance. The telemarketing version is harder, because the data is older and the chain of custody is murkier.

    TRAI and DPDPA are parallel rails, not the same track

    This intersection confuses people, so it is worth being precise. TRAI's commercial communication rules, including the DND registry, regulate how and when commercial messages can be sent over telecom networks. The DPDPA regulates whether you may process a person's data for marketing at all. One is an opt-out regime managed at the network level. The other is an opt-in regime that applies to you as a Data Fiduciary.

    So a customer not on the DND list has not consented to anything under the DPDPA. And a customer who has given you valid DPDPA consent for marketing may still fall under DND category restrictions you must respect. Your compliance framework has to satisfy both regimes simultaneously, because passing one does not excuse failure under the other.

    What a compliant outbound operation looks like in practice

    Strip away the legal language and a DPDPA-ready telemarketing operation needs four working components.

    A consent database that records which customers consented to which channels, voice, SMS, WhatsApp, each tracked separately with timestamps and the notice version shown. Real-time consent verification before any call or message fires, not a monthly batch scrub. An automated suppression mechanism that pulls withdrawn-consent contacts out of queues before campaign execution, because a withdrawal processed three days late is still a violation. And a tamper-proof audit trail proving consent status at the moment of every single communication, since that is what the Data Protection Board of India will ask to see.

    Most campaign tools were built to maximise reach, not to verify consent. Adding consent checks to an old dialler through manual lists and patches rarely survives scrutiny, which is why platforms like Easyrewardz build consent verification directly into the campaign workflow itself.

    The penalty math at campaign scale

    If you use someone's personal data without valid consent, you are breaking the Act. The penalty for this can go up to ₹50 crore. Now think about what this means for telemarketing. A single campaign reaches ten lakh people. If a large number of them never gave you proper consent, you have not broken the law once. You have broken it ten lakh times in one day, and your own campaign logs are the proof. Telemarketing runs on volume. But under the DPDPA, volume without consent only means bigger trouble.

    Four things to do before your next campaign

    1. Audit your contact database for consent provenance. Tag every record by source and consent status.

    2. Isolate contacts with no verifiable DPDPA-compliant marketing consent. Suppress them now, not after a notice arrives.

    3. Run a consent refresh campaign. Yes, response rates will be modest. A smaller consented list outperforms a large non-compliant one on every metric that matters.

    4. Build real-time consent gating into campaign execution, so no communication leaves your system without a live consent check.

    The honest takeaway

    Telemarketing's business model depends on scale. The DPDPA requires that scale be built on consent, not assumption. The teams that rebuild their data operations around verified consent will end up with smaller lists, better engagement, and durable customer relationships. The ones that keep dialling old databases are simply waiting for the complaint that triggers a DPBI inquiry.

    If you're rethinking outbound engagement for the consent era, Easyrewardz offers a DPDPA-compliant customer engagement platform that puts consent verification at the centre of every campaign.

    Frequently Asked Questions

    Have more questions?

    Search our full DPDP knowledge base for more answers.

    See it live

    See OneConsent in action

    Get a personalised walkthrough of how OneConsent helps your teams stay DPDPA compliant.

    • 30-minute walkthrough
    • DPDPA-ready by design
    • Tailored to your stack