Offline Data Collection and DPDPA: What BFSI and Retail Must Fix in Their Branch Processes
Most DPDPA compliance conversations focus on digital channels. But India's BFSI and retail sectors collect enormous amounts of customer data offline — and this data is equally subject to the Act.

Physical branches, insurance offices, and retail loyalty counters across India continue to use paper forms for account opening, KYC-related processes, loan applications, policy servicing, and loyalty enrolment. Most DPDPA consent management work to date has focused on digital channels: websites, apps, and online onboarding flows. Offline collection at the branch counter is a natural next area to bring into that same planning, and a DPDPA consent management platform built to handle both channels is what makes that possible in practice.
Does the DPDPA Apply to Data Collected Through Paper Forms?
Yes, once that data is digitised. Section 3 of the DPDPA covers personal data collected in digital form, and personal data collected in non-digital form and subsequently digitised. For banks, insurers, and retailers, this means a paper KYC form, loan application, or loyalty enrolment slip becomes part of the DPDPA compliance picture once it is scanned, entered into a CRM, or otherwise converted into a digital record. A form that stays entirely on paper and is never digitised does not, by itself, bring the Act into play.
How Much Offline Data Is Involved
The scale is worth putting into context. A bank with a large branch network processing several hundred account opening forms per branch each day can generate a substantial volume of new records daily across its network, each carrying several categories of personal data alongside a name and address. Extend that picture to insurance companies with field agents collecting applications across small towns and rural districts, retailers running loyalty sign-ups from a counter inside a shopping mall, or microfinance institutions gathering borrower details village by village, often with no digital infrastructure present at the point of collection.
Every one of these is a personal data collection activity. Once the resulting forms are digitised, that data becomes part of the same DPDPA consent management picture as the organisation's website and app.
What Changes When Paper Data Is Digitised
The DPDPA gives Data Fiduciaries more than one ground for processing personal data. Section 4 permits processing where the Data Principal has given consent, or where a specified legitimate use under Section 7 applies. Where consent is the applicable basis for a given form or workflow, organisations should align that offline collection process with the notice and consent requirements under Sections 5 and 6 of the DPDPA.
In practical terms, this means a branch, field, or point-of-sale process should be reviewed for three things once the data it collects is going to be digitised: whether a notice is given before collection, whether consent (where consent is the basis) is captured for a specific stated purpose, and whether a record exists showing what was agreed to and when.
Notice Before Collection
A notice needs to reach the customer before collection begins. Branch teams can use a notice designed to meet the applicable DPDPA requirements, explaining the personal data being collected and the specified purpose or purposes. This does not need to be elaborate. It could be a printed handout, a QR code linking to a fuller digital notice, or, for customers who cannot read, a script staff members read aloud. Timing is what matters: the notice should reach the customer before collection, presented on its own instead of buried inside a form signed afterward. A DPDPA notice management tool that can generate and version multilingual consent notices, including regional-language, printed, and QR-linked formats, makes this easier to run consistently across a branch network. Section 6 also requires that consent requests offer the option to access them in English or a language listed in the Eighth Schedule.
Purpose-Specific Consent
Consent should be structured around the specific purposes for which it is required, and kept separate from a single blanket agreement covering everything the organisation might eventually want to do with the data. Organisations should avoid combining unrelated purposes into one consent request, since Section 6 requires consent to be specific to the stated purpose.
Consent Records and Notice Versioning
Organisations should maintain an auditable record showing how and when consent was obtained, the purpose associated with it, and the notice presented to the Data Principal at that time. Depending on the workflow, this record may include a signed form, a digitally logged confirmation, or another appropriate method. The organisation should also retain the applicable notice version, so it can establish what information was presented when consent was given, since notice terms and consent language change over time.
Where Traditional Branch Forms Create Consent Gaps
A common pattern in existing forms places a single line near the bottom, in small print, that accepts "all terms and conditions" and folds in consent for data processing within it. One tick box, one signature, and the process concludes. A single clause covering every purpose at once does not give a customer a genuine, informed choice about each individual use of their data, which is the specificity Section 6 asks for.
Redesigning a form this way is a structural change. Each processing purpose gets its own line item, explained in language an ordinary customer can follow, paired with its own separate consent action. This takes more effort upfront and is the more reliable route to specific, informed consent.
Connecting Offline Consent to a Central Consent Management Platform
Collecting the right consent at the branch level accounts for only half the requirement. That consent then needs to flow into the organisation's central DPDPA consent management platform, otherwise it remains on paper inside a filing cabinet, disconnected from everything else the organisation holds about that customer. This is the same principle behind omnichannel consent management software: the same customer's consent choices should hold consistently whether they were captured at a branch counter, a billing counter, or online.
This calls for a few supporting processes. Branch staff need a defined mechanism to log each consent grant into the central system at the point of collection. Organisations need a plan for reconciling the volume of forms collected before this process existed. An ongoing reconciliation process should identify gaps between offline records and the central consent record over time. Organisations should also use data mapping to understand where information collected through branch forms is stored, transferred, and processed after collection. Most of this work happens behind the scenes, and skipping it moves the compliance gap from the front counter to the back office.
What Branch Staff Need to Know
This shift is easy to underestimate. The individual behind the counter now carries genuine responsibility for DPDPA compliance in a real operational sense. Staff need to know which notices to provide, how to explain each consent purpose without jargon, how to handle a customer declining one specific use of their data without derailing the transaction, how to log that consent accurately, and how to respond when a customer asks what rights they hold over their own information.
This is a considerable expectation for frontline staff who, until recently, were mainly processing paperwork. Training programmes may need to be built or extended, delivered as an ongoing operational discipline and not a single session.
Where the DPDPA Rules Stand Today
The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, with a phased commencement. Rule 4, covering registration of Consent Managers, takes effect on 13 November 2026. Rules 3 and 5 to 16, 22, and 23, which cover notice, consent mechanics, security safeguards, breach notification, and data retention in detail, take effect on 13 May 2027. Organisations reviewing offline collection processes now have a defined implementation window to align branch, field, and point-of-sale workflows with the requirements that will apply when those provisions commence.
Why This Deserves Attention Now
Offline collection was never carved out as an exception under the DPDPA. It is a part of the law that has not yet received the same attention as digital channels. For BFSI and retail organisations with substantial physical footprints, branch and counter-level collection is worth bringing into the same DPDPA consent management planning already applied to the website and app.
Read more about DPDPA compliance for BFSI
For organisations running physical billing counters, this connects to a related need: capturing point of sale consent as well as consent at onboarding, since both involve collecting personal data in person, not on a screen. POS DPDPA consent capture software addresses this specific gap for retail environments, where billing counters and account-opening desks are both collecting personal data that eventually needs to sit in the same record as everything collected online.
Redesigning forms, training branch staff, and integrating consent capture with central systems all take sustained effort. Organisations that begin this work now will find it easier to manage as regulatory attention extends to offline channels alongside digital ones.
How a DPDPA Consent Management Platform Supports Offline and Digital Workflows
A DPDPA consent management platform gives BFSI and retail organisations one place to bring branch, field, and point-of-sale consent together with what is collected online. OneConsent, a DPDPA-focused consent management platform, is built to support consent capture across channels, so consent gathered on paper or at a counter can be logged into the same central record as consent captured online. This is designed to give organisations one auditable trail across branches, call centres, and digital channels, in place of separate systems that need to be reconciled by hand.
Explore the OneConsent & Book a demo to see offline-to-online consent management in action.
Frequently Asked Questions
Have more questions?
Search our full DPDP knowledge base for more answers.