What Indian CMOs Need to Know About DPDPA: Consent, Campaign Reach, and Marketing Data Governance
Understand what DPDPA means for Indian CMOs, from purpose-based consent and campaign reach to audience governance, withdrawal management, and building marketing strategies on consented customer data.

Legal tells the CMO the DPDPA compliance project is on track. The CMO's real question is different: what happens to next quarter's WhatsApp campaign reach, the retargeting audience built on loyalty data, and the marketing calendar once every consent has to be specific, evidenced, and withdrawable. That question rarely gets answered in a compliance briefing, because most DPDPA guidance is written for a legal audience and stops at what the law requires, leaving out what it changes about how marketing runs day to day.
This article sets out what the Digital Personal Data Protection Act, 2023 requires of marketing specifically, what current industry reporting shows about its effect on addressable audience and campaign economics, and how a CMO should think about owning marketing consent management instead of leaving it entirely to legal.
Why DPDPA Is a CMO Problem, Not Only a Legal One
Section 6 of DPDPA places the burden of demonstrating valid consent on the Data Fiduciary. In practice, for most consumer businesses, marketing is where that burden lands first, because marketing owns the majority of the touchpoints where consent is collected: lead forms, WhatsApp opt-ins, loyalty sign-ups, ad landing pages, and checkout flows.
Legal can set the standard a consent flow needs to meet. It cannot single-handedly fix a WhatsApp opt-in built by a growth team eighteen months ago, or a retargeting audience assembled from a loyalty database with no record of what purpose the customer agreed to. That is marketing operations work, which is why the CMO's office, alongside the DPO's, needs to treat DPDPA as an operating requirement for the marketing function.
What DPDPA Changes About Consent for Marketing Specifically
Three provisions of DPDPA matter most for a marketing organisation, and each changes a specific piece of how campaigns are built. A timing note applies to all three: Section 5, Section 6(1) mechanics, Section 6(4), and Rule 3 fall within the core operational obligations that come into force on 13 May 2027, eighteen months after the DPDP Rules were notified in November 2025. Marketing teams have a defined runway to redesign these flows rather than an obligation that starts today, though the planning work described below is worth starting well before that date.
Consent has to be granular, per purpose. Section 6(1) requires consent to be specific and unbundled. A single "I agree to receive marketing communications" checkbox covering email, SMS, WhatsApp, and third-party sharing does not meet this standard. Each purpose, and in practice each channel, needs its own separately captured consent.
Every collection point needs a real notice. Section 5 and Rule 3 require a notice describing the data collected, the purpose, and how to withdraw, shown before or alongside the consent request. A landing page form or a WhatsApp opt-in message that skips this is building an audience on a weak legal foundation, whatever the conversion rate looks like today.
Withdrawal has to reach every system the data touches. Section 6(4) requires withdrawal to be as easy as giving consent, and current industry commentary on India's adtech sector makes the practical stakes clear: in a real-time bidding chain, every party handling a customer's data, from publisher to ad exchange to demand-side platform, is a Data Fiduciary or Processor in its own right, and a withdrawal that only updates one system leaves the rest of the chain processing data without valid consent.
The Campaign Reach Trade-Off: What Changes in Addressable Audience
This is the part most DPDPA content skips, and it is the part a CMO plans a quarter around.
Industry executives speaking to trade press have been direct about the near-term effect. Data and marketing leaders quoted in coverage of DPDPA's rollout describe an expected short-term contraction in addressable audience size as legacy, loosely consented data gets purged and customers exercise the right to withhold or withdraw consent. Separate industry reporting on the advertising sector estimates a meaningful increase in short-term compliance and operational costs for agencies and MarTech teams adapting their systems, which is part of why the shift toward a proper DPDP compliance platform is gathering pace across marketing-heavy sectors such as BFSI, retail, and D2C.
The effect is sharpest for audiences built on second-hand or assumed consent. Retargeting pools and lookalike audiences built from loyalty programme data or hashed customer lists face a specific exposure: whether the original data collection ever included consent for advertising use in the first place, and whether sharing that list with an ad platform requires its own separate consent. Audiences assembled without that foundation carry more than a compliance risk under DPDPA. Industry commentary increasingly describes them as commercially unreliable too, since a list built on unverifiable consent cannot be defended if challenged, and a Data Fiduciary cannot be confident it is reaching people who agreed to be reached.
This is where the trade-off has a genuine upside alongside the cost. Channels built on first-party, authenticated customer relationships, such as retail media and owned loyalty programmes, are positioned as earlier beneficiaries of this shift precisely because their audiences were already closer to what DPDPA now requires. A CMO who treats this as a data quality exercise, and a legal one, ends up with a smaller but better-documented audience that converts on terms the organisation can stand behind.
The practical planning exercise is straightforward to describe, harder to execute: work out what share of the addressable audience is reachable using first-party, consented data alone, compare that to what marketing currently reaches using third-party signals and loosely governed lists, and treat the gap between those two numbers as the near-term exposure.
Our guide on minimising drop-off in the consent journey covers the mechanics of the opt-in flow itself in more depth.
Marketing Data Governance: Who Owns What
Once consent moves from a checkbox to an operating requirement, marketing consent management needs an explicit owner inside the marketing organisation, not an assumed one.
A workable division of responsibility looks like this. The DPO or legal team sets the compliance standard: what Section 6 requires, what the notice needs to contain, and what the withdrawal process has to guarantee. Marketing operations owns execution: making sure every campaign type, from WhatsApp promotions to email newsletters to SMS offers, captures consent against that standard at the point of collection. The CRM or MarTech team owns the technical layer: making sure a withdrawal or preference change propagates to every connected system, instead of updating only the platform where it was raised.
The most common governance failure is not a missing policy. It is a "shadow consent list," where a growth or performance marketing team keeps its own opt-in data inside an ad platform or an email service provider, disconnected from the organisation's official consent record. That list can look perfectly healthy on a campaign dashboard while carrying none of the evidence DPDPA requires if it is ever challenged.
A Practical Framework for Auditing Campaign-Level Consent
A CMO evaluating exposure does not need to start with the statute. A campaign-level audit works better, and some of it can be run through a DPDP consent management platform once the ownership map above is agreed.
Inventory every campaign type and its consent source. List WhatsApp, SMS, email, retargeting, and loyalty campaigns, and identify exactly where the consent behind each one was captured.
Check purpose specificity. For each source, confirm the consent named a specific purpose instead of a general marketing agreement.
Check the notice. Confirm each collection point showed a notice covering what Section 5 and Rule 3 require, in language a Data Principal could reasonably understand.
Check withdrawal sync. Confirm that a withdrawal recorded on one channel reaches every other system using the same customer's data.
Check third-party sharing. For any audience shared with an ad platform or agency, confirm the original consent covered that specific use.
Flag Significant Data Fiduciary exposure. If the organisation processes data at a scale that could trigger Significant Data Fiduciary obligations, confirm whether a DPIA is required for marketing data flows specifically, and for the organisation overall.
A Quick Self-Check for Marketing Leaders
Name the consent behind the three largest campaign audiences. State exactly what consent each one is built on.
Trace withdrawal across systems. Confirm that a consent withdrawn through the app also reaches connected ad platforms and agency-held lists, not only the CRM.
Measure the first-party gap. Establish the gap between the audience reachable using first-party consented data alone and the current addressable audience size.
Assign clear ownership. Confirm there is a single person or team accountable for marketing consent management, rather than leaving it unassigned between legal and marketing.
Confirm evidence readiness. Check that consent evidence for a specific customer in a retargeting audience could be produced on request from a regulator.
Where OneConsent Fits
OneConsent is a DPDP consent management platform built for marketing and compliance teams working together, rather than a legal tool marketing has to work around. It gives marketing teams purpose-based consent capture across WhatsApp, SMS, email, app, point of sale, and web, tied to a single Data Principal record instead of scattered across separate campaign systems, so a CMO's audience data stays traceable back to the consent it was built on.
As one of the more marketing-oriented consent management platforms in India, OneConsent's consent sync hub propagates withdrawal and preference changes across connected CRM and MarTech systems, closing the shadow-list gap described above. Consent evidence and audit trail capabilities keep the purpose and notice version behind every campaign audience on record, giving a marketing team the evidence to defend a retargeting list once it is built.
A Practical Next Step
If a marketing organisation currently treats DPDPA as a legal workstream instead of a campaign planning input, a useful starting point is running the campaign-level audit above against the three highest-value audiences and measuring the gap it surfaces. Whether that gap gets closed through an internal process or a dedicated DPDP compliance solution, the audit itself is the part worth doing first.
Book a demo to review how a consent-first marketing data setup would change current campaign reach.
Visit OneConsent to explore the platform in more detail.
Frequently Asked Questions
Have more questions?
Search our full DPDP knowledge base for more answers.