Email Marketing
India's DPDP Act and Email Marketing — A Practical Compliance Guide
What this guide covers
- What the Act says at a high level
- Consent, notices and data handling considerations
- Third-party processors and retention questions
- Why this article is informational, not legal advice
India's Digital Personal Data Protection Act, 2023 (DPDP Act) is no longer a future concern — the DPDP Rules were formally notified in November 2025, and the law is now in a phased rollout, with the next major milestone (the consent manager framework) landing around November 2026 and full enforcement, including penalties, expected by May 2027. For anyone running email marketing in India, now is the right time to get your list-building and consent practices in order — not after enforcement begins.
This is a practical overview, not legal advice — if your business handles significant volumes of personal data, talk to a lawyer familiar with the DPDP Act. But for most small businesses and solo marketers building an email list, the core principles are straightforward.
What the DPDP Act Actually Covers
The DPDP Act governs how organizations — called "Data Fiduciaries" under the law — collect, process, and store the personal data of individuals in India, called "Data Principals." An email address is personal data. If you collect email addresses from people in India for marketing purposes, the Act applies to you, regardless of where your company is registered.
What This Means for Email List Building
Consent Must Be Specific and Informed
The DPDP Act is built around a consent-first model. Pre-ticked checkboxes, bundled consent ("by signing up you agree to marketing emails, our partners' offers, and data sharing"), and vague sign-up language are the kind of practices the Act is designed to end. Each purpose you plan to use someone's email address for should be clear at the point of collection.
People Have the Right to Withdraw Consent
Subscribers must be able to withdraw consent as easily as they gave it. In practice, this means a working, one-click unsubscribe link on every marketing email — something that is good email practice regardless, but is now a compliance requirement, not just a best practice.
Data Minimization
Only collect what you actually need. If your sign-up form asks for a phone number, date of birth, and full address just to send a weekly newsletter, that is more data than the stated purpose requires — a pattern the Act specifically discourages.
Breach Notification
If your subscriber list or email platform is compromised, the Act includes obligations to notify the Data Protection Board of India and, in relevant cases, affected individuals. This is a strong reason to use a reputable email service provider with proper security practices rather than a low-cost, low-security alternative.
Practical DPDP Readiness Checklist for Email Marketers
Penalties Are Significant
The DPDP Act allows for substantial penalties for serious violations — reported to reach into the hundreds of crores of rupees for significant breaches, though enforcement mechanisms and actual penalty patterns are still developing as the Data Protection Board becomes fully operational. Even for small businesses unlikely to face maximum penalties, the direction of travel is clear: consent-based, transparent data collection is becoming a baseline expectation, not an optional nicety.
What to Do Right Now
You do not need to wait for full enforcement in 2027 to get this right. Most of the practical steps — clear consent language, working unsubscribe links, minimal data collection, using a reputable platform — are also just good email marketing practice that improves deliverability and subscriber trust in the meantime. Getting ahead of DPDP compliance now means less scramble later, and better-performing email in the short term as a side effect.
Frequently Asked Questions
Yes, if you collect the personal data — including email addresses — of individuals in India for any purpose, including marketing. The Act applies regardless of your company's size or where it is registered.
The DPDP Rules were notified in November 2025 with a phased rollout. The consent manager framework is expected around November 2026, with full enforcement including penalties expected by May 2027.
A working, easy-to-use unsubscribe link is one practical requirement, but full compliance also involves clear consent at sign-up, data minimization, and secure handling of subscriber data. This article is a practical overview, not legal advice.
Quick Summary
- The DPDP Act is in a phased rollout, with full enforcement expected by May 2027
- An email address counts as personal data under the Act
- Consent must be specific, informed, and not bundled with unrelated purposes
- Subscribers must be able to withdraw consent as easily as they gave it
- Only collect the data fields your stated purpose actually requires
- Penalties for serious violations can be substantial
- Good compliance practices overlap heavily with good email deliverability practices
Sources & references
Primary and authoritative references used when preparing or reviewing this article. Product features, policies and standards can change, so verify current requirements before making production changes.
Runs PowerMTA.in alongside his own email marketing and affiliate operations targeting Indian audiences — hands-on with bulk sending infrastructure, live campaigns, and content properties. Read more →