You are a Data Fiduciary for your own staff and candidates, and usually a Data Processor for the client data your teams work on. Data of people outside India, handled under a contract with a foreign client, is mostly outside the Act, but security and responsibility for sub-contractors still apply.
The first four things to sort out
Consent for newsletters.
No bought lists without proof.
Notices on forms.
Cookie and tracking review.
A worked example: A webinar sign-up list
Day 1Marketing wants to add attendees to the newsletter.
Day 1The form had a separate newsletter box.
Day 2Only those who ticked it are added.
AfterThe rule is standard.
Evidence kept: Form; List.
Separate boxes make it easy.
What others in the sector usually do. B2B marketers are cleaning old prospect lists.
Short answer: Only with separate consent and an easy way to stop
Marketing needs consent that is separate and specific, unless the person clearly expects it from the relationship. Bought or scraped lead lists are risky because you cannot show consent. Every message should carry an easy way to stop.
From your seat: Marketing department. Every campaign list needs a consent source. If you cannot say where the consent came from, do not use the list.
In IT and ITeS
B2B prospect lists still need a lawful source and an easy unsubscribe.
Short answer: It depends on the use; most organisations need both
For every use of personal data you need one basis: consent, or one of the legitimate uses in Section 7, such as a legal duty, employment, a medical emergency, or data a person gave voluntarily for a specific purpose. Anything beyond what the person expects, such as marketing, profiling or sharing with partners, usually needs consent.
From your seat: Marketing department. Ask marketing consent separately and keep the record with the date and version.
In IT and ITeS
Payroll and background checks are employment purposes. Newsletters to prospects need consent.
What the law says
Section 4 allows processing only with consent or for a legitimate use. Section 6 sets what valid consent looks like. Section 7 lists the uses that need no consent. Section 4 · Section 6 · Section 7
Steps
List each purpose for which you use personal data.
Against each purpose, write the basis: consent or the exact clause of Section 7.
Where the basis is consent, check that it was asked separately, with a clear action and no pre-ticked box.
Stop or re-paper any purpose with no basis.
Review the list whenever a new product, campaign or system starts.
Evidence to keep
Purpose and basis register
Consent records with date, version and channel
Legal sign-off on each legitimate use relied on
Common mistakes
Treating account terms as consent for marketing
Bundling several purposes in one tick-box
Relying on 'legitimate interest', which the Indian Act does not have
Short answer: Stop that use quickly, across every system and vendor
Withdrawal must be as easy as giving consent. Once someone withdraws, you and every vendor working for you must stop that use within a reasonable time. What was done before withdrawal stays lawful, and data that a law requires you to keep is kept.
From your seat: Marketing department. Make the stop option work across every channel and agency within a day.
What the law says
Section 6(4) to 6(6) give the right to withdraw at any time, with the same ease, and require processors to stop as well. Section 8(7) then asks for erasure unless a law requires retention. Section 6 · Section 8(7) · Rule 8 · Section 8(1)–(2)
Steps
Give one simple way to withdraw on every channel where consent is taken.
Record the withdrawal against the person and the purpose.
Push the change to every system and vendor that uses that purpose.
Confirm to the person, in writing, what has stopped and what is kept by law.
Check a sample every month to see that the change actually reached every list.
Evidence to keep
Withdrawal log with time stamps
Proof that downstream systems and vendors updated
Confirmation sent to the person
Common mistakes
Withdrawal by email only, while consent was one tap in an app
Stopping in the main system but not in vendor lists
Short answer: Yes, at every point where you collect data
A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.
From your seat: Marketing department. Landing pages, contest forms and event sign-ups each need a short notice.
In IT and ITeS
Your careers page, candidate portal, employee onboarding and website forms need notices. For client data, the client gives the notice.
What the law says
Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14
Steps
List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
Write one short notice per collection point, with the data items and purpose side by side.
Add how to withdraw consent, how to make a request and the DPO or contact person's details.
Offer the notice in English and in the languages your client customers actually use.
Keep each version with the date it went live.
Evidence to keep
Screenshots or copies of the notice at each collection point, with dates
Notice version history
Translations, where used
Common mistakes
Hiding the notice inside terms and conditions
One notice for everything, with no link between data items and purposes
Short answer: Check every channel; children often appear where you least expect
Anyone under 18 is a child under the Act. For a child's data you need verifiable consent from a parent or lawful guardian, and you must not track, behaviourally monitor or show targeted ads to children. Some classes and purposes are exempt under Rule 12 and the Fourth Schedule, for example healthcare to the extent needed to protect the child's health, and educational institutions for their educational work.
From your seat: Marketing department. Switch off targeting for under-18 audiences and avoid tracking them.
In IT and ITeS
Usually only if a client's service involves children, or in staff dependants' records.
What the law says
Section 9 sets the duties. Rule 10 explains how to verify the parent. Rule 12 and the Fourth Schedule list the exemptions. Section 9 · Rules 10, 12 · Section 6
Steps
Find where children's data enters: customers, dependants, interns, visitors, scholarships, app sign-ups.
Decide whether an exemption in the Fourth Schedule applies to that purpose.
Where none applies, add an age question and a parent-consent step.
Switch off tracking and targeted ads for under-18 users.
Record the decision for each channel.
Evidence to keep
Channel-by-channel note on children's data
Parent-consent records
Ad and tracking settings
Common mistakes
Assuming 'we are B2B, so no children'
Using the age 13 or 16 from foreign laws
Treating a tick-box from the child as parental consent
Short answer: Yes, every vendor that touches personal data
You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.
From your seat: Marketing department. Agencies, ad platforms and event partners receive data. Their contracts need data terms.
In IT and ITeS
Sub-contractors working on client data need the same terms you signed with the client.
Section 5 · Rule 3: Notice. Candidate portals, employee onboarding and your own website forms need notices. For client data, the client normally gives the notice.
Section 6: Consent. Marketing to prospects and optional employee programmes need proper consent.
Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to NIC or NPL time servers. Data centres, VPS, cloud and VPN providers keep specified subscriber information for five years.
Breach handling must meet the six-hour CERT-In clock and the DPDP report to the Board. Subscriber records need DPDP-level protection.