A multi-channel marketing-permission framework covering DPDP readiness, TRAI telecom rules, lead forms, suppression and vendors.
A lead form is not lifetime permission to send promotional messages across every channel, product and group company.
The DPDP framework is phased. The 14 November 2025 commencement notification brought specified institutional and enabling provisions into force immediately; section 6(9), section 27(1)(d) and rule 4 follow after one year; most operating duties and rules follow eighteen months after Gazette publication. As of 22 June 2026, readiness should distinguish current law from future-state DPDP controls.
DPDP consent principles require specified purpose and meaningful withdrawal once the relevant provisions commence.
TRAI separately regulates promotional calls and messages, sender registration, headers, templates, consent and customer preferences.
Transactional or service communication should not disguise promotion.
| Check | What to examine |
|---|---|
| Source | Website, event, partner, customer or purchased list. |
| Purpose | Response, service or promotion. |
| Channel | Email, SMS, WhatsApp, voice or push. |
| Proof | Language, time, sender and version. |
| Withdrawal | Suppression and vendor sync. |
A user downloads a tax guide and provides a mobile number. The company adds the person to promotional WhatsApp, SMS and partner offers, though the form supported only delivery of the guide.
Maintain permission by channel and purpose. One CRM opt-in flag should not control every communication.
Ensure withdrawal propagates to agencies, campaign tools and warehouses while preserving a secure suppression record.
Identify the people, data, system, purpose, owner, vendor and transaction or event. Review source, purpose and channel together. Do not start from a policy template or software feature; start from what the business and system actually do.
Apply the 14 November 2025 commencement notification provision by provision. Continue complying with currently operative IT, CERT-In, telecom, banking, insurance, employment, consumer, contract and criminal-law requirements. Build the future DPDP process now, but do not describe a scheduled rule as already legally operative.
Keep the approved decision, notice or workflow version, access or event logs, vendor evidence, user communications and remediation record. Update product design, role access, retention, support scripts or incident playbooks so the same weakness does not recur.
Privacy governance is an operating system, not a policy PDF. The data map, purpose, access, vendor, retention, user workflow, incident response and evidence file must all tell the same story.
Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.