At a glanceEven basic contact details — name, phone number, email — are personal data under India’s DPDP Act, so the basics apply: tell the customer why you’re collecting it, and use it only for that purpose. The reassuring part: where a customer voluntarily gives you their number to get the very thing they asked for, that can be a “legitimate use,” so you don’t always need a separate consent box for the core service. But anything beyond it — especially marketing — is a different purpose that needs its own opt-in.
Educational resource only. This explains collecting basic contact data under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.
The situation
Not every intake is Aadhaar and KYC — most is mundane: a name and a number to call back, an email to send a booking. Businesses often wonder if the DPDP Act now means a consent ceremony for every phone number. It doesn’t. But “basic” data still has basic rules, and the line between “using it to serve them” and “using it for more” is where care is needed.
Yes, a phone number is “personal data”
A name, phone number, or email identifies a person — so it’s personal data, and collecting it makes you a Data Fiduciary. There’s no “too trivial to count” threshold. That doesn’t mean every field needs a heavy process; it means the ordinary duties — be clear about the purpose, use it only for that, keep it secure, don’t hold it forever — apply to contact data just as they do to anything else. The weight is proportionate: basic data, handled for an obvious purpose, needs a light touch, not none.
What you actually need for basic contact details
Tell them why, and stick to it — that’s the core of it. For everyday contact data:
- A clear purpose, stated (Section 5) — “to confirm your booking,” “to deliver your order.” The person should know what the number or email is for.
- Purpose-binding — use it only for what you said. A number taken to send an OTP isn’t a marketing list.
- Minimisation — collect what the purpose needs. A callback needs a number, not a date of birth.
- Security and retention — keep it reasonably safe, and don’t hold it beyond the purpose.
That’s a light routine, not a legal project — but it’s not nothing, and the purpose-binding part is where most slip-ups happen.
When you don’t need a consent box: legitimate use
Where a customer hands you their details specifically to get what they asked for, you can often rely on “legitimate use” rather than a separate consent tick. The DPDP Act recognises certain legitimate uses (Section 7) — including where a person voluntarily provides their data for a specified purpose and hasn’t indicated they object. So when someone gives you their phone number so you can call them back about their enquiry, you generally don’t need a distinct consent box to use it for exactly that.
Two guardrails keep this honest: it only covers the purpose the person offered the data for, and you should still be transparent about that purpose. It is not a doorway to using the same number for unrelated things.
Where it goes wrong: using it for more than you said
The failure is almost always scope creep — taking data for one purpose and quietly using it for another. The classic example: a customer gives their number to complete a purchase, and it ends up on a promotional SMS list. Fulfilling the order is one purpose (and may be a legitimate use); marketing is a separate purpose that needs its own specific consent. The same applies to sharing the contact with a “partner,” or reusing an enquiry email for a newsletter. Keep each new purpose to its own opt-in, and the basics stay simple.
FAQ
Do I need consent just to take a customer’s phone number?
Not always. Where they give it to you specifically to get what they asked for, that can be a legitimate use — so a separate consent box isn’t always required for the core service. You should still be clear about the purpose and use it only for that.
Is a name and email really “personal data” under the DPDP Act?
Yes. Anything that identifies a person is personal data, so the ordinary duties apply — proportionate to how basic the data is.
Can I add a customer’s number to my marketing list?
Only with their specific consent for marketing. Fulfilling their request and marketing to them are different purposes; the second needs its own opt-in.
How long can I keep a customer’s contact details?
As long as the purpose needs them. Once there’s no live purpose (and no legal duty to retain), delete them.