At a glance
Marketing agencies live at the exact point the DPDP Act was aimed at: campaigns built on personal data — client CRM lists, pixel audiences, bought databases — used for a purpose (marketing) that almost always needs its own consent. The working rules: on client data you’re a processor, entitled to rely on the client’s consent trail but wise to ask for it; bought and scraped lists are now radioactive, because unprovable consent is unusable data; tracking-built audiences need a consent basis; and targeted advertising at children is off-limits entirely.
Educational resource only. This explains how India’s Digital Personal Data Protection Act, 2023 (DPDP Act) applies to digital marketing and advertising agencies; it is not formal legal advice.
The situation
Every campaign is a data operation wearing a creative brief: the client’s customer list uploaded for a lookalike, the pixel feeding retargeting pools, the “database vendor” WhatsApping a lakh numbers for a launch blast. The industry’s habits formed when none of this had rules; the DPDP Act is the rulebook arriving after the game — and it lands hardest on the two things agencies do most: use data collected for something else, and acquire data whose origins nobody can prove. Agencies that can run consent-clean campaigns are about to become the safe pair of hands every compliance-nervous client wants.
Does DPDP apply to agency work?
Yes, in both of the Act’s roles — processor for the client’s data, fiduciary for your own. Running campaigns on a client’s customer data makes you a Data Processor: the Act requires that to happen under a valid contract, on the client’s instructions — which is why data terms now arrive stapled to every agency retainer. Your own operation — the leads pipeline, the newsletter, case-study data, your employees — makes you a Data Fiduciary with the standard duties. And the moment an agency enriches, merges or reuses client data on its own initiative — building a cross-client audience pool, say — it has quietly become a fiduciary for that pool, with duties nobody scoped and consent nobody collected. Knowing which hat each dataset puts on you is the profession’s first compliance skill.
The data an agency actually runs on
Other people’s data, in every direction.
- Client-supplied lists — CRM exports, customer databases, lapsed-lead files: the fiduciary’s data, in your processor hands.
- Tracking-generated audiences — pixel and SDK events, site behaviour, retargeting pools, lookalike seeds: personal data manufactured by the campaign itself.
- Acquired lists — bought, swapped, scraped, “sourced” databases: the inventory whose consent trail is the whole question.
- Campaign exhaust — form fills, contest entries, chat-bot conversations, call-tracking recordings: collected under your creative, governed by whoever’s notice (if any) stood behind it.
- Your own pipeline — prospects, pitches, the agency newsletter: the ordinary fiduciary estate.
The obligation that actually bites: consent you can trace
Marketing is a purpose that needs consent — and the burden of proving it sits with the fiduciary, which makes every list’s provenance a legal question before it’s a deliverability one.
- The client’s list needs the client’s consent trail. As processor you act on the client’s basis — but “act on” isn’t “assume.” A client whose list was built from purchases with no marketing opt-in is asking you to run a campaign on unconsented data; the agency that asks “can you show the consent behind this list?” before the blast is protecting both parties. Make it an onboarding question, in writing.
- Bought lists are radioactive. A database vendor’s lakh numbers come with no provable consent, no notice trail, and no answer when a recipient complains. Under a law where unprovable consent is unusable data, acquired lists aren’t a grey area anymore — they’re the industry habit to retire first.
- The pixel builds personal data. Behavioural tracking, retargeting pools and lookalike audiences are processing — they need a notice-and-consent basis on the site that feeds them, which is the client’s banner and policy to get right and the agency’s job to insist on before deploying the tag.
- Campaign exhaust needs a notice at the point of capture. The landing-page form and contest entry are points of collection: what’s collected, why, and the marketing opt-in unbundled from the prize draw — patterns the consent-design guides on this site spell out.
Where DPDP meets the telecom spam rules and the children’s ban
Two overlays sit on top of the consent machinery — the old spam regime and the new children’s rule. SMS and voice campaigns have long lived under the telecom regulator’s commercial-communication rules (the DND registry and its consent framework) — that regime continues, and DPDP layers the general data-protection duties over it: the number’s consent trail, the purpose limits, the erasure rights. Running a tele-campaign now means clearing both bars, and the DND-scrubbed-but-never-consented list clears neither. The second overlay is absolute: targeted advertising directed at children is prohibited — not consent-gated, prohibited. Audience pipelines that can’t exclude under-18s (age-ambiguous social audiences, broad lookalikes on youth-heavy platforms) need designing around that line, and “the platform handles it” is an assumption, not an answer, when the campaign is yours.
Common mistakes agencies make
Industry defaults, now liabilities.
- The database vendor habit — bought lists blasted for launches; unprovable consent, unusable data, and the complaint lands on a real regulator now.
- Running the client’s list on faith — never asking whether marketing consent exists behind the CRM export; the processor’s contract protects the agency that asked, not the one that didn’t.
- Cross-client audience pooling — one client’s data seeding another’s campaigns: an unscoped fiduciary role with nobody’s consent behind it.
- Pixels before banners — deploying tracking on client sites whose notice and consent flows don’t cover it.
- The pre-ticked opt-in on the landing page — still everywhere, still invalid.
- Contest data as harvest — entries collected for a prize, worked as a marketing list forever after: purpose limitation’s textbook violation.
Running campaigns compliantly
Make provenance a deliverable. Onboarding asks the consent question in writing (list source, opt-in mechanism, notice version) and the retainer carries real data terms — the DPA pattern in this site’s templates section is the shape. Campaign builds put the notice and unbundled opt-in on every capture point, deploy tracking only over consent flows that cover it, and design audiences that can honour the children’s line. Data handling runs processor-clean: per-client segregation, no cross-pollination, deletion at campaign or retainer end, and campaign exhaust handed to the client with its consent records attached — because that consent trail is what makes the list an asset instead of a liability. The agency that delivers provable audiences is selling something the market is about to price very highly.
FAQ
Can we still run campaigns on bought databases?
Practically, no — a bought list carries no provable consent, and the burden of proof sits with the fiduciary running the campaign. The defensible growth tools are consented capture, provable first-party lists and platform targeting that doesn’t require holding the data at all.
Is the client’s consent our problem as an agency?
Legally the trail is the client’s to hold; practically, the agency executes the blast and shares the fallout. Ask for the consent basis in writing at onboarding — it’s one email, and it’s the difference between a processor doing its job and an accomplice with a contract.
Do retargeting pixels need consent?
The behavioural data they collect needs a lawful basis, which means the site’s notice and consent flows must cover the tracking before the tag goes live. Deploying the pixel is the agency’s act; insisting on the banner first is the agency’s protection.
Can we target ads at teenagers?
Targeted advertising directed at children — under-18s — is prohibited outright, not consent-gated. Audience designs need to exclude minors by construction, and platform defaults don’t discharge a duty that sits on the campaign.
What should agencies change first?
Retire acquired lists and start asking the provenance question on every client list — those two moves eliminate most of the exposure. Then wire notices and unbundled opt-ins into every capture point you build; that’s where compliant lists come from.