At a glanceCollecting customer or client data compliantly under India’s DPDP Act follows a repeatable recipe: give a clear notice at the point of collection, take valid consent for each purpose (or rely on a defined legitimate use), collect only the data the purpose needs, use it only for that purpose, keep it secure, set a retention-and-deletion limit, and be able to prove the consent and honour people’s rights. Get that flow right once and it applies to every form, upload and intake channel you run.
Educational resource only. This explains how to collect personal data in line with India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice, and DPDP compliance is an organisation-wide obligation broader than any single intake step.
Whether you collect through a web form, a document upload, a WhatsApp message or a paper form that gets digitised, the same obligations apply. This is the umbrella; the specific channels — Google Forms, WhatsApp Business, KYC collection — each have their own guide in this section.
Start with the notice
Before you collect anything, tell the person plainly what you’re taking and why.
The DPDP Act requires a notice at the point of collection (Section 5). It has to state, in clear language, what personal data you’re collecting, the purpose it’s for, how the person can withdraw consent, and how they can complain — to you and to the Data Protection Board of India. The notice is what makes any consent that follows “informed,” so it comes first, not buried in a policy the person never reads.
Take valid consent — per purpose
Consent has to be a clear, specific “yes” to a stated purpose — not one bundled tick covering everything.
Consent under the DPDP Act must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action (Section 6). In practice that means:
- One purpose, one consent. If you’ll use a phone number for delivery and marketing, those are two purposes — split them, don’t bundle.
- No pre-ticked boxes or “by continuing you agree.” The person must actively opt in.
- As easy to withdraw as to give. Build the withdrawal route from the start.
Collect only what the purpose needs
Ask for the minimum the stated purpose requires — extra fields are a liability, not a bonus.
Collection is tied to purpose: gather only the data genuinely needed for what you told the person you’d do. A delivery needs an address, not a date of birth; an OTP needs a phone number, not an Aadhaar. Over-collecting isn’t just non-compliant — every extra field you hold is more to secure, more to delete later, and more exposure if you’re ever breached.
Secure it, set retention, and honour rights
Holding data compliantly means protecting it, not keeping it forever, and being able to act on requests.
Once you’ve collected data, the DPDP Act’s fiduciary obligations kick in (Section 8): keep it reasonably secure, use it only for the stated purpose, and don’t hold it longer than needed — set a retention limit and delete when the purpose is over (Section 8 read with the erasure duty). You also have to be able to honour rights requests (access, correction, erasure) and, crucially, to prove the consent you relied on — the burden of showing valid consent sits with you, so keep a demonstrable record.
Where consent isn’t the basis: legitimate use
A few situations let you process without a consent box — but they’re a defined, limited list.
Not everything runs on consent. The Act lists specific legitimate uses (Section 7) — for example, data a person voluntarily provides for a clear purpose, or certain employment purposes — where a consent box isn’t required. It’s a closed list, not a catch-all: if your situation doesn’t fit one of them, consent is back to being the rule, and the notice, security and retention duties still apply either way.
Applying this to your actual intake
The recipe is the same; the specifics change with the channel — so start from the channel guides.
The obligations above don’t change whether you use a form, an upload link, or a chat. What changes is how you implement them in each tool — and some common tools don’t provide compliant notice, purpose-bound consent, or a provable record on their own. See the dedicated guides in this section for the channels you actually use (web forms, Google Forms, WhatsApp Business, document/KYC collection) to apply the recipe correctly.
FAQ
Do I need consent for every piece of data I collect?
Usually yes, per purpose — unless a defined legitimate use (Section 7) applies. Even then, the notice, security and retention duties still hold.
Is a single “I agree” checkbox enough?
No. Consent must be specific to a purpose and unbundled. One tick covering several unrelated uses doesn’t meet the standard.
How long can I keep the data I collect?
Only as long as the stated purpose needs it. Set a retention limit and delete when the purpose is over, unless a law requires you to keep specific records for a set period.
What if I use Google Forms or WhatsApp to collect data?
Those tools collect data but don’t, on their own, provide a compliant notice, purpose-bound consent, or a provable consent record — the responsibility to meet those stays with you. See the channel-specific guides in this section.