Confidential Dispatch

"Just email it to me" — why email document collection breaks DPDP, and what to do

4 min readUpdated 2026-07-04
On this page
  1. 01Why email feels fine but isn’t
  2. 02The four duties email quietly misses
  3. 03The copies problem nobody thinks about
  4. 04What to do instead
  5. 05FAQ
At a glance

“Just email me your Aadhaar and PAN” is the most common way Indian businesses collect documents — and one of the weakest under the DPDP Act. Email gives no notice or specific consent at collection, sends sensitive documents over a channel you don’t control, and leaves permanent copies scattered across inboxes, sent folders, and backups with no retention limit. It’s not that email is banned; it’s that it quietly misses the notice, consent, security, and deletion duties that are yours. There are simple, better ways to collect.

Educational resource only. This explains why email is a weak channel for document collection under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice, and DPDP compliance is an organisation-wide obligation broader than any single channel.

The situation

It’s the reflex request: “just email me your documents.” The client attaches their Aadhaar, PAN, and a bank statement, hits send, and you both move on. It’s frictionless — which is exactly why the risk is invisible. Under the DPDP Act, that one email has created several problems you now own.

Why email feels fine but isn’t

Email is built to send messages, not to collect personal data safely — and the mismatch is where the trouble sits. It’s familiar and universal, so it feels like a safe default. But an email attachment travels and rests on servers you don’t control, lands in a mailbox that’s a long-lived store rather than a secure vault, and arrives with no notice, no purpose-bound consent, and no retention attached. The convenience hides the fact that none of the DPDP basics were met at the point of collection.

The four duties email quietly misses

Each step of the recipe that a proper intake would handle, email skips. Specifically:

  • Notice (Section 5). “Email me your documents” carries no clear statement of purpose, withdrawal, or grievance route.
  • Specific consent (Section 6). Sending an attachment isn’t a recorded, purpose-bound opt-in — and you can’t easily prove what was agreed.
  • Security (Section 8). Ordinary email isn’t a controlled channel; attachments sit unencrypted in inboxes and may be forwarded onward.
  • Retention. The documents now live indefinitely across mailboxes and backups, with no deletion schedule.

None of these are exotic requirements — they’re the core duties, and the email habit misses all four at once.

The copies problem nobody thinks about

The real danger of email is duplication: one send creates many permanent copies you’ll never fully round up. A single emailed PAN exists in the sender’s sent folder, your inbox, anyone you forward it to, every device that synced the mailbox, and every backup taken since. Months later, that document is still sitting in a dozen places, long past the purpose it was collected for — the opposite of minimisation and retention. When a mailbox is breached, that accumulated pile of clients’ identity documents is the prize. You can’t secure or delete what you can’t even locate.

What to do instead

Swap the open inbox for a channel that carries notice, consent, and control — and hold less. The practical alternatives:

  1. Use a purpose-built, access-controlled intake — a secure form or portal that presents a notice and captures specific consent at the point of upload, rather than an email attachment.
  2. Present the notice and take consent first — state what you need, why, and for how long, and record the agreement.
  3. Minimise and mask — ask only for the documents the purpose needs, and accept masked versions (like a masked Aadhaar) where the full one isn’t required.
  4. Control storage and retention — receive documents into one secured location, not a mailbox, and delete on a schedule.
  5. If email is truly unavoidable, at least reduce exposure: ask for masked/redacted documents, move them out of the mailbox into secured storage on receipt, and delete the email copies.

FAQ

Is collecting documents by email actually against the DPDP Act?

Email isn’t banned, but it misses the notice, consent, security, and retention duties that are yours — so routine document collection by email leaves you exposed. A controlled intake channel is a much better fit.

What’s the single biggest problem with email intake?

Permanent, scattered copies. One attachment lives in multiple inboxes and backups indefinitely, defeating minimisation and retention and creating a rich target if a mailbox is breached.

Does a client emailing me their documents count as consent?

No. It isn’t a recorded, purpose-bound opt-in, and it comes with no notice. You can’t reliably prove what was consented to.

What if a client insists on emailing?

Reduce the exposure: request masked documents, move them into secure storage on receipt, delete the email copies, and keep a proper consent record separately.

Reviewed by Confidential Dispatch Editorial Team
Last updated 4 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →