The DPDP compliance guide for Indian email marketers
The Digital Personal Data Protection Act 2023 is now backed by the November 2025 Rules. Indian email programs have until 14 May 2027 to get substantive.[1][2] Here is what to fix, what to demand from your ESP, and a 30-day checklist.

1. What changed with the November 2025 Rules
The DPDP Act 2023 was notified in the Gazette of India on 11 August 2023. It was originally silent on the enforcement trigger date, leaving Indian data fiduciaries uncertain about their compliance runway.
On 13 November 2025, the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)).[1] The Rules clarify the obligations of Data Fiduciaries, the rights of Data Principals, and the notice-andconsent regime. The headline effective dates:
- Rule 1(4) — Most obligations (notice, consent, breach notification, Data Principal rights) effective one year from notification — that is, 13 November 2026.
- Rule 4 — Data Principal rights to access, correction, erasure, and portability for digital personal data collected before the Rules: two years from notification — that is, 13 November 2027.
- Sub-rule 1(5) — Substantial obligations for Significant Data Fiduciaries: 18 months from notification — that is, 13 May 2027.
For most B2B email marketers using LoopNow or similar ESPs, the relevant deadline is 14 May 2027 — the date that Rule 1(4) obligations become enforceable against smaller Data Fiduciaries as well, once the 18-month Significant Data Fiduciary period elapses.
2. Section 8: the notice you must publish
Section 8 of the Act requires every Data Fiduciary to publish a notice — in English and in any of the 22 languages in the Eighth Schedule — describing what personal data is being collected, the purpose, the manner of processing, and the rights of Data Principals. The Rules specify that this notice must be standalone (not buried in a privacy policy), itemise each purpose, and be reachable in one click from every form that collects personal data.
3. Consent must be specific, informed, and revocable
Section 6 requires consent that is free, specific, informed, unconditional, and unambiguous. Pre-ticked boxes, bundled consents, and consent obtained through deceptive UI are all non-compliant. The Rules require that the consent notice itemise each purpose, that the user can withdraw consent with the same ease as giving it, and that withdrawal is processed within 72 hours.
For email marketers, this means: separate consent for marketing vs. transactional email, separate consent for list-rental or third-party sharing, and a one-click unsubscribe that does not require login.
4. Data Principal rights you must honour
Data Principals have the right to:
- Access a copy of their personal data (Section 11).
- Correct inaccurate or misleading data (Section 12).
- Erase personal data once the purpose is fulfilled or consent is withdrawn (Section 12).
- Nominee appointment for transmission in case of death or incapacity (Section 14).
You must acknowledge a request within 72 hours and fulfil it within 30 days. Failure to respond is treated as a deemed refusal and is appealable to the Data Protection Board.
5. Breach notification in 72 hours
Section 8(7) requires notification to the Data Protection Board and affected Data Principals within 72 hours of becoming aware of a personal data breach that is likely to cause harm. The Rules add a 6-hour window to inform the Board of any breach that includes children's data or sensitive financial data.
6. Children's data
Section 9 prohibits processing personal data of children under 18 without verifiable parental consent. Marketing to children is presumptively non-compliant unless (a) you have a verifiable parental consent mechanism, and (b) you do not use behavioural monitoring or targeted advertising. The Rules define "verifiable" as a token-based system or a video-KYC process.
7. What to demand from your ESP
If you are evaluating or re-evaluating your email service provider for DPDP readiness, here is the checklist we recommend:
- Consent receipts: every form should generate a tamper-evident receipt (timestamp, IP, source, exact consent text).
- Purpose limitation: the ESP should let you tag each list with a purpose, and refuse to send a campaign whose stated purpose does not match the consent receipt.
- One-click unsubscribe: must work without login. Gmail and Yahoo now require this anyway.
- Data Principal access: a self-service portal where a Data Principal can view, export, and erase their data.
- Breach playbooks: documented 72-hour breach notification process.
- Data residency: AWS Mumbai (ap-south-1) by default, with the ability to pin specific datasets to India.
- Sub-processor list: published and updated at least 30 days in advance of any change.
8. 30-day DPDP compliance checklist
Here is a pragmatic order of operations. None of these are hard on their own; the order matters.
- Day 1–3: Audit your data — what personal data do you hold, where, for what purpose, on what legal basis?
- Day 4–7: Publish a standalone notice (Section 8). Link it from every form.
- Day 8–10: Refactor every consent form to be specific, granular, and revocable in one click.
- Day 11–14: Verify your unsubscribe works without login and is honoured within 72 hours.
- Day 15–18: Stand up a Data Principal access workflow (or use your ESP's built-in).
- Day 19–22: Document a breach notification playbook. Tabletop it.
- Day 23–25: Sign a DPA with your ESP. Publish your sub-processor list.
- Day 26–30: Train your team. Run a 2-hour refresher on what counts as personal data and what doesn't.
Sources
- Government of India, Ministry of Electronics and Information Technology. Digital Personal Data Protection Rules, 2025 — Notification G.S.R. 846(E), 13 November 2025.
- Government of India. Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), assented 11 August 2023.