Compliance · Part of: TRAI TCCCPR and AI calling: what the rules require

The DPDP Act for sales teams: leads, consent and vendors

What India's DPDP Act and Rules mean for a sales team's leads: notice, consent, purpose, rights, breaches, and how duties split with a calling vendor.

The Digital Personal Data Protection Act, 2023 applies to the leads your sales team works. A name, a mobile number, a budget and a call recording are digital personal data. Your business decides why and how that data is used, so it is the Data Fiduciary and it answers for it. A calling vendor that processes leads on your behalf is a Data Processor, and may only do so under a valid contract. The DPDP Rules, 2025 were published on 13 November 2025, and the Rules behind most day-to-day duties come into force eighteen months later, on 13 May 2027. This is the position as of September 2026.

When it applies

Parliament passed the DPDP Act in August 2023 (Act text on MeitY (PDF), opens in a new tab). The DPDP Rules, 2025 (PDF), opens in a new tab, notified as G.S.R. 846(E) in the Gazette dated 13 November 2025, come into force in three steps under Rule 1:

  • On publication: definitions and the Rules on the Data Protection Board (Rules 1, 2 and 17 to 21).
  • One year after, 13 November 2026: registration of consent managers (Rule 4).
  • Eighteen months after, 13 May 2027: notice, security safeguards, breach intimation, retention, contact details, rights and the rest (Rules 3, 5 to 16, 22 and 23).

The government's press release of 14 November 2025 describes this as an eighteen-month phased compliance timeline. Timelines can be changed by notification, so check MeitY before planning around a date. Eighteen months is not long for a CRM holding years of call history.

What counts as personal data in a lead

The Act defines personal data as any data about an individual who is identifiable by or in relation to that data. It applies to personal data collected in digital form, or collected on paper and digitised later.

A qualified property lead holds a lot of it. By the end of a BlackWolf call, the lead record carries:

  • name and mobile number
  • budget, such as ₹85 lakh to ₹1.1 crore
  • configuration, locality and timeline
  • purpose, own use or investment
  • the site visit booked
  • sentiment and a summary
  • the full transcript and the recording of the caller's voice

All of it relates to one identifiable person. Consent under the Act must be limited to the personal data necessary for the specified purpose, so lead qualification should ask what qualifying needs and stop there.

The Act lets you process personal data for a lawful purpose on one of two grounds: the person's consent, or a "legitimate use" the Act lists.

Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. The request for consent must come with a notice, or after one. Rule 3 says the notice must stand on its own, itemise the personal data, state the specific purpose and describe the goods or services involved. It must also link to where the person can withdraw consent as easily as they gave it, exercise their rights and complain to the Data Protection Board. The person must be able to read the notice and the consent request in English or any language in the Eighth Schedule to the Constitution, which includes Hindi and Gujarati.

Legitimate use covers data a person voluntarily provided for a specified purpose, where they have not said they do not consent to its use. The Act's own illustration is a property case: a person messages a real estate broker asking for help finding a rented flat, and the broker may use her data to send her options. When she tells the broker she no longer needs help, the broker must stop processing her data.

Two practical points follow.

First, the notice lives where the data is collected. If leads come from a portal or an ad platform, check what the person was told there about who would contact them and why.

Second, decide what "no longer needed" means in your CRM. BlackWolf does not treat "I have already bought somewhere else" as a do-not-call instruction, because it is not one. Whether that lead should stay in your pipeline for the same purpose afterwards is a separate data question, and the broker illustration suggests it deserves an answer.

TRAI's consent is a different thing again. TRAI's Third Amendment to the TCCCPR, notified on 18 September 2026 (PDF), opens in a new tab, limits "consent" in the TCCCPR to permission for commercial communication, and says nothing in those regulations exempts a sender from the DPDP Act. A registered TRAI consent does not cover how you store, share or reuse the data. The telecom side is in TRAI's TCCCPR and AI calling.

Purpose limitation

Consent is tied to a specified purpose. A buyer who enquired about a 3 BHK in one project gave data for that. Pitching a different project, or passing the number to a channel partner, is arguably a different purpose. Decide the basis before the campaign, not after a complaint.

The same logic governs how long you keep data. The fiduciary must erase personal data when consent is withdrawn or when it is reasonable to assume the purpose is no longer served, unless a law requires it to be kept, and must make its processors erase it too. The Rules fix deemed-expiry periods only for large e-commerce, online gaming and social media platforms, so a developer has to set its own.

Against that, Rule 8(3) requires every fiduciary to keep personal data, associated traffic data and logs of processing for at least one year from the processing, including processing done by a processor. Its illustration makes the point with a cloud provider: the fiduciary must ensure the processor also keeps the data and logs for a year. So a lead cannot simply be wiped the day after its last call, either.

What a buyer can ask for

The Act gives the Data Principal, the buyer, these rights against the fiduciary:

  • Access. A summary of their personal data and the processing done, plus the identities of every other fiduciary and processor it has been shared with. You need to know which vendors hold a lead to answer this.
  • Correction, completion, updating and erasure. Erasure applies unless the data is still needed for the purpose or a law requires keeping it.
  • Withdrawal of consent, as easily as it was given. The fiduciary must then stop processing within a reasonable time, and make its processors stop.
  • Grievance redressal. Rule 14 requires a published grievance process with a response period of no more than ninety days. The buyer must use it before going to the Board.
  • Nomination of someone to act for them in death or incapacity.

Rule 9 adds that every fiduciary must publish the contact details of a person who can answer questions about its processing, and mention them in every reply to a rights request.

On a call, some of these arrive as speech. "Delete my details from your database" is one of the phrasings BlackWolf treats as an opt-out: the number goes on the suppression list the moment it is said. That stops the calls. The erasure request itself is yours to act on, as the fiduciary.

Data fiduciary and data processor

The Act draws the line by who decides. A Data Fiduciary determines the purpose and means of processing. A Data Processor processes personal data on a fiduciary's behalf. When a platform calls your leads, for your projects, on your instructions, you are usually the fiduciary and the platform your processor. The contract should say so.

DutyThe business (Data Fiduciary)The calling vendor (Data Processor)
Accountable under the ActYes, for its own processing and for processing done on its behalf, whatever the contract saysThrough its contract with the fiduciary
Notice and consentGives the notice, holds the consent or legitimate-use basisProcesses only for the purposes it is given
Security safeguardsMust ensure them, including at the processor, and put them in the contractImplements them: encryption, access control, logs, backups
BreachMust inform the Board and each affected buyerMust tell the fiduciary fast enough for it to do so
ErasureErases, and makes the processor eraseErases on instruction, keeps what the law requires
Rights requestsReceives and answers themHelps it find and export the data

Rule 6 sets the minimum safeguards: encryption, obfuscation, masking or tokens; access control; logs and monitoring to detect unauthorised access; backups; keeping those logs for a year; and a contract clause on safeguards between fiduciary and processor.

Breach reporting

When a fiduciary becomes aware of a personal data breach, Rule 7 requires it to tell each affected buyer without delay, in plain language: what happened, the likely consequences, what is being done, what the buyer can do, and whom to contact. It must tell the Board without delay, and send a detailed report within 72 hours of becoming aware, unless the Board allows longer on a written request.

A breach at your calling vendor is your breach to report. The 72 hours start when you become aware, and you only become aware when the vendor tells you. Put that notice period in the contract, in hours.

The penalties are set in the Act's Schedule. The government's explainer of 17 November 2025 (PDF), opens in a new tab summarises them: up to ₹250 crore for failing to maintain reasonable security safeguards, up to ₹200 crore each for failing to notify a breach and for breaching obligations relating to children, and up to ₹50 crore for other violations.

What to ask your calling vendor

  1. Will you sign as our Data Processor, processing our leads only for our purposes? Will our data train or inform anything used for another client? BlackWolf's agent keeps its memory within a client's own calls and CRM; it does not learn across clients.
  2. What are your security safeguards, against Rule 6? BlackWolf keeps each client's data in its own workspace, with isolation tested on every change. Recordings sit in private storage behind links that expire, credentials are encrypted at rest with AES-256-GCM, and the dashboard is served only over HTTPS. Details are on our security page.
  3. How many hours after you learn of a breach will you tell us?
  4. Which subprocessors touch our data, and where?
  5. Can you export everything held on one number, lead fields, transcripts and recordings, for an access request? Can you correct it, and erase it on instruction?
  6. How does an opt-out heard on a call reach us? It should be recorded at once, not left to a CRM status.
  7. How long do you keep recordings by default, and how does that fit the one-year minimum for logs?

For how these duties sit with the telecom rules on the same call, see our compliance page. An AI voice agent handling property leads is described on the real estate page.

What to do next

Map where each lead's data lives today, from the form to the call recording, and put a processor contract in place with every vendor on that map before May 2027.

This article is general information, not legal advice.

About us

We build BlackWolf’s voice agents and the dashboard they write to, and we write about what we learn doing it for businesses in India, the UAE, the UK and the US: how callers talk on the phone, the rules calls must follow, and what a call costs.

Frequently asked.

Is a mobile number on its own personal data?

Yes, when it relates to an identifiable person, which a lead's number does. The Act defines personal data as any data about an individual who is identifiable by or in relation to that data. It applies to personal data collected in digital form, or collected on paper and digitised later.

Does the DPDP Act replace TRAI's rules on commercial calls?

No. TRAI's TCCCPR decides whether and how a commercial call may be made. The DPDP Act governs the personal data behind the call. TRAI's Third Amendment, notified on 18 September 2026, says its consent rules do not exempt a sender from the DPDP Act.

Can a buyer ask us to delete their call recording?

A buyer can ask for erasure of personal data they consented to, and the fiduciary must erase it unless it is still needed for the purpose or a law requires keeping it. The Rules also require processing logs and associated data to be kept for at least a year. Settle how the two interact for recordings, with counsel, before the first request arrives.

Does a small developer have to appoint a Data Protection Officer?

The Act requires a Data Protection Officer only from Significant Data Fiduciaries, a class the government notifies. Every fiduciary must still publish the contact details of someone who can answer questions about its processing, and mention them in every reply to a rights request.

The agent, for real estate.

See what it would do with your leads.