India's DPDP Act makes your business responsible for every personal record in your CRM. You need clear notice and consent before using lead data, a way to honor withdrawal, access, correction and erasure requests, reasonable security, breach reporting, and deletion once the purpose is served. Core obligations apply from around May 2027, with penalties up to ₹250 crore.
For most Indian SMBs, the CRM is where personal data concentrates: IndiaMART enquiries, Facebook Lead Ads, WhatsApp chats, walk-in visitor details. That makes DPDP Act CRM compliance less about paperwork and more about how your system captures, stores and deletes records. This guide explains what changes and gives you a feature checklist. It is general information, not legal advice.
Key takeaways
- The DPDP Rules were notified on 14 November 2025. Most core duties phase in over 18 months, so plan to be ready by May 2027.
- Your business is the data fiduciary. You stay accountable even when your CRM vendor processes data for you.
- Consent must be tied to a stated purpose and be as easy to withdraw as to give.
- Erase data once its purpose is served, and keep records of consent and processing.
- Maximum penalties reach ₹250 crore for failing to take reasonable security safeguards.
What the DPDP Act means for CRM data
The Digital Personal Data Protection Act, 2023 covers digital personal data processed in India, and data processed abroad when offering goods or services to people in India, according to PRS Legislative Research. A lead's name, mobile number, email, WhatsApp chat and purchase history in your CRM all count.
Key roles:
- Data principal: the lead or customer.
- Data fiduciary: your business, which decides why and how the data is used.
- Data processor: your CRM vendor, or an agency running campaigns for you.
Unlike Europe's GDPR, the Indian law does not offer a broad "legitimate interests" basis. Outside a narrow list of legitimate uses, you generally need consent.
DPDP Rules 2025 timeline
According to India Briefing, the rules phase in like this:
| When | What starts |
|---|---|
| 14 November 2025 | Rules notified; Data Protection Board provisions take effect |
| About November 2026 (12 months) | Registration and functioning of consent managers |
| About May 2027 (18 months) | Core obligations: notice, consent, purpose limits, children's data, security, retention and erasure, breach reporting |
As of September 2026, you are inside the preparation window. CRM changes take time, so start now.
Core obligations mapped to CRM features
| DPDP obligation | What it means in your CRM | Feature to look for |
|---|---|---|
| Notice before collection | Tell leads what you collect and why | Form templates with a notice link and purpose text |
| Purpose-specific consent | Record consent per purpose, such as sales calls or WhatsApp offers | Consent fields with timestamp, source and purpose |
| Easy withdrawal | Opt-out must be as easy as opt-in | One-click unsubscribe; "STOP" handling on WhatsApp |
| Accuracy and completeness | Keep records correct when used for decisions | Validation rules, duplicate checks, edit history |
| Reasonable security safeguards | Protect data from breaches | Role-based access, 2FA, encryption, export controls |
| Breach notification | Inform the Board and affected people | Audit logs to reconstruct who accessed what |
| Erasure when purpose ends | Delete leads you no longer need | Retention rules and bulk erasure |
| Data principal rights | Access, correction, erasure, grievance | Easy record export and a request log |
| Children's data | Verifiable parental consent under 18 | Age flag on forms where relevant |
On breaches, India Briefing reports the rules require notifying affected individuals without delay and giving the Board a detailed report within 72 hours. Clean records help here too. Our guide to CRM data quality covers deduplication and validation.
India-specific scenarios to check
IndiaMART, JustDial and portal leads
A buyer who sends an enquiry has shared details for that enquiry. Replying about it is reasonable. Adding that person to unrelated marketing sequences for years is harder to justify. Tag each record's source and purpose at import.
Facebook and Instagram lead ads
Put your notice link and purpose in the lead form, and map consent answers into CRM fields. See our guide to connecting Facebook Lead Ads to your CRM.
WhatsApp follow-ups
WhatsApp has its own rules. Meta's opt-in policy requires businesses to clearly state that a person is opting in to WhatsApp messages and to name the business. Store that opt-in in the CRM and honor opt-outs immediately. Our explainer on what a WhatsApp CRM does covers the setup.
Purchased contact lists
Bought databases rarely come with valid consent for your purpose. Under the DPDP Act they are a liability, not an asset.
A practical DPDP readiness checklist for your CRM
- Map your data. List every source that creates CRM records and the fields each collects.
- Rewrite notices. Add plain-language purpose text to every lead capture form.
- Add consent fields. Capture purpose, timestamp, channel and proof for each lead.
- Set retention rules. Decide how long unconverted leads stay, then auto-archive or erase.
- Lock down access. Limit exports, enable two-factor login and review user roles.
- Sign a data processing agreement with your CRM vendor and any agency.
- Create a request workflow for access, correction and erasure, with a named owner.
- Write a breach plan covering who investigates, who notifies and within what time.
If you're choosing software, weigh these features alongside price in our roundup of the best CRM in India.
Complying with India's Digital Personal Data Protection (DPDP) Act requires maintaining verifiable consent audit trails within your CRM database. Implement automated data subject access and deletion request workflows, and restrict employee access to personal data using granular RBAC. Prioritizing data privacy governance protects corporate reputation while building buyer confidence in your commercial operations.
Frequently asked questions
Does the DPDP Act apply to small businesses using a CRM?
Yes. The Act applies to anyone processing digital personal data of individuals in India, with no general exemption by company size, though the government can notify exemptions for certain classes such as startups. If your CRM stores names, phone numbers or emails of Indian customers or leads, plan to comply and check any exemptions that are later notified.
Is my CRM vendor responsible for DPDP compliance?
Mainly no. Your business decides why and how lead data is used, so it is the data fiduciary and stays responsible, including for what a vendor does on its behalf. The CRM vendor acts as a data processor. Choose one with strong security, a clear data processing agreement, and tools for consent, access, erasure and audit logs.
Can I still send WhatsApp messages to leads under the DPDP Act?
Yes, if you have valid consent for that purpose and honor withdrawals. WhatsApp separately requires businesses to get opt-in that names the business and states that the person will receive WhatsApp messages. Record when and where each lead opted in, and stop messaging immediately when someone opts out.
When do DPDP Act obligations take effect?
The DPDP Rules were notified on 14 November 2025 with a phased rollout. Data Protection Board provisions started immediately, consent manager rules follow about 12 months later, and most core obligations, including notice, consent, security safeguards and erasure, apply about 18 months after notification, around May 2027. Confirm dates against official notifications.
Conclusion: build compliance into the CRM, not around it
The DPDP Act rewards businesses that collect less, record consent properly and delete on time. Most of that is CRM configuration: forms, consent fields, access controls and retention rules. Start the changes now, and check specific questions with a qualified legal advisor.
Want a CRM that captures leads with consent fields from forms, WhatsApp and social in one place? Try Autometa CRM free.
Related reading
- How to Implement a CRM: A Step-by-Step Roadmap
- The CRM Features Checklist: 20 Must-Haves in 2026
- Why Use a CRM? 10 Benefits Backed by 2026 Data
- How to Connect AI Agents to Your CRM (Without Breaking Your Data)
Sources
- DPDP Rules 2025: India's Data Protection Law Compliance — India Briefing, 2025
- The Digital Personal Data Protection Bill, 2023 — PRS Legislative Research, 2023
- Get opt-in for WhatsApp — Meta for Developers, 2026

