India’s Digital Personal Data Protection Act, 2023 (DPDP Act) is the country’s first dedicated data protection law, and it rewrites the rules for anyone processing personal data digitally — including sales and marketing teams.
What counts as personal data?
Any data about an identifiable individual. Crucially for B2B: data about a company — its legal name, GSTIN, registered address, or board line number — is not personal data. But the moment a record identifies a person (a named director, a personal mobile number, an individual’s email), the DPDP Act applies to it.
The core obligations
- Consent or legitimate use: processing personal data needs free, specific, informed consent — or must fall under a defined “legitimate use”.
- Notice: data principals must be told what’s collected and why, in plain language.
- Rights: individuals can demand access, correction, and erasure, and can complain to the Data Protection Board of India.
- Penalties: up to ₹250 crore per instance for serious breaches — this is not a slap-on-the-wrist regime.
What B2B teams should do now
Audit your lists: separate establishment-level business data from person-level data. Source from providers who verify against public registries. Honour opt-outs immediately — under the DPDP Act, withdrawal of consent must be as easy as giving it.
This article is general information, not legal advice.