The short answer: A digital marketing agency is usually a Data Processor for the audience and customer data it handles on a client's instruction, and a Data Fiduciary for its own leads, contacts and pitch lists. But agencies occupy a third position no other sector does: they install the trackers that create the client's consent obligation, which makes agency work the most common single cause of a client's non-compliance.

DPDP for Digital Marketing Agencies

📢 Sector: Digital Marketing Agencies⚖️ Key provisions: s. 8(1)–(2) accountability and processor contracts · s. 6 consent standard · s. 7 voluntary provision · s. 9(3) no targeted advertising to children · Rule 3 notice content📅 In force: 13 May 2027
On this page
  1. Why agencies are a genuinely distinct case
  2. Which role are you in?
  3. The tag stack problem, precisely
  4. Lead generation: the bundling problem
  5. Section 9(3): behavioural targeting of children ends
  6. Your client contracts need work
  7. What to do in the next quarter
  8. Where Consiva fits
  9. Frequently asked questions

Why agencies are a genuinely distinct case

The DPDP Act is sector-neutral. Obligations attach to the processing of digital personal data, so most sector guidance is one checklist with a different logo.

Agencies are different for a reason that has nothing to do with a special provision. The agency is usually the party that physically deploys the mechanism that breaches the law. The remarketing pixel on the client's checkout page, the third-party analytics loading before the banner reads consent, the lead-gen form that bundles a download with a marketing opt-in, the audience list uploaded to an ad platform — these are agency deliverables.

The client carries the liability. Under section 8(1) a Data Fiduciary is responsible for compliance in respect of processing undertaken by it or on its behalf by a Data Processor, notwithstanding any agreement to the contrary. So the client cannot contract the exposure back to you. But they can, and will, come after you commercially and under your contract — and from 13 May 2027 their procurement will start testing whether you know any of this.

That cuts both ways, and it is the commercial point of this page. An agency that can run a compliant tag stack, evidence consent-gated tracking and hand a client a clean audit trail has a service line. An agency that cannot is a liability its clients will eventually price.

Which role are you in?

What you're handlingYour roleWho answers to the Board
Client's customer lists, CRM exports, audience segmentsData ProcessorYour client
Tags, pixels and tag manager configuration on the client's propertyData Processor — acting on instructionYour client
Campaign performance data tied to identifiable individualsData Processor, usuallyYour client
Lead-gen form submissions collected for a clientData Processor — but see belowYour client
Your own prospect and pitch listsData FiduciaryYou
Your own website visitors, newsletter subscribers, event attendeesData FiduciaryYou
Your staff and contractor dataData FiduciaryYou
Audience data you enrich, blend across clients, or reuseData Fiduciary — you chose that purposeYou

The last row is the one that catches agencies out. The moment you use data gathered for Client A to inform work for Client B, or blend it into a proprietary audience product, you have determined a new purpose and become a Data Fiduciary for it — with your own notice, consent and rights obligations, and no client to stand behind. If your pitch deck mentions proprietary audience data or cross-client benchmarking built from identifiable individuals, that is what you are doing.

The working test: if you would be the one deciding to start a new use of the data, you are the Fiduciary for it.

The tag stack problem, precisely

Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by clear affirmative action. From 13 May 2027, where a cookie or tracker processes personal data, that standard engages.

The failure mode is not the banner. It is the firing order.

A correctly configured consent banner sitting on top of tags that load on first paint is a compliance failure with a compliant-looking interface. The client sees a banner, believes they are covered, and every page view has already sent data to three ad platforms before anyone clicked anything.

This is almost always an agency-side configuration issue, and it is the single most valuable thing an agency can fix for a client before 2027:

A practical note on evidence. Being able to show a client "here is the tracker inventory, here is what fires before consent, here is what we fixed, here is the dated scan proving it" is a deliverable you can charge for. It is also exactly what their auditor will ask for.

Lead generation: the bundling problem

Agency lead-gen is where consent architecture most reliably breaks, because the standard playbook is built on an exchange the Act does not permit.

The standard playbook: gate a whitepaper behind a form, collect the email, add it to a nurture sequence.

The problem: section 6 requires consent to be unconditional and limited to the personal data necessary for the specified purpose. Under section 7, personal data voluntarily provided for a specified purpose may be processed for that purpose. Downloading a whitepaper is the purpose. A twelve-email nurture sequence is a different purpose.

Making the download conditional on accepting marketing means the consent is not free and not unconditional. The part that infringes is invalid to that extent.

What works instead

On purchased and scraped lists. Third-party B2B contact data used for outbound is processing personal data you did not obtain from the individual. That needs disclosure in your own privacy notice, an objection route, and a defensible basis. An agency selling cold outbound as a service should have a clear position on this before a client asks.

Section 9(3): behavioural targeting of children ends

This is the hard stop, and it has no workaround.

Section 9(3) prohibits a Data Fiduciary from undertaking tracking or behavioural monitoring of children, or targeted advertising directed at children. A child is anyone who has not completed eighteen years — considerably higher than GDPR's 13-to-16 range or COPPA's 13.

For an agency this is not an edge case. It affects:

ActivityPosition
Remarketing audiences that include under-18sProhibited
Interest or behavioural targeting where children are in the audienceProhibited
Lookalike audiences seeded from lists containing minorsProhibited
Any campaign for a product whose audience is predominantly under-18Effectively contextual-only
Contextual advertising on youth-oriented contentPermitted — no profiling involved
Session recording and heatmaps on child-facing pagesBehavioural monitoring — treat as prohibited

Note the practical difficulty: you often cannot tell whether an audience contains children. Section 9(1) requires verifiable parental consent before processing a child's personal data at all, and 9(3) bans the tracking outright. An agency running broad-reach remarketing for a consumer brand cannot readily demonstrate the audience is adults-only.

[LEGAL COUNSEL REVIEW RECOMMENDED] The safe operating position for youth-adjacent brands is contextual targeting plus age assurance where the client's product justifies it. This is an area where the market has not settled and where an agency's documented reasoning matters more than certainty.

Also relevant: section 9(2) prohibits processing likely to cause a detrimental effect on a child's well-being, and it cannot be disapplied by any Schedule or notification. Engagement mechanics designed to maximise time-on-platform for a young audience sit uncomfortably against it.

Your client contracts need work

Section 8(2) permits a Data Fiduciary to engage a Data Processor only under a valid contract. From 2027 your clients will need one with you, and most agency MSAs are silent on data protection.

What a client's counsel will look for:

That last item is worth pricing. An erasure request that has to propagate into audience lists across four ad platforms is real work, and it will arrive with a deadline attached.

What to do in the next quarter

  1. Audit every client's tag stack in a clean profile. Document what fires before consent. This is a billable engagement and the highest-value thing on this list.
  2. Determine your role per data set. Where are you Processor, where Fiduciary, and where have you quietly become a Fiduciary by reusing data?
  3. Rebuild lead-gen forms to unbundle the asset from the marketing consent, and fix withdrawal parity.
  4. Strip behavioural targeting from anything youth-adjacent, and document the reasoning.
  5. Get a DPA template drafted and offer it to clients before they ask. Arriving with one is a differentiator; being asked for one you don't have is not.
  6. Publish your own privacy notice properly — including how you handle third-party prospecting data — and name a privacy contact. You are a Data Fiduciary for your own lists.
  7. Fix your own site's banner and firing order before you sell the service.

Where Consiva fits

Two ways, and the second is the commercially interesting one.

For your clients' properties. Automated cookie and tracker scanning across domains, consent banners in any of 22 Eighth Schedule languages, consent signals passed to tag managers, form consent capture, and dated scan evidence you can hand a client.

As an agency service line. The Pro plan covers 5 domains, with the Domain Pack adding 10 domains for ₹80,000 a year plus applicable taxes — ₹8,000 per domain plus applicable taxes (available on annual Pro and Enterprise billing). For an agency running consent across a client portfolio, that is a per-client cost you can package into a retainer at a margin, with one dashboard across every property. Enterprise supports unlimited domains where the portfolio is larger.

Start free — 1 domain, 1,000 cookie consents and 50 form consents a month, no card. Enough to run a real scan on your own site before you pitch it. → Pricing

Frequently asked questions

Is a marketing agency a Data Processor or a Data Fiduciary under the DPDP Act?

Usually a Data Processor for client data handled on instruction, and a Data Fiduciary for its own prospect lists, website visitors and staff data. An agency also becomes a Data Fiduciary for any data it reuses across clients or blends into a proprietary audience product, because it has then determined the purpose itself.

Who is liable if an agency installs a tracking pixel without valid consent?

The client, as Data Fiduciary. Section 8(1) makes them responsible for processing carried out on their behalf notwithstanding any agreement to the contrary. The agency's exposure is contractual and commercial rather than direct to the Board — which in practice means indemnity claims and lost accounts.

Can we run remarketing campaigns under the DPDP Act?

For adults, yes, with valid purpose-specific consent obtained before the trackers fire. For children — anyone under eighteen — section 9(3) prohibits behavioural tracking and targeted advertising outright, and there is no consent route around it.

Can we still gate content behind a form and add people to a nurture sequence?

You can gate the content and collect the data for the purpose of delivering it. Adding the person to a marketing sequence is a separate purpose requiring separate, unbundled consent that is not a condition of the download. Making the download conditional on marketing consent fails the "free" and "unconditional" tests in section 6.

Do we need a data processing agreement with our clients?

Yes. Section 8(2) permits a Data Fiduciary to engage a Data Processor only under a valid contract. Most existing agency MSAs are silent on data protection and will need a DPA or schedule added.

How quickly must we tell a client about a breach?

Fast enough for them to meet their own deadlines — which means hours. Clients face a 6-hour CERT-In reporting window today, and from 13 May 2027 a DPDP duty to intimate the Board "without delay". A contractual 72-hour notification from you would put them in breach.

Does DPDP apply to our own outbound prospecting?

Yes, and you are the Data Fiduciary for it. Business contact data obtained from third-party providers is personal data you did not collect from the individual, which needs disclosure in your privacy notice, an objection route and a defensible basis.

Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023, ss. 6, 7, 8(1)–(2), 9(1)–(3), 11; DPDP Rules, 2025, Rules 3, 8(3). Positions marked as interpretation are not settled law. Reference material about the law, not legal advice — see /disclaimer.

DPDP compliance built for Digital Marketing Agencies

Consiva.ai covers every obligation above with pre-configured workflows, templates, and automated jobs — purpose-built for India's data protection law.

Start Free — No Credit Card →