The DPDP Act is sector-neutral. Obligations attach to the processing of digital personal data, so most sector guidance is one checklist with a different logo.
Agencies are different for a reason that has nothing to do with a special provision. The agency is usually the party that physically deploys the mechanism that breaches the law. The remarketing pixel on the client's checkout page, the third-party analytics loading before the banner reads consent, the lead-gen form that bundles a download with a marketing opt-in, the audience list uploaded to an ad platform — these are agency deliverables.
The client carries the liability. Under section 8(1) a Data Fiduciary is responsible for compliance in respect of processing undertaken by it or on its behalf by a Data Processor, notwithstanding any agreement to the contrary. So the client cannot contract the exposure back to you. But they can, and will, come after you commercially and under your contract — and from 13 May 2027 their procurement will start testing whether you know any of this.
That cuts both ways, and it is the commercial point of this page. An agency that can run a compliant tag stack, evidence consent-gated tracking and hand a client a clean audit trail has a service line. An agency that cannot is a liability its clients will eventually price.
| What you're handling | Your role | Who answers to the Board |
|---|---|---|
| Client's customer lists, CRM exports, audience segments | Data Processor | Your client |
| Tags, pixels and tag manager configuration on the client's property | Data Processor — acting on instruction | Your client |
| Campaign performance data tied to identifiable individuals | Data Processor, usually | Your client |
| Lead-gen form submissions collected for a client | Data Processor — but see below | Your client |
| Your own prospect and pitch lists | Data Fiduciary | You |
| Your own website visitors, newsletter subscribers, event attendees | Data Fiduciary | You |
| Your staff and contractor data | Data Fiduciary | You |
| Audience data you enrich, blend across clients, or reuse | Data Fiduciary — you chose that purpose | You |
The last row is the one that catches agencies out. The moment you use data gathered for Client A to inform work for Client B, or blend it into a proprietary audience product, you have determined a new purpose and become a Data Fiduciary for it — with your own notice, consent and rights obligations, and no client to stand behind. If your pitch deck mentions proprietary audience data or cross-client benchmarking built from identifiable individuals, that is what you are doing.
The working test: if you would be the one deciding to start a new use of the data, you are the Fiduciary for it.
Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by clear affirmative action. From 13 May 2027, where a cookie or tracker processes personal data, that standard engages.
The failure mode is not the banner. It is the firing order.
A correctly configured consent banner sitting on top of tags that load on first paint is a compliance failure with a compliant-looking interface. The client sees a banner, believes they are covered, and every page view has already sent data to three ad platforms before anyone clicked anything.
This is almost always an agency-side configuration issue, and it is the single most valuable thing an agency can fix for a client before 2027:
A practical note on evidence. Being able to show a client "here is the tracker inventory, here is what fires before consent, here is what we fixed, here is the dated scan proving it" is a deliverable you can charge for. It is also exactly what their auditor will ask for.
Agency lead-gen is where consent architecture most reliably breaks, because the standard playbook is built on an exchange the Act does not permit.
The standard playbook: gate a whitepaper behind a form, collect the email, add it to a nurture sequence.
The problem: section 6 requires consent to be unconditional and limited to the personal data necessary for the specified purpose. Under section 7, personal data voluntarily provided for a specified purpose may be processed for that purpose. Downloading a whitepaper is the purpose. A twelve-email nurture sequence is a different purpose.
Making the download conditional on accepting marketing means the consent is not free and not unconditional. The part that infringes is invalid to that extent.
On purchased and scraped lists. Third-party B2B contact data used for outbound is processing personal data you did not obtain from the individual. That needs disclosure in your own privacy notice, an objection route, and a defensible basis. An agency selling cold outbound as a service should have a clear position on this before a client asks.
This is the hard stop, and it has no workaround.
Section 9(3) prohibits a Data Fiduciary from undertaking tracking or behavioural monitoring of children, or targeted advertising directed at children. A child is anyone who has not completed eighteen years — considerably higher than GDPR's 13-to-16 range or COPPA's 13.
For an agency this is not an edge case. It affects:
| Activity | Position |
|---|---|
| Remarketing audiences that include under-18s | Prohibited |
| Interest or behavioural targeting where children are in the audience | Prohibited |
| Lookalike audiences seeded from lists containing minors | Prohibited |
| Any campaign for a product whose audience is predominantly under-18 | Effectively contextual-only |
| Contextual advertising on youth-oriented content | Permitted — no profiling involved |
| Session recording and heatmaps on child-facing pages | Behavioural monitoring — treat as prohibited |
Note the practical difficulty: you often cannot tell whether an audience contains children. Section 9(1) requires verifiable parental consent before processing a child's personal data at all, and 9(3) bans the tracking outright. An agency running broad-reach remarketing for a consumer brand cannot readily demonstrate the audience is adults-only.
Also relevant: section 9(2) prohibits processing likely to cause a detrimental effect on a child's well-being, and it cannot be disapplied by any Schedule or notification. Engagement mechanics designed to maximise time-on-platform for a young audience sit uncomfortably against it.
Section 8(2) permits a Data Fiduciary to engage a Data Processor only under a valid contract. From 2027 your clients will need one with you, and most agency MSAs are silent on data protection.
What a client's counsel will look for:
That last item is worth pricing. An erasure request that has to propagate into audience lists across four ad platforms is real work, and it will arrive with a deadline attached.
Two ways, and the second is the commercially interesting one.
For your clients' properties. Automated cookie and tracker scanning across domains, consent banners in any of 22 Eighth Schedule languages, consent signals passed to tag managers, form consent capture, and dated scan evidence you can hand a client.
As an agency service line. The Pro plan covers 5 domains, with the Domain Pack adding 10 domains for ₹80,000 a year plus applicable taxes — ₹8,000 per domain plus applicable taxes (available on annual Pro and Enterprise billing). For an agency running consent across a client portfolio, that is a per-client cost you can package into a retainer at a margin, with one dashboard across every property. Enterprise supports unlimited domains where the portfolio is larger.
Start free — 1 domain, 1,000 cookie consents and 50 form consents a month, no card. Enough to run a real scan on your own site before you pitch it. → Pricing
Usually a Data Processor for client data handled on instruction, and a Data Fiduciary for its own prospect lists, website visitors and staff data. An agency also becomes a Data Fiduciary for any data it reuses across clients or blends into a proprietary audience product, because it has then determined the purpose itself.
The client, as Data Fiduciary. Section 8(1) makes them responsible for processing carried out on their behalf notwithstanding any agreement to the contrary. The agency's exposure is contractual and commercial rather than direct to the Board — which in practice means indemnity claims and lost accounts.
For adults, yes, with valid purpose-specific consent obtained before the trackers fire. For children — anyone under eighteen — section 9(3) prohibits behavioural tracking and targeted advertising outright, and there is no consent route around it.
You can gate the content and collect the data for the purpose of delivering it. Adding the person to a marketing sequence is a separate purpose requiring separate, unbundled consent that is not a condition of the download. Making the download conditional on marketing consent fails the "free" and "unconditional" tests in section 6.
Yes. Section 8(2) permits a Data Fiduciary to engage a Data Processor only under a valid contract. Most existing agency MSAs are silent on data protection and will need a DPA or schedule added.
Fast enough for them to meet their own deadlines — which means hours. Clients face a 6-hour CERT-In reporting window today, and from 13 May 2027 a DPDP duty to intimate the Board "without delay". A contractual 72-hour notification from you would put them in breach.
Yes, and you are the Data Fiduciary for it. Business contact data obtained from third-party providers is personal data you did not collect from the individual, which needs disclosure in your privacy notice, an objection route and a defensible basis.
Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023, ss. 6, 7, 8(1)–(2), 9(1)–(3), 11; DPDP Rules, 2025, Rules 3, 8(3). Positions marked as interpretation are not settled law. Reference material about the law, not legal advice — see /disclaimer.
Consiva.ai covers every obligation above with pre-configured workflows, templates, and automated jobs — purpose-built for India's data protection law.
Start Free — No Credit Card →