Data protection law
Personalise campaigns within the DPDP Act, from your own cloud
With Actions, your team draws on everything clients agreed to, and client data stays under your firm’s control.
The DPDP Act covers any firm processing digital personal data in India
It reaches data collected digitally or digitised later, which a firm may process on the person’s consent or a legitimate use the Act names.
95.8Cr
active internet users in India in 2025, whose data the Act covers
IAMAI and Kantar, Internet in India Report 2025
Data fiduciary
Whoever decides why and how personal data is processed
Data principal
The person whose personal data is processed
Data processor
Anyone processing personal data for a fiduciary
Consent manager
A registered company people give and withdraw consent through
Significant data fiduciary
One the government notifies for added duties
Most duties under the DPDP Act apply from 14 May 2027
On that day the DPDP Act also takes over from the privacy rules made under the IT Act.
221days
until most of the Act’s duties apply
The Act
Signed into law on 11 August 2023
The Rules
Notified on 14 November 2025, the Data Protection Board set up with them
Consent managers
Register with the Board from 14 November 2026
RBI’s own rule
Promotions from banks and NBFCs only on explicit consent, from 1 January 2027
Most duties
Notice, security safeguards and breach intimation among them
Your firm answers for its vendors, whatever the contract says
A campaign may use a client’s data only for a purpose they agreed to, and their withdrawal has to reach every vendor processing that data.
In broking, the DPDP Act adds to SEBI’s own rules on client data
The Act prevails only where the two conflict, and a record SEBI requires is kept even after a client asks for erasure.
8years
the least time a broker keeps its client records under SEBI’s rules
Records
Account forms, KYC, ledgers and contract notes
Confidentiality
Client details disclosed only as law requires, or with written permission
Outsourcing
SEBI’s cybersecurity framework has you audit your third-party providers’ IT
Existing clients
Owed a notice of their data and its purposes, by email or in-app
Minors’ accounts
A parent’s verifiable consent, and no advertising aimed at the child
Actions in your cloud means fewer vendors hold your client data
Actions computes each campaign where holdings, orders and P&L already sit, and a channel receives only the message and its address.
Segments draw on 100+ attributes and drop any client who opts out
Matchbook finds the clients a recommendation fits, and Commentary designs their nudge from the same data.
>66%
of consumers would share data for personalisation
82%
of consumers rank data protection as key to trust
PwC India, Voice of the Consumer Survey 2024