Data protection law

Personalise campaigns within the DPDP Act, from your own cloud

With Actions, your team draws on everything clients agreed to, and client data stays under your firm’s control.

The DPDP Act covers any firm processing digital personal data in India

It reaches data collected digitally or digitised later, which a firm may process on the person’s consent or a legitimate use the Act names.

95.8Cr

active internet users in India in 2025, whose data the Act covers

IAMAI and Kantar, Internet in India Report 2025

Data fiduciary

Whoever decides why and how personal data is processed

Data principal

The person whose personal data is processed

Data processor

Anyone processing personal data for a fiduciary

Consent manager

A registered company people give and withdraw consent through

Significant data fiduciary

One the government notifies for added duties

Most duties under the DPDP Act apply from 14 May 2027

On that day the DPDP Act also takes over from the privacy rules made under the IT Act.

221days

until most of the Act’s duties apply

The Act

Signed into law on 11 August 2023

The Rules

Notified on 14 November 2025, the Data Protection Board set up with them

Consent managers

Register with the Board from 14 November 2026

RBI’s own rule

Promotions from banks and NBFCs only on explicit consent, from 1 January 2027

Most duties

Notice, security safeguards and breach intimation among them

Your firm answers for its vendors, whatever the contract says

A campaign may use a client’s data only for a purpose they agreed to, and their withdrawal has to reach every vendor processing that data.

In broking, the DPDP Act adds to SEBI’s own rules on client data

The Act prevails only where the two conflict, and a record SEBI requires is kept even after a client asks for erasure.

8years

the least time a broker keeps its client records under SEBI’s rules

Records

Account forms, KYC, ledgers and contract notes

Confidentiality

Client details disclosed only as law requires, or with written permission

Outsourcing

SEBI’s cybersecurity framework has you audit your third-party providers’ IT

Existing clients

Owed a notice of their data and its purposes, by email or in-app

Minors’ accounts

A parent’s verifiable consent, and no advertising aimed at the child

Actions in your cloud means fewer vendors hold your client data

Actions computes each campaign where holdings, orders and P&L already sit, and a channel receives only the message and its address.

Explore security and trust

Segments draw on 100+ attributes and drop any client who opts out

Matchbook finds the clients a recommendation fits, and Commentary designs their nudge from the same data.

>66%

of consumers would share data for personalisation

82%

of consumers rank data protection as key to trust

PwC India, Voice of the Consumer Survey 2024

What firms ask before they upgrade

Does this solve a problem for you, or are you looking to upgrade?