All insights
ChecklistDPDP Compliance

Marketing vendor privacy controls under the DPDP Act

A source-led checklist for reviewing agencies, campaign tools, pixels and enrichment vendors before customer data is used for marketing.

Data>Nuance

Marketing vendors can turn one customer list into a confetti cannon with login credentials.

What to review

Marketing stacks process more personal data than many teams realise: lead lists, newsletter subscribers, event registrations, website identifiers, CRM segments, customer attributes, campaign results and suppression lists. Under the DPDP Act, the business that chooses the campaign purpose is usually the Data Fiduciary. Agencies, email platforms, analytics pixels, enrichment tools and campaign automation systems may be Data Processors, independent fiduciaries or both depending on how they use the data.

The review should start before a campaign launch, not after a dashboard goes live. Map what data enters the tool, whether consent or another lawful basis supports the use, whether the notice explains marketing use, and whether opt-outs are honoured across every vendor. Pay special attention to uploads, lookalike audiences, enrichment, retargeting and data-sharing features that can quietly expand the processing.

Good marketing governance is not anti-growth. It gives growth teams clearer boundaries, cleaner lists and fewer surprises when a vendor adds a new feature, sub-processor or export option.

The most useful review is campaign-specific. A newsletter platform, agency workspace and advertising account may each be acceptable in isolation, but the combined campaign may create a larger data trail than expected. For example, a lead form can feed the CRM, trigger an email journey, sync with a retargeting audience and land in an agency reporting sheet. Each transfer should have a purpose, owner, deletion expectation and suppression route. That level of detail helps marketing teams move quickly because approved patterns are reusable.

Implementation steps

  1. Build an inventory of marketing vendors, including agencies, email platforms, SMS providers, webinar tools, analytics tags, landing-page builders, enrichment services and ad platforms.
  2. Classify the data handled by each vendor: contact details, identifiers, behavioural events, purchase history, preference data, location signals and derived segments.
  3. Confirm the purpose and notice basis for each use. A lead nurture email, abandoned-cart reminder, retargeting audience and enrichment workflow may need different controls.
  4. Check whether consent, opt-out and suppression choices flow to every tool that sends, profiles or retargets people.
  5. Review contracts for documented instructions, confidentiality, security safeguards, sub-processor controls, breach support, deletion, return and restrictions on using the data for the vendor's own purposes.
  6. Limit exports and audience uploads. Require named owners, approval steps and deletion dates for CSV transfers, platform audiences and agency workspaces.
  7. Review tags and pixels with security and marketing operations. Remove unused tags, document data fields, and check whether identifiers are sent beyond the intended platform.
  8. Keep campaign evidence: vendor role, data fields, source list, suppression process, contract extract, risk owner and review date.

Add a launch gate for new vendors and high-volume campaigns. The gate does not need to be slow: confirm the audience source, check the notice and opt-out path, approve any customer-list upload, and record the vendor's deletion or suppression obligation. After launch, sample the actual data moving through the platform. If the tool is receiving fields that were not approved, pause the integration and correct the event, form or sync rule before the campaign becomes a permanent habit.

Common mistakes

  • Assuming an agency's tool is covered because the agency contract says "confidential information."
  • Uploading customer lists to advertising platforms without recording purpose, notice basis and deletion expectations.
  • Treating unsubscribe handling as an email-only issue while SMS, retargeting and enrichment vendors keep processing.

How DataNuance can help

DataNuance helps Indian growth, legal and privacy teams review marketing stacks without slowing every campaign to a crawl. We can map tools, test consent and suppression flows, review vendor clauses, and create a launch checklist for new campaigns. For help with marketing vendor privacy controls, speak with DataNuance's privacy advisory team.

FAQs

Are marketing agencies Data Processors under the DPDP Act?

Often, but not always. If the agency processes data only on the business's instructions, it is likely processor-like. If it decides its own reuse, enrichment or sharing, the role needs closer analysis.

What marketing tools need the most scrutiny?

Prioritise tools that receive customer lists, track behaviour, enrich profiles, create audiences, send communications or allow agency access. These systems can multiply data use quickly.

Should suppression lists be treated as personal data?

Yes. Suppression records still identify people or contact points and should be protected, retained only as needed, and shared with vendors only for opt-out enforcement.

What evidence should be kept for a campaign review?

Keep the source list, purpose, notice or consent basis, vendor role, contract extract, data fields, suppression process, tag review, risk owner and deletion date.

This publication is general information and is not legal advice for a specific organisation or matter.

Continue reading

DPDP Compliance

HR vendor privacy checklist under the DPDP Act

A practical checklist for reviewing payroll, recruitment, benefits and HR technology vendors before employee personal data is shared.

Read insight

Processors and vendors

Data processing clauses for Indian customer contracts

A practical checklist for Indian businesses adding DPDP-ready data processing clauses to customer contracts and order forms.

Read insight

Start with context

Book a focused DPDP Act consultation.

Bring an upcoming launch, notice review, data mapping question, incident readiness issue or implementation deadline. We will help identify the right next step.