Authority Guides6 mins

Authority Guide to DPDP 2023 for Adtech and Programmatic Chains in D2C

A definitive analysis for General Counsels navigating the Digital Personal Data Protection Act, 2023, and Rules, 2025, concerning adtech operations. With exactly 280 days remaining until the 13 May 2027 deadline, legal teams must urgently untangle programmatic consent chains and reallocate liability across media buyers and publishers.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

The digital advertising ecosystem relies heavily on bundled consent and opaque data sharing between brands, demand side platforms, and publishers. The Digital Personal Data Protection Act, 2023, disrupts this architecture by imposing strict accountability on the Data Fiduciary. General Counsels at D2C and e-commerce enterprises face severe contract risks if their programmatic partners fail to record itemised, explicit consent for targeting. With exactly 280 days remaining until the 13 May 2027 hard compliance deadline, legal heads must prioritize vendor renegotiation, limitation of liability clauses, and the deployment of compliant consent architecture. Ignoring this transition exposes the enterprise to maximum penalties of INR 250 crore per breach.

Statutory Framework For Adtech Operations

The DPDP Act, 2023, establishes strict boundaries for collecting and processing personal data in adtech. Under Section 4, a person may process digital personal data only for a lawful purpose. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. For D2C brands, this means bundling marketing consent with shipping data is no longer permissible. Furthermore, Section 8 of the Act dictates that a Data Fiduciary remains entirely responsible for compliance, irrespective of any agreement to the contrary. When a brand engages an ad network as a Data Processor, Section 8 requires a valid contract to govern that relationship. Legal teams must draft stringent indemnity clauses to cover processor errors, as the fiduciary cannot contract out of its statutory liability.

Targeted Advertising And Child Data Limits

D2C brands operating in the edtech, gaming, or youth apparel sectors must strictly observe Section 9 of the Act. Section 9 prohibits Data Fiduciaries from undertaking tracking or behavioural monitoring of children. It also issues a blanket ban on targeted advertising directed at children. Before processing personal data of a child, fiduciaries must obtain verifiable parental consent in the manner prescribed by the Rules, 2025. Violations of Section 9 obligations carry severe financial exposure, with penalty ceilings up to INR 200 crore. Outside counsel spend will balloon rapidly if a brand is investigated for programmatic campaigns inadvertently targeting minors due to poorly configured audience segments.

Rules 2025 Operational Layer For Marketers

The DPDP Rules, 2025, introduce significant operational shifts for standard marketing funnels. Rule 3 mandates that the itemised notice preceding consent must be made available in 22 languages. For e-commerce companies scaling into Tier-2 markets, translating technical privacy terms requires specialised tooling, not just manual legal review. The Rules also specify that consent must be granular, forcing a separation between transactional data required for fulfillment and behavioral data used for retargeting. Furthermore, brands processing high volumes of data may be classified as Significant Data Fiduciaries. This SDF designation brings additional duties, including the appointment of an independent data auditor and conducting periodic Data Protection Impact Assessments for programmatic campaigns.

Enforcement Trajectory And The DPBI

Enforcement by the Data Protection Board of India will likely focus on systemic failures in consent architecture rather than isolated errors. In the event of a programmatic data spill or unauthorized sharing by an ad exchange, the Rules, 2025, require the Data Fiduciary to intimate affected Data Principals without delay. Simultaneously, a detailed report must be filed with the Data Protection Board within 72 hours. Defensibility during a regulatory inquiry depends entirely on the audit trails your platforms generate. A legal department cannot establish a safe harbour if marketing teams use fragmented spreadsheets to track user opt-outs across multiple programmatic networks.

Comparative Context For Cross Border Transfers

Legal heads familiar with foreign privacy regimes must recalibrate for India. The Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. Regarding cross-border transfers to foreign ad servers, transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. This negative list approach requires a different vendor diligence framework compared to foreign regulations. Additionally, Indian law does not recognise a separate sensitive data classification requiring higher consent thresholds, meaning risk and volume are assessed holistically to determine obligations.

Decision Matrix For Programmatic Liability

Scenario 1 Media Buying via DSP. Obligation is securing unbundled marketing consent before syncing identifiers. Owner is CMO and Legal. Artifact is a verifiable consent receipt matching campaign IDs.

Scenario 2 Engaging third-party analytics. Obligation is a Section 8 data processor contract with strict limitation of liability caps. Owner is General Counsel. Artifact is an executed Data Processing Agreement.

Scenario 3 E-commerce checkout. Obligation is presenting Rule 3 itemised notices in the user language. Owner is CTO. Artifact is multilingual notice rendering logs.

Scenario 4 Age verification for targeted campaigns. Obligation is blocking behavioral tracking for minors under Section 9. Owner is Ad Ops. Artifact is verifiable parental consent records.

What To Ask Any Provider During Vendor Evaluation

When evaluating a compliance platform for your D2C operations, enterprise diligence is paramount. Do not rely on a heavy banking GRC tool for agile e-commerce needs. Instead, ensure the platform features a consent unbundler that specifically separates shipping data from marketing data. Verify if the tool automatically translates the required Rule 3 notices into all 22 languages for Tier-2 customers without burdening your outside counsel. Demand to see the technical evidence trail it generates for regulatory inquiries, ensuring logs are immutable. Finally, review their SLA for breach support, as your legal team will need immediate forensic data to meet the 72-hour DPBI reporting window.

Implementation Roadmap For Legal And Marketing

Day 30 Milestone. General Counsel initiates a privileged review of all existing ad agency and programmatic vendor contracts to assess current indemnity gaps under Section 8. Day 60 Milestone. Marketing and IT deploy consent unbundling mechanisms across all D2C web properties to isolate transactional data from behavioral identifiers. Day 90 Milestone. Legal signs off on automated multilingual notice deployment and finalises the incident response playbook for the 72-hour breach reporting window.

Further Reading For The Enterprise GC

For deeper legal analysis on related operational obligations, legal teams should review ComplyDP guides on Data Processor Contractual Guardrails, Rule 3 Multilingual Notice Strategies for E-commerce, and the General Counsel Framework for DPDP Board Investigations.

Establishing defensibility in your programmatic adtech stack requires specialized tooling that bridges the gap between marketing velocity and legal stringency. Book a consultation with ComplyDP or start with our free assessment at freescan.complydp.com to evaluate your current adtech compliance gaps.

Sources

Frequently asked questions

Does the DPDP Act allow us to bundle marketing consent with shipping information?

No. Under the DPDP Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. Bundling is prohibited, meaning D2C brands must unbundle shipping data from marketing data to ensure consent is free, specific, and informed.

Who is liable if our programmatic advertising agency violates the DPDP Act?

Under Section 8 of the Act, the Data Fiduciary remains fully responsible for compliance irrespective of any agreement to the contrary. You must ensure you have a valid contract with the agency as a Data Processor and establish robust limitation of liability and indemnity clauses.

Can we continue to run targeted advertising campaigns directed at youth demographics?

Section 9 strictly prohibits Data Fiduciaries from undertaking tracking, behavioural monitoring, or targeted advertising directed at children. If you process data of individuals under 18, you must obtain verifiable parental consent as prescribed by the Rules, 2025, or risk penalties up to INR 200 crore.

What is the timeline for reporting a data breach involving advertising identifiers?

The Rules, 2025, require the Data Fiduciary to provide intimation to affected Data Principals without delay plus a detailed report to the Data Protection Board within 72 hours. Your legal and IT teams must have an incident response playbook ready to meet this strict window.

How do we handle cross-border data transfers to our foreign demand side platforms?

The Act permits cross-border transfers of personal data unless the Central Government restricts transfer to notified countries or territories via a negative list. You must maintain contracts with foreign processors under Section 8 to protect your liability.