DPDP compliance for advertising and digital marketing agencies

DPDP compliance for advertising and digital marketing agencies
Advertising

DPDP compliance for advertising and digital marketing agencies

Ad agencies and digital marketing firms handle client customer data and third-party audience data at scale. Here is what the DPDP Act requires.

Quick Answer: Advertising and digital marketing agencies occupy a complex position under the DPDP Act: they are Data Processors when handling client customer data for campaigns, and Data Fiduciaries when using that data for their own purposes or building their own audience assets. Every campaign involving personal data requires a Data Processing Agreement with the brand client. Third-party data used for audience targeting — DMP segments, purchased lists, lookalike audiences — must have a valid consent trail traceable to the original collection. Agencies must stop using client data for any purpose not covered in the DPA. Enforcement begins May 2027.

Are advertising agencies Data Fiduciaries or Data Processors under DPDP?

When an agency runs a campaign using a client's customer data — email list, CRM segment, purchase history — and does so strictly on the client's instructions, the agency is a Data Processor and the brand is the Fiduciary. When the agency uses that data for its own purposes — building proprietary audience models, benchmarking across clients, training its own AI tools — it becomes a Fiduciary for that use. Most agencies are both, in different contexts, and need clear internal governance to keep the roles distinct.

What must a DPA between an agency and a brand client include?

The DPA must: specify exactly which data the agency can access and for which campaign purposes; prohibit the agency from using the client's customer data for cross-client benchmarking or proprietary model training without explicit permission; require the agency to delete campaign data at the end of the engagement; mandate breach notification to the client within a defined window; restrict sub-processors (ad tech vendors, media buying platforms) to those the client has approved; and document the security measures the agency will apply to client data.

How does DPDP affect third-party data and DMP segments?

Third-party audience data — segments purchased from Data Management Platforms, demographic enrichment data, contextual intent signals — must have a valid consent basis at the original collection source. Agencies using third-party data for Indian audiences must verify that the data provider has appropriate consent from Indian data principals, or that the data is genuinely anonymised. Buying 'Indian HNI intent segments' from a data broker without verifiable consent is a significant DPDP risk — both for the agency and the brand client.

What are the DPDP rules for retargeting and pixel tracking?

Retargeting campaigns use pixels — small code snippets that track website visitors across the internet. These pixels create identifiable profiles of browsing behaviour, which is personal data under the DPDP Act. Before loading a tracking pixel, you need the visitor's consent. Consent must be obtained through a proper consent mechanism on the client's website, and the consent must specifically cover the third-party platforms (Meta pixel, Google tag) whose pixels are being loaded. Review the consent infrastructure on every client website where you run retargeting.

How does DPDP apply to programmatic advertising?

Programmatic advertising uses personal data — device IDs, cookie profiles, behavioural segments — to target ads to individuals in real time. This is profiling-based advertising that requires consent from the target individual. The consent trail in programmatic is complex: the publisher collected the consent, passed data to a DSP, which shared it with the SSP, which ran the auction. Agencies using programmatic for Indian audiences need to understand the consent architecture of the supply chain they are buying through — and stop buying inventory where valid Indian consent cannot be verified.

What must agencies do with client data at end of contract?

On contract termination, the DPA should require the agency to: delete all client customer data from its systems; certify deletion in writing; and ensure sub-processors (ad platforms, analytics tools) have also deleted or revoked access. Many agencies retain client data informally in team drives, analytics dashboards, or pitch decks after the contract ends — this is a DPDP risk. Build a structured data offboarding process triggered by contract expiry.

Frequently asked questions

Can an agency use one client's customer data to build audience models for another client?

No. Using Client A's customer data to build or inform audience models for Client B is a clear data breach under the DPDP Act and almost certainly a breach of Client A's DPA. Client data used in a campaign must be used only for that client's purposes and deleted or returned when the engagement ends. Even anonymised or aggregated data derived from Client A's customers cannot be shared without Client A's consent if there is any risk of re-identification.

Does DPDP apply to influencer marketing campaigns?

DPDP applies when influencer campaigns involve collecting personal data from the influencer's audience — sign-up forms, giveaway entries, DMs forwarded to the brand. The influencer's audience members are data principals whose data requires consent. If the campaign involves collecting email addresses or other personal data, you need a proper consent mechanism and a privacy notice, and the data must be handled under the brand's (or agency's) Data Fiduciary obligations.

Are marketing analytics platforms (GA4, Mixpanel, Amplitude) compliant with DPDP?

Marketing analytics platforms receive personal data — IP addresses, device IDs, user behaviour — via tags on client websites. These platforms are Data Processors and require DPAs. Most major platforms have updated their data processing terms for GDPR, which provide a reasonable starting point for DPDP DPAs, but you should verify that the terms cover: India-specific consent requirements, data residency or approved transfer countries, and breach notification to the Indian Data Fiduciary.

Review your agency's DPDP compliance

Niti Bharat's Vendor Risk Assessment covers ad tech stacks, DPA gaps with brand clients, third-party data consent risks, and pixel/programmatic compliance under DPDP.

Start Agency DPDP Assessment
Previous Post Next Post

Get Free DPDP Checklist