DPDP compliance for real estate companies
Real estate developers and brokers collect rich buyer profiles and financial data. Here is what the DPDP Act requires from your sales and operations teams.
What personal data do real estate companies collect under DPDP?
Real estate companies accumulate detailed buyer profiles: name, contact details, PAN, Aadhaar, financial capability information (loan pre-approval, salary slips), site visit records, communication history, negotiation details, and post-sale documentation. Property management companies additionally hold tenant records, lease terms, maintenance request histories, and access credentials. Each of these is personal data requiring a lawful basis and a defined retention period.
Do real estate companies need consent for marketing to site visitors?
Yes. Capturing a prospect's contact details at a site visit or through a property portal requires disclosure of how that data will be used. If the developer or broker plans to add the prospect to a marketing database, send WhatsApp messages, or share data with co-brokers, each of these uses requires consent at the point of collection. Pre-checked consent boxes or implicit consent ('by visiting our site you agree to receive updates') do not meet the DPDP standard.
How does DPDP interact with RERA disclosure requirements?
RERA requires developers to disclose project details and maintain transparency with allottees. DPDP adds a parallel layer: buyers have the right to access the personal data the developer holds about them, including their financial profile and communication history in the CRM. These are complementary obligations — RERA protects the buyer's project rights; DPDP protects their personal data rights. Ensure your customer-facing team can handle both types of requests.
Can real estate companies share buyer data with co-brokers?
Sharing a buyer's personal data — financial profile, contact details, loan eligibility — with a co-broker requires the buyer's explicit consent for that specific sharing. Many developers and brokers routinely share prospect data across their broker networks without consent. This is a significant DPDP risk — audit your data sharing practices and put data protection clauses into your co-broker agreements, treating co-brokers as Data Processors where they act on your instructions.
What are the DPDP implications of proptech and digital sales tools?
CRMs, property portals, virtual site tours, and digital booking platforms all process buyer personal data. Each vendor is a Data Processor requiring a DPA. Particular attention should be paid to property portals — if you list properties on platforms like MagicBricks, 99acres, or Housing.com and share buyer leads from those platforms in your CRM, ensure you understand the consent basis under which the portal collected that data and whether onward use in your marketing database is covered.
How long can real estate companies retain buyer data after a failed sale?
If a buyer makes an inquiry but does not purchase, the data should be retained only for the period covered by your consent — typically the duration of their active search. After that, delete from your marketing database. For completed sales, retain documents for the statutory period (registration documents for 30 years, financial records for 7 years). Tenancy records should be retained for the statutory limitation period for property disputes after the lease ends.
Frequently asked questions
Does DPDP apply to property management companies running housing societies?
Yes. Housing societies and their management companies process resident personal data — name, flat details, family members, vehicle data, visitor logs — and are Data Fiduciaries for that data. Many housing societies use apps for visitor management and facility bookings that collect significant personal data. These must be covered by a resident privacy notice, and data shared with the app vendor requires a Data Processing Agreement.
Can we use buyer data collected during an inquiry for a different project launch?
Using contact data collected for one project to market a new project launch is a repurposing of data that was not covered by the original consent. If the buyer consented to receive updates 'about properties from [company]' broadly, that may cover new projects. If the consent was project-specific, you need fresh consent for the new launch. When in doubt, send a consent re-confirmation before adding to the new project's marketing list.
Do we need a DPA with home loan DSAs who collect customer data on our behalf?
Yes. If a home loan DSA or financial advisor collects buyer financial data on your behalf as part of the booking process, they are a Data Processor and you need a DPA specifying what they can do with the data, prohibiting them from using it for their own financial product marketing, and requiring them to delete it after the booking process is complete.
Assess your real estate DPDP readiness
Niti Bharat's DPDP Readiness Assessment covers real estate developers and brokers — buyer consent, CRM data sharing, RERA overlap, and proptech vendor DPAs.
Start Real Estate DPDP Assessment