India's Digital Personal Data Protection Act, 2023 (DPDP Act) is the country's first comprehensive data protection law, and it has direct implications for real estate developers who collect, process, and share personal data as part of their sales operations. If your business generates leads from digital enquiries, runs ad campaigns that collect phone numbers and email IDs, or shares prospect data with channel partners, brokers, or CRM vendors — the DPDP Act applies to you.
The implementing rules are still being finalised by the Data Protection Board, so some specifics remain subject to change. But the Act's core obligations are already in force. Here's what real estate developers need to understand now.
The basics: what the DPDP Act covers
The DPDP Act applies to the processing of "digital personal data" — any data about an individual that is collected, stored, used, or shared in digital form. In real estate sales, this includes:
- Lead contact details collected via web forms, landing pages, portal enquiries, or WhatsApp
- Behavioural data captured through website analytics tools, retargeting pixels, or CRM activity logs
- Financial and demographic information collected during qualification calls or site visits
- Personal data shared with channel partners, co-brokers, or third-party CRM and lead management vendors
The Act designates organisations that determine the purpose and means of processing personal data as "Data Fiduciaries." Real estate developers who collect buyer enquiry data are Data Fiduciaries for that data. The CRM vendor, lead intelligence platform, or marketing agency you engage to process that data on your behalf is a "Data Processor" — they process data under your instruction, but your obligations as the Data Fiduciary remain.
Consent: the central obligation
The DPDP Act requires that personal data be processed on the basis of free, specific, informed, unconditional, and unambiguous consent. In practice, this means:
Your web forms and landing pages need compliant consent language
A checkbox that says "I agree to the Terms and Privacy Policy" — pre-ticked or bundled with site terms — does not meet the DPDP standard. Consent must be specific to the purpose you're collecting data for. A form collecting a phone number for a sales callback needs to clearly state that purpose, and the user must affirmatively opt in.
The notice accompanying the consent request must be in plain language and, where the user requests it, in a language listed in the Eighth Schedule of the Indian Constitution. For developers marketing to buyers across different language regions of India, this is a practical consideration for your form and landing page copy.
Consent for sharing data with channel partners needs to be explicit
If a buyer enquires on your website and you then share their details with a network of 50 channel partners who each call them independently, the buyer consented to a callback from you — not to having their data shared with 50 third parties. The DPDP Act requires that consent cover the specific purpose and the specific entities who will process the data. Bulk sharing of lead data with CP networks, without specific consent for that sharing, is a compliance risk.
This doesn't mean you can't work with channel partners — it means the consent language on your lead collection forms needs to accurately describe who will contact the lead and why.
Data Principal rights: what buyers can ask of you
The DPDP Act grants individuals ("Data Principals") a set of rights over their personal data that you must be operationally prepared to honour:
Right to information
A buyer can ask what personal data you hold about them, for what purpose, and with whom you've shared it. Your CRM must be able to produce a clear, complete answer to this question for any given contact — including which third parties (brokers, co-marketing partners, lead intelligence vendors) received their data.
Right to correction and erasure
A buyer can ask you to correct inaccurate data or delete their personal data. "Delete from CRM" sounds simple, but in practice it needs to propagate: if you've already shared the lead with three brokers, you need a mechanism to communicate the erasure request to those parties as well. Your data sharing agreements with channel partners and vendors should include an obligation to process erasure requests received from you.
Right to withdraw consent
A buyer can withdraw their consent to processing at any time — and withdrawal must be as easy as giving consent. If a prospect who enquired six months ago calls your CRM team and says "please stop calling me and delete my data," that needs to result in a suppression record in your system, not just a note in a spreadsheet that gets lost when the sales executive leaves.
Retention: keep data only as long as you need it
The DPDP Act requires that personal data be retained only for as long as necessary to fulfil the purpose for which it was collected. For real estate sales, the practical question is: how long do you keep a cold lead who never responded?
There's no prescribed retention period in the Act — it's purpose-based. A reasonable interpretation for a prospect who enquired, was contacted three times over 60 days, and never responded would be a retention window of 6-12 months before either seeking re-consent or deleting the record. Keeping every lead contact you've ever generated in an indefinitely growing CRM, with no purge policy, is not DPDP-compliant.
Third-party vendors: your obligations don't transfer
When you use a CRM, lead management platform, or marketing analytics tool that processes personal data on your behalf, you remain the Data Fiduciary. Your vendor is the Data Processor. The Act requires that you:
- Only engage Data Processors who can provide adequate data protection guarantees
- Have a written contract (Data Processing Agreement) with every vendor who processes personal data for you
- Ensure the vendor processes data only per your instructions and does not retain it beyond the engagement
If your CRM vendor, lead intelligence platform, or portal partner experiences a data breach involving your leads' data, you as the Data Fiduciary have notification obligations. The Act requires reporting significant data breaches to the Data Protection Board and, where required, to affected Data Principals.
What to do now, before the rules are finalised
The implementing rules will add specifics — retention periods, breach notification timelines, definitions of "significant" data fiduciaries who face additional obligations. But the core obligations (consent, purpose limitation, rights fulfilment, vendor contracts) are already law. The steps that are useful now:
- Audit your lead collection touchpoints — every form, landing page, portal integration, and WhatsApp opt-in. Do they have DPDP-compliant consent language? Is sharing with third parties disclosed?
- Map your data flows — where does a lead's contact data go after it enters your CRM? Which vendors, brokers, and partners receive it? Can you answer a "who has my data?" question for any given contact?
- Review your vendor agreements — does your CRM vendor, lead intelligence platform, and marketing analytics provider have a Data Processing Agreement in place? Do those agreements include erasure and breach notification obligations?
- Implement a suppression mechanism — a DNC (do-not-contact) list that propagates across your sales team and your vendor stack when a Data Principal withdraws consent.
- Set a data retention policy — define, in writing, how long you retain cold leads, enquiries, and site visitor data, and implement a purge or re-consent workflow accordingly.
Frequently asked questions
Does DPDP apply to real estate developers in India?
Yes. Any Indian developer that collects personal data from prospective buyers — via portal enquiry forms, WhatsApp opt-ins, landing pages, or third-party lead platforms — is a Data Fiduciary under the Digital Personal Data Protection Act, 2023. DPDP applies to the collection, processing, and storage of that personal data, regardless of company size. The implementing rules (still being finalized as of mid-2026) will add specifics, but the core consent and rights obligations are already in force.
What consent is required before contacting a real estate lead under DPDP?
DPDP requires that consent be free, specific, informed, unconditional, and unambiguous — and that it clearly state the purpose for which the data is being collected. For real estate developers, this means consent language on enquiry forms must explicitly disclose that the prospect will be contacted by the developer's sales team (and any partners, if applicable). Pre-ticked boxes and implied consent don't meet this standard. A buyer who submitted a form on a portal hasn't necessarily consented to you specifically contacting them.
How long can a real estate developer retain lead data under DPDP?
DPDP uses a purpose-based retention standard — personal data must be deleted once the purpose for which it was collected is fulfilled or no longer applies. There is no prescribed statutory period, but a reasonable framework for cold real estate leads is 6–12 months from last engagement, after which you should either seek fresh consent or delete the record. Indefinitely retaining every lead you've ever generated without a purge policy is not defensible under DPDP.
What happens if a prospective buyer asks to have their data deleted?
Under DPDP, Data Principals (the individuals whose data you hold) have the right to request erasure. When a prospective buyer makes this request, you must delete their personal data from your systems and ensure the deletion propagates to any vendors (CRMs, lead platforms, marketing tools) that received the data. You should also suppress their contact from future outreach — adding them to a DNC list that persists even after the underlying data is deleted, so you don't inadvertently re-acquire and re-contact them.
What should a real estate developer's Data Processing Agreement with vendors include?
At a minimum, a DPA with a CRM vendor, lead intelligence platform, or marketing tool should specify: the categories of personal data being processed, the purposes for which the vendor can use the data, data security standards, breach notification timelines, obligations to assist with Data Principal rights requests (access, correction, erasure), and sub-processor disclosure requirements. Any vendor that processes buyer personal data on your behalf without a signed DPA creates a compliance gap under DPDP.
Lead intelligence built for compliant real estate sales operations.
Siggnals processes buyer signals under a defined legal basis, with data handling designed to support DPDP-compliant workflows — so your team can act on quality leads without creating compliance exposure.
Free Trial