Is Buying Contact Databases Legal Under DPDP?
Liability Check
Buying contact databases containing personal data without explicit, verifiable consent of each individual is a direct highway to DPDP violations, risking penalties up to ₹250 Crore.
Why Is Buying Contact Databases Legal Under DPDP? is at Risk
The DPDP Act 2023 mandates that all personal data processing must have a **lawful basis**, and for marketing and sales, this almost always means **explicit, informed consent** from the Data Principal. When you purchase a contact database from a third-party vendor, you inherit their data collection practices. Unless each individual in that database has given granular consent specifically for your company to contact them for your stated purpose, you are likely processing their personal data without a lawful basis. This applies whether you're a startup in a Bengaluru tech park or an established Mumbai conglomerate. The Data Protection Board will not accept 'we bought it' as an excuse for violating Data Principal rights.
Common Violations
- 1.Using purchased contact lists for outbound marketing (emails, calls, WhatsApp) without verifying prior, purpose-specific consent.
- 2.Assuming implied consent or relying solely on third-party assurances of DPDP compliance without independent verification.
- 3.Failing to provide Data Principals (the individuals) with a Notice of processing and consent withdrawal mechanism upon first contact.
The Immediate Fix
Immediately cease using purchased databases for new outreach campaigns. Conduct an urgent audit of all existing contact lists to identify data points collected without explicit, verifiable consent and segregate them. For any future lead generation, prioritize direct consent capture or partner with vendors who can provide auditable consent trails specific to your use case.
Get DPDP Updates for Is Buying Contact Databases Legal Under DPDP?
We'll send you compliance alerts and deadline reminders specific to your area. No spam — unsubscribe anytime.
Projected Compliance Deadline: Immediate
Next step after the audit
The audit shows the gaps. Sanctum closes them. One programme covers legal position, data map, gap analysis, implementation, tooling, training, a written readiness opinion, and breach cover, under one accountable owner. See the all-in-one programme
What Should You Do Next?