Are Referral Programs Legal Under DPDP?
Liability Check
Your lucrative referral program is now a major DPDP liability if you're collecting personal data (like emails or phone numbers) without explicit consent from the *referred individual*. Ignoring this could land you fines up to ₹250 Crore.
Why Are Referral Programs Legal Under DPDP? is at Risk
The DPDP Act demands **explicit, informed consent** from the Data Principal (the individual whose data is processed) for *any* personal data collection. For referral programs, this means the **referred person** must consent to you processing their data, not just the referrer. Simply accepting an email from a referrer without direct consent from the recipient is a direct violation. Your business, as the **Data Fiduciary**, is ultimately accountable for ensuring **lawful consent** has been obtained *before* processing any data, whether it's for a new SaaS signup or a food delivery app's referral bonus. The Board will scrutinize how you verify this consent.
Common Violations
- 1.Collecting personal data (name, email, phone) of referred individuals directly from the referrer without their prior, explicit consent.
- 2.Assuming the referrer has obtained consent on your behalf without any verifiable mechanism or audit trail.
- 3.Sending marketing communications to referred individuals *before* they have directly given their consent to your organization.
The Immediate Fix
Immediately audit your referral program's data flow. Implement a two-step consent process: the referrer can *initiate* an invite, but you must obtain direct, explicit consent from the *referred individual* themselves before collecting or processing any of their personal data (e.g., via a unique link that requires their consent before signup).
Get DPDP Updates for Are Referral Programs Legal Under DPDP?
We'll send you compliance alerts and deadline reminders specific to your area. No spam — unsubscribe anytime.
Projected Compliance Deadline: Immediate
Next step after the audit
The audit shows the gaps. Sanctum closes them. One programme covers legal position, data map, gap analysis, implementation, tooling, training, a written readiness opinion, and breach cover, under one accountable owner. See the all-in-one programme
What Should You Do Next?