Why marketing needs purpose-level consent
Section 7 lists the purposes that may be processed without consent. Marketing, profiling and targeted advertising are not listed. This means every marketing use of personal data requires consent under Section 6.
Section 6(3) requires consent for each specified purpose. "Marketing" as a single bundled purpose is unlikely to satisfy this. Each purpose must be itemised: email marketing, retargeting, lookalike audience building, cross-sell recommendations, affiliate data sharing.
Section 6(5) provides that consent must not be made a condition of accessing a service unless the personal data is necessary for that service. Marketing is rarely necessary for the service itself. This means a platform cannot refuse service to a user who declines marketing consent.
Profiling and targeting under DPDPA
Profiling — building a user profile based on browsing behaviour, purchase history, location, demographics or interests — is processing personal data. Each profiling activity must have a lawful ground.
Where the profiling is for the user’s benefit within the service (for example, personalising a news feed the user subscribed to), Section 7(a) may apply if the Data Principal voluntarily provided the data.
Where the profiling is for advertising purposes — targeting, retargeting, lookalike audiences — consent under Section 6 is required. The notice must explain what data is used for profiling and how.
The absolute prohibition on advertising to children
Section 9(2) prohibits targeted advertising directed at children. This is not a consent requirement — it is a prohibition. No amount of parental consent allows it.
For platforms with mixed audiences (adults and children), this requires age gating or separate data pathways that exclude children from all advertising targeting, not just from seeing certain categories of ads.
Withdrawal and erasure: the opt-out must work
Section 6(4) requires withdrawal to be as easy as giving consent. For marketing, this means:
- If consent was given with one click at sign-up, withdrawal must also be one click.
- The withdrawal must stop all marketing processing, not just email delivery.
- Section 8(7) requires erasure when consent is withdrawn. The marketing profile, not just the subscription flag, must be deleted.
- Section 8(2) requires the Data Fiduciary to ensure each Data Processor also stops processing. If the adtech vendor holds a copy of the profile, it must be erased.
Third-party data and vendor relationships
Many marketing programmes rely on third-party data: purchased lists, data enrichment services, DMP/CDP platforms, programmatic ad exchanges. Under DPDPA:
- The organisation using the data is the Data Fiduciary and must ensure consent was obtained for the purpose of sharing.
- Each vendor that processes personal data is a Data Processor under Section 8(1) and must have a valid contract.
- Third-party cookies and tracking pixels that collect personal data require consent under Section 6.
How AMLEGALS advises on adtech and marketing compliance
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.
The team maps each marketing activity to its lawful ground, reviews vendor contracts, advises on consent architecture for marketing purposes, and designs the withdrawal and erasure workflow.

