
Advertising & AdTech
DPDPA Impact on Advertising & AdTech
Advertising and adtech rely on identifiers and behavioural signals that, when linked to an identifiable individual, are personal data — bringing consent, purpose limitation and the children’s-advertising bar squarely into scope.
In short
Advertising and adtech fall under the DPDP Act, 2023 whenever identifiers, cookies or behavioural signals are linked to an identifiable individual, making them digital personal data. Consent under Section 6 must be obtained before tracking, and behavioural monitoring or targeted advertising directed at children is prohibited under Section 9 read with Rule 10.
- Device and advertising identifiers linked to a person are personal data and need a lawful basis under the Act.
- Tracking that relies on consent must be gated by consent under Section 6 and be as easy to withdraw as to give.
- Behavioural monitoring and targeted advertising directed at children are prohibited under Section 9 read with Rule 10.
When the Act applies
The Act applies wherever advertising activity processes the digital personal data of Data Principals in India, including processing outside India connected with offering goods or services in India.
Personal data typically in play
- Advertising and device identifiers linked to an individual
- On-site and cross-site behavioural and cookie data
- Audience segments and look-alike profiles
- Conversion and attribution events
- Contact data used for retargeting
Mapped obligations
Itemised notice
Give each Data Principal a clear, itemised notice — in English or any language in the Eighth Schedule to the Constitution — describing the personal data collected and the specified purpose, before or at the time of seeking consent.
Consent that is free & withdrawable
Where processing rests on consent, it must be free, specific, informed, unconditional and unambiguous, limited to the specified purpose, and as easy to withdraw as it was to give.
Children & persons with disability
Obtain verifiable consent of a parent or lawful guardian before processing a child’s personal data, and do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
Retention limits & erasure
Erase personal data on withdrawal of consent or once the specified purpose is no longer being served, unless retention is required by law.
Processor under valid contract
Engage every Data Processor — vendors, sub-contractors and technology partners — only under a valid contract, and remain accountable for the personal data throughout.
Reasonable security safeguards
Implement reasonable security safeguards — including measures such as encryption, access control, logging and monitoring — to prevent a personal data breach.
Data Principal rights
Enable the rights to access a summary of personal data and processing, to correction and erasure, to grievance redressal and to nominate — and publish the manner in which these are exercised.
Recurring compliance risks
- Dropping tracking technologies before valid consent is obtained
- Behavioural monitoring or targeted advertising directed at children
- Treating hashed identifiers as outside the Act when they remain linkable
- No mechanism to honour consent withdrawal across the ad stack
Actions that follow
- 1Deploy a consent mechanism that gates tracking and is as easy to withdraw as to give
- 2Suppress behavioural tracking and targeted ads for users identified as children
- 3Contractually bind every DSP, SSP and data partner under Section 8(2)
- 4Build audience deletion and suppression on consent withdrawal
