
OTT & Digital Media
DPDPA Impact on OTT & Digital Media
OTT and digital-media platforms process subscriber identities, payment references and rich viewing-behaviour data used for recommendations — with distinct duties where profiles belong to children.
In short
OTT and digital-media platforms fall under the DPDP Act, 2023 because subscriber identities, payment references and viewing-behaviour profiles are digital personal data. Where profiles belong to children, verifiable parental consent is required and behavioural monitoring or targeted advertising is prohibited under Section 9 read with Rule 10.
- Viewing history and recommendation signals are personal data and must be confined to the notified purpose.
- Child profiles require verifiable parental consent and cannot be behaviourally targeted, under Section 9 read with Rule 10.
- Watch history must not be retained indefinitely after account closure, under Section 8(7) read with Rule 8.
When the Act applies
The Act applies to subscriber and viewer personal data processed in India, and to platforms outside India offering streaming or media services to Data Principals in India.
Personal data typically in play
- Subscriber account and authentication data
- Payment and billing references
- Viewing history and behavioural profiles
- Recommendation and personalisation signals
- Child-profile and family-account data
Mapped obligations
Itemised notice
Give each Data Principal a clear, itemised notice — in English or any language in the Eighth Schedule to the Constitution — describing the personal data collected and the specified purpose, before or at the time of seeking consent.
Consent that is free & withdrawable
Where processing rests on consent, it must be free, specific, informed, unconditional and unambiguous, limited to the specified purpose, and as easy to withdraw as it was to give.
Children & persons with disability
Obtain verifiable consent of a parent or lawful guardian before processing a child’s personal data, and do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
Retention limits & erasure
Erase personal data on withdrawal of consent or once the specified purpose is no longer being served, unless retention is required by law.
Reasonable security safeguards
Implement reasonable security safeguards — including measures such as encryption, access control, logging and monitoring — to prevent a personal data breach.
Breach intimation
On becoming aware of a personal data breach, intimate each affected Data Principal without delay and give the Data Protection Board an initial description without delay, followed by detailed information within 72 hours (or such longer period as the Board may allow).
Data Principal rights
Enable the rights to access a summary of personal data and processing, to correction and erasure, to grievance redressal and to nominate — and publish the manner in which these are exercised.
Recurring compliance risks
- Behavioural profiling or targeted advertising on child profiles
- Using viewing data for new purposes without fresh notice or consent
- Retaining watch history indefinitely after account closure
- Weak safeguards over subscriber and payment identifiers
Actions that follow
- 1Separate child profiles and disable behavioural targeting on them
- 2Limit viewing-data use to the specified, notified purpose
- 3Provide account, correction, erasure and grievance flows
- 4Time-box retention and align breach handling to Rule 7
