
Telemarketing & Tele-calling
DPDPA Impact on Telemarketing & Tele-calling
Outbound tele-calling depends on large contact databases and recorded calls — both of which are personal data requiring a lawful basis, notice and disciplined retention under the Act.
In short
Outbound tele-calling is governed by the DPDP Act, 2023 because calling databases and call recordings are digital personal data. Each calling list needs a documented lawful basis and notice under Section 5 read with Rule 3, and call recording must be disclosed, with defined retention under Section 8(7) read with Rule 8.
- Purchased or aggregated calling databases need a demonstrable lawful basis and notice before use.
- Call recordings are personal data and their capture must be disclosed to the individual.
- Lead data passed to clients requires a valid Section 8(2) contract with each client and dialler or CRM vendor.
When the Act applies
The Act applies to calling databases and call recordings of Data Principals in India, whether the calling operation sits in India or offshore while offering goods or services in India.
Personal data typically in play
- Purchased or aggregated contact databases
- Consent and do-not-disturb status
- Call recordings and transcripts
- Lead-scoring and disposition notes
- CRM histories shared with clients
Mapped obligations
Itemised notice
Give each Data Principal a clear, itemised notice — in English or any language in the Eighth Schedule to the Constitution — describing the personal data collected and the specified purpose, before or at the time of seeking consent.
Consent that is free & withdrawable
Where processing rests on consent, it must be free, specific, informed, unconditional and unambiguous, limited to the specified purpose, and as easy to withdraw as it was to give.
Processor under valid contract
Engage every Data Processor — vendors, sub-contractors and technology partners — only under a valid contract, and remain accountable for the personal data throughout.
Retention limits & erasure
Erase personal data on withdrawal of consent or once the specified purpose is no longer being served, unless retention is required by law.
Reasonable security safeguards
Implement reasonable security safeguards — including measures such as encryption, access control, logging and monitoring — to prevent a personal data breach.
Breach intimation
On becoming aware of a personal data breach, intimate each affected Data Principal without delay and give the Data Protection Board an initial description without delay, followed by detailed information within 72 hours (or such longer period as the Board may allow).
Data Principal rights
Enable the rights to access a summary of personal data and processing, to correction and erasure, to grievance redressal and to nominate — and publish the manner in which these are exercised.
Recurring compliance risks
- Calling on databases with no demonstrable lawful basis or notice
- Recording calls without informing the individual
- Indefinite retention of contact lists and recordings
- Passing lead data to clients without a Section 8(2) contract
Actions that follow
- 1Establish and document the lawful basis for each calling list
- 2Give a clear notice and, where relied on, capture withdrawable consent
- 3Disclose call recording and set defined retention windows
- 4Contract with every client and dialler/CRM vendor under Section 8(2)
