AMLEGALS — Strategic Lawyering

Tracking Pixels, SDKs and DPDPA: The Processors Hiding in Your Tag Manager

Tracking Pixels, SDKs and DPDPA: The Processors Hiding in Your Tag Manager

You installed a snippet. You appointed a processor.

The scene

The growth team added pixels the way other teams add fonts. Each one promised better attribution. An audit found forty-one on the checkout page, eleven belonging to companies no one could name, three sending hashed emails abroad.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Pixels are just analytics.

They transmit identifiers and behaviour to third parties; that is processing.

Inventory pixels as processors, with contracts.

Hashing makes it anonymous.

A hashed email that can be matched to a person is still personal data.

Treat hashed identifiers as personal data.

A governed tag manager

One owner. An approval step for every new tag. A quarterly review that removes what no longer earns its place. Consent-gated firing for anything marketing.

Monday morning

01 Export the tag manager container.

02 Name the company behind every tag.

03 Remove the ones nobody can explain.

Questions, answered plainly

Are advertising pixels subject to DPDPA? +

Yes, where they process personal data such as identifiers, device data or hashed emails. The brand generally acts as Data Fiduciary and should have a basis, a notice and appropriate contracts.

Is hashed email data personal data under DPDPA? +

Hashed data that can be matched back to an individual remains data about an identifiable person and should be treated as personal data.

Sector · E-commerce & D2C Your funnel runs on consent. The Act just redefined consent. Read →

E-commerce & D2C · Deep dive A trick is not an agreement. Read →

E-commerce & D2C · Deep dive Inactive is not a retention strategy. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).