DPDP Guide for Sales Teams
Manage lead data, CRM records, and field agents under DPDP. Learn to handle sales data flows without breaching Indian privacy laws.
Discuss this page with an LLM
DPDP Action Sheet
Use this before your next workflow goes live. It keeps the useful parts visible and turns DPDP into checks your team can actually answer.
For DPDP Guide for Sales Teams, the DPDP question is how personal data enters the workflow, where it is stored, which tools touch it, what purpose was explained, and how deletion or withdrawal will work.
1. Lead Forms
Check:
- What data are you collecting?
- Is the purpose clear at the point of collection?
- Is marketing consent separate from service communication?
- Can the user withdraw consent later?
Common mistake: one checkbox that silently covers newsletters, sales calls, partner sharing and remarketing.
2. Email and WhatsApp
Check:
- Who is on the list?
- Where did consent come from?
- Is the list imported from a vendor, event, webinar, scrape or old CRM?
- Can you prove the source of consent?
Common mistake: treating every lead as permanently marketable.
3. Ads and Retargeting
Check:
- Are pixels or ad platforms receiving identifiable user behavior?
- Are audiences built from customer lists?
- Are lookalike or remarketing audiences using personal data?
Common mistake: assuming "the ad platform handles it" means your company has no DPDP responsibility.
4. Website Analytics
Check:
- Which tools run on the site?
- Are IP address, device identifiers, session IDs or form fields being captured?
- Is analytics used only for measurement, or also for profiling and targeting?
Common mistake: installing tools first and asking privacy questions later.
5. Vendor List
Make a quick list:
- CRM
- Email platform
- WhatsApp provider
- Analytics
- Ad pixels
- Form tool
- Landing page builder
- Webinar tool
For each vendor, answer: what data goes there, why, who can access it and how deletion works.
6. This Week's Action
Map one campaign from first click to final follow-up. Mark every place personal data is collected, enriched, shared, uploaded or used for targeting.
If your team cannot answer where the data came from and where it goes next, start with a data flow map before rewriting policy copy.
Book a DPDP clarity callWant all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.
CRM and Lead Sourcing Compliance
Sales teams often collect personal data through web forms, LinkedIn, and cold outreach. Under DPDP, every lead in your CRM must be linked to a specific notice or consent record. If a lead provides their business card at a conference, your team can process that data for the specific purpose of a follow-up, but you cannot automatically sign them up for unrelated marketing newsletters without a separate consent. Legacy data already in your CRM requires a review to ensure you have a record of how and why the data was collected.
Field Agent Data Management
Field agents frequently collect data on the move, often using personal messaging apps or physical notebooks. This creates “shadow data” that the company cannot track or protect. Under DPDP, the company is responsible for all data processed by these agents. If an agent loses a notebook containing customer addresses or shares lead lists over unencrypted personal channels, the company faces a security safeguard failure. Moving all field communication to a centralized, company-controlled CRM application is necessary to maintain an audit trail.
Sales Workflow Risk Mapping
| Sales Activity | Personal Data Involved | DPDP Risk Factor |
|---|---|---|
| Cold Outreach | Names, personal mobile numbers, LinkedIn URLs | High (Lack of prior notice) |
| CRM Data Entry | Email, job title, purchase history, lead scores | Medium (Data accuracy and retention) |
| Field Visits | Live location, home/office addresses, meeting photos | High (Unsecured device storage) |
| Referral Programs | Friend/Colleague contact details | High (Third-party data collection) |
| Sales Analytics | Call recordings, performance tracking, behavior maps | Medium (Purpose limitation) |
This week
Review your CRM’s “Lead Source” field and identify any records marked as “Imported” or “Purchased.” For these records, verify if you have a documented trail showing the leads were notified that your company would process their data. If no such trail exists, pause automated email sequences to these contacts until you establish a valid legal basis for outreach.
Now think about your work. Where does personal data enter your workflows? Where does it sit? Who else touches it?
Frequently asked questions
Can we still use lead lists purchased from third-party vendors?
Using purchased lists is high risk under DPDP. You must verify that the vendor obtained specific consent for data sharing and that the lead was notified your company would process their data.
Are field agents allowed to store lead contact details on personal phones?
Storing professional lead data on personal devices creates a data security risk. Companies should use managed business applications or mobile device management (MDM) to ensure data can be wiped if the agent leaves.
Does DPDP apply to B2B sales contacts and LinkedIn sourcing?
Yes, DPDP applies to all personal data, including professional email addresses and phone numbers. Sourcing data from public platforms still requires a valid legal basis or notice if the data is processed for sales outreach.