Compliance Guide

DPDP Guide for Sales Teams

Manage lead data, CRM records, and field agents under DPDP. Learn to handle sales data flows without breaching Indian privacy laws.

Discuss this page with an LLM

DPDP Action Sheet

Use this before your next workflow goes live. It keeps the useful parts visible and turns DPDP into checks your team can actually answer.

For DPDP Guide for Sales Teams, the DPDP question is how personal data enters the workflow, where it is stored, which tools touch it, what purpose was explained, and how deletion or withdrawal will work.

1. Lead Forms

Check:

  • What data are you collecting?
  • Is the purpose clear at the point of collection?
  • Is marketing consent separate from service communication?
  • Can the user withdraw consent later?

Common mistake: one checkbox that silently covers newsletters, sales calls, partner sharing and remarketing.

2. Email and WhatsApp

Check:

  • Who is on the list?
  • Where did consent come from?
  • Is the list imported from a vendor, event, webinar, scrape or old CRM?
  • Can you prove the source of consent?

Common mistake: treating every lead as permanently marketable.

3. Ads and Retargeting

Check:

  • Are pixels or ad platforms receiving identifiable user behavior?
  • Are audiences built from customer lists?
  • Are lookalike or remarketing audiences using personal data?

Common mistake: assuming "the ad platform handles it" means your company has no DPDP responsibility.

4. Website Analytics

Check:

  • Which tools run on the site?
  • Are IP address, device identifiers, session IDs or form fields being captured?
  • Is analytics used only for measurement, or also for profiling and targeting?

Common mistake: installing tools first and asking privacy questions later.

5. Vendor List

Make a quick list:

  • CRM
  • Email platform
  • WhatsApp provider
  • Analytics
  • Ad pixels
  • Form tool
  • Landing page builder
  • Webinar tool

For each vendor, answer: what data goes there, why, who can access it and how deletion works.

6. This Week's Action

Map one campaign from first click to final follow-up. Mark every place personal data is collected, enriched, shared, uploaded or used for targeting.

If your team cannot answer where the data came from and where it goes next, start with a data flow map before rewriting policy copy.

Book a DPDP clarity call

Want all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.

CRM and Lead Sourcing Compliance

Sales teams often collect personal data through web forms, LinkedIn, and cold outreach. Under DPDP, every lead in your CRM must be linked to a specific notice or consent record. If a lead provides their business card at a conference, your team can process that data for the specific purpose of a follow-up, but you cannot automatically sign them up for unrelated marketing newsletters without a separate consent. Legacy data already in your CRM requires a review to ensure you have a record of how and why the data was collected.

Field Agent Data Management

Field agents frequently collect data on the move, often using personal messaging apps or physical notebooks. This creates “shadow data” that the company cannot track or protect. Under DPDP, the company is responsible for all data processed by these agents. If an agent loses a notebook containing customer addresses or shares lead lists over unencrypted personal channels, the company faces a security safeguard failure. Moving all field communication to a centralized, company-controlled CRM application is necessary to maintain an audit trail.

Sales Workflow Risk Mapping

Sales ActivityPersonal Data InvolvedDPDP Risk Factor
Cold OutreachNames, personal mobile numbers, LinkedIn URLsHigh (Lack of prior notice)
CRM Data EntryEmail, job title, purchase history, lead scoresMedium (Data accuracy and retention)
Field VisitsLive location, home/office addresses, meeting photosHigh (Unsecured device storage)
Referral ProgramsFriend/Colleague contact detailsHigh (Third-party data collection)
Sales AnalyticsCall recordings, performance tracking, behavior mapsMedium (Purpose limitation)

This week

Review your CRM’s “Lead Source” field and identify any records marked as “Imported” or “Purchased.” For these records, verify if you have a documented trail showing the leads were notified that your company would process their data. If no such trail exists, pause automated email sequences to these contacts until you establish a valid legal basis for outreach.

Now think about your work. Where does personal data enter your workflows? Where does it sit? Who else touches it?

Frequently asked questions

Can we still use lead lists purchased from third-party vendors?

Using purchased lists is high risk under DPDP. You must verify that the vendor obtained specific consent for data sharing and that the lead was notified your company would process their data.

Are field agents allowed to store lead contact details on personal phones?

Storing professional lead data on personal devices creates a data security risk. Companies should use managed business applications or mobile device management (MDM) to ensure data can be wiped if the agent leaves.

Does DPDP apply to B2B sales contacts and LinkedIn sourcing?

Yes, DPDP applies to all personal data, including professional email addresses and phone numbers. Sourcing data from public platforms still requires a valid legal basis or notice if the data is processed for sales outreach.

Book clarity call