Security & compliance

India’s Digital Personal Data Protection Act, 2023 & your CRM

India DPDP Act 2023 and CRM: lawful basis, notices, data principal rights, subprocessors, and what to review with counsel.

Reviewed August 2026 3 min read By the Vertex CRM team

The DPDP Act frames obligations around lawful processing, notice, consent where required, the rights of data principals, security safeguards, and breach reporting for digital personal data in India. Your CRM holds names, phone numbers, email addresses, and increasingly WhatsApp conversation history—so it is in scope for your governance programme regardless of who hosts the application.

This page is orientation, not legal advice. It describes how CRM operations intersect with a privacy programme. Interpretation for your business belongs with your counsel.

The data lifecycle you need to be able to describe

Personal data through a CRM, end to endCollectform, call, WhatsAppNoticepurpose statedProcesssales + delivery useSharesubprocessorsRetain / eraseon scheduleSubprocessor list unmapped — a common gap
You should be able to describe every stage of this for an auditor: what you collect, why, on what basis, who it reaches, how long you keep it, and how it is deleted. Gaps usually appear at the last two.

What to document, per data element

  • Lawful basis for each element you collect—not for “CRM data” as a blanket category
  • Purpose, stated at collection in language a person understands
  • Retention schedule, which will differ between an active client and a lead that went nowhere three years ago
  • Subprocessors—hosting, email delivery, analytics, messaging—with agreements in place
  • Access scope: who inside your organisation can see it, and the break-glass process for administrators
  • Runbooks for export and erasure when a data principal exercises a right

Handling a data principal request

A rights request, with owners at each stepIntakeOperationsLegalRequest receivedIdentity verifiedScope + basischeckedRecords locatedExport or eraseResponse issued
The step teams most often lack is the last one in the operations lane: confirming erasure or export reached backups and downstream systems, not just the primary record.

Where CRM operations meet the programme

Programme requirementWhat it looks like in daily CRM work
Purpose limitationNot repurposing a support contact list for cold marketing
Data minimisationRemoving fields nobody reports on; not collecting what you cannot justify
AccuracyDeduplication and correction processes that actually run
Storage limitationA retention schedule applied to dormant leads, not only to closed accounts
Security safeguardsRBAC, MFA for admins, TLS, export monitoring
Breach readinessAn audit trail you can query, and a decision-maker named in advance

Where Vertex CRM fits architecturally

Vertex CRM provides access control, authenticated APIs, administrative visibility, and operational surfaces your administrators govern. Compliance is never “checkbox complete”, because your policies, contracts, and incident response determine the outcome. Pair this overview with counsel and read our privacy policy for product-level statements.

Related: CRM security overview, audit trail, and WhatsApp and consent.

Frequently asked questions

Does using Vertex CRM make us compliant?
No software alone guarantees compliance; you need policies, contracts, and operational controls.
What should legal review in a CRM?
Subprocessors, data residency statements, access logs, retention, and breach notification workflows.

Ready when your team is

Bring your stages, owners, and messy spreadsheet—we’ll map it into a pipeline your leadership can defend.