The DPDP Act and what it meant for our client data practices

When the Digital Personal Data Protection Act was passed in 2023 and began moving toward implementation, we did what most small agencies probably did: we noted it, worried about it mildly, and then got back to work. By early 2024, we realised that the "getting back to work" posture was not sustainable. The Act was going to touch almost everything we did for clients, and we needed to understand it properly before it became someone else's problem that we had failed to prevent.
The DPDP Act creates obligations around how personal data is collected, processed, stored, and shared. For a digital agency, that is most of what we do. We collect form submissions on behalf of clients. We run ad campaigns that involve audience data. We manage email lists. We access client CRMs. Almost all of that involves personal data of Indian individuals.
What we actually audited
We started with a data mapping exercise. For each client, we listed every point where personal data entered or left our systems. Lead forms, ad platform audiences, email marketing lists, CRM access, reporting tools. The exercise itself was uncomfortable because it revealed how many informal handoffs we had been making without documentation.
CRM access was the most exposed area. In several engagements, we had login credentials to a client's CRM that we used to check lead quality and update campaign audiences. The Act creates obligations around data processors, and we were clearly acting as a data processor in those situations. We needed to formalise this in our contracts, specifically around what we could access, what we could not share, and how we would handle a data request if a customer of the client came asking.
What we changed
We updated our standard client contract to include a data processing addendum. It is short. It specifies what data we can access, for what purpose, and how long we retain anything. It includes a clause about notifying the client promptly in the event of a data incident.
We also changed our reporting setup. We moved from exporting raw lead data into spreadsheets on our own drives to viewing it within the client's systems where possible. When we do need exports, we time-bound them and delete the file once the analysis is done.
These are not dramatic changes. They are the kind of hygiene that should have been in place earlier. The DPDP Act was the forcing function we needed to do the audit we had been putting off. If you run an agency handling client customer data and have not done this exercise, we would recommend doing it before the implementation frameworks lock in and the penalties become concrete.