Industries

DPDP consent, sector by sector.

Every industry collects personal data differently and answers to its own regulator. The DPDP Act 2023 applies to all of them. See where the data comes from, where it goes, and how Promiz handles each case with one record, one rulebook and the same queues.

Last reviewed 18 September 2026

One consent recordWeb and appBranch or deskPartner or agentLegal-basis purposeMarketingPartner systems One consent recordWeb and appBranch or deskPartner or agentLegal-basis purposeMarketingPartner systems
Every channel writes to one consent record. Each purpose then keeps, stops or alerts on its own rules.
Banking
RBIDPDP

Why is DPDP consent hard in banking?

A bank meets the same customer at a branch counter, in a mobile app, at a call centre and through a relationship manager. Each channel collects personal data under a different mix of consent and legal obligation. RBI record-keeping directions require some of that data to stay for years after an account closes. The DPDP Act asks you to stop processing on withdrawal and erase once a purpose ends. You can only reconcile the two when every purpose carries its own legal basis and retention clock.

Regulators.RBI directions on record retention apply alongside the DPDP Act 2023 and DPDP Rules 2025. Confirm retention periods for each purpose with your legal team.

How banking data flows
One customer recordBranch counterMobile appCall centreRelationshipmanagerMarketing offersCross-sellanalyticsKYC records(RBI retention)Disputed account(legal hold) One customer recordBranch counterMobile appCall centreRelationshipmanagerMarketing offersCross-sellanalyticsKYC records(RBI retention)Disputed account(legal hold)

Four channels write to one record. Each purpose carries its own legal basis and retention clock.

Continues on its legal basis Stops Needs follow-up
The hard case
What Promiz does
Legal-obligation purposes stop use on withdrawal, but are not erased
Each purpose is tagged with its legal basis and retention clock. Withdrawal stops consent-based use, and legal-obligation records stay untouched.
Legal holds freeze erasure during disputes
Legal holds pause the erasure queue for a disputed account. Promiz logs who placed the hold and why.
Branch staff send consent links by email
Branch and call-centre staff send single-use consent links by email. The record stores the exact notice version shown.
NBFC & lending
RBIDPDP

Why is DPDP consent hard in NBFC lending?

Lending runs on a chain of processors: sourcing partners, bureaus, KYC vendors, co-lenders and collection agencies. Borrower data leaves your systems on day one. A withdrawal is only complete when every processor has stopped too. Digital lending journeys also collect consent fast, on a phone, often in a regional language. Proof of the notice shown is harder to keep than the signature.

Regulators.RBI digital lending and outsourcing directions apply alongside the DPDP Act 2023 and DPDP Rules 2025. Confirm your processor obligations with your legal team.

How nbfc & lending data flows
Webhooks to partnersLoan app(OTP consent)Sourcing partnerBranch agentCredit bureau(legal reporting)KYC vendorCo-lenderCollection agency(not confirmed) Webhooks to partnersLoan app(OTP consent)Sourcing partnerBranch agentCredit bureau(legal reporting)KYC vendorCo-lenderCollection agency(not confirmed)

Borrower consent reaches every processor through signed webhooks.

Continues on its legal basis Stops Needs follow-up
The hard case
What Promiz does
Every partner system must hear about a withdrawal
Signed webhooks push each withdrawal and erasure to partner systems at once, and Promiz waits for their confirmation.
A partner does not confirm the stop
Each stop-processing task has a deadline. An overdue alert fires when a partner has not confirmed the stop.
Consent on loan forms is fast and hard to prove
Loan forms capture OTP-verified consent per purpose, with a snapshot of the notice in the language the borrower saw.
Insurance
IRDAIDPDP

Why is DPDP consent hard in insurance?

Insurers collect some of the most sensitive personal data in the market: health history, family details, income and nominee information. Agents and brokers gather much of it on paper or over a phone, long before the customer uses a portal. When a customer later asks what they agreed to, the proposal form rarely shows the notice that was read out. Quotes, underwriting, claims and marketing are often bundled under one signature.

Regulators.IRDAI regulations on policyholder data and outsourcing apply alongside the DPDP Act 2023 and DPDP Rules 2025. Confirm sector requirements with your legal team.

How insurance data flows
Notice snapshot savedAgent (offline)BrokerOnline portalQuotesPolicy and claimsservicingMarketing Notice snapshot savedAgent (offline)BrokerOnline portalQuotesPolicy and claimsservicingMarketing

Offline customers accept the notice themselves through a single-use email link. Each record keeps a snapshot of what they saw.

Continues on its legal basis Stops Needs follow-up
The hard case
What Promiz does
Offline customers never see the notice
Agents send a single-use email link, so offline customers read and accept the notice themselves. The record is theirs, not the agent’s.
No proof of the exact notice shown
Every consent record stores a snapshot of the exact notice text and language shown at that moment.
One signature covers every purpose
Quotes, claims servicing and marketing are separate purposes, each with its own consent, retention and withdrawal.
Healthcare
DPDP

Why is DPDP consent hard in healthcare?

Hospitals, clinics, labs and digital health apps hold records that clinicians must reach in an emergency. The same systems hold data used only for research, wellness programmes or marketing. Patients include minors and people who cannot consent for themselves. A single withdraw-everything switch is unsafe for care. A single keep-everything policy is unlawful for the rest.

Regulators.The DPDP Act 2023 and DPDP Rules 2025 apply, with the children’s data provisions (S. 9, Rule 10). Confirm any sector-specific record-keeping duties with your legal team.

How healthcare data flows
Consent per purposePatientGuardian(DigiLocker)Hospital appClinical care recordLab and pharmacyResearchWellness marketing Consent per purposePatientGuardian(DigiLocker)Hospital appClinical care recordLab and pharmacyResearchWellness marketing

Each purpose has its own legal basis and retention period. Guardians of minors are verified through DigiLocker.

Continues on its legal basis Stops Needs follow-up
The hard case
What Promiz does
Care and non-care data live in the same systems
Each purpose has its own legal basis and retention period.
Essential care purposes must stay on
Withdrawal and erasure queues work per purpose, so a research opt-out never touches the clinical record.
Minors need a guardian’s consent
Guardian consent for minors is verified through DigiLocker and recorded against the child’s purposes.
E-commerce & retail
DPDP

Why is DPDP consent hard in e-commerce and retail?

Retail sites change all the time: a new ad pixel, an A/B testing script, a chat widget, a payments SDK. Each one can set cookies and read personal data before compliance hears about it. Shoppers arrive from every state and expect a notice they can read. Marketing teams need consent that survives the next campaign tool.

Regulators.The DPDP Act 2023 and DPDP Rules 2025 apply to online and offline retail data. Confirm consumer-protection overlaps with your legal team.

How e-commerce & retail data flows
Tags wait for consentStorefrontMobile appCheckoutAnalytics tagsAd pixelsOrder fulfilmentNew tracker foundby scanner Tags wait for consentStorefrontMobile appCheckoutAnalytics tagsAd pixelsOrder fulfilmentNew tracker foundby scanner

Every tag stays blocked until the shopper allows its purpose. The scanner re-crawls the site on a schedule.

Continues on its legal basis Stops Needs follow-up
The hard case
What Promiz does
Your tracker list is out of date
The cookie scanner re-crawls your site on a schedule and flags every new tracker, so the notice matches reality.
Tags fire before consent
Every tag stays blocked until the shopper allows its purpose. The choice is stored in a chained, tamper-evident record.
Shoppers read different languages
Notices are served in 23 languages (English and the 22 Eighth Schedule languages), with a version history per language.
Education & ed-tech
DPDPChildren’s data

Why is DPDP consent hard in education and ed-tech?

Schools, coaching platforms and ed-tech apps process data about learners who are mostly under 18. The DPDP Act requires verifiable parental consent for a child’s data. It bans tracking, behavioural monitoring and targeted advertising directed at children, with narrow exemptions in the Fourth Schedule. Product analytics that is routine for adults becomes a compliance question here.

Regulators.DPDP Act 2023 S. 9 and DPDP Rules 2025 Rule 10, Rule 12 and the Fourth Schedule govern children’s data. Confirm which exemptions apply to you with your legal team.

How education & ed-tech data flows
Child flags onLearner (under 18)Guardian(DigiLocker)School adminClasses and progressFourth ScheduleexemptionBehavioural trackingTargeted ads Child flags onLearner (under 18)Guardian(DigiLocker)School adminClasses and progressFourth ScheduleexemptionBehavioural trackingTargeted ads

A guardian is verified as an adult through DigiLocker before consent is recorded for the child.

Continues on its legal basis Stops Needs follow-up
The hard case
What Promiz does
The guardian must be a verified adult
A guardian is verified as an adult through DigiLocker before consent is recorded for the child.
Tracking and targeted ads are banned for children
Child-restriction flags on a purpose block tracking and targeted-advertising tags for that learner.
Exemptions are narrow and must be justified
The Fourth Schedule exemptions your organisation relies on are recorded once and applied per purpose.
Travel & hospitality
DPDP

Why is DPDP consent hard in travel and hospitality?

A single stay creates data at the online travel agent, the booking engine, the front desk, the loyalty programme and often a third-party check-in kiosk. Staff collect passport and ID scans at the desk and rarely tie them to a consent record. When a guest asks for erasure, most properties cannot say where all the copies are.

Regulators.The DPDP Act 2023 and DPDP Rules 2025 apply to guest data. Confirm identity-document retention rules with your legal team.

How travel & hospitality data flows
One guest recordOnline travel agentBooking engineFront desk / kioskLoyalty sign-upStay and billingID scan(retention clock)Loyalty offersPartner promotions One guest recordOnline travel agentBooking engineFront desk / kioskLoyalty sign-upStay and billingID scan(retention clock)Loyalty offersPartner promotions

Web, forms and front-desk capture all write to one record, so every channel sees the same status.

Continues on its legal basis Stops Needs follow-up
The hard case
What Promiz does
Guest data sits in many channels
Web, forms and front-desk capture write to one consent record per guest, so every channel sees the same status.
Nobody knows when to erase
Each booking purpose has its own retention clock. Erasure starts when the purpose ends, after the 48-hour notice.
Guest requests arrive by phone
A branded self-service portal lets guests view consents and raise access, correction or erasure requests.
SaaS & technology
DPDP

Why is DPDP consent hard for SaaS and technology companies?

A software company is a Data Fiduciary for its own users and a Data Processor for the personal data its customers load into the product. Rights requests arrive in both roles. Engineering must wire consent into sign-up flows, settings pages and back-end jobs without building a compliance system from scratch.

Regulators.The DPDP Act 2023 and DPDP Rules 2025 apply to you as a Data Fiduciary for your own users, and through contracts as a Processor. Confirm your processor terms with your legal team.

How saas & technology data flows
Rights requests queueSign-up flowSettings pageBack end(API and SDK)Core productProduct emailsUsage analyticsCustomer-owned data(routed to owner) Rights requests queueSign-up flowSettings pageBack end(API and SDK)Core productProduct emailsUsage analyticsCustomer-owned data(routed to owner)

Your back end records consent, checks status and receives withdrawal events through the REST API or Python SDK.

Continues on its legal basis Stops Needs follow-up
The hard case
What Promiz does
Many products under one company
Multiple applications and brands sit under one login, each with its own notices, purposes and records.
Engineering needs consent in code
A REST API and Python SDK let your back end record consent, check status and receive withdrawal events.
Rights requests have deadlines
Rights requests land in a queue with tracked deadlines. Processor requests can be routed to the customer who owns the data.
Don't see your industry?

Promiz works for any Data Fiduciary that collects personal data in digital form.

Book a demo

Bring one purpose. Leave with the proof.

A 30-minute session on your own use case.

  1. 5 min Find your DPDP gaps for that purpose
  2. 20 min Build the notice, collect consent, withdraw it, and close the task
  3. 5 min Download the receipt and verify the chain

Book your demo

Enter your website. We scan its cookies before the call and show you the results.

Reply within 1 business day