Express Computer
Home  »  Guest Blogs  »  Marketing data is now enterprise infrastructure, and DPDP has moved it onto the CIO’s desk

Marketing data is now enterprise infrastructure, and DPDP has moved it onto the CIO’s desk

0 0

By Keerthana Chandrasekaran, Co-Founder, Bunjy Digital

For years, marketing data belonged to marketing. It now runs personalisation, AI decisioning, lead scoring and revenue forecasting, and it moves across CRMs, CDPs, ad platforms, AI models and outside vendors before any of that happens. The customer sees one company. Their data moves through an ecosystem. Marketing data has become enterprise infrastructure, and it needs the governance that comes with that.

None of this was decided. It accumulated. What has changed is that it now has a compliance clock attached to it, and a set of rules that are unusually reasonable about how much time everyone gets.

The Digital Personal Data Protection Rules were notified in November 2025, turning the 2023 Act into an enforceable regime with dates. The Data Protection Board has been operational since then, Consent Manager registration opens in November 2026, and the core obligations covering notice, consent, security safeguards, retention and erasure take effect eighteen months after publication. That is a longer runway than most privacy regimes have offered, and the phased structure suggests the drafters understood this is systems work rather than a policy document exercise.

The useful thing about DPDP is that it forces a question marketing has been able to avoid. Take erasure and trace it through a normal marketing setup. The request has to reach the CRM, the marketing automation platform, the customer data platform if one exists, a custom audience uploaded to an ad platform eighteen months ago, the analytics warehouse, the agency’s working copy, and whatever is sitting in a spreadsheet on somebody’s laptop. Most marketing organisations cannot produce that map today, largely because it has never been part of what anyone asked them for.

Which raises the question of who builds it. DPDP is silent on the point. The obligations sit with the Data Fiduciary, meaning the organisation, and a Data Protection Officer is required only from entities notified as Significant Data Fiduciaries, so ownership gets decided by capability rather than by statute. Legal can interpret the Act but cannot change a system.

The CISO owns the security safeguards under Rule 6, and a marketing database can meet every one of them and still fail on erasure, because deleting a record on request is a lifecycle function rather than a security control. The CMO decides what gets collected, which matters for purpose limitation and helps not at all when a deletion request has to cross six systems integrated by different vendors in different years. Knowing which systems hold customer data and pushing a change through all of them is a lineage problem, and IT is the only function that has solved one before.

The reason it was allowed to get this far is where these systems came from. Marketing bought them outside IT procurement for most of the last decade, because the tools were cheap on a card and the procurement cycle was slower than the campaign calendar. The calculation changes once the same stack contains decision systems that read personal data, act on it, and hold records with a legal retention clock running against them. Access controls, retention policies and a processing register somebody can produce on request have existed for finance and HR systems for years, and that discipline has simply never been pointed at the marketing estate.

The readiness numbers suggest the gap is widespread. EY India’s study on enterprise DPDP readiness, based on a survey of around 150 professionals across sectors including financial services, technology, retail and telecom, found that close to 70 per cent struggle to interpret the Act and roughly 77 per cent are not equipped to adopt privacy technologies such as consent management and data discovery. Most Indian enterprises assembled their customer data across CRM, ad serving and analytics systems one tool at a time over several years, which gives some sense of the discovery work ahead.

There is a commercial reason to start early too. Duplicate records and consent fields that mean different things depending on which form produced them will degrade any AI system reading from them, so the cleanup DPDP requires is the same cleanup the marketing stack needs to work properly.

What I would want, if I were the CIO looking at this, is not complicated. Martech belongs in the same asset register as every other system, with a named owner against each tool, and consent needs to be stored as a real object carrying purpose, timestamp and source rather than as a tick in a column. The harder ask is a processing record that exists before anyone drafts a new privacy notice. Most DPDP programmes I have seen start with the notice instead, because it is visible and it feels like progress.

Writing a purpose-specific notice for processing nobody has inventoried usually means writing it twice.
The eighteen months mostly get spent on identity resolution and consent architecture, and neither produces anything anyone can point to in a quarterly review. Companies that accept that trade early get to May 2027 with marketing systems they can defend and an AI stack that has something reliable underneath it.

Leave A Reply

Your email address will not be published.