All articles
Compliance8 min read19 June 2026

DPDPA 2023: What Every Business Must Know About Email Data

India's Digital Personal Data Protection Act 2023 has direct implications for how businesses handle data extracted from business emails. Here is a plain-language guide for finance and operations teams.

India's Digital Personal Data Protection Act, 2023 (DPDPA) came into force in stages through 2025 and is now a live compliance requirement for most Indian businesses. Unlike GDPR, which generated years of commentary, DPDPA has received comparatively little practical guidance for operations teams dealing with everyday business data — including the structured data extracted from email.

This guide covers what DPDPA means for teams that process business emails containing personal data about vendors, customers, and counterparties.

What counts as "personal data" in a business email?

DPDPA defines personal data as any data about an identifiable individual. In a typical business email or invoice, this includes:

  • The sender's name and email address
  • Contact person names within the vendor organisation
  • Delivery addresses that contain individual names
  • Bank account details linked to a named individual
  • GST numbers associated with sole proprietors or partnership firms

Purely organisational data — a company's registered GST number, a corporate bank account, a business address — is not personal data under DPDPA. But most emails contain a mix of both.

The five key obligations for data fiduciaries

Under DPDPA, any entity that determines the purpose and means of processing personal data is a "data fiduciary." If your company receives, stores, or processes business emails, you are likely a data fiduciary for at least some of that data. Your obligations include:

  1. Purpose limitation: Personal data collected for one purpose (processing an invoice) cannot be used for another purpose (building a marketing list) without fresh consent.
  2. Data minimisation: Collect only what you need. If you only need the invoice amount and due date, extracting and storing the sender's personal phone number is non-compliant.
  3. Storage limitation: Personal data should not be retained longer than necessary for the stated purpose. Invoice data needed for 7 years for tax purposes is fine; marketing data retained indefinitely is not.
  4. Accuracy: You must take reasonable steps to ensure personal data is accurate and up to date.
  5. Security: Reasonable technical and organisational safeguards must be in place. Storing extracted personal data in an unsecured public Google Sheet would be a compliance failure.

Legitimate bases for processing

DPDPA requires a lawful basis for processing personal data. For most B2B email processing, the relevant basis is contractual necessity — you need to process the data to fulfil a contract or prepare to enter one. Processing a vendor's invoice is clearly necessary to pay them. This gives you a solid legal footing for invoice and PO processing without requiring explicit consent from every vendor contact.

Where you will need to be more careful: using contact data from business emails for purposes beyond the immediate transaction — like adding vendor contacts to a CRM or sending them marketing emails — requires a separate lawful basis or explicit consent.

Data principal rights you need to handle

DPDPA gives individuals several rights, including the right to:

  • Access: Know what personal data you hold about them
  • Correction: Have inaccurate data corrected
  • Erasure: Have their data deleted (subject to retention requirements for legal and financial records)
  • Grievance redressal: Raise a complaint with a contact person at your organisation

In practice, this means you need a way to identify and retrieve all personal data you hold about a specific individual, and a process for handling requests. For email-derived data stored in spreadsheets, this is a non-trivial operational requirement.

What this means for email automation tools

If you are using a third-party tool to process business emails and extract data, that tool becomes a "data processor" under DPDPA — you remain the data fiduciary, responsible for compliance, but the processor handles the actual data. Your obligations:

  • Ensure the processor has a data processing agreement in place
  • Verify the processor's security practices are adequate
  • Confirm the processor does not use your data for their own purposes (training AI models, analytics, etc.)
  • Ensure data does not leave India without appropriate safeguards if you are handling sensitive personal data

Practical steps to take now

  1. Map what personal data flows through your email-based workflows
  2. Document the purpose for which each category of data is processed
  3. Review retention periods and delete data that has exceeded them
  4. Designate a grievance officer and publish their contact details
  5. Review any third-party tools that process email data and confirm DPA coverage

DPDPA compliance for email-based workflows is not onerous if you have clean processes. The risk is in undocumented, ad-hoc handling of personal data — the kind that accumulates in shared inboxes and unmanaged spreadsheets over years of normal business operation.

The best time to get this right was before DPDPA took effect. The second best time is now.

Ready to automate your email data entry?

Start free with 100 parsing credits — no credit card required.