Not legal advice — and a live rulebook
This is a checklist to take to a qualified Indian data protection lawyer, not a substitute for one. India's Digital Personal Data Protection Act, 2023 is being brought into force in phases, with implementing rules notified in late 2025 and different provisions commencing on different dates running into 2027. Checked July 2026. Confirm the current commencement position and the exact obligations that apply to you before relying on anything here — a general article is the wrong source for a compliance decision.
The defence offered across the Indian B2B data market is that registration data is public, so anything derived from it is fair game. That argument is weaker than its confidence suggests, and it fails first in exactly the place this market is densest: the mobile number of a proprietor.
Two things drive the analysis. First, whether the data is personal data at all. Second, whether the publicly available carve-out genuinely reaches it. Vendors tend to assume yes to the second without examining the first.
Is business contact data personal data?
It depends on the entity type, and the market's most common records are the hardest cases.
| Record | Personal data? | Reasoning |
|---|---|---|
| A company's registered address | Generally no | Relates to a corporate entity |
| A company's filed MCA email | Usually no | An organisational contact point |
info@company.com | Usually no | Role address, not an individual |
| A named director's details | Yes | Identifies an individual |
| A proprietor's mobile number | Yes | The business is the individual |
| A named employee's direct line | Yes | Identifies an individual |
| A partner's personal email | Yes | Identifies an individual |
For a proprietorship there is no separation between the business and the person. The proprietor's phone number is a natural person's phone number, and calling it a business contact does not change what it is. Since proprietorships are a large share of the GST register — and the part MCA-derived products cannot reach at all — this is not an edge case. It is the core of the dataset. See GST data vs MCA company data.
The publicly available carve-out, read carefully
The Act's exclusion for publicly available personal data is not "anything findable on the internet". As drafted, it turns on personal data made public by the individual themselves, or by someone under a legal obligation to make it public.
Apply that to how contact databases are actually assembled — the four methods in how GST contact databases are built:
- A proprietor listing their own mobile on a public directory. The strongest case for the carve-out. The individual published it.
- A number on the business's own website. Similarly strong, where the business published it deliberately.
- MCA-filed company email. Published under a filing obligation. Reasonable footing, and it is usually a corporate contact rather than personal data in any case.
- A number sourced from a third-party contact panel with undocumented provenance. No basis for the carve-out, because nobody can show who made it public or whether the individual did. This is the method behind most cheap "GST leads with mobile numbers", and it is the weakest position in the market.
The GST registration data itself sits differently again: it is published by the GST system, not by the individual, and the registration fields are largely about the entity rather than a person. The exposure is concentrated in the enrichment layer, not the registration layer — which is precisely the layer vendors are least willing to document.
The practical test
For any contact record, ask: can I show who published this and that they intended it to be public? If yes, you have an argument. If the honest answer is "the vendor won't say", you do not have one — and you will be the one holding the data when a complaint arrives, not them.
Nine controls to have in place
Roughly in order of how often they are missing:
1. A data inventory. Every field, its source, its collection date, its lawful basis. If you cannot produce this on request, nothing else on this list is real. Most organisations discover the gaps here.
2. Documented provenance per field, from the vendor, in writing. Not "public sources" — the actual source category and date. Refusal to provide it should end the procurement, as covered in the data quality checklist.
3. A stated purpose, and purpose limitation in practice. Data acquired for prospecting is not automatically available for other uses. Write the purpose down and apply it, including when another team asks for the file.
4. Retention limits with actual deletion. Define how long you keep prospect data that never converts, and build the deletion. "Indefinitely, in a spreadsheet on someone's drive" is the real answer in most organisations, and it is not defensible.
5. Correction and erasure workflow. A named route for an individual to reach you, a defined response time, and a mechanism that reaches every copy — including exports, backups and the CRM. This is the control most often absent and most likely to be tested.
6. Suppression that is permanent and organisation-wide. One list, checked before every campaign, honoured at the account level. Not per-campaign.
7. Vendor contracts that address the source. Warranties on lawful collection, indemnity, cooperation with data subject requests, and defined obligations on termination.
8. Security proportionate to the data. Access control, encryption at rest, logging of who exported what. An exported prospect file on a laptop is where breaches actually originate.
9. Grievance handling. A published contact point, a log, and defined timelines. Complaints handled properly rarely escalate; complaints ignored reliably do.
Questions to put to a vendor in writing
- For each contact field, what is the source category and collection date?
- What is your stated lawful basis for holding and licensing this data?
- What is your process when an individual requests correction or deletion, and what is the SLA?
- Do you propagate deletion requests to customers who already received the record?
- What usage rights do we have — internal, client work, resale — and what happens at termination?
- Do you distinguish proprietorship contact data from corporate contact points in your own records?
- What warranties and indemnities do you offer on lawful sourcing?
Put these to every provider you are considering — ClearTax, Tofler, Apollo.io, FinScreener (built by the team publishing this site — see our disclosure) or anyone else. The answers vary far more than the marketing does.
Question 4 is the one that separates operators with a real compliance function from resellers. Most cannot answer it, because they have no mechanism to reach data they have already shipped.
Where this intersects the telecom rules
Data protection governs whether you may hold and use the data. A separate regime governs whether you may call or message the number — registered senders, consent registration, subscriber preferences. Both apply simultaneously, and satisfying one says nothing about the other. See the TRAI, DND and cold calling guide.
A campaign can be flawless on data protection and still breach telecom rules on the first dial.
Common questions
Is B2B data exempt from Indian data protection law? There is no general B2B exemption. The analysis is whether the data identifies a natural person — which a proprietor's mobile number does, whatever label is attached to it.
Does buying from a vendor transfer the risk? No. You determine the purpose and means of your own processing, which makes you responsible for it. A contract may give you recourse against a vendor; it does not remove your obligations.
We only email, never call. Does that help? It removes the telecom layer for that channel. It does not change the data protection analysis of holding and using personal data, and it does not remove suppression obligations.
When do the main obligations actually bite? Provisions are commencing in phases, with major processing and rights obligations scheduled well after the initial notifications. Verify the current position — and build the controls now regardless, because they take longer to implement than the remaining runway.
What happens if we get this wrong? The Act provides for significant financial penalties and a Data Protection Board to adjudicate. The more immediate risks for most B2B teams are complaints, channel damage and a failed customer due-diligence review.