The Practice

A business development team, while preparing a proposal for a new client in the same industry, references contact details of senior stakeholders gathered during a previous client engagement — names, designations, and email addresses — to personalise the pitch. The data was captured under the scope of the earlier project contract.

 

Questions Raised for Compliance Review

  1. Does the use of personal data collected under one engagement for the purposes of a separate commercial pitch constitute a violation under DPDP?
  2. What breach risks arise from maintaining informal contact repositories across business development teams?
  3. What is the compliant approach to managing stakeholder contact data across multiple client engagements?

 

Is This Permitted Under DPDP?

Not permissible as described. Personal data collected under a specific client engagement — where the purpose was project delivery — cannot be repurposed for unrelated business development activity without a fresh consent basis or a separately declared purpose. The individuals whose details are being used did not consent to receiving commercial outreach from the organisation in a different context.

 

Where the Breach Risks Sit

  • Purpose limitation violation — The data was collected for a defined project purpose. Using it to drive a separate
    commercial pitch is a textbook purpose limitation breach under DPDP Section 5, regardless of whether the two
    engagements are in the same industry or with similar types of organisations.
  • No consent for marketing use — Unless the individuals specifically opted into receiving commercial
    communications from the organisation, their contact details cannot be used for outreach. This applies even if the outreach is framed as a 'thought leadership share' or an 'industry update' rather than a direct pitch.
  • Informal data stores — Business development teams routinely maintain personal spreadsheets, CRM notes, or
    email threads containing stakeholder contact information gathered across years of engagements. These informalrepositories sit outside any data governance framework — unregistered, unreviewed, and often retained indefinitely.
     

The Ideal Compliant Approach

  1. Separate project data from commercial intelligence. Establish a clear policy that contact data collected during a client engagement is ring-fenced to that engagement. Any stakeholder whose details the organisation wishes to retain for future commercial purposes must be given a separate opportunity to consent — typically at the close of an engagement through an explicit opt-in. 
  2.  Maintain a governed contact database. Where the organisation wishes to maintain an outreach list for business development, this must be a formally maintained CRM with declared purpose, consent records, and a documented retention and deletion policy. Informal spreadsheets maintained by individuals are not compliant data stores. 
  3. Honour unsubscribe and erasure requests. Any individual on a commercial contact list must be able to withdraw consent and have their data removed. DPDP requires that withdrawal be as simple as the original consent.
     

DPDP Risk Summary

ElementStatusRecommended Action
Reuse of project contact data for BDNot permittedCease practice; obtain fresh consent or separate opt-in
Informal BD contact spreadsheetsNon-compliant data storeMigrate to governed CRM with consent records
No opt-out mechanism in placeMandatory requirementImplement unsubscribe pathway for all commercial outreach
Stakeholder data retained post-projectNeeds defined retention policyDefine and enforce data retention and deletion timelines
No purpose declaration for BD useRequired under DPDPUpdate privacy notice and engagement terms to disclose BD use