A business development team, while preparing a proposal for a new client in the same industry, references contact details of senior stakeholders gathered during a previous client engagement — names, designations, and email addresses — to personalise the pitch. The data was captured under the scope of the earlier project contract.
Questions Raised for Compliance Review
Does the use of personal data collected under one engagement for the purposes of a separate commercial pitch constitute a violation under DPDP?
What breach risks arise from maintaining informal contact repositories across business development teams?
What is the compliant approach to managing stakeholder contact data across multiple client engagements?
Is This Permitted Under DPDP?
Not permissible as described. Personal data collected under a specific client engagement — where the purpose was project delivery — cannot be repurposed for unrelated business development activity without a fresh consent basis or a separately declared purpose. The individuals whose details are being used did not consent to receiving commercial outreach from the organisation in a different context.
Where the Breach Risks Sit
Purpose limitation violation — The data was collected for a defined project purpose. Using it to drive a separate commercial pitch is a textbook purpose limitation breach under DPDP Section 5, regardless of whether the two engagements are in the same industry or with similar types of organisations.
No consent for marketing use — Unless the individuals specifically opted into receiving commercial communications from the organisation, their contact details cannot be used for outreach. This applies even if the outreach is framed as a 'thought leadership share' or an 'industry update' rather than a direct pitch.
Informal data stores — Business development teams routinely maintain personal spreadsheets, CRM notes, or email threads containing stakeholder contact information gathered across years of engagements. These informalrepositories sit outside any data governance framework — unregistered, unreviewed, and often retained indefinitely.
The Ideal Compliant Approach
Separate project data from commercial intelligence. Establish a clear policy that contact data collected during a client engagement is ring-fenced to that engagement. Any stakeholder whose details the organisation wishes to retain for future commercial purposes must be given a separate opportunity to consent — typically at the close of an engagement through an explicit opt-in.
Maintain a governed contact database. Where the organisation wishes to maintain an outreach list for business development, this must be a formally maintained CRM with declared purpose, consent records, and a documented retention and deletion policy. Informal spreadsheets maintained by individuals are not compliant data stores.
Honour unsubscribe and erasure requests. Any individual on a commercial contact list must be able to withdraw consent and have their data removed. DPDP requires that withdrawal be as simple as the original consent.
DPDP Risk Summary
Element
Status
Recommended Action
Reuse of project contact data for BD
✗ Not permitted
Cease practice; obtain fresh consent or separate opt-in
Informal BD contact spreadsheets
✗ Non-compliant data store
Migrate to governed CRM with consent records
No opt-out mechanism in place
✗ Mandatory requirement
Implement unsubscribe pathway for all commercial outreach
Stakeholder data retained post-project
⚠ Needs defined retention policy
Define and enforce data retention and deletion timelines
No purpose declaration for BD use
✗ Required under DPDP
Update privacy notice and engagement terms to disclose BD use