Information Security & Data Privacy (ISDP)Version 1.0
Consent Policy for Marketing Data
Governing the collection, use and processing of personal data for marketing and promotional communications.
This Consent Policy for Marketing Data (“Policy”) establishes the mandatory standards by which Fusion CX Limited (“Fusion CX”, “the Company”) obtains, records, manages, and honors consent from Data Principals for the collection and processing of Personal Data used in marketing, promotional, and outreach activities. The Policy operationalizes the consent requirements of the Digital Personal Data Protection Act, 2023 (“DPDPA 2023”) and applies this standard uniformly across Fusion CX’s global BPO/ITES delivery footprint, including engagements undertaken on behalf of clients.
This Policy exists because marketing communications — outbound calling, SMS, email, WhatsApp, and retargeting campaigns — are among the highest-risk processing activities for consent violations, and because Fusion CX’s role as a data processor for client marketing programs (in addition to processing data as a controller for its own promotional activity) requires a single, auditable consent standard that both roles can be measured against.
This Policy applies to:
This Policy does not override a client’s own consent framework where Fusion CX processes data strictly as a processor under a signed Data Processing Agreement (DPA); in such cases, the stricter of the two standards applies.
| Term | Definition |
|---|---|
| Consent | Free, specific, informed, unconditional, and unambiguous indication of the Data Principal’s wishes by a clear affirmative action, signifying agreement to the processing of their Personal Data for marketing purposes, as defined under Section 6 of the DPDPA 2023. |
| Data Principal | The individual to whom the Personal Data relates — a prospect, customer, or client end-customer. |
| Data Fiduciary | Fusion CX, where it determines the purpose and means of processing marketing data (e.g., its own corporate marketing). |
| Data Processor | Fusion CX, where it processes marketing data solely on the documented instructions of a client who is the Data Fiduciary. |
| Consent Manager | A person or platform registered with the Data Protection Board that enables Data Principals to give, manage, review, and withdraw consent, per Section 6(7)–(9) DPDPA 2023. |
| Notice | The mandatory disclosure made to the Data Principal, in clear and plain language, at or before the point consent is sought. |
| Withdrawal of Consent | The Data Principal’s right to withdraw consent at any time, with the withdrawal being as easy as the giving of consent (Section 6(4)). |
| Legitimate Use | Processing without consent permitted only in the narrow circumstances listed under Section 7 of the DPDPA 2023; general marketing outreach does not qualify as a Legitimate Use. |
Fusion CX shall not collect, process, or use Personal Data for any marketing purpose — including telemarketing, SMS, email, WhatsApp/RCS messaging, push notifications, retargeted advertising, or profiling for marketing segmentation — unless valid, verifiable consent has been obtained and recorded in accordance with this Policy, or the data subject has been provided a compliant Notice under Section 5 of the DPDPA 2023 prior to consent capture.
Marketing is treated as a distinct and separate processing purpose from transactional or service communications. Consent obtained for service delivery, account servicing, OTPs, or grievance handling shall never be reused, repurposed, or inferred as consent for marketing without a fresh, specific consent capture.
For consent to be treated as valid under this Policy, it must satisfy all of the following, mirroring Section 6 of the DPDPA 2023:
Before or at the time consent is requested, the Data Principal must be given a Notice, independently of any other information, describing:
Every instance of marketing consent must be captured through a mechanism that produces a durable, auditable record. Verbal telemarketing consent must be captured via call recording with a documented consent script, or reduced to a logged confirmation (e.g., confirmatory SMS/email) within the same interaction.
| Field | Requirement |
|---|---|
| Data Principal identifier | Name and at least one verifiable contact point (email/phone) linked to the consent record. |
| Timestamp | Date and time of consent capture, in a tamper-evident log. |
| Channel of capture | Web form, IVR, call recording reference, physical form scan, app screen, etc. |
| Consent text version | Exact version/hash of the Notice and consent language presented at the time. |
| Purpose(s) selected | The specific marketing purpose(s) and channel(s) (email/SMS/WhatsApp/call) the Data Principal agreed to. |
| Source | Whether first-party captured or received from a third-party list, with the source’s consent evidence reference. |
| Status | Active / Withdrawn / Expired, with all status-change timestamps retained. |
Consent records shall be retained for the duration the consent remains active, plus a minimum retention period thereafter as prescribed by the Fusion CX Data Retention Schedule, to allow the Company to demonstrate compliance to the Data Protection Board or a client audit.
Withdrawal of consent must be as easy as giving it, per Section 6(4) of the DPDPA 2023. Fusion CX shall provide, at minimum:
Withdrawal does not affect the lawfulness of processing carried out before withdrawal, but all future marketing processing on that Data Principal must cease upon withdrawal and be reflected in the consent record’s status field without avoidable delay.
| Role | Responsibility |
|---|---|
| Head of ISDP (CPO/DPO) | Policy owner; approves exceptions; reports consent-compliance metrics to the Board; serves as escalation point for Data Protection Board inquiries. |
| Marketing/CRM Leadership | Ensures campaign tooling enforces consent status before any send; maintains suppression lists; trains campaign teams. |
| ISDP Function | Conducts periodic audits of consent records, Notice language, and third-party list provenance; maintains this Policy and its supporting registers. |
| Client Account Owners | Ensure client-instructed marketing campaigns operate under the client’s own valid consent basis and that Fusion CX’s processor role is documented in the DPA. |
| All Employees engaged in outreach | Follow approved scripts/templates only; never bypass consent-status checks in the CRM/dialer. |
Fusion CX shall not onboard any third-party marketing data source (purchased lists, co-registration data, affiliate-sourced leads) without prior ISDP review confirming the source can produce DPDPA-compliant consent evidence for each record supplied. Vendor contracts for marketing data or marketing technology platforms must include data protection clauses consistent with the Fusion CX vendor risk management standard and, where the vendor processes data outside India, cross-border transfer safeguards consistent with Section 16 of the DPDPA 2023 and any related Government notifications in force at the time of transfer.
Any suspected use of Personal Data for marketing without valid consent — including a missed withdrawal request, use of an unverified third-party list, or a dark-pattern UI defect — must be reported to the ISDP function within 24 hours of discovery via the Fusion CX incident reporting channel, consistent with the Company’s Personal Data Breach Response Plan. Confirmed breaches involving marketing consent failures are subject to the same regulatory notification thresholds and timelines applicable under the Company’s CERT-In and DPDPA breach-notification procedures.
Non-compliance with this Policy by employees may result in disciplinary action; non-compliance by vendors constitutes a material breach of the applicable services agreement.
This Policy shall be reviewed annually by the ISDP function and the Head of ISDP (CPO/DPO), or earlier upon: (a) amendment to the DPDPA 2023 or issuance of Rules thereunder; (b) a material CERT-In direction affecting marketing data handling; or (c) a significant client contractual requirement necessitating a stricter standard.
The following illustrates the minimum three-line consent capture note to be used on marketing sign-up forms, apps, and IVR/web scripts, paired with a clear toggle control that lets the Data Principal accept or opt out with equal ease, per Section 6(4) of the DPDPA 2023.
Data Principal has actively selected “I Agree”; marketing processing may proceed for the stated purpose(s) and channel(s) only.
Data Principal has actively selected “I Disagree / Opt-Out”; no marketing processing may occur, and the record must be logged as Withdrawn per Section 5.1 and Section 6 of this Policy.
Both toggle states must be presented with equal visual prominence — neither option may be pre-selected, hidden, or styled to discourage selection, consistent with the prohibition on dark patterns in Section 4.3.