Legal

Consent Policy

Information Security & Data Privacy (ISDP)Version 1.0

Consent Policy for Marketing Data

Governing the collection, use and processing of personal data for marketing and promotional communications.

Document ID
FCX-DPDPA-012
Version
1.0
Owner
Head of Information Security & Data Privacy (CPO/DPO)
Review cycle
Annual, or upon material regulatory change
Applicable frameworks
DPDPA 2023 (India), CERT-In Directions; aligned with ISO 27001:2022, SOC 2 Type II, HIPAA, PCI DSS v4.0 marketing-adjacent clauses
Scope
All Fusion CX delivery centers, business units, and marketing/CRM functions handling personal data of prospects, customers, and clients’ end customers across all 13 countries of operation

01Purpose

This Consent Policy for Marketing Data (“Policy”) establishes the mandatory standards by which Fusion CX Limited (“Fusion CX”, “the Company”) obtains, records, manages, and honors consent from Data Principals for the collection and processing of Personal Data used in marketing, promotional, and outreach activities. The Policy operationalizes the consent requirements of the Digital Personal Data Protection Act, 2023 (“DPDPA 2023”) and applies this standard uniformly across Fusion CX’s global BPO/ITES delivery footprint, including engagements undertaken on behalf of clients.

This Policy exists because marketing communications — outbound calling, SMS, email, WhatsApp, and retargeting campaigns — are among the highest-risk processing activities for consent violations, and because Fusion CX’s role as a data processor for client marketing programs (in addition to processing data as a controller for its own promotional activity) requires a single, auditable consent standard that both roles can be measured against.

02Scope

This Policy applies to:

  • All Fusion CX business units, delivery centers, and support functions (Sales, Marketing, CRM, Digital, and Client Operations) across all countries of operation.
  • All Personal Data of prospects, existing customers, former customers, and client end-customers collected, purchased, appended, or processed for marketing, telemarketing, email marketing, SMS/WhatsApp campaigns, retargeting, profiling, or lead generation.
  • All third parties, vendors, list brokers, and sub-processors engaged by Fusion CX to execute marketing activity on the Company’s behalf or on behalf of a client.
  • Marketing activity undertaken by Fusion CX as a Data Fiduciary (its own brand promotion) and as a Data Processor executing campaigns under client instruction.

This Policy does not override a client’s own consent framework where Fusion CX processes data strictly as a processor under a signed Data Processing Agreement (DPA); in such cases, the stricter of the two standards applies.

03Definitions

TermDefinition
ConsentFree, specific, informed, unconditional, and unambiguous indication of the Data Principal’s wishes by a clear affirmative action, signifying agreement to the processing of their Personal Data for marketing purposes, as defined under Section 6 of the DPDPA 2023.
Data PrincipalThe individual to whom the Personal Data relates — a prospect, customer, or client end-customer.
Data FiduciaryFusion CX, where it determines the purpose and means of processing marketing data (e.g., its own corporate marketing).
Data ProcessorFusion CX, where it processes marketing data solely on the documented instructions of a client who is the Data Fiduciary.
Consent ManagerA person or platform registered with the Data Protection Board that enables Data Principals to give, manage, review, and withdraw consent, per Section 6(7)–(9) DPDPA 2023.
NoticeThe mandatory disclosure made to the Data Principal, in clear and plain language, at or before the point consent is sought.
Withdrawal of ConsentThe Data Principal’s right to withdraw consent at any time, with the withdrawal being as easy as the giving of consent (Section 6(4)).
Legitimate UseProcessing without consent permitted only in the narrow circumstances listed under Section 7 of the DPDPA 2023; general marketing outreach does not qualify as a Legitimate Use.

04Policy Statement

Fusion CX shall not collect, process, or use Personal Data for any marketing purpose — including telemarketing, SMS, email, WhatsApp/RCS messaging, push notifications, retargeted advertising, or profiling for marketing segmentation — unless valid, verifiable consent has been obtained and recorded in accordance with this Policy, or the data subject has been provided a compliant Notice under Section 5 of the DPDPA 2023 prior to consent capture.

Marketing is treated as a distinct and separate processing purpose from transactional or service communications. Consent obtained for service delivery, account servicing, OTPs, or grievance handling shall never be reused, repurposed, or inferred as consent for marketing without a fresh, specific consent capture.

4.1 Elements of Valid Consent

For consent to be treated as valid under this Policy, it must satisfy all of the following, mirroring Section 6 of the DPDPA 2023:

  1. Free — given without coercion, bundling, or being a precondition for an unrelated service.
  2. Specific — tied to the exact marketing purpose(s) and channel(s) described in the Notice; a single generic consent may not cover multiple unrelated purposes.
  3. Informed — preceded by a Notice in clear and plain language, made available in English and in the relevant regional/vernacular language of the Data Principal.
  4. Unconditional — not made a condition for availing an unrelated product, service, or benefit.
  5. Unambiguous — evidenced by a clear affirmative action (e.g., an unchecked opt-in box actively checked, a signed form, a recorded verbal confirmation with a documented script). Pre-ticked boxes, silence, inactivity, or continued use of a service do not constitute valid consent.
  6. Limited to necessary data — only the Personal Data necessary for the specified marketing purpose may be collected under the consent.
  7. Time-bound where applicable — consent captured for a campaign of defined duration shall not be treated as perpetual unless the Notice expressly says so and the Data Principal agreed to that duration.

4.2 Notice Requirements

Before or at the time consent is requested, the Data Principal must be given a Notice, independently of any other information, describing:

  • The Personal Data to be collected and the specific marketing purpose(s) of processing (e.g., “to send you offers on our BPO/ITES services via email and WhatsApp”).
  • The manner in which the Data Principal may exercise their rights under Section 6(4) and Section 13 of the DPDPA 2023, including withdrawal of consent.
  • The manner in which the Data Principal may make a complaint to the Data Protection Board of India.
  • Identity and contact details of the Data Fiduciary and, where applicable, the Consent Manager.
  • Where data is shared with third parties (list brokers, ad networks, marketing automation vendors), the categories of such recipients.

4.3 Prohibited Consent Practices

  • No pre-ticked or default opt-in checkboxes for any marketing channel.
  • No “dark patterns” — deliberately confusing UI/UX, disproportionately prominent “Accept” versus “Decline” options, or consent buried in unrelated Terms of Service.
  • No bundling marketing consent with consent required for core service delivery.
  • No purchase, rental, or scraping of third-party marketing lists unless the list provider furnishes documented evidence of DPDPA-compliant consent capture at the point of original collection, verified by ISDP prior to use.
  • No reliance on “implied consent” or “soft opt-in” theories for marketing communications; DPDPA 2023 does not recognize implied consent as a basis for marketing processing.
  • No processing of a child’s (under 18) Personal Data for marketing, behavioral monitoring, or targeted advertising under any circumstances, per Section 9 of the DPDPA 2023 — verifiable parental consent does not create an exception for marketing/ad-targeting to children.

05Consent Capture, Recording, and Evidence

Every instance of marketing consent must be captured through a mechanism that produces a durable, auditable record. Verbal telemarketing consent must be captured via call recording with a documented consent script, or reduced to a logged confirmation (e.g., confirmatory SMS/email) within the same interaction.

5.1 Mandatory Consent Record Fields

FieldRequirement
Data Principal identifierName and at least one verifiable contact point (email/phone) linked to the consent record.
TimestampDate and time of consent capture, in a tamper-evident log.
Channel of captureWeb form, IVR, call recording reference, physical form scan, app screen, etc.
Consent text versionExact version/hash of the Notice and consent language presented at the time.
Purpose(s) selectedThe specific marketing purpose(s) and channel(s) (email/SMS/WhatsApp/call) the Data Principal agreed to.
SourceWhether first-party captured or received from a third-party list, with the source’s consent evidence reference.
StatusActive / Withdrawn / Expired, with all status-change timestamps retained.

Consent records shall be retained for the duration the consent remains active, plus a minimum retention period thereafter as prescribed by the Fusion CX Data Retention Schedule, to allow the Company to demonstrate compliance to the Data Protection Board or a client audit.

06Withdrawal of Consent

Withdrawal of consent must be as easy as giving it, per Section 6(4) of the DPDPA 2023. Fusion CX shall provide, at minimum:

  • An unsubscribe link on every marketing email, functional and processed within a defined SLA not exceeding 10 business days, and immediately where technically feasible.
  • A “STOP” keyword mechanism for SMS/WhatsApp marketing, processed in real time by the messaging platform.
  • A documented Do-Not-Call (DNC) request process for telemarketing, with the number added to the internal suppression list before the next calling cycle.
  • Where Fusion CX operates as a Consent Manager-integrated channel or a client mandates use of a registered Consent Manager, withdrawal requests routed through that Consent Manager shall be honored with the same priority.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal, but all future marketing processing on that Data Principal must cease upon withdrawal and be reflected in the consent record’s status field without avoidable delay.

07Roles and Responsibilities

RoleResponsibility
Head of ISDP (CPO/DPO)Policy owner; approves exceptions; reports consent-compliance metrics to the Board; serves as escalation point for Data Protection Board inquiries.
Marketing/CRM LeadershipEnsures campaign tooling enforces consent status before any send; maintains suppression lists; trains campaign teams.
ISDP FunctionConducts periodic audits of consent records, Notice language, and third-party list provenance; maintains this Policy and its supporting registers.
Client Account OwnersEnsure client-instructed marketing campaigns operate under the client’s own valid consent basis and that Fusion CX’s processor role is documented in the DPA.
All Employees engaged in outreachFollow approved scripts/templates only; never bypass consent-status checks in the CRM/dialer.

08Third-Party and Vendor Marketing Data

Fusion CX shall not onboard any third-party marketing data source (purchased lists, co-registration data, affiliate-sourced leads) without prior ISDP review confirming the source can produce DPDPA-compliant consent evidence for each record supplied. Vendor contracts for marketing data or marketing technology platforms must include data protection clauses consistent with the Fusion CX vendor risk management standard and, where the vendor processes data outside India, cross-border transfer safeguards consistent with Section 16 of the DPDPA 2023 and any related Government notifications in force at the time of transfer.

09Breach and Non-Compliance

Any suspected use of Personal Data for marketing without valid consent — including a missed withdrawal request, use of an unverified third-party list, or a dark-pattern UI defect — must be reported to the ISDP function within 24 hours of discovery via the Fusion CX incident reporting channel, consistent with the Company’s Personal Data Breach Response Plan. Confirmed breaches involving marketing consent failures are subject to the same regulatory notification thresholds and timelines applicable under the Company’s CERT-In and DPDPA breach-notification procedures.

Non-compliance with this Policy by employees may result in disciplinary action; non-compliance by vendors constitutes a material breach of the applicable services agreement.

10Monitoring and Audit

  • Quarterly sampling audit of active marketing consent records against this Policy’s mandatory fields (Section 5.1).
  • Quarterly review of unsubscribe/DNC/STOP request turnaround times against SLA.
  • Annual review of all Notice templates for plain-language and multi-language compliance.
  • Ad hoc audit triggered by any client complaint, regulatory inquiry, or Data Protection Board notice.

11Policy Review

This Policy shall be reviewed annually by the ISDP function and the Head of ISDP (CPO/DPO), or earlier upon: (a) amendment to the DPDPA 2023 or issuance of Rules thereunder; (b) a material CERT-In direction affecting marketing data handling; or (c) a significant client contractual requirement necessitating a stricter standard.

12Related Documents

  • Notice and Consent Framework (General)
  • Data Retention and Erasure Schedule
  • Personal Data Breach Response Plan
  • Cross-Border Data Transfer Standard
  • Fusion CX Vendor Risk Management Standard
  • Privacy Policy – Global

13Appendix A: Sample Consent Capture Note and Opt-Out Toggle

The following illustrates the minimum three-line consent capture note to be used on marketing sign-up forms, apps, and IVR/web scripts, paired with a clear toggle control that lets the Data Principal accept or opt out with equal ease, per Section 6(4) of the DPDPA 2023.

Three-Line Consent Note

  1. I consent to Fusion CX contacting me with marketing communications about its products and services via email, SMS, WhatsApp, and/or phone.
  2. I understand I can withdraw this consent at any time by using the unsubscribe link, replying STOP, or requesting Do-Not-Call; withdrawal will not affect processing carried out before that date.
  3. I have read Fusion CX’s Privacy Notice explaining how my personal data will be collected, used, and protected.

Consent toggle — State 1: Consent given

Data Principal has actively selected “I Agree”; marketing processing may proceed for the stated purpose(s) and channel(s) only.

Consent toggle — State 2: Consent withdrawn / opted out

Data Principal has actively selected “I Disagree / Opt-Out”; no marketing processing may occur, and the record must be logged as Withdrawn per Section 5.1 and Section 6 of this Policy.

Both toggle states must be presented with equal visual prominence — neither option may be pre-selected, hidden, or styled to discourage selection, consistent with the prohibition on dark patterns in Section 4.3.

Approved by:Head of Information Security & Data Privacy (CPO/DPO)
Fusion CX Limited