Your Name Is On Bank's Screen Before You Say Hello: What DPDPA Says About Call-Centre Data
Purva Gandhi
6 Sept 2026 11:00 AM IST

A practical guide for banks on consent, caller data and purpose limitation under the DPDPA
Let's start with a scenario. Rohan is thinking of applying for a personal loan. He finds a toll-free number on a bank's website, dials it, and within three rings, the call connects. Before he even asks his first question, his mobile number has been captured and if he is an existing customer, his name may already be visible on the agent's screen. If not, the agent may key it in as the call begins. Nobody pauses to ask, “Do you consent to us recording and storing your number and name?” It simply happens, as it does on countless call-centre lines every day.
Is this a violation of the Digital Personal Data Protection Act, 2023 (“DPDPA” or “the Act”)? Should the institution have stopped Rohan at the first ring and taken consent before recording anything? The question looks technical, but the answer sits in the Act itself.
Getting the Basic Grammar of the DPDPA Right
Before solving Rohan's phone call, let's first ensure we have a crystal-clear understanding of the following:
1. The bank or RBI-regulated entity here is the “Data Fiduciary”, meaning the entity that decides why and how personal data is processed. Rohan is the “Data Principal”, meaning the individual to whom the personal data relates.
2. Section 4 of the Act lays down the golden rule: personal data may be processed only for a lawful purpose and that lawful purpose exists either because the Data Principal gave consent or because the processing falls under one of the "certain legitimate uses" listed in Section 7, a closed list of situations where consent is not required.
3. Section 5 says that any request for consent under Section 6 must be preceded or accompanied by a clear notice, explaining what data is being collected, why and how the individual can withdraw consent or complain.
The Twist Hiding in Section 7(a): “Voluntarily Provided” Data
Section 7 allows certain processing without fresh consent. Section 7(a) covers the specified purpose for which the Data Principal has voluntarily provided personal data, provided she has not indicated that she does not consent to that use. The Act's own illustration makes the logic clear: where a customer voluntarily gives a mobile number to receive an SMS receipt from a pharmacy, the pharmacy need not take a separate consent for that receipt. The data was given for that specific purpose. Older commentary sometimes called this idea “deemed consent,” but the Act now uses the language of “certain legitimate uses.”
Now apply that to Rohan. He dialed the toll-free number himself, allowed his number to reach the bank's system and stayed on the line while the agent identified him and addressed the query. On these facts, the specified purpose is to identify the caller, respond to the enquiry, maintain a service or complaint record where required and follow up on that same loan query if needed. He has not objected to that processing.
So, capturing the caller's number and name for the call itself need not be an unlawful, consent-less act. It may fall within Section 7(a), provided the processing remains tied to the purpose for which the caller made contact.
The Consent Exception Ends Where the Purpose Ends
That is where many institutions get the analysis wrong. Section 7(a) is not a blank cheque. It is tied to the specified purpose and nothing more. For Rohan's call, the bank is on safer ground only for what is necessary to handle that enquiry: identifying him, answering the query, keeping a service, quality or grievance record where justified and following up on that same loan enquiry. If the same number is later added to a marketing database, shared with a lead-generation partner, used for unrelated profiling or retained indefinitely “just in case,” the Section 7(a) shield weakens and specific, informed consent under Section 6, with a Section 5 notice, becomes necessary.
The core discipline is simple: know where the original purpose ends. Service, response and same-enquiry follow-up may fit Section 7(a); unrelated marketing, sharing or analytics should not be treated as covered by the initial call.
Why May 2027 Is Not Far Away
There is a timing point, but it should not be read as comfort. The Act received presidential assent on 11 August 2023. The commencement notification was published in the Official Gazette on 13 November 2025. Some provisions came into force immediately on that date. Section 6(9) and Section 27(1)(d) are scheduled to come into force on 13 November 2026. The provisions central to this discussion: Sections 3 to 5, Sections 6(1) to 6(8) and 6(10) and Sections 7 to 10, are scheduled to come into force on 13 May 2027, eighteen months from publication of the notification. As we sit in September 2026, that may still look like time on paper. In practice, it is the period institutions need to build, test and prove their compliance architecture.
Consultants and in-house teams are already reminding clients of this because compliance is not a document exercise that can be finished a few weeks before May 2027. Notice templates, consent logs, call scripts, retention schedules, vendor controls and separate service-versus-marketing data flows all need to be designed, tested and embedded into live systems. By the time enforcement begins, the question should not be whether the institution has started; it should be whether the institution can prove how personal data moves through its business.
The DPDPA Is Not the Only Rulebook
For banks and other RBI-regulated entities, the DPDPA should not be read in isolation. The RBI's 2023 IT Governance Directions are also relevant because they apply to scheduled commercial banks, small finance banks, payments banks, NBFCs, credit information companies and specified all-India financial institutions. While the DPDPA tells the institution when and why personal data may be processed through consent, notice, specified purpose and certain legitimate uses, the RBI framework tells the institution how that processing must be controlled in practice. It expects board oversight, an IT governance framework, senior management accountability, access controls, audit trails, third-party arrangement controls, information-security risk management, business continuity planning and information systems audit.
For Rohan's call, this means the Section 7(a) analysis cannot stop at saying “the caller voluntarily provided the data.” The bank must also be able to show who can access that call data, how long it is retained, whether it is separated from marketing systems, whether vendors handling the call line are controlled, and whether the movement of that data is auditable. In simple terms, the DPDPA defines the legal basis; the RBI Direction demands the governance discipline to prove that the legal basis is being respected.
What Smarter Institutions Are Already Doing
In practice, the first control can be simple. Many institutions already use a brief pre-call disclosure before the call is connected, for example: “This call may be recorded for quality and service purposes and your number may be used to assist with this query.” This is a useful approach because it gives the caller early visibility on the purpose of processing. If the recording is also used for training, analytics, profiling, sales improvement or marketing, the institution should consider a clearer consent step, such as asking the caller to continue after the disclosure or select an option confirming consent.
The disclosure also must be supported by the back-end system. Enquiry-only callers should be identified separately from onboarded customers; call data should be retained only for as long as necessary and contact details should not move into marketing lists unless a separate consent process has been completed. This is the operational discipline required by Section 7(a): personal data provided for one purpose should not quietly be repurposed for another.
The Practical Playbook: A Compliance Checklist for Financial Institutions
1. Map the purpose before the data: Know why the number, name or call recording is being captured. If the purpose is limited to answering the enquiry or following up on the same request, Section 7(a) may apply. If the purpose includes marketing, profiling, cross-selling or future outreach, a separate consent route should be used.
2. Separate service and marketing data: The same phone number may be lawful for one use and unlawful for another. A number captured to resolve a query should not automatically become part of a campaign list. Service records and marketing databases should be technically and operationally separated.
3. Add a short call-start disclosure: A brief pre-call message can tell the caller that the call may be recorded and that the number may be used to assist with the query. This improves transparency and also prepares the institution for more formal notice obligations once the relevant provisions are enforced.
4. Set retention limits for enquiry-only callers: Once the query is resolved, the original purpose may be over unless the data is still required for service, legal, regulatory, audit or grievance-handling reasons. If the entity wants to retain the contact details beyond that purpose for marketing, promotional communication or future outreach, it should provide clear notice and obtain separate consent where required.
5. Build notice and consent flows early: Compliance should not depend only on a policy document. Banks should decide when notice will be given, how consent will be collected, how consent will be recorded, who owns the process, and how withdrawal or complaints will be handled.
6. Train agents on the purpose limitation: Call-centre agents should understand that data collected during a query is not free for every later use. Simple training on what can be recorded, what can be promised and when consent is needed can reduce misuse at the first point of collection.
So, did the bank do something wrong when it captured Rohan's number and name before he asked his first question? Not necessarily, if the data was used only for the call he initiated and for closely connected service or grievance purposes. He voluntarily called for a specific purpose, and the bank processed basic details for that purpose. But the moment that data becomes a lead, a cross-sell opportunity, a shared dataset or a permanent entry, the shield starts to disappear and notice and consent come back into the picture.
Sector-specific guidance on inbound calls, recorded lines and call-centre retention may still evolve. Until then, the safest approach is to build systems around a narrow reading of “specified purpose,” short disclosures, limited retention and separate consent for any secondary use.
Author is a Lawyer and a Senior Associate with Data Privacy and Cyber Security team at PwC India. Views are personal.

