Sector wise readiness
Real estate and proptech: the lead you bought has a consent history
- Can you buy or share property leads under DPDP?
- Only if the consent behind them supports it. A lead is a person's name, phone number, budget, and the fact that they are about to make the largest purchase of their life. By the third hop between portals, brokers and banks, nobody can say what that person consented to.
- Who this affects
- Developers, brokers, property portals and lead aggregators.
- What to do about it
- Keep evidence of the consent chain for every lead you acquire, and put processor controls around whoever you pass it to.
A misconception I keep seeing when developers, brokers and property portals read DPDP checklists: "leads are the currency of this business, everyone shares them."
That shared habit is precisely the exposure. The auditor's observation for this sector is direct: property portals resell and share leads widely, and consent and processor control is the usual gap.
Think about what a property lead actually is. A person's name, phone number, budget, and the fact that they are about to make the largest purchase of their life. It gets passed to brokers, banks, and back again. By the third hop, nobody can say what that person consented to.
A sector map is a superset, not a launch checklist.
What applies from the start, whatever your size
- ✅ Notice
- ✅ Consent and easy withdrawal
- ✅ Security safeguards
- ✅ Rights handling
- ✅ Grievance mechanism
- ✅ Processor contracts
- ✅ Breach response
What real estate carries from day one
- ✅ Consent for lead marketing, and no indiscriminate resharing. If you cannot show what a lead agreed to, you cannot lawfully market to them, and buying the list does not fix it.
- ✅ KYC and financial document security. You hold ID, income proof and loan documents. Secure them properly. This is a day one duty.
- ✅ Visitor and resident data. Gated community visitor management apps need a basis and real minimisation. A society app logging every guest is processing personal data.
- ✅ Bind your chain. Brokers, banks and facility vendors all need a Data Processing Agreement. This is the one this sector skips.
What may not apply
- ❌ SDF obligations. Generally not a Significant Data Fiduciary, even though lead and KYC data is sensitive. That status comes only on Government notification.
- ❌ A mandatory Data Protection Officer, annual DPIAs and independent audits. These attach to SDF status once notified.
The better question
The better question is not "is lead sharing normal in our industry?"
It is "for every lead in our CRM, can we show what that person actually agreed to?"
Law creates obligations. Scale and risk influence implementation. But consent provenance on leads and document security apply from your first buyer. Neither waits for scale.
If you work in property, could you trace the consent behind the leads you bought last month?