DPDP for Marketing Teams: Campaign Consent, Cookies and Attribution
Attribution pixels, remarketing lists and email campaigns all run on personal data. A practical look at what marketing teams need to change.
Consent is the default ground for marketing
Unlike employment or fraud prevention, most marketing processing doesn't fit neatly into a Section 7 legitimate use. Sending promotional emails, building remarketing audiences, and running attribution across ad platforms generally need consent under Section 6 — free, specific, informed, unconditional and unambiguous, obtained through a clear affirmative action rather than a pre-checked box.
This means the newsletter signup, the lead-gen form on a landing page, and the cookie banner on your site are not just UX elements — they're your consent capture points, and they need to hold up if someone later asks 'where did you get permission to email me.'
Cookies, pixels and the attribution stack
Analytics cookies, ad-network pixels and cross-site tracking scripts collect personal data (identifiers tied to a browser or device) the moment they load, so consent needs to be captured before non-essential cookies fire, not after. A banner that says 'by continuing to browse you accept cookies' without giving a real choice does not meet the free-and-specific bar.
Where campaigns rely on shared audiences — lookalike lists built from your customer data and uploaded to an ad platform — treat the ad platform as a party receiving personal data and make sure your notice to customers actually mentions this kind of sharing, not just 'we may share data with partners.'
Attribution data that ties an individual's on-site behaviour to a specific ad click or email open is still personal data even if it's stored as an ID rather than a name. Don't assume pseudonymised identifiers are out of scope.
Segmentation, lookalikes and targeted ads to minors
If any part of your audience could include people under 18, Section 9 prohibits behavioural monitoring and targeted advertising directed at children, and requires verifiable parental consent before processing a child's data at all. This matters for products or content categories where a meaningful share of the audience skews young — don't build segments assuming your whole base is adult unless you actually know that.
Review whether any lookalike or interest-based segment could function as a proxy for age, health, or other sensitive characteristics inferred from browsing behaviour. Even where not directly restricted, this is exactly the kind of profiling that draws regulatory attention and customer complaints.
Withdrawal has to actually work
Section 6 requires withdrawal of consent to be as easy as giving it, and requires that withdrawal propagate to any processor you've shared the data with. If a contact unsubscribes from email but their record still gets synced to an ad platform for remarketing next week, that's a gap, not a technicality.
Build the unsubscribe and 'opt out of retargeting' actions to trigger a real suppression flag that flows through to your CRM, email platform and ad integrations — a single click that only stops one channel out of three isn't real withdrawal.
Where to go next
Use the Consent Notice Builder for campaign sign-up forms and cookie banners, and map every marketing tool that receives customer data into the Data Flow Mapper so gaps in the attribution chain become visible.