
Real estate runs on phone numbers. Leads are bought, shared between brokers and called repeatedly, and buyers hand over identity documents, income proof and bank details. Much of the industry's current practice with lead data will not fit the DPDP Act once its obligations apply on 13 May 2027.
Lead data and consent
A person who fills an enquiry form on your site for a specific project has given data for that purpose. A phone number bought in a list has not. Under the Act you need consent, or a legitimate use, for each person whose data you process, and you must be able to show it.
A lead you cannot trace to a consent is a lead you should not be calling.
Sharing between builders and brokers
When a builder passes leads to channel partners, or a broker registers a buyer with several builders, personal data is moving between separate businesses. The notice should name this sharing. Agreements with channel partners should limit use to the project, forbid resale and require deletion when the mandate ends.
Site visits, CCTV and visitor apps
Site visit registers, visitor management apps and CCTV at sales offices and in housing societies all capture personal data. Display a notice, collect only what is needed for entry and security, restrict who can view footage and logs, and set a retention period.
Buyer and tenant KYC
Booking a flat involves PAN, Aadhaar, photographs, income documents and bank details. Much of this is needed for the agreement, registration, tax and loan processing, so retention has a legal basis. Store it encrypted with role-based access, mask Aadhaar numbers where the full number is not required, and do not circulate documents over personal email or messaging apps.
What a CRM needs
A real estate CRM should carry the lead source and consent for every record, honour opt-outs across all projects and telecallers, stop calls to anyone who has withdrawn, and delete stale leads after a defined period. Marketing calls and messages also fall under TRAI's commercial communication rules, which need their own consent registration.
Society and tenant apps
Apps for residents hold family details, vehicle numbers, domestic staff records and visitor logs. The residents' association is usually the Data Fiduciary and the app provider its processor. Children's data needs parental consent. Associations should check what the provider does with the data and whether it is used for advertising.
- Digital Personal Data Protection Act, 2023 (MeitY)
- Digital Personal Data Protection Rules, 2025: notification summary (Press Information Bureau)
This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.





