DPDP Act & QR Codes: India Data Privacy Compliance Made Simple
India's DPDP Act 2023 affects every QR code campaign. Learn what scan data you can collect, when you need consent, and how SMLLR stays DPDP-compliant.
The Compliant Scan: What India's DPDP Act Means for QR Marketing
India's Digital Personal Data Protection (DPDP) Act 2023 is the country's first comprehensive data privacy law. Every QR code campaign that collects user data — location, email, phone number — must now comply. SMLLR is built for Indian businesses: our platform uses privacy-preserving analytics by default, never stores full IP addresses, and gives you the consent management tools required under the Act. This guide walks through exactly what you need to know.
What is the DPDP Act 2023 and Why Does It Matter for Marketers?
The Digital Personal Data Protection (DPDP) Act 2023 governs how Indian businesses collect, process, and store personal data of Indian citizens. Violations can result in fines up to ₹250 crore. For QR marketers, this means:
- You cannot collect personal data without informed, unambiguous consent
- Data must be used only for the purpose stated at time of collection
- Users have the right to withdraw consent and have their data erased
- Critical personal data must be stored on servers within India
This isn't just a legal checkbox — it's a competitive advantage. Indian consumers increasingly choose brands they trust with their data.
What Data Does a QR Scan Collect?
There is a critical distinction regulators care about. Scan Metadata (non-personal) includes device type, time of scan, and city-level geolocation derived from IP address. This is generally permitted for internal analytics without explicit consent. Personal Data includes names, email addresses, phone numbers, and precise GPS coordinates. Collecting this through a QR-linked form requires clear opt-in consent.
- City-level IP geolocation: Permitted for aggregate analytics under DPDP.
- Precise GPS coordinates: Requires explicit, pop-up browser permission from the user.
- Lead forms behind QR codes: Must include a consent checkbox and link to your privacy policy.
- Scan history / re-targeting: Must disclose if scan data is used to re-target the user later.
Building a Consent-First QR Scan Journey
If your QR code leads to a lead-generation form, the form must have a clear opt-in checkbox explaining what the data will be used for and a visible link to your privacy policy. For regulated industries (healthcare, finance, education), SMLLR recommends a Double Opt-in Landing Page — the user scans, sees a consent screen, confirms, and only then reaches the destination. This creates an audit trail of consent you can show regulators.
Location Analytics and the DPDP Act: What's Allowed
Under the DPDP Act, precise geolocation is classified as sensitive personal data. SMLLR's scan analytics record city-level location derived from IP address — which falls outside the sensitive data classification. For precise GPS location (available on Premium plans for heatmap analytics), SMLLR requests explicit browser permission and discloses the purpose before collecting coordinates, keeping you compliant without sacrificing campaign insights.
Data Residency: Where Does SMLLR Store Your Campaign Data?
SMLLR's redirect and reporting infrastructure runs on Vercel's Edge Network, with backend peering directly at NIXI (National Internet Exchange of India) nodes in Mumbai, Delhi, and Bangalore, keeping Indian traffic on India-proximate infrastructure rather than routing internationally. To be direct about a real limitation: SMLLR does not currently offer a separate, selectable multi-region data residency option (e.g., a dedicated EU-only or India-only storage guarantee distinct from its default infrastructure) — an organization with a hard, formally-documented data-residency requirement as part of DPDP compliance should confirm this directly against their own obligations rather than assume a guarantee that isn't formally offered today.
Data Erasure, Audit Logs & the Right to be Forgotten
Under DPDP, Indian users have the right to request that their personal data be erased. SMLLR provides scan-level audit logs for every campaign and allows account owners to permanently delete scan records for specific users on request. All deletions are logged with timestamps, giving your compliance team a defensible audit trail.
Related Reading
Frequently Asked Questions
Does the DPDP Act apply to QR code campaigns in India?
Yes. Any QR campaign that collects personal data from Indian users — including email, phone, or location — is subject to the DPDP Act 2023.
Do I need a privacy policy linked to my QR code?
Yes. Any QR code that leads to a data collection form must display a clear privacy policy before the user submits their information.
Is SMLLR DPDP-compliant?
SMLLR is built India-first and designed around DPDP Act principles — data minimization, purpose-limited consent capture, and India-proximate infrastructure (Vercel Edge + NIXI peering in Mumbai, Delhi, Bangalore). It does not offer a separately-guaranteed, selectable data-residency option beyond that default infrastructure — confirm this specific point directly if your compliance program requires it.
What fines can my business face for DPDP non-compliance?
The DPDP Act sets tiered penalties depending on the nature of the violation, with the most severe (e.g., failing to take reasonable security safeguards) reaching up to ₹250 crore. Exact fine amounts vary considerably by violation type — consult the Act's schedule or your legal counsel for the specific tier that applies to your situation rather than a single flat figure.
How long can I store QR scan data under DPDP?
As long as it continues to serve the purpose it was collected for — DPDP doesn't set a fixed retention ceiling, it requires that data not be kept beyond what's necessary and that erasure requests be honored. SMLLR retains scan and lead data for the life of your account and provides manual deletion tools for user-level erasure requests at any time.