Your enquiry database is a large collection of personal data spread across spreadsheets, phones and broker groups. The practical questions are what you hold, why you hold it, who can see it, and what consent supports reviving old enquiries. Put those to your adviser. This is general background, not legal advice.
The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, but they commence in stages: the consent-manager rules at twelve months, and the substantive obligations — notice, security safeguards, breach reporting and erasure — around mid-May 2027. The Data Protection Board still had no appointed Chairperson or Members as of August 2026. The Schedule to the Act sets a maximum penalty of ₹250 crore for failing to take reasonable security safeguards. Worth knowing: the fixed three-year erasure clock in the Rules applies only to large e-commerce, online gaming and social media entities — a developer falls instead under the general test in section 8(7). Sources: Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023, assented 11 August 2023) and the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025), MeitY. Position as at 17 August 2026; the commencement timeline was under review and should be re-checked.
A developer’s enquiry database is a large collection of personal data — names, phone numbers, budgets, family circumstances, sometimes financial details — usually spread across spreadsheets, WhatsApp, portal dashboards and a few personal phones.
India’s Digital Personal Data Protection Act, 2023 makes that worth thinking about deliberately.
This article raises the questions developers should be asking. It is not legal advice, and the rules, notified provisions and enforcement position continue to develop. Confirm your obligations and your compliance approach with your legal adviser.
Why it lands on real estate
Property enquiries generate unusually rich personal data, from unusually many sources — portals, your website, walk-ins, broker introductions, event registrations, telephone enquiries.
That data then gets shared onward: with brokers, with a calling agency, with a marketing partner, sometimes with other developers. Each of those hand-offs is worth examining.
The questions to put to your adviser
Notice and purpose. What are you telling people at the point they give you their details, about what you will do with them?
Consent. What is the basis on which you contact them, and how is it recorded? A portal-generated enquiry, a website form and a scanned visitors’ book are different situations.
Sharing. When you pass an enquiry to a broker or an agency, what governs that transfer and what are they permitted to do with it afterwards?
Retention. Enquiry databases going back seven years exist in most sales offices. How long may data be kept, and for what purpose?
Security. Where does the data physically live? Personal phones, unprotected spreadsheets and shared logins are the norm and the obvious weak point.
Rights requests. What happens when someone asks to see their data or asks you to delete it — who handles it, and how quickly?
Practical steps that are sensible regardless
Some of these are good operational practice whatever the compliance position turns out to be:
Know where your data is. List every place enquiry data currently sits — CRM, spreadsheets, portal dashboards, WhatsApp, individual phones. Most developers are surprised by this list.
Consolidate into a system you control. This is also the single best sales improvement most developers can make. See CRM for real estate developers.
Fix access. Individual logins, access removed when someone leaves, no shared passwords, no full database on a personal phone.
Have a clear notice at collection. Simple language, on your website form and enquiry capture, saying what you will do with the details.
Contract properly with anyone you share data with. Brokers, calling agencies, marketing partners — the terms should be written rather than assumed.
Have a retention position. Decide how long you keep enquiry data and why, then apply it.
On reviving old enquiries
Contacting a database that is several years old is a common tactic and a reasonable question to put to your adviser before running it — particularly around the basis on which those people were originally contacted and what they were told.
The practical selling side of this is covered in reviving old enquiries; the compliance side belongs with your legal adviser.
The sensible posture
Treat buyer data as something you hold on someone else’s behalf. That framing gets most operational decisions right on its own, and it also happens to be how the buyers themselves see it.
The 99-Day Sprint
Crudoimage installs and operates the full selling system on your project for 99 days — enquiries, follow-up, qualification, brokers and site visits, run daily. You set the price and close. If no flat sells in 99 days, your monthly fee is ₹0.
See how the 99-Day Sprint works →
Frequently asked questions
Does the DPDP Act apply to real estate enquiry data?
Enquiry databases contain personal data, so the Act is relevant. The specific obligations and timelines should be confirmed with your legal adviser.
Can I share buyer enquiries with brokers?
It is a transfer of personal data and should be governed by written terms. Discuss the basis and the restrictions with your legal adviser.
Is it acceptable to contact enquiries from several years ago?
It depends on the basis on which they were originally collected and what they were told. Raise it with your legal adviser before running a revival campaign.
