Sector guide

DPDP Compliance for E-commerce and D2C

E-commerce collects more personal data per customer than almost any other sector, and shares it with more parties — payment gateways, logistics partners, marketplaces, ad platforms and analytics. The DPDP Act does not object to any of that. It objects to doing it without a stated purpose, a recorded basis and a way to stop.

Priya Gupta

The four places D2C brands usually fail

  • Marketing consent bundled into checkout. Consent must be free and specific; making promotional messaging a condition of buying is neither.
  • Abandoned-cart and retargeting flows built on data collected for fulfilment. That is a purpose change, and it needs its own basis.
  • Ad-platform and analytics pixels firing before any consent decision has been made.
  • Logistics and marketplace partners receiving customer contact data with no processor terms and no record of the transfer.

Consent that survives scrutiny

Separate transactional messaging from promotional messaging, and record them independently. A customer who withdraws marketing consent must still receive their delivery updates — if your system cannot do that, withdrawal becomes impossible in practice and the consent was never really withdrawable.

Bind each consent record to the notice version and language it was given against, so you can show what the customer actually saw.

What to do first

Audit what fires before consent. On most Indian D2C sites, tags load on page one and the consent banner is decorative. That is the fastest thing to fix and the easiest to be caught on, because anyone can observe it from outside.

Then list every partner receiving customer data and confirm each has processor terms and appears in your RoPA.

Frequently asked questions

Do e-commerce sites in India need a cookie consent banner under the DPDP Act?

Where cookies and similar technologies process personal data for purposes beyond what the service strictly requires, you need a lawful basis and, for most marketing and analytics uses, consent — collected before the tags fire, not after.

Can we email customers offers after they buy?

Only with a basis for that purpose. Fulfilment data collected to deliver an order does not automatically support promotional messaging; that is a purpose change requiring its own consent, recorded separately from transactional messaging.

Are we responsible for our logistics partner's handling of customer data?

In effect yes. As the Data Fiduciary you remain answerable for the personal data, so processor terms, disclosure of sub-processors and a record of the transfer are your obligation.

Priya GuptaPriya writes on compliance operations at ProtectComply, including data principal rights, grievance handling and sector-specific programmes.

Where do you stand under DPDP?

Take the free readiness check and find out in 10 minutes.

Start free readiness check →