Sector guide
E-commerce collects more personal data per customer than almost any other sector, and shares it with more parties — payment gateways, logistics partners, marketplaces, ad platforms and analytics. The DPDP Act does not object to any of that. It objects to doing it without a stated purpose, a recorded basis and a way to stop.
Separate transactional messaging from promotional messaging, and record them independently. A customer who withdraws marketing consent must still receive their delivery updates — if your system cannot do that, withdrawal becomes impossible in practice and the consent was never really withdrawable.
Bind each consent record to the notice version and language it was given against, so you can show what the customer actually saw.
Audit what fires before consent. On most Indian D2C sites, tags load on page one and the consent banner is decorative. That is the fastest thing to fix and the easiest to be caught on, because anyone can observe it from outside.
Then list every partner receiving customer data and confirm each has processor terms and appears in your RoPA.
Where cookies and similar technologies process personal data for purposes beyond what the service strictly requires, you need a lawful basis and, for most marketing and analytics uses, consent — collected before the tags fire, not after.
Only with a basis for that purpose. Fulfilment data collected to deliver an order does not automatically support promotional messaging; that is a purpose change requiring its own consent, recorded separately from transactional messaging.
In effect yes. As the Data Fiduciary you remain answerable for the personal data, so processor terms, disclosure of sub-processors and a record of the transfer are your obligation.
Priya Gupta — Priya writes on compliance operations at ProtectComply, including data principal rights, grievance handling and sector-specific programmes.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →