DPDP for D2C and E-Commerce
How India's DPDP Act applies to D2C and e-commerce businesses, covering checkout data, marketing consent, cart abandonment tracking and vendor risk.
D2C and e-commerce businesses sit right at the centre of DPDP's scope: every checkout, every marketing list, and every cart-abandonment email involves personal data. Getting the basics right early avoids a scramble later.
Key facts at a glance
- DPDP applies to any business processing personal data digitally in India, regardless of size, including small D2C brands selling via social media or marketplaces.
- Full substantive DPDP obligations, including notice and consent, become enforceable 13 May 2027, with no stated grace period.
- Penalties for inadequate security safeguards can reach up to Rs 250 crore per instance.
- Cart abandonment tracking, retargeting, and marketing lists all count as personal data processing if they can identify or track an individual.
- The Consent Manager registration framework under DPDP Rules 2025 becomes operational 13 November 2026.
- Data shared with payment gateways, logistics, and marketing vendors remains the business's responsibility under DPDP even though a third party handles it.
Where D2C and e-commerce businesses collect the most personal data
A typical D2C or e-commerce business touches personal data at several points: account signup, checkout (name, address, phone, payment details), customer support chats, marketing opt-ins, and behavioural tracking such as browsing and cart data. Each of these is a distinct processing activity, and DPDP expects each to have a clear, identifiable purpose rather than being lumped together as "customer data."
Checkout and order data
Name, address, phone number, and order history collected at checkout are processed primarily to fulfil the order. Using that same data later for unrelated marketing without a separate basis stretches beyond the original purpose.
Marketing and retargeting
Email lists, WhatsApp broadcast lists, and ad retargeting pixels all involve personal data. Consent captured for order confirmations is not automatically consent for ongoing promotional messaging; these are commonly treated as separate purposes requiring their own basis.
Cart abandonment and behavioural tracking
If a business emails a customer about an item left in their cart, it has identified and tracked that individual, which brings the activity within DPDP's scope. This is a common blind spot because it feels automated and impersonal, but the underlying activity is still personal data processing.
Customer support interactions
Chat logs, call recordings, and support tickets often contain personal and sometimes sensitive information (such as a complaint referencing a health condition for a product return). These should be handled with the same care as core transactional data.
Vendor exposure specific to e-commerce
E-commerce businesses typically rely on a chain of vendors: payment gateways, logistics and courier partners, marketing automation tools, and marketplace platforms. Each of these touches customer personal data, and the business remains accountable for how that data is handled even though it does not directly manage the vendor's systems.
| Vendor type | Data typically shared | Key DPDP consideration |
|---|---|---|
| Payment gateway | Name, contact, payment details | Security certification, breach notification terms |
| Logistics/courier partner | Name, address, phone number | Data used only for delivery, not resold or reused |
| Marketing automation platform | Email, phone, purchase behaviour | Consent scope matches marketing use, opt-out honoured |
| Marketplace platform (if selling via one) | Order and customer details shared by the marketplace | Clarify which party is the fiduciary for that data |
| Customer support/helpdesk tool | Chat and ticket content | Access limited to support staff, retention schedule set |
Practical steps for a D2C or e-commerce business
Start by mapping exactly what personal data is collected at each customer touchpoint and what it is used for. Separate transactional purposes (fulfilling an order) from promotional purposes (marketing), since these typically need distinct consent. Review vendor contracts with payment, logistics, and marketing partners to confirm they include reasonable security and data-handling obligations. Finally, build a simple process for handling a customer's request to stop marketing communications or delete their data, since this is one of the most common real-world requests a consumer-facing business will receive.
If you are not sure where your D2C or e-commerce business stands on DPDP compliance, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.
Sources
- Ministry of Electronics and Information Technology - meity.gov.in
- Data Protection Board of India (as constituted under DPDP) - meity.gov.in
- Reserve Bank of India, for payment data handling norms - rbi.gov.in
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- Does DPDP apply to a small D2C brand selling only through Instagram and WhatsApp?
- Yes. The Digital Personal Data Protection Act 2023 applies to any business processing personal data of individuals in India in a digital form, regardless of size or the specific platform used to sell.
- Can a D2C brand keep sending marketing messages after a customer's first purchase?
- Only if it has a valid basis for that further processing, typically fresh or previously scoped consent, since DPDP requires processing to stay within the purpose the data was originally collected for.
- Does cart abandonment tracking count as personal data processing under DPDP?
- Yes, if it involves identifying or tracking an individual, such as through an email captured at checkout or a logged-in account, it falls within DPDP's scope and needs a proper basis and notice.
- When do DPDP's consent and notice obligations become enforceable for e-commerce businesses?
- Full substantive DPDP obligations, including notice and consent requirements, become enforceable on 13 May 2027, with no stated grace period after that date.
- Do e-commerce businesses need to worry about payment gateway and logistics vendor data too?
- Yes. Any vendor handling customer personal data on the business's behalf, including payment gateways, logistics partners and marketing platforms, should be covered by contracts with appropriate security and data-handling obligations.
- What happens if a customer asks a D2C brand to delete their data?
- Once DPDP's data-principal rights become enforceable, businesses will need a process to receive and act on erasure requests, subject to any longer retention required by other laws such as tax or accounting rules.
Check your status
DPDP Gap Assessment
A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.