Skip to content

E-commerce and retail

DPDP compliance for e-commerce and retail

Online stores collect personal data at every step, from sign-up to delivery. The Rules set a specific erasure timetable for large platforms, and marketing is where consent most often goes wrong.

The data you hold

  • Customer accounts and addresses
  • Order and payment history
  • Phone numbers for delivery
  • Marketing lists and preferences
  • Reviews and support chats

What the Act asks of you

Erase inactive users after three years
An e-commerce entity with 2 crore or more registered users in India must erase a user's data after three years without contact, giving 48 hours' notice first, unless a law requires keeping it.
Rule 8, Third Schedule
Marketing needs its own consent
Consent must be specific to each purpose and as easy to withdraw as to give. Bundling marketing into the terms of sale doesn't count.
Section 6(1), 6(4)
Payment and delivery partners
Payment gateways, courier partners and marketing tools that process customer data for you need valid contracts.
Section 8(2)
Answer rights requests
Customers can ask what you hold, correct it, erase it and complain. Grievances must be answered within the period the Rules set.
Sections 11–13, Rule 14

How GRC Flow handles it

  • Consent records with withdrawals, and requests with their response clocks.

    See how it works
  • Discovery maps the customer exports, and the inventory records a retention period for each field.

    See how it works
  • Privacy notice and RoPA drafted from your own inventory and vendors.

    See how it works