E-commerce and retail
DPDP compliance for e-commerce and retail
Online stores collect personal data at every step, from sign-up to delivery. The Rules set a specific erasure timetable for large platforms, and marketing is where consent most often goes wrong.
The data you hold
- Customer accounts and addresses
- Order and payment history
- Phone numbers for delivery
- Marketing lists and preferences
- Reviews and support chats
What the Act asks of you
- Erase inactive users after three years
- An e-commerce entity with 2 crore or more registered users in India must erase a user's data after three years without contact, giving 48 hours' notice first, unless a law requires keeping it.
- Rule 8, Third Schedule
- Marketing needs its own consent
- Consent must be specific to each purpose and as easy to withdraw as to give. Bundling marketing into the terms of sale doesn't count.
- Section 6(1), 6(4)
- Payment and delivery partners
- Payment gateways, courier partners and marketing tools that process customer data for you need valid contracts.
- Section 8(2)
- Answer rights requests
- Customers can ask what you hold, correct it, erase it and complain. Grievances must be answered within the period the Rules set.
- Sections 11–13, Rule 14
How GRC Flow handles it
Consent records with withdrawals, and requests with their response clocks.
See how it worksDiscovery maps the customer exports, and the inventory records a retention period for each field.
See how it worksPrivacy notice and RoPA drafted from your own inventory and vendors.
See how it works