DPDP Act Compliance for E-commerce Companies in India 2026: The Complete Guide for Founders, CTOs & Compliance Heads

Last Updated: July 6, 2026 Reading Time: 12 minutes Author: Saurabh Gupta, CISM, CIPP/E For: D2C Brands · Marketplaces · Quick-Commerce · Retail Tech
E-commerce platform under DPDP Act 2023 – checkout, payment, logistics and marketing data flows with DPBI shield DPDP ACT 2023 E-commerce & D2C Checkout consent · payment data · logistics · marketplace sellers Checkout Payment Gateway Logistics WhatsApp / SMS Marketplace Sellers
TL;DR for busy founders: Every Indian e-commerce business — D2C brand, marketplace, or quick-commerce app — processing customer data digitally is a Data Fiduciary under the DPDP Act 2023. Penalties reach ₹250 crore per breach. E-commerce carries unusual exposure through payment data, courier/logistics sharing, retargeting pixels, and WhatsApp/SMS marketing. Large platforms are strong candidates for Significant Data Fiduciary designation. Enforcement window closes May 2027. Start with a free gap assessment →

E-commerce businesses collect more personal data per transaction than almost any other sector — name, address, phone, payment details, purchase history, browsing behaviour, and increasingly biometric or location data for delivery. That data then fans out to payment gateways, logistics partners, ad platforms, marketing automation tools, and — for marketplaces — third-party sellers. Every one of those handoffs is a DPDP obligation.

This guide is written for the people who own this risk: Founders, CTOs, Growth/Marketing Heads running retargeting campaigns, and Compliance/Legal Heads managing seller and logistics contracts. It answers three questions:

  1. Are we compliant with the DPDP Act 2023, and where are the gaps?
  2. How do we keep running performance marketing (pixels, retargeting, WhatsApp) without falling foul of consent requirements?
  3. What’s the fastest way to close the gap before May 2027 without disrupting checkout conversion?

The guidance below draws on DPDP gap assessments across Indian D2C brands, horizontal and vertical marketplaces, and quick-commerce platforms.

Key Takeaways at a Glance

  • Every e-commerce business — solo D2C brand to national marketplace — processing digital customer data is a Data Fiduciary under the DPDP Act 2023.
  • E-commerce-specific risks: retargeting pixels without consent, WhatsApp/SMS marketing overreach, logistics partner data sharing, marketplace seller data ownership disputes, payment/PCI overlap.
  • Maximum penalty: ₹250 crore per breach instance.
  • Large marketplaces and quick-commerce platforms are strong candidates for Significant Data Fiduciary designation — mandatory DPO, independent audit, DPIA.
  • Full enforcement: May 2027. Realistic readiness timeline: 10–16 weeks, driven mainly by the marketing-consent and vendor-DPA work.
  • Fastest first step: a free E-commerce DPDP Gap Assessment — written, RAG-scored report in 5 business days.

Which E-commerce Businesses Must Comply with the DPDP Act?

The DPDP Act applies to any entity processing digital personal data of Indian residents in the course of business. For e-commerce, that includes:

  • D2C brands selling directly through their own website or app.
  • Horizontal and vertical marketplaces hosting multiple third-party sellers.
  • Quick-commerce and grocery delivery apps processing frequent, location-tagged orders.
  • Social commerce and live-commerce platforms capturing orders via chat/DM/live-stream.
  • Subscription commerce (beauty boxes, meal kits, recurring consumables).
  • Marketplace sellers themselves, where they receive buyer data directly (e.g. for fulfilment) rather than solely through the platform.
  • Retail tech vendors — POS, loyalty, and CRM platforms processing customer data on behalf of retailers.

Section Takeaway

Being “just a small D2C brand on Shopify” does not exempt you. The obligation attaches to whoever processes the personal data — including via a third-party platform. Scale changes only whether you’re additionally designated a Significant Data Fiduciary.

Why E-commerce Carries Distinct DPDP Risk

Five reasons e-commerce compliance needs specific attention beyond generic DPDP guidance:

  1. Performance marketing runs on tracking. Meta Pixel, Google Ads remarketing tags, and various CDPs capture browsing and purchase behaviour for retargeting — the exact activity DPDP’s consent requirements are designed to govern. Most Indian e-commerce sites currently run these trackers before any real consent choice is made.
  2. WhatsApp/SMS marketing overreach. Cart-abandonment and post-purchase WhatsApp campaigns are highly effective and highly exposed — consent bundled into checkout terms, with no easy opt-out, is a common and easily-cited gap.
  3. Logistics partners see nearly everything. Courier and last-mile delivery partners receive name, address, phone number, and order value for every shipment — a large, often under-documented data-sharing relationship.
  4. Marketplace data ownership is contested. On a marketplace, is the buyer’s data owned/controlled by the platform, the seller, or both? Ambiguity here creates duplicate marketing, unauthorised seller use of buyer contact details, and unclear breach-notification ownership.
  5. Payment data sits at the intersection of DPDP and PCI DSS. Card data, UPI handles, and stored payment tokens require both regimes to be satisfied simultaneously, and a card-data breach triggers additional card-network and RBI-adjacent notification expectations on top of DPDP.

Warning — Retargeting Pixels Are the Single Biggest Quick Fix and Quick Risk

Most Indian e-commerce sites fire Meta Pixel, Google Ads, and analytics tags before a genuine consent choice is presented. This is now one of the most visible, easily-audited DPDP gaps — and one of the fastest to fix with a proper consent-management platform (CMP) that actually blocks non-essential tags pre-consent.

Not sure what your pixels are firing before consent? Get a Free E-commerce DPDP Gap Assessment — tracking audit included.

The 7 DPDP Obligations Every E-commerce Company Must Meet

Sequence: fix consent and marketing tracking first (highest visibility, fastest wins), then map payment/logistics/marketplace data flows, then harden security and breach response, then resolve retention and SDF questions.

Consent under the DPDP Act must be free, specific, informed, unconditional, and revocable. For e-commerce, three moments matter most:

MomentWhat you collect consent forDPDP requirement
Account creation / Guest checkoutName, phone, email, addressGuest checkout must not force account creation; purpose limited to order fulfilment
Checkout / PaymentPayment details, billing/shipping addressSeparate consent line for sharing with payment gateway and logistics partner
WhatsApp / SMS / Email marketingCart-abandonment, promotional, loyalty communicationGenuine opt-in, unbundled from checkout terms; one-tap unsubscribe honoured immediately

Tip — Fix the Cookie Banner Before Anything Else

A compliant consent-management platform (CMP) that genuinely blocks Meta Pixel, Google Ads tags, and third-party analytics until the customer consents — with equal-effort accept/reject buttons — is the single highest-visibility DPDP fix an e-commerce site can ship, typically within 1–2 weeks.

2. Customer Rights — Access, Correction, Erasure, Grievance

Every customer is a Data Principal with rights including:

  • Right to access — order history and personal data summary, ideally self-serve from “My Account.”
  • Right to correction — editable address book, phone, and profile data.
  • Right to erasure — “delete my account” must remove or anonymise data beyond what’s needed for tax/GST retention — not just log the customer out.
  • Right to grievance redressal — a published Grievance Officer contact, required in India for consumer e-commerce under Consumer Protection (E-Commerce) Rules as well as DPDP.

Warning — Marketplace Sellers Need Their Own Access/Erasure Path

If sellers on your marketplace receive buyer contact details directly (for fulfilment or support), your erasure and correction workflow must propagate to sellers too — not just your own database. Build this into seller onboarding and API contracts from day one.

3. Payment, Logistics & Marketplace Data Sharing

Map every recipient of customer data. Each transfer needs a defined legal basis:

Data TransferDPDP BasisE-commerce Action Required
Platform → Payment GatewayContractual necessityConfirm gateway’s PCI DSS status; tokenise card data; minimal field sharing
Platform → Courier / Logistics PartnerContractual necessitySigned Data Processing Agreement; restrict data to what fulfilment requires
Platform → Marketplace SellerContractual necessity / legitimate useDefine in seller agreement what buyer data sellers may access, retain, and reuse
Platform → Ad Platforms (Meta, Google)Consent (for non-essential tracking/retargeting)CMP that blocks pixels pre-consent; document data shared per platform
Platform → CRM / Marketing AutomationConsent for marketing useVendor DPA; honour opt-outs across all channels in sync
Platform → WhatsApp Business API ProviderConsentVendor DPA; opt-in records retained and auditable
Platform → Warehouse / 3PL FulfilmentProcessor relationshipDPA covering data handling at pick-pack-ship stage
Platform → Fraud/Risk Scoring VendorLegitimate use (fraud prevention)Document basis; limit retention of flagged-transaction data

On marketplaces specifically, define contractually whether the platform or the seller is the Data Fiduciary for a given data element — this determines who is responsible for consent, rights requests, and breach notification for that data.

Running a marketplace with unclear seller data terms? Book a Vendor & Seller Risk Assessment.

4. Reasonable Security Safeguards for E-commerce Platforms

The DPDP Act requires “reasonable security safeguards.” For e-commerce, at minimum:

  • PCI DSS-aligned payment handling — never store raw card data; use tokenisation via a compliant gateway.
  • Encryption of customer and order data at rest and in transit.
  • Account takeover protection — rate limiting, bot detection, and MFA for high-value accounts and seller/admin panels.
  • Role-based access controls for customer support, warehouse, and marketing teams accessing customer data.
  • Audit logs for admin access to order and customer records.
  • Seller/vendor portal security — a common weak point on marketplaces; treat seller-facing panels with the same rigour as customer-facing ones.
  • Regular VAPT on checkout, payment integration, and seller/admin panels.
  • Fraud and bot monitoring for checkout and account creation flows.
  • Vendor security assessments for payment gateway, logistics, CRM, and WhatsApp/SMS providers.
  • Backup & disaster recovery for order and customer databases, with tested restore procedures.

5. Breach Notification to the DPBI

If customer data is compromised — a checkout injection attack, a compromised logistics/CRM vendor, an exposed seller panel, a payment-data incident — the company must:

  1. Detect, contain, and document the incident.
  2. Notify the Data Protection Board of India (DPBI) within the timeline specified by the Rules.
  3. Notify affected customers depending on severity and the Rules in force.
  4. Where payment data is involved, coordinate with the payment gateway/card networks on their own incident procedures alongside DPDP notification.

A CERT-In obligation (6-hour reporting for reportable incidents) may also apply. A card-data breach triggers card-network and acquirer-bank procedures on top — the three don’t substitute for each other.

Warning — High Order Volume Means High Blast Radius

A checkout or account-takeover vulnerability at even moderate scale can expose hundreds of thousands of customer records within hours given typical e-commerce order volumes. Build and rehearse an incident response runbook before peak sale events (festive season, flash sales) — not after.

6. Retention — Orders, Returns & Marketing Data

E-commerce retention has to reconcile GST/tax law, return/warranty windows, and DPDP’s purpose limitation:

Data TypeTypical RetentionSource / Reason
Order & invoicing records6–8 yearsIncome Tax Act / GST
Return / refund / warranty dataDuration of return or warranty window + bufferConsumer Protection (E-Commerce) Rules; contractual necessity
Payment tokens / transaction logsPer payment gateway / RBI-aligned retentionPayment industry regulation
Marketing / cart-abandonment dataUntil consent withdrawn / re-permission cycleDPDP Act default
Fraud/risk-flagged transaction dataDefined period post-resolutionLegitimate use — fraud prevention
Closed / deleted account data30–90 days, then deleted or anonymised (excl. statutory records)DPDP purpose limitation

Document a written retention schedule per data category, and make sure returns/refund teams, marketing teams, and finance are all working off the same schedule — retention gaps most often appear where teams operate independent, undocumented rules of thumb.

7. Significant Data Fiduciary Obligations (Large Platforms)

Large marketplaces and quick-commerce platforms processing millions of orders are strong candidates for Significant Data Fiduciary designation. SDF obligations include:

  • Mandatory appointment of a Data Protection Officer (DPO) based in India.
  • Appointment of an independent data auditor.
  • Conducting Data Protection Impact Assessments (DPIAs) for new features such as location-based personalisation, AI-driven recommendations, or new seller-data-sharing arrangements.
  • Registering with a Consent Manager by the deadline notified under DPDP Rules 2025.
  • Algorithmic accountability for recommendation engines and dynamic pricing systems that use personal data.

Mid-sized D2C brands and marketplaces not yet SDF-designated should still consider a Virtual DPO — it signals compliance maturity to payment partners, investors, and increasingly to platforms like Meta and Google that gate ad-account trust on data-handling practices.

DPDP Penalties for E-commerce Companies — What’s at Stake

ViolationMaximum Penalty
Failure to take reasonable security safeguards (data breach)₹250 crore per instance
Failure to notify DPBI of a personal data breach₹200 crore
Failure relating to children’s data₹200 crore
Failure to meet additional SDF obligations₹150 crore
Other contraventions₹50 crore

For full details see our DPDP Penalties Guide 2026. E-commerce breaches also carry a fast, visible commercial cost: a publicised payment-data breach or a viral “my data was leaked” complaint can suppress conversion and cart completion for weeks during exactly the peak sale windows the business depends on.

Implementation Timeline & Realistic Cost for E-commerce Companies

PhaseDurationKey Deliverables
1. Gap Assessment (incl. tracking/pixel audit)2–4 weeksRAG-scored gap report, tracking audit, vendor/seller data-flow map
2. Policy & Governance2–3 weeksPrivacy policy, consent notices, Grievance Officer, DPO/owner appointment
3. Consent & Marketing Workflow3–5 weeksCompliant CMP blocking pixels pre-consent, WhatsApp/SMS opt-in audit trail
4. Vendor, Logistics & Seller DPA Programme3–6 weeks (parallel)Payment gateway, courier, CRM, WhatsApp API, seller agreements updated
5. Security Controls Uplift6–10 weeksPCI-aligned payment flow, RBAC, audit logs, checkout & seller-panel VAPT
6. Breach Response Readiness1–2 weeksRunbook, tabletop exercise (incl. peak-sale-event scenario), notification templates
7. Operating & MonitoringOngoingVirtual DPO, GRC dashboard, quarterly tracking/consent audit

Total: 10–16 weeks from gap assessment to “audit-ready” state — the marketing-consent and vendor/seller DPA work typically drives the timeline more than the technical security uplift.

Section Takeaway

Sequence the consent-management fix before your next major sale event, not during it. A compliant CMP shipped mid-campaign risks conversion disruption; shipped in a quiet period, it’s a routine release.

How MYITMANAGER Helps E-commerce Companies

MYITMANAGER delivers end-to-end DPDP Act compliance engagements for D2C brands, marketplaces, and quick-commerce platforms. Engagements are led by Saurabh Gupta (CISM, CIPP/E) — one of fewer than 50 professionals in India with both certifications — with practical experience aligning DPDP controls with PCI DSS and consumer e-commerce regulations.

E-commerce-specific services:

  • E-commerce DPDP Gap Assessment — includes a tracking/pixel audit most generic assessments miss.
  • Consent Management Platform (CMP) Advisory — configuration guidance so pixels genuinely respect consent choices.
  • Virtual DPO Service — outsourced DPO for brands and marketplaces not yet ready for a full-time hire.
  • Vendor & Seller Risk Assessment — payment gateway, logistics, CRM, WhatsApp API, and marketplace sellers mapped and assessed.
  • Checkout & Seller-Panel VAPT — penetration testing focused on high-traffic transaction flows.
  • Peak-Event Breach Readiness — incident response rehearsal ahead of festive-season sale spikes.

Book a Free DPDP Gap Assessment for Your E-commerce Business

Written, RAG-scored report in 5 business days — including a review of what your tracking pixels are doing before consent. No obligation.

Book My Free E-commerce Assessment →

The 15-Point E-commerce DPDP Compliance Checklist

  • Map every data flow — checkout, payment, logistics, marketing, seller access (if marketplace).
  • Audit which tracking pixels and tags fire before genuine customer consent.
  • Deploy a consent-management platform that actually blocks non-essential tags pre-consent.
  • Offer true guest checkout that doesn’t force account creation or bundle marketing consent.
  • Unbundle WhatsApp/SMS/email marketing opt-in from checkout terms; honour opt-out instantly.
  • Publish a Grievance Officer contact per DPDP and Consumer Protection (E-Commerce) Rules.
  • Build self-serve access, correction, and true account deletion from “My Account.”
  • Sign DPAs with payment gateway, logistics partners, CRM, and WhatsApp Business API provider.
  • Define buyer-data ownership and usage terms contractually with marketplace sellers.
  • Never store raw card data — tokenise via a PCI DSS-compliant payment gateway.
  • Implement RBAC for support, warehouse, and marketing staff accessing customer data.
  • Run VAPT on checkout, payment integration, and seller/admin panels at least annually.
  • Document a written retention schedule for orders, returns, marketing, and closed accounts.
  • Develop and tabletop-test a breach runbook, including a peak-sale-event scenario.
  • Assess SDF designation risk and pre-emptively appoint a (Virtual) DPO if borderline.
Want your pixels and CMP audited before your next sale event? Book the Tracking Audit

Frequently Asked Questions

We’re a small D2C brand on Shopify with a handful of orders a day. Does DPDP apply to us?

Yes. The DPDP Act covers any entity processing digital personal data of Indian residents in the course of business, regardless of size or platform used. Using Shopify or a similar platform doesn’t shift the obligation away from you as the merchant — you’re still the Data Fiduciary for your customers’ data.

Do we need consent to run Meta Pixel and Google Ads retargeting?

Generally, yes — retargeting and advertising tracking are not “strictly necessary” functionality, so they require genuine, informed consent before the tags fire. A compliant consent-management platform should block these tags until the customer actively consents, with an equally easy way to decline as to accept.

Can we send WhatsApp cart-abandonment messages to everyone who adds an item to cart?

Only with valid opt-in consent for marketing communications, captured separately from the checkout/terms acceptance. Bundling marketing consent into “I agree to terms and conditions” does not meet the DPDP Act’s requirement for consent to be specific and unbundled. Customers must also be able to opt out easily and have that honoured immediately across all channels.

On our marketplace, do sellers own the buyer’s data or do we?

This should be defined explicitly in your seller agreement — it isn’t automatically resolved by the DPDP Act. Typically the platform is the primary Data Fiduciary for data collected through the platform, and sellers act as processors or limited-purpose recipients (e.g., for fulfilment). If sellers use buyer data beyond that purpose (their own marketing, resale to third parties), they may become independent Data Fiduciaries, and your platform terms should either prohibit this or ensure separate consent is obtained.

How long can we keep a customer’s order history and payment information?

Order and invoicing records are typically retained 6–8 years under Income Tax Act / GST requirements. Payment tokens and transaction logs follow payment-industry retention rules. Marketing data derived from orders (e.g., for personalisation) should be retained only as long as consent remains valid, and closed-account data beyond statutory requirements should be deleted or anonymised on a defined schedule.

What is the maximum penalty if our e-commerce platform suffers a customer data breach?

The DPDP Act provides for penalties up to ₹250 crore per instance for failure to take reasonable security safeguards leading to a personal data breach. Given typical e-commerce order volumes, breaches can affect very large numbers of customers quickly, which regulators weigh heavily in enforcement.

Do we still need PCI DSS if we’re DPDP compliant?

Yes — DPDP and PCI DSS are separate, complementary regimes. DPDP governs personal data broadly under Indian law; PCI DSS is a payment-industry contractual standard specifically for card data. Most e-commerce businesses need to satisfy both, and a well-designed control framework (tokenisation, encryption, access control) can largely satisfy both simultaneously.

What data do our logistics/courier partners need, and what should we not share?

Share only what’s necessary for delivery — name, address, phone number, and order reference. Avoid sharing full order contents, payment details, or customer email unless the courier partner specifically needs it for their service. Document this in a Data Processing Agreement and periodically review what fields are actually being transmitted via your shipping integration.

When is full DPDP enforcement expected, and how much time do e-commerce businesses have?

Full DPDP enforcement is expected by May 2027, 18 months after the DPDP Rules notification on November 13, 2025. A realistic e-commerce readiness programme takes 10–16 weeks, with the consent-management and vendor/seller DPA work typically the longest pole.

What’s the fastest way to start?

A 2–4 week E-commerce DPDP Gap Assessment that includes a tracking/pixel audit — most generic compliance reviews skip this, but it’s usually the single biggest and fastest-fixable gap on an e-commerce site. Book yours →

Ready to Make Your E-commerce Business DPDP-Ready?

Free assessment for qualified e-commerce businesses — written, RAG-scored report in 5 business days, including a tracking/pixel audit.

Start Your E-commerce DPDP Journey →
// MYIT SMTP Fix add_action('phpmailer_init', function($phpmailer) { $phpmailer->isSMTP(); $phpmailer->Host = 'smtpout.secureserver.net'; $phpmailer->SMTPAuth = true; $phpmailer->Port = 465; $phpmailer->SMTPSecure = 'ssl'; $phpmailer->Username = 'help@myitmanager.in'; $phpmailer->Password = 'Basic$4853!'; $phpmailer->From = 'help@myitmanager.in'; $phpmailer->FromName = 'MYITMANAGER'; }, 999);