How e-commerce brands in India should manage customer consent under DPDP

    E-commerce platforms are the most data-intensive consumer businesses in India — and they have been collecting, profiling, and monetising customer data with minimal consent infrastructure. DPDPA changes that completely.

    OneConsentBlog
    9 min read
    Thursday, 23 July 2026
    A complete guide to DPDPA law compliance for e-commerce businesses in India

    What is DPDP Compliance for E-Commerce?

    There's a specific kind of confidence that India's e-commerce sector has operated with for the last decade. The confidence that customer data like browsing behaviour, purchase history, device identifiers, and location signals is fair game the moment someone creates an account. That a pre-ticked marketing opt-in buried in sign-up terms is good enough. That personalization and profiling are just features, not consent questions.

    That confidence is now a liability. DPDP compliance for e-commerce isn't a checkbox exercise it's a structural rethink of how customer data moves through your platform.

    DPDPA doesn't ask e-commerce platforms to stop using customer data. It asks them to use it only when customers have explicitly agreed to each specific use. That's a fundamental shift, and for most platforms, it means rebuilding consent infrastructure from the ground up.

    Every Touchpoint Is a Consent Question

    The scale of data collection in e-commerce is what makes this complicated. It's not one collection point. There are dozens, each generating personal data, each requiring its own legal basis.

    User registration collects name, email, phone, and address. Checkout adds payment details, delivery address, and purchase intent. Browsing and search generate behavioural data and preference signals. Marketing communications like email, SMS, push notifications use all of the above. Loyalty enrolment adds another layer. Third-party social login pulls in data from another platform entirely.

    Who Is a Data Fiduciary  and What Are Their Duties?

    Under DPDPA, any e-commerce business that decides why and how customer personal data is processed is a data fiduciary. That covers virtually every online retailer, marketplace, and D2C brand operating in India — the moment you collect a name, phone number, or address, you take on fiduciary obligations, not just technical ones.

    Data fiduciary duties under DPDPA include:

    Obtaining valid consent
    - free, specific, informed, unambiguous, and given through a clear affirmative action, for each purpose separately.
    Purpose limitation -  using personal data only for the purpose it was collected for, not repurposing checkout data for marketing without fresh consent.
    Data minimisation - collecting only what's necessary for the stated purpose.
    Reasonable security safeguards - protecting customer data against breach, leak, or unauthorised access.
    Breach notification - informing the Data Protection Board and affected customers in the event of a data breach.
    Honouring withdrawal of consent - making it as easy to withdraw consent as it was to give it, and stopping the relevant processing when it happens.
    Grievance redressal - providing a mechanism for customers to raise data-related complaints.
    Appointing a Data Protection Officer (DPO) -  mandatory for platforms classified as Significant Data Fiduciaries based on data volume and sensitivity.

    These aren't abstract legal duties they translate directly into product and engineering decisions how your consent banner works, how your marketing suppression list is built, how your breach response plan is documented. An e-commerce platform that hasn't mapped its data fiduciary duties to specific systems is operating with legal exposure it can't currently measure.

    key obligations every data fiduciary must know under the DPDP Rules 2025"

    Marketing Consent The Compliance Gap That Affects Every Platform

    Ask any e-commerce compliance team how their marketing list was built, and the answer is usually some version of "accounts that registered, customers who checked out, users who downloaded the app." In other words, everyone, automatically, from day one.

    Under DPDPA, marketing communications require explicit, informed, specific consent  separate from consent for the core transactional service. A pre-ticked checkbox at sign-up doesn't meet this standard. A clause in the terms and conditions that most users never read doesn't meet this standard either.

    What this means practically: your current marketing database almost certainly contains a large proportion of contacts who have never given DPDPA-compliant consent for marketing use of their data. A retroactive consent collection campaign  sending a compliant notice and consent request to your existing base  is not optional. It is necessary, and it's a core part of DPDP compliance for e-commerce businesses moving forward.

    This isn't just a legal obligation. It's also an opportunity. Customers who explicitly opt in to marketing are more engaged, have higher open rates, and convert better. A smaller, genuinely consented list outperforms a bloated list built on questionable consent every time.

    Each of these touchpoints requires its own consent basis under DPDPA. The consent a customer gives at registration to create an account does not automatically extend to marketing, profiling, or data sharing with partners. These are separate purposes and need to be treated as such.

    Most platforms currently treat account creation as a catch for all consent events. It isn't and the gap between what was collected and what was consented to is where penalty exposure lives.

    Marketing Consent The Compliance Gap That Affects Every Platform

    Ask any e-commerce compliance team how their marketing list was built and the answer is usually some version of accounts that registered, customers who checked out, users who downloaded the app. In other words, everyone automatically, from day one.

    What this means practically: your current marketing database almost certainly contains a large proportion of contacts who have never given DPDPA-compliant consent for marketing use of their data. A retroactive consent collection campaign like sending a compliant notice and consent request to your existing base is not optional. It is necessary.

    This isn't just a legal obligation. It's also an opportunity. Customers who explicitly opt in to marketing are more engaged, have higher open rates, and convert better. A smaller, genuinely consented list outperforms a bloated list built on questionable consent every time.

    restructuring CRM and marketing infrastructure for DPDP

    Checkout Data What You Can Use and What You Can't

    Checkout is where the line between legitimate processing and consent-required processing gets blurry and where many platforms get it wrong.

    Collecting a delivery address and payment details at checkout has a contractual basis. You need that data to fulfil the order. Processing it for that specific purpose like completing the transaction doesn't require separate consent.

    But using that same checkout data to feed a personalisation engine, build a recommendation model, or target the customer with marketing after the transaction is a different purpose entirely. Post-purchase data use requires separate consent. If your recommendation system is using purchase history to generate "you might also like" suggestions, that's profiling and it requires the customer's consent for that specific purpose.

    Most platforms post-purchase data policies haven't been reviewed through this lens. That review needs to happen before the next enforcement cycle begins.

    Cookies and Tracking Your Banner Probably Isn't Compliant

    Cookie compliance is one of the most visible and most widely botched parts of DPDPA readiness in Indian e-commerce. Almost every major platform has some version of a cookie banner. Almost none of them meet the actual standard.

    A banner that says "We use cookies to improve your experience OK" is not compliant consent. It's a notification. DPDPA requires a genuine opt-in mechanism one where the customer can choose to accept or decline different categories of cookies independently, where declining is as easy as accepting, and where non-essential tracking doesn't fire until consent is given.

    Behavioural tracking through cookies, pixels, and device identifiers falls squarely within DPDPA's personal data definition. If your analytics tags, advertising pixels, or retargeting scripts fire before a user has consented to them, that processing is happening without a valid legal basis. At the scale Indian e-commerce platforms operate, that's not a minor technical issue.

    A cookie consent audit is identifying every cookie your platform sets, categorising them, and implementing genuine per-category opt-in is a foundational compliance task that most platforms haven't completed.

    Personalization and Profiling Valuable, But Not Automatic

    Personalisation is arguably the most commercially valuable use of customer data in e-commerce. Recommendation engines, dynamic pricing, targeted offers, curated home pages all of it depends on building and using customer profiles. None of it is automatically permitted under DPDPA.

    Profiling based on personal data requires consent for that specific purpose. If your recommendation engine uses browsing data, purchase history, and location signals to generate suggestions, and your customers only consented to account creation then you have a compliance gap.

    This doesn't mean personalization is off the table. It means consent for personalisation needs to be collected explicitly, as a separate purpose, at the right moment in the customer journey. The right moment is usually after the customer has experienced enough of your platform to understand what personalization means in practice not at the point of registration before they've seen anything.

    What Needs to Change at Platform Level

    The infrastructure gap in Indian e-commerce consent management is structural. Fixing it requires more than updating a privacy policy.

    A consent management platform that captures per-purpose consent at every touchpoint, be it registration, checkout, app install, loyalty enrolment. A real-time enforcement layer that checks consent status before any processing operation executes and blocks campaigns from running against non-consented contacts. Integration with marketing automation platforms to suppress customers who haven't consented to specific communication channels. And cookie consent infrastructure that actually meets DPDPA's standard, not just the appearance of it.

    The Consent lifecycle under DPDPA from notice through grant, management, withdrawal, and audit needs to be operationally real, not just documented in a policy.

    OneConsent integrates with e-commerce platforms to deliver per-purpose consent management at every customer touchpoint with real-time enforcement, withdrawal handling, and the audit trail required for DPDPA compliance.

    The Cost of Doing Nothing Is Higher Than the Cost of Fixing It

    The e-commerce sector's current data practices are, in many cases, structurally non-compliant with DPDPA. That's not an accusation, it's a description of an industry that built itself before this law existed.

    The investment required to rebuild consent infrastructure is significant. The penalty exposure of continuing current practices at scale is larger. A single enforcement action against a major platform for running marketing campaigns on non-consented data, or for cookie tracking without valid opt-in will cost more than the infrastructure to fix it would have.

    The platforms that move first will also build something valuable in the process. A customer data asset built on genuine, explicit consent that holds its commercial value as third-party data access continues to erode globally.

    how BFSI is restructuring consent frameworks under DPDPA

    Frequently Asked Questions

    Have more questions?

    Search our full DPDP knowledge base for more answers.

    See it live

    See OneConsent in action

    Get a personalised walkthrough of how OneConsent helps your teams stay DPDPA compliant.

    • 30-minute walkthrough
    • DPDPA-ready by design
    • Tailored to your stack