AMLEGALS — Strategic Lawyering
DPDPA for Global Retail & E-Commerce

International Retailers Entering India Must Build DPDPA Compliance Into Their Market Entry Architecture

Customer accounts, payment data, delivery addresses, purchase history, browsing behaviour, loyalty programmes — every data point a retailer collects from Indian consumers is personal data under the DPDPA.

Request a Briefing28+ Years of Counsel-Led Practice

International retail and e-commerce companies entering the Indian market face one of the most data-intensive compliance environments in the world. A single customer transaction generates personal data across multiple systems — account registration, payment processing, order fulfilment, delivery logistics, customer service, marketing, and post-purchase analytics.

Under the DPDPA, every processing purpose requires a specific notice (Section 5) and specific consent (Section 6). A global retailer's existing privacy framework — designed for GDPR, CCPA, or APPI — cannot be transplanted into India without structural modification.

Consent Architecture for Retail Operations

A retail platform processing customer data for account management, payment processing, order fulfilment, marketing communications, behavioural analytics, and personalisation must obtain specific consent for each purpose. Section 6 prohibits bundled consent. A single "by creating an account, you agree to our privacy policy" is non-compliant. Each processing purpose — particularly marketing and personalisation — requires separate, informed consent.

Statutory Map

Key DPDPA Obligations

ObligationSection / RuleDescription
Purpose-specific consentSection 6Separate consent for each retail processing purpose — transactions, marketing, analytics, personalisation
Payment data localisationRBI 2018 + Section 16Payment data stored in India per RBI mandate; other personal data per DPDPA Section 16
Marketplace seller governanceSection 8(2)DPAs with marketplace sellers who process customer data through the platform
Delivery partner dataSection 8(2)Contractual controls on personal data shared with logistics and delivery partners

Request a Retail Market Entry DPDPA Compliance Review

A confidential assessment of your India retail data architecture — consent mechanisms, payment compliance, marketplace governance, and cross-border data flows.

Request a Confidential Briefing

Our data privacy counsel will reach out within one working day.

Your information is handled in accordance with our privacy obligations. No spam, ever.

Insights & Answers

Frequently Asked Questions

Does DPDPA apply to international retailers selling to Indian consumers online?

Yes. Section 3(b) extends the Act to any entity outside India processing personal data in connection with offering goods or services to Data Principals within India. An international e-commerce platform accessible from India and processing Indian customer data is within scope.