
Logistics & Supply Chain
DPDPA Impact on Logistics & Supply Chain
Logistics and last-mile operators sit on dense flows of consignee names, addresses, phone numbers and location trails — much of it processed on behalf of e-commerce and enterprise clients as a Data Processor.
In short
The DPDP Act, 2023 applies to logistics and last-mile operators because consignee names, addresses, phone numbers and driver location data are digital personal data. Operators are usually Data Processors for their e-commerce and enterprise clients, so a valid Section 8(2) contract, reasonable security safeguards under Section 8(5) read with Rule 6, and purpose-limited retention under Section 8(7) read with Rule 8 are the core duties.
- Consignee and driver data are personal data; most fleet and courier firms act as Data Processors under Section 8(2).
- Delivery data must be erased once the purpose is served, under Section 8(7) read with Rule 8.
- A personal data breach triggers intimation to affected Data Principals without delay and a detailed report to the Data Protection Board within 72 hours, under Section 8(6) read with Rule 7.
When the Act applies
The Act applies to consignee, sender and driver personal data processed in digital form in India, and to processing outside India connected with offering delivery or fulfilment services to Data Principals in India.
Personal data typically in play
- Consignee & sender names, addresses and phone numbers
- Delivery OTPs and proof-of-delivery signatures/photographs
- Driver and rider identity, licence and live location data
- Address books ingested from client platforms
- Call-recording between riders and customers
Mapped obligations
Itemised notice
Give each Data Principal a clear, itemised notice — in English or any language in the Eighth Schedule to the Constitution — describing the personal data collected and the specified purpose, before or at the time of seeking consent.
Consent that is free & withdrawable
Where processing rests on consent, it must be free, specific, informed, unconditional and unambiguous, limited to the specified purpose, and as easy to withdraw as it was to give.
Processor under valid contract
Engage every Data Processor — vendors, sub-contractors and technology partners — only under a valid contract, and remain accountable for the personal data throughout.
Reasonable security safeguards
Implement reasonable security safeguards — including measures such as encryption, access control, logging and monitoring — to prevent a personal data breach.
Breach intimation
On becoming aware of a personal data breach, intimate each affected Data Principal without delay and give the Data Protection Board an initial description without delay, followed by detailed information within 72 hours (or such longer period as the Board may allow).
Retention limits & erasure
Erase personal data on withdrawal of consent or once the specified purpose is no longer being served, unless retention is required by law.
Data Principal rights
Enable the rights to access a summary of personal data and processing, to correction and erasure, to grievance redressal and to nominate — and publish the manner in which these are exercised.
Recurring compliance risks
- Retaining consignee address books long after delivery is complete
- Sharing customer numbers with riders without masking or purpose limits
- No written Section 8(2) contract governing data received from client platforms
- Location trails of drivers repurposed beyond the delivery task
Actions that follow
- 1Map every flow where you act as Data Fiduciary versus Data Processor
- 2Put Section 8(2) contracts in place with every client and sub-contracted fleet
- 3Introduce number-masking and time-boxed retention for delivery data
- 4Stand up a breach-intimation runbook aligned to Rule 7 timelines
