AMLEGALS — Strategic Lawyering
Logistics & Supply Chain — DPDPA sector brief

Logistics & Supply Chain

DPDPA Impact on Logistics & Supply Chain

Logistics and last-mile operators sit on dense flows of consignee names, addresses, phone numbers and location trails — much of it processed on behalf of e-commerce and enterprise clients as a Data Processor.

In short

The DPDP Act, 2023 applies to logistics and last-mile operators because consignee names, addresses, phone numbers and driver location data are digital personal data. Operators are usually Data Processors for their e-commerce and enterprise clients, so a valid Section 8(2) contract, reasonable security safeguards under Section 8(5) read with Rule 6, and purpose-limited retention under Section 8(7) read with Rule 8 are the core duties.

  • Consignee and driver data are personal data; most fleet and courier firms act as Data Processors under Section 8(2).
  • Delivery data must be erased once the purpose is served, under Section 8(7) read with Rule 8.
  • A personal data breach triggers intimation to affected Data Principals without delay and a detailed report to the Data Protection Board within 72 hours, under Section 8(6) read with Rule 7.

When the Act applies

The Act applies to consignee, sender and driver personal data processed in digital form in India, and to processing outside India connected with offering delivery or fulfilment services to Data Principals in India.

Personal data typically in play

  • Consignee & sender names, addresses and phone numbers
  • Delivery OTPs and proof-of-delivery signatures/photographs
  • Driver and rider identity, licence and live location data
  • Address books ingested from client platforms
  • Call-recording between riders and customers

Mapped obligations

Section 5 · Rule 3

Itemised notice

Give each Data Principal a clear, itemised notice — in English or any language in the Eighth Schedule to the Constitution — describing the personal data collected and the specified purpose, before or at the time of seeking consent.

Section 6

Consent that is free & withdrawable

Where processing rests on consent, it must be free, specific, informed, unconditional and unambiguous, limited to the specified purpose, and as easy to withdraw as it was to give.

Section 8(2)

Processor under valid contract

Engage every Data Processor — vendors, sub-contractors and technology partners — only under a valid contract, and remain accountable for the personal data throughout.

Section 8(5) · Rule 6

Reasonable security safeguards

Implement reasonable security safeguards — including measures such as encryption, access control, logging and monitoring — to prevent a personal data breach.

Section 8(6) · Rule 7

Breach intimation

On becoming aware of a personal data breach, intimate each affected Data Principal without delay and give the Data Protection Board an initial description without delay, followed by detailed information within 72 hours (or such longer period as the Board may allow).

Section 8(7) · Rule 8

Retention limits & erasure

Erase personal data on withdrawal of consent or once the specified purpose is no longer being served, unless retention is required by law.

Sections 11–14 · Rule 14

Data Principal rights

Enable the rights to access a summary of personal data and processing, to correction and erasure, to grievance redressal and to nominate — and publish the manner in which these are exercised.

Recurring compliance risks

  • Retaining consignee address books long after delivery is complete
  • Sharing customer numbers with riders without masking or purpose limits
  • No written Section 8(2) contract governing data received from client platforms
  • Location trails of drivers repurposed beyond the delivery task

Actions that follow

  1. 1Map every flow where you act as Data Fiduciary versus Data Processor
  2. 2Put Section 8(2) contracts in place with every client and sub-contracted fleet
  3. 3Introduce number-masking and time-boxed retention for delivery data
  4. 4Stand up a breach-intimation runbook aligned to Rule 7 timelines

Frequently asked questions

Is a courier or logistics company a Data Fiduciary or a Data Processor under the DPDP Act?
It depends on the flow. When an operator processes consignee data on behalf of an e-commerce or enterprise client under that client’s instructions, it is a Data Processor and must operate under a valid Section 8(2) contract. Where it decides the purpose and means itself — for example its own customer accounts — it is a Data Fiduciary and carries the full set of Fiduciary obligations.
How long can delivery addresses and consignee phone numbers be retained?
Only for as long as the specified purpose is served. Under Section 8(7) read with Rule 8, personal data must be erased on withdrawal of consent or once the delivery purpose is complete, unless retention is required by law.
Does driver live-location tracking fall under the DPDP Act?
Yes. A driver’s or rider’s identity and live location are personal data. Their use must be confined to the specified purpose — completing and verifying the delivery — with notice under Section 5 read with Rule 3 and reasonable security safeguards under Section 8(5) read with Rule 6.