AMLEGALS — Strategic Lawyering

DPDPA for E-commerce and D2C Brands

DPDPA for E-commerce and D2C Brands

Abandoned cart. Abandoned consent.

The scene

A shopper bought one pair of shoes in 2022. Since then she has received four hundred messages across email, SMS and WhatsApp, been added to lookalike audiences on three ad platforms, and had her address shared with a delivery partner that later changed hands. She agreed to buy shoes.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Buying means agreeing to marketing.

Purchase and marketing are separate purposes needing separate consent.

Ask for marketing on its own, and accept no.

Pixels are just analytics.

Pixels send personal data to third parties; that is processing on your behalf.

Treat every pixel as a processor, with a contract.

Pre-selected boxes convert better.

Consent needs a clear affirmative action; dark patterns are also regulated as unfair practices.

Earn the yes. A trick is not consent.

Erasure clocks for large platforms

The DPDP Rules set a time limit for certain large e-commerce entities: personal data of users inactive for three years must be erased, after notice to the user. Size brings its own schedule.

The full E-commerce & D2C briefing 3 deep dives

Deep dive 01 →

Forty pixels on checkout. Forty processors without paper.

You installed a snippet. You appointed a processor.

Deep dive 02 →

A trick is not an agreement.

If the customer had to be fooled into yes, you do not have a yes.

Deep dive 03 →

Inactive is not a retention strategy.

The customer left. The data should follow.

Monday morning

01 Export your tag manager. Count the pixels.

02 Separate transactional messaging from marketing, in systems and in consent.

03 Remove one pre-selected box this week.

Questions, answered plainly

Do e-commerce companies need separate consent for marketing under DPDPA? +

Generally yes. Consent must be specific to a purpose. Processing an order and sending marketing are different purposes, so marketing typically requires its own consent that can be refused and withdrawn.

What is the three-year erasure rule in the DPDP Rules? +

The Rules require certain classes of large Data Fiduciaries, including e-commerce entities above a user threshold, to erase personal data of users who have not engaged for three years, after notifying them in advance.

Sector · SaaS & IT services You think you're the processor. Your contract may disagree. Read →

Sector · Telecom A billion subscribers. A billion Data Principals. Read →

Sector · Insurance Your agent's phone is part of your data estate. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).