AMLEGALS — Strategic Lawyering

The DPDP Rules' Three-Year Erasure Rule for E-commerce Platforms

The DPDP Rules' Three-Year Erasure Rule for E-commerce Platforms

The customer left. The data should follow.

The scene

Forty percent of accounts had not logged in for three years. Marketing called them ‘win-back potential’. Under the Rules, for a platform of that size, they were a deletion queue with a notice period.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Dormant users might come back.

For covered platforms the Rules require erasure after three years of inactivity, with prior notice.

Notify, invite back, then erase on schedule.

Order history must be kept forever.

Keep what tax and consumer law require; erase the rest.

Separate invoices from profiles.

Designing the notice

The Rules require notice before erasure. Treat it as the last honest message: here is what we hold, here is when it goes, here is how to keep your account.

Monday morning

01 Count accounts inactive for over three years.

02 Separate records required by law.

03 Draft the pre-erasure notice.

Questions, answered plainly

What is the three-year erasure rule for e-commerce under the DPDP Rules? +

The Rules require certain e-commerce entities above a registered-user threshold in India to erase personal data of users who have not engaged for three years, after informing them at least 48 hours in advance, unless retention is required by law.

Can e-commerce companies keep invoices after erasing accounts? +

Yes, where tax or other law requires retention. Only data required by law should be retained, for the period required.

Sector · E-commerce & D2C Your funnel runs on consent. The Act just redefined consent. Read →

E-commerce & D2C · Deep dive Forty pixels on checkout. Forty processors without paper. Read →

E-commerce & D2C · Deep dive A trick is not an agreement. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).