DPDP compliance for D2C brands

DPDP compliance for D2C brands
D2C

DPDP compliance for D2C brands

D2C brands are built on first-party customer data. The DPDP Act sets clear consent, retention, and sharing rules that every brand must understand before the 2027 deadline.

Quick Answer: Direct-to-consumer brands are Data Fiduciaries under the DPDP Act for the personal data of their customers — purchase history, behavioural data, loyalty information, and payment details. Consent for marketing communications, profiling, and personalisation must be freely given and specific. D2C brands using Shopify, WhatsApp Business API, email automation, and Meta/Google ads must ensure each vendor has a DPA and that consent flows through the entire martech stack. Customer right-to-erasure requests affect product recommendation models trained on purchase data. Enforcement begins May 2027.

What customer data does a D2C brand process under DPDP?

D2C brands collect: name, contact details, delivery address, purchase history, browsing and cart behaviour, payment data, customer service interactions, product reviews, loyalty points, referral details, and app usage data. Brands selling health or wellness products additionally collect health-adjacent data (supplement stacks, workout goals) which may approach sensitive personal data. Each category requires a lawful basis and a retention period.

Do D2C brands need consent for WhatsApp and SMS marketing?

Yes. WhatsApp Business API messages and SMS marketing require prior consent. Opt-in must be explicit — a checkout confirmation message does not automatically consent the customer to receive promotional WhatsApp messages. Build separate opt-in at checkout for transactional messages (order updates) and for promotional messages (offers, new launches). This split is essential because many D2C brands conflate the two and send promotional messages on a transactional consent basis.

How do DPDP consent requirements apply to D2C subscription models?

Subscription customers have an ongoing relationship with the brand, but that relationship does not imply blanket consent for all data uses. The subscription consent covers processing data to fulfil the subscription — recurring orders, billing, delivery. Separate consent is needed for: using subscription data for marketing other products; sharing subscriber profiles with advertising partners; and using subscription behaviour for AI-driven personalisation beyond product recommendations. Review your subscription sign-up consent form.

How does DPDP affect D2C brand data on Meta and Google ad platforms?

When a D2C brand uploads a customer list to Meta or Google for lookalike audiences or retargeting, this shares personal data with a third party (Meta/Google) which requires: (a) explicit customer consent for this specific use in your privacy notice, and (b) a DPA with the ad platform. Check your checkout consent flow — if customers consented to 'marketing communications' but not to 'sharing your data with advertising platforms to show you relevant ads', your lookalike audience campaign may be out of compliance.

What DPDP obligations arise from D2C product recommendation engines?

Product recommendation engines use purchase and browsing data to profile customers. This profiling requires disclosure in your privacy notice and consent if you are making inferences that go beyond obvious product suggestions. If a customer's purchase history reveals health conditions, dietary needs, or financial constraints, and your recommendation engine uses these inferences to target them, this is sensitive inference that needs explicit consent. Train your data science team on DPDP's profiling rules.

How should D2C brands handle customer data requests at scale?

At D2C scale — thousands of orders per month — you will receive data access and erasure requests regularly. Build a self-service mechanism in your customer portal: account download (all data associated with the account) and account deletion. When a customer deletes their account, cascade the deletion across: your Shopify/platform database, email marketing tool, WhatsApp CRM, loyalty system, and any analytics warehouse. Automated deletion workflows are essential at scale.

Frequently asked questions

Can we use a customer's purchase history to train our product recommendation AI?

Using purchase history to train a product recommendation AI is a specific processing purpose that requires disclosure. If your privacy notice says 'we use your purchase data to improve our recommendations' and customers consented to this, you have a basis. If the consent was for 'fulfilling your order' only, retraining AI on purchase data is a secondary use requiring fresh consent or a privacy notice update with re-consent. Generally, anonymise training data wherever possible.

Do we need a DPA with Shopify?

Yes. Shopify processes personal data on your behalf — customer records, order data, payment information — as your Data Processor. Shopify provides a standard Data Processing Agreement that covers GDPR and can form the basis for DPDP compliance. Review the Shopify DPA for DPDP-specific requirements: data residency (Shopify has India infrastructure options), breach notification SLAs, and sub-processor disclosure.

If a customer asks us to delete their data, must we delete their reviews?

A product review posted publicly is personal data (it is linked to the customer's name and purchase). On an erasure request, you should either delete the review or anonymise it (remove the customer's name and account link). If the review is genuinely anonymised — not linkable to the individual — it can remain as aggregate product feedback. Communicate clearly to the customer what will happen to their review as part of the deletion response.

Audit your D2C brand's DPDP compliance

Niti Bharat's DPDP Consent Audit covers D2C brands — WhatsApp opt-in, email consent, ad platform data sharing, recommendation engine profiling, and customer deletion workflows.

Start D2C Consent Audit
Previous Post Next Post

Get Free DPDP Checklist