DPDP compliance for retail and e-commerce businesses
Retail and e-commerce companies sit on large customer databases. The DPDP Act sets clear rules on consent, marketing, loyalty programmes, and data sharing with delivery and payment partners.
What personal data do retail and e-commerce businesses hold under DPDP?
A typical e-commerce business processes: registration data (name, email, phone, address); transaction data (order history, payment method, value); behavioural data (browsing history, search terms, wishlist items, session duration); loyalty programme data (points, tier, redemption history); and potentially device and location data. Each category requires a lawful basis and a retention period. Payment data is particularly sensitive and may also be subject to RBI requirements if you operate your own payment stack.
Do you need consent to send marketing emails or WhatsApp messages to customers?
The most commercially sensitive area of DPDP for retailers is marketing. Sending promotional emails or WhatsApp messages to customers requires their consent. Consent must be specific — a customer who consented to receive order updates has not consented to receive promotional offers unless the consent form was explicit on that point. Audit your existing mailing list: how was each contact's consent captured, and does the consent cover the messages you are currently sending?
How do DPDP consent rules apply to retail loyalty programmes?
Loyalty programmes are a major source of customer data collection, and they must comply with DPDP. The loyalty programme membership form must disclose what data you collect, why, and with whom it is shared. Enrolment cannot be made compulsory as a condition of purchase — that would make consent non-freely-given. The benefits of the programme should be available without requiring data collection beyond what is necessary to operate it.
Can e-commerce companies share customer data with delivery and payment partners?
E-commerce operations involve sharing customer data with multiple parties: payment gateways, logistics providers, customer support tools, marketing platforms, and analytics vendors. Every one of these is a Data Processor relationship requiring a Data Processing Agreement. The DPA must specify what the processor can do with the data, prohibit use for the processor's own purposes (a major risk with ad-tech and analytics vendors), and require deletion when the relationship ends.
Does product personalisation and recommendation profiling require consent under DPDP?
Product recommendations and personalised search results are built on profiling — using behavioural data to infer preferences and drive purchase decisions. The DPDP Act requires that profiling-based personalisation be disclosed in your privacy notice and, if it involves sensitive inferences (e.g. about health or finances from purchase patterns), be subject to explicit consent. Customers must be able to access the data you hold on them and to withdraw consent for profiling without losing access to the platform.
How must retailers respond to a customer data breach under DPDP?
A breach of customer data — whether from a hacked database, misconfigured cloud storage, or a compromised third-party vendor — requires notification to the Data Protection Board and to affected customers within the prescribed timeline. E-commerce companies typically hold large databases with financial and personal data, making them attractive targets. Your breach-response plan must be tested, your incident-detection capabilities must be live, and your notification templates must be ready before you need them.
Frequently asked questions
Can I send WhatsApp marketing messages to customers who bought from me?
A past purchase does not automatically entitle you to send marketing messages. You need consent for marketing communications. If the customer consented to marketing at checkout or through a subsequent opt-in, you can send messages. If you only have their number from a transaction, you can send transactional updates about that transaction, but not promotional content without separate consent.
Do I need to delete a customer's data if they request it but have an active loyalty balance?
If the customer requests erasure, you should stop processing their data for marketing and profiling purposes immediately. The loyalty balance creates a contractual obligation — you may need to retain the record of the balance until it is redeemed or the programme period closes. Discuss with the customer: you can honour the balance without continuing to send marketing to them. Once the balance is resolved and there is no other lawful basis, full erasure applies.
Can I sell customer data to a third-party data broker?
No. Selling customer personal data to a third party without the customer's explicit, informed consent is unlawful under the DPDP Act. Even if you have a broad consent in your terms of service, a generic consent for 'data sharing with partners' is unlikely to be sufficiently specific to authorise sale of data to a data broker for their own commercial purposes. Do not sell customer data without specific, granular, informed consent for that purpose.
Check your retail DPDP compliance
Niti Bharat's DPDP Readiness Assessment covers retail and e-commerce companies — consent for marketing, loyalty data, third-party DPAs, and breach response — in a structured 5-day engagement.
Start Retail DPDP Assessment