Sector Guide 8 min read 25 July 2026

DPDP for E-commerce & D2C Brands: Orders, COD Data, and Marketplaces

Every order an Indian e-commerce or D2C brand takes collects personal data — names, addresses, phone numbers, payment details. Here's what the DPDP Act requires, from checkout consent to courier data sharing.

PDF ↓ Download the free one-page guide Branded PDF summary with a QR code back to this guide — print it for your desk or team. PDF →

An online store cannot take a single order without collecting personal data: a name, a delivery address, a phone number, often payment details. That makes every Indian e-commerce and D2C business a Data Fiduciary under the DPDP Act 2023 — and the deadline for getting this right is May 13, 2027.

Where Your Store Collects Personal Data

Map it honestly and the list is longer than checkout: the order form, guest checkout emails, the newsletter popup, WhatsApp order chats, Instagram DMs, COD confirmation calls, product reviews, and the analytics and ad pixels on every page. Each is a collection point that needs to be covered by your notice and consent. If you sell on Shopify specifically, we have a dedicated Shopify compliance checklist; WhatsApp and Instagram sellers have their own guides too.

The Five Duties That Bite for E-commerce

1. Checkout consent that actually counts

Consent must be a clear, affirmative action for stated purposes (Section 6). A checkbox at checkout works — a pre-ticked one doesn't, and neither does silently adding every buyer to your marketing list. Delivery and marketing are different purposes; collect them separately.

2. A notice customers can read

Your privacy notice must itemise what you collect and why, in plain language (Section 5(1), Rule 3 of the DPDP Rules 2025) — and be available in the customer's language on request (Section 5(3)). For most D2C brands that means at least English plus your main customer languages. See how to write the notice.

3. Your delivery and payment partners

Couriers, payment gateways, fulfilment centres and marketing tools all process customer data on your behalf. You remain responsible (Section 8(2)) — so their contracts need data-protection clauses, and your notice must disclose the sharing.

4. Deletion when the purpose ends

Order data can't live in your systems forever. Keep what tax law requires (GST records have their own retention rules), delete what nothing requires — abandoned-cart data, stale marketing lists, old COD call recordings (Section 8(7)).

5. Requests and breaches

Customers can ask what you hold and demand corrections or deletion (Sections 11–12) — you need a working channel and published response times (Rule 14). And if order data leaks, the 72-hour breach clock applies to you like everyone else.

Getting It Done

Work through the interactive DPDP compliance checklist — the 14 steps cover everything above in order. The recurring work — consent at every channel, request handling, the records that prove it — is what consent management built for Indian selling channels automates, and the free checker will tell you your specific exposure in two minutes.

References & Sources

  1. Ministry of Electronics & IT — The Digital Personal Data Protection Act, 2023 (Sections 5, 6, 8(2), 8(7), 11–12).
  2. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 3 (notice), Rule 7 (breach intimation), Rule 14 (rights of Data Principals).

General information, not legal advice. Verify obligations against the notified text for your specific business.

E-commerceD2CDPDPComplianceOnline Selling

Check Your DPDP Compliance

Free 2-minute checker — get your specific obligations and penalty exposure.