Checkout consent is not marketing consent.
D2C brands collect customer data at checkout, then use it for remarketing, segmentation, and analytics. Under DPDP, those are different purposes and each requires a separate, specific consent action. We untangle your consent flows, implement purpose-specific consent at every touchpoint, and build the rights portal your customers can actually use.
Six entities. One customer's data touching all of them.
A D2C brand's data ecosystem spans payment gateways, logistics partners, ad platforms, and marketplaces. Under DPDP, every handoff needs a lawful basis. Every vendor needs a contract. And marketing is never a free rider on transactional consent.
Customer
Data Principal
Data handled
Name, address, phone, email, payment details, browsing and purchase behaviour
DPDP obligation
Consent required per purpose. Checkout consent does not cover remarketing, segmentation, or third-party sharing.
D2C Brand
Primary Data Fiduciary
Data handled
Full customer PII, order history, behavioural analytics, CRM data
DPDP obligation
Owns notice, purpose-specific consent, rights fulfilment, retention limits, and breach notification.
Payment Gateway
Data Processor
Data handled
Card data, UPI IDs, transaction records
DPDP obligation
Processor contract required. RBI PCI-DSS obligations sit alongside DPDP — both apply.
Marketing and Ad Platforms
Independent Data Fiduciary or Processor
Data handled
Behavioural signals, custom audiences, retargeting data
DPDP obligation
Separate consent required before sharing customer data for marketing purposes. Pre-checked opt-ins are invalid.
Logistics and Courier Partners
Data Processor
Data handled
Delivery address, phone number, order contents
DPDP obligation
Processor contract required. Data must not be used beyond delivery fulfilment without separate consent.
Marketplaces (Amazon, Flipkart)
Independent Data Fiduciary
Data handled
Customer data collected via marketplace transactions
DPDP obligation
Marketplace and brand obligations are separate. Data received from marketplace channels cannot be used for direct marketing without independent consent.
Five obligations. All of them are engineering problems.
Purpose-specific consent at every touchpoint
A single consent at checkout cannot cover order processing, remarketing, loyalty programmes, analytics, and third-party ad sharing. Each purpose requires its own consent box, its own notice, and its own withdrawal mechanism. We rebuild your consent flows from the ground up — checkout, account creation, post-purchase, and re-engagement — so every purpose has a lawful basis.
Three-year retention for large platforms
E-commerce entities with two crore or more users must delete personal data within three years of the customer's last transaction or login. That requires automated tracking of last-interaction dates, lifecycle-aware deletion pipelines, and a mechanism to notify customers 48 hours before erasure. We implement this end-to-end.
Marketing vendor agreements
Every ad platform, email service provider, CRM, and analytics tool that receives customer data is a processor or a joint fiduciary. Each needs a written data processing agreement. Where a platform independently determines how it uses your customer data — retargeting, lookalike audiences, profiling — it may be classified as a Fiduciary for those activities. We map your entire MarTech stack and implement the right agreements.
Data principal rights portal
Customers have the right to access their data, correct inaccuracies, opt out of marketing, and request deletion. Under Rule 14, you must respond within seven days. We ship a rights portal integrated into your storefront and CRM that handles requests end-to-end with audit trails for every response.
Breach notification within 72 hours
A customer data breach triggers a 72-hour clock for notifying the Data Protection Board and affected customers simultaneously. For a D2C brand with thousands of customer records, this is an operational problem as much as a legal one. We build the runbook, the detection integrations, and the notification templates before you need them.
Questions we get from D2C brands.
Our terms of service already include a data processing clause. Is that enough?
No. Consent bundled into terms of service or pre-ticked at checkout is invalid under DPDP. Consent must be free, specific, informed, unconditional, and based on a clear affirmative action — one box per purpose. A generic TOS clause does not satisfy the itemised notice and separate consent requirements for each processing activity.
We use Meta Pixel, Google Analytics, and a CRM. Do all of them need processor contracts?
Yes — and some may not qualify as processors at all. Where Meta or Google independently determine how they use your customer data (for their own ad models, for example), they act as independent Fiduciaries. That means sharing data with them requires separate customer consent, not just a DPA. We classify each tool in your stack and implement the right legal mechanism for each.
What counts as a 'last transaction or login' for the three-year retention rule?
The DPDP Rules refer to the customer's last approach to the platform — which includes any login, purchase, or meaningful interaction. The precise technical definition will be clarified by the Data Protection Board. We implement a conservative interpretation that tracks the last authenticated session or transaction and begins the retention clock from that point.
We sell on Amazon and Flipkart as well as our own D2C site. Do marketplace customers need separate consent?
Yes. Data received through marketplace channels is governed by the marketplace's consent framework, not yours. If you want to use that data for your own marketing, CRM, or analytics, you need to obtain independent consent from those customers through your own channels. Using marketplace customer data for direct outreach without consent is a DPDP violation.
We have customers who bought once years ago. Do old records need to be cleaned up?
Yes. The DPDP Act's processing obligations apply regardless of when the data was originally collected. Historical customer records that no longer serve a lawful purpose and lack a valid consent basis must be reviewed. Where no retention basis exists, erasure is required. We build a data inventory and historical records audit as part of the engagement.
Penalties under the DPDP Act can reach ₹250 crore for breach of security safeguard obligations. This engagement covers the technical and product layer of compliance. Pair it with your legal counsel for full coverage.