Industries/E-commerce and D2C

Checkout consent is not marketing consent.

D2C brands collect customer data at checkout, then use it for remarketing, segmentation, and analytics. Under DPDP, those are different purposes and each requires a separate, specific consent action. We untangle your consent flows, implement purpose-specific consent at every touchpoint, and build the rights portal your customers can actually use.

The data chain

Six entities. One customer's data touching all of them.

A D2C brand's data ecosystem spans payment gateways, logistics partners, ad platforms, and marketplaces. Under DPDP, every handoff needs a lawful basis. Every vendor needs a contract. And marketing is never a free rider on transactional consent.

Customer

Data Principal

Data handled

Name, address, phone, email, payment details, browsing and purchase behaviour

DPDP obligation

Consent required per purpose. Checkout consent does not cover remarketing, segmentation, or third-party sharing.

D2C Brand

Primary Data Fiduciary

Data handled

Full customer PII, order history, behavioural analytics, CRM data

DPDP obligation

Owns notice, purpose-specific consent, rights fulfilment, retention limits, and breach notification.

Payment Gateway

Data Processor

Data handled

Card data, UPI IDs, transaction records

DPDP obligation

Processor contract required. RBI PCI-DSS obligations sit alongside DPDP — both apply.

Marketing and Ad Platforms

Independent Data Fiduciary or Processor

Data handled

Behavioural signals, custom audiences, retargeting data

DPDP obligation

Separate consent required before sharing customer data for marketing purposes. Pre-checked opt-ins are invalid.

Logistics and Courier Partners

Data Processor

Data handled

Delivery address, phone number, order contents

DPDP obligation

Processor contract required. Data must not be used beyond delivery fulfilment without separate consent.

Marketplaces (Amazon, Flipkart)

Independent Data Fiduciary

Data handled

Customer data collected via marketplace transactions

DPDP obligation

Marketplace and brand obligations are separate. Data received from marketplace channels cannot be used for direct marketing without independent consent.

What we build

Five obligations. All of them are engineering problems.

Purpose-specific consent at every touchpoint

DeliverableConsent flow redesign, purpose registry, consent ledger

A single consent at checkout cannot cover order processing, remarketing, loyalty programmes, analytics, and third-party ad sharing. Each purpose requires its own consent box, its own notice, and its own withdrawal mechanism. We rebuild your consent flows from the ground up — checkout, account creation, post-purchase, and re-engagement — so every purpose has a lawful basis.

Three-year retention for large platforms

DeliverableRetention policy, last-interaction tracking, erasure automation, 48-hour pre-deletion notice

E-commerce entities with two crore or more users must delete personal data within three years of the customer's last transaction or login. That requires automated tracking of last-interaction dates, lifecycle-aware deletion pipelines, and a mechanism to notify customers 48 hours before erasure. We implement this end-to-end.

Marketing vendor agreements

DeliverableMarTech vendor mapping, DPA templates, contract execution support

Every ad platform, email service provider, CRM, and analytics tool that receives customer data is a processor or a joint fiduciary. Each needs a written data processing agreement. Where a platform independently determines how it uses your customer data — retargeting, lookalike audiences, profiling — it may be classified as a Fiduciary for those activities. We map your entire MarTech stack and implement the right agreements.

Data principal rights portal

DeliverableRights request portal, 7-day SLA automation, CRM integration

Customers have the right to access their data, correct inaccuracies, opt out of marketing, and request deletion. Under Rule 14, you must respond within seven days. We ship a rights portal integrated into your storefront and CRM that handles requests end-to-end with audit trails for every response.

Breach notification within 72 hours

DeliverableBreach runbook, Board notification template, customer notification flow

A customer data breach triggers a 72-hour clock for notifying the Data Protection Board and affected customers simultaneously. For a D2C brand with thousands of customer records, this is an operational problem as much as a legal one. We build the runbook, the detection integrations, and the notification templates before you need them.

Common questions

Questions we get from D2C brands.

Our terms of service already include a data processing clause. Is that enough?

No. Consent bundled into terms of service or pre-ticked at checkout is invalid under DPDP. Consent must be free, specific, informed, unconditional, and based on a clear affirmative action — one box per purpose. A generic TOS clause does not satisfy the itemised notice and separate consent requirements for each processing activity.

We use Meta Pixel, Google Analytics, and a CRM. Do all of them need processor contracts?

Yes — and some may not qualify as processors at all. Where Meta or Google independently determine how they use your customer data (for their own ad models, for example), they act as independent Fiduciaries. That means sharing data with them requires separate customer consent, not just a DPA. We classify each tool in your stack and implement the right legal mechanism for each.

What counts as a 'last transaction or login' for the three-year retention rule?

The DPDP Rules refer to the customer's last approach to the platform — which includes any login, purchase, or meaningful interaction. The precise technical definition will be clarified by the Data Protection Board. We implement a conservative interpretation that tracks the last authenticated session or transaction and begins the retention clock from that point.

We sell on Amazon and Flipkart as well as our own D2C site. Do marketplace customers need separate consent?

Yes. Data received through marketplace channels is governed by the marketplace's consent framework, not yours. If you want to use that data for your own marketing, CRM, or analytics, you need to obtain independent consent from those customers through your own channels. Using marketplace customer data for direct outreach without consent is a DPDP violation.

We have customers who bought once years ago. Do old records need to be cleaned up?

Yes. The DPDP Act's processing obligations apply regardless of when the data was originally collected. Historical customer records that no longer serve a lawful purpose and lack a valid consent basis must be reviewed. Where no retention basis exists, erasure is required. We build a data inventory and historical records audit as part of the engagement.

Penalties under the DPDP Act can reach ₹250 crore for breach of security safeguard obligations. This engagement covers the technical and product layer of compliance. Pair it with your legal counsel for full coverage.

Ready to build DPDP compliance into your D2C product?

Take the readiness check