Readiness assessment
E-commerce & Retail

The DPDP Act for E-commerce & Retail

Marketplaces, D2C brands and retailers collect profiles, orders, payments and behaviour; the Act governs how you use all of it.

In short

Every marketplace, D2C brand and retailer collects profiles, orders, payment and behavioural data. The Act requires consent for marketing, data minimization at checkout, honouring deletion, and controlling the many vendors in your stack. Penalties reach ₹250 crore.

What the Act asks of you

The obligations that shape compliance in this sector.

Consent for marketing

Take clear opt-in consent before you profile customers or send marketing; no pre-ticked boxes.

Cookie and tracking consent

Trackers, pixels and analytics that identify users need consent and a real opt-out.

Data minimization

Collect only what a checkout needs; avoid hoarding data you will never use.

Customer rights

Honour access, correction and account-deletion requests, and make them easy to find.

Vendor and processor control

Logistics, marketing, analytics and payment vendors are processors under contract.

Breach reporting

Report breaches of customer data to the affected people and the Board.

See where you stand.

Run the free readiness check for a sector-specific gap report.

Take the readiness check