Readiness assessment
E-commerce & Retail · D2C

The DPDP Act for D2C Brands

D2C brands live on first-party data built through ads and CRM: emails, phone numbers and purchase history.

In short

D2C brands run on first-party data. The Act governs how you collect it, market with it, and let customers take it back. Penalties reach ₹250 crore.

Core impacts

What changes for this sub-sector.

First-party data and consent

Building a first-party list is fine; using it for marketing needs clear consent and an easy opt-out.

Ad pixels and tracking

Meta and Google pixels and conversion APIs send personal data to ad platforms; consent and disclosure apply.

CRM and segmentation

Profiling for segments and lookalikes is processing; be transparent and honour objections.

Customer rights

Handle access, correction and deletion, including from your email tool and CRM, on request.

Vendors

Your email platform, CDP, reviews and support tools are processors under contract.

Minimization and retention

Keep customer data only while it serves a stated purpose.

Check your marketing stack.

The readiness check flags consent, pixel and vendor gaps.

Take the readiness check