E-commerce marketplaces, D2C brands and retailers

DPDP compliance for e-commerce and retail

Online stores collect personal data at every step: sign-up, checkout, delivery, loyalty and marketing. The DPDP Act expects each use to have a clear notice and a lawful basis, and large platforms must erase data from inactive accounts. ConsentLo turns that into a workflow.

What DPDP changes for you

  • Marketing by email, SMS and WhatsApp needs consent that is separate from placing an order.
  • Large e-commerce platforms must erase personal data after a period of inactivity, with 48 hours' notice before erasure.
  • Courier, payment, analytics and ad partners all process customer data.
  • Customers expect to see, correct and delete their data quickly, in their own language.

How ConsentLo helps

Consent SDK for web and app

Drop-in consent capture with notices in English and 22 Indian languages, and one-click withdrawal.

Inactivity erasure

Retention rules find inactive accounts, send the advance notice and erase on schedule, with evidence.

Self-service privacy portal

Customers access, correct or erase their data and manage preferences without raising a ticket.

Vendor register

Processors, contracts and cross-border checks in one register, with withdrawal cascades to each vendor.

Frequently asked questions

Do e-commerce companies need consent for marketing under DPDP?

Yes. Marketing is a separate purpose from fulfilling an order, so it needs its own free, specific and informed consent that can be withdrawn as easily as it was given.

When must an e-commerce platform delete inactive accounts?

The DPDP Rules, 2025 treat personal data of large e-commerce entities as no longer needed after three years of inactivity, and require notice at least 48 hours before erasure so the user can log in and keep the account.

Related DPDP guides