Most sectors read a general statute and work out what it means for them. E-commerce is one of three classes written into the Third Schedule to the Rules by name, alongside online gaming and social media intermediaries — each with its own user-count threshold and erasure clock.
The Act also uses online marketplaces in several of its own illustrations, which makes the drafters' intent unusually visible for this sector.
The Third Schedule's note defines the term by reference to the Consumer Protection Act, 2019: any person who owns, operates or manages a digital facility or platform for e-commerce. And then it carves out something significant:
it does not include a seller offering her goods or services for sale on a marketplace e-commerce entity as defined in that Act.
So the classification splits:
| You are | Third Schedule item 1? |
|---|---|
| A marketplace platform (you operate the facility others sell on) | Yes, at ≥ 2 crore registered users |
| A D2C brand selling through your own storefront | Yes, if you operate the platform and cross the threshold |
| A brand selling only as a seller on someone else's marketplace | No — expressly excluded |
| A brand doing both | Yes for your own storefront; excluded for your marketplace-seller activity |
That last row is the common case for Indian D2C, and it means the same company can be inside the Schedule for one channel and outside it for another. The general obligations in Chapter II apply regardless — the Third Schedule adds a time-bound erasure duty on top.
Also note the Schedule's definition of "user" for an e-commerce entity: any person who accesses or avails any computer resource of the entity. That is broader than "customer who has purchased." Registered users who never bought anything still count towards two crore.
Crossing it brings you within Rule 8(1), and three obligations follow.
You must erase personal data if the Data Principal neither approaches you for performance of the specified purpose nor exercises her rights for three years — unless retention is necessary for compliance with any law.
The clock runs from the later of: the date she last approached you, or the commencement of the Rules. For a dormant customer who last ordered in 2024, the clock effectively starts at commencement rather than at that order.
The erasure duty covers all purposes except:
In practice: wallet balances, store credit, gift card value and loyalty points that function as value do not disappear at three years, and neither does the account shell needed to reach them. This is a consumer-protective carve-out and it is narrower than "keep the whole profile" — it covers what is needed for access, not the full order history.
Rule 8(2) requires you to inform the Data Principal at least forty-eight hours before the period completes that her data will be erased, unless she logs in, otherwise initiates contact for the specified purpose, or exercises her rights.
This is the requirement that surprises engineering teams, because it is not a policy — it is a scheduled job running per customer against a per-customer clock, with a notification, a re-engagement listener that resets the clock, and an audit record. At two crore users, a meaningful number of these fire every day.
Rule 8(3) separately requires retention of personal data, associated traffic data and processing logs for a minimum of one year from the date of processing.
The Rules illustrate it with e-commerce specifically: a customer buys an e-book; once delivery completes the specified purpose is served; the platform must still retain order confirmation, payment and delivery records and logs for at least a year even if the customer deletes her account.
So "delete my account" cannot mean "delete my data," and a deletion flow that purges everything is non-compliant in the other direction. → Retention & Erasure
D2C and e-commerce consent architecture fails in a predictable place: the checkout-to-marketing slide.
A customer provides an address to receive an order. Under section 7, personal data voluntarily provided for a specified purpose, where the individual has not indicated objection, may be processed for that purpose. Delivery is that purpose. Marketing is not.
Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, limited to the personal data necessary for the specified purpose. A single tickbox at checkout covering delivery, marketing, analytics and partner sharing is not specific consent, and the part that infringes is invalid to that extent.
Three consequences for the build:
D2C storefronts typically run the heaviest tag stack of any sector — analytics, remarketing pixels, affiliate tracking, session recording, A/B testing, chat widgets. Where these process personal data, the Act's consent requirements engage from 13 May 2027.
The failure mode is well known and worth checking today: tags that fire before the consent signal is read. A correctly configured banner sitting on top of tags that load on first paint is a compliance failure with a compliant-looking interface. Verify in a clean browser profile with the network tab open, not by looking at the banner. → Cookie Consent
Consiva runs purpose-level consent capture at checkout and across your storefront, cookie and tracker consent with pre-consent firing detection, the Rule 8 clocks with the 48-hour notification, and the retention conflict register. The user-count determination and your channel classification are yours to make.
Start free — 1 domain, 1,000 cookie consents a month, no card. Pro (₹5,999/month plus applicable taxes, or ₹60,000/year plus applicable taxes) adds automated scheduled scanning, 22 languages, automated DSR workflows and the breach tracker. Multi-storefront brands can add domains via the Domain Pack. → Pricing
Yes, and e-commerce entities are additionally named in the Third Schedule to the Rules. Those with not less than two crore registered users in India carry a time-bound erasure duty after three years of customer inactivity, on top of the general Chapter II obligations.
It is the point at which an e-commerce entity or social media intermediary falls within the Third Schedule erasure duty. For online gaming intermediaries the threshold is fifty lakh. "User" means any person who accesses or avails the entity's computer resource, not only purchasers.
No. The Schedule's definition expressly excludes a seller offering goods or services on a marketplace e-commerce entity. A brand that also runs its own storefront is within scope for that storefront if it crosses the threshold.
Data voluntarily provided for a purchase is provided for that purpose. Marketing is a different purpose requiring its own specific consent, unbundled from the transaction and not a condition of it.
Not for at least a year. Rule 8(3) requires retention of the personal data, traffic data and processing logs for a minimum of one year from processing, and the Rules illustrate this with a customer who deletes her account after an e-book purchase.
No. The Third Schedule carves out access to the user account and to a virtual token stored on the platform that can be used to obtain money, goods or services. The carve-out covers what is needed for that access, not the entire customer profile.
Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023, ss. 6, 7, 8(7), 12; DPDP Rules, 2025, Rule 8 and the Third Schedule including its definitional note. Reference material about the law, not legal advice — see /disclaimer.
Consiva.ai covers every obligation above with pre-configured workflows, templates, and automated jobs — purpose-built for India's data protection law.
Start Free — No Credit Card →