The short answer: E-commerce entities are one of only three classes the DPDP Rules name outright. An e-commerce entity with not less than two crore registered users in India must erase personal data after three years of a Data Principal's inactivity, give forty-eight hours' notice before doing so, and preserve account-access and virtual-token data through the clock.

DPDP for D2C & E-commerce

🛒 Sector: D2C & E-commerce⚖️ Key provisions: Third Schedule item 1 (via Rule 8(1)) · Rule 8(2) · Rule 8(3) · s. 6📅 In force: 13 May 2027
On this page
  1. Why e-commerce doesn't have to reason by analogy
  2. Are you an "e-commerce entity"? The definition excludes more than you'd expect
  3. What the two crore threshold triggers
  4. The retention floor underneath all of it
  5. The consent problem specific to this sector
  6. Cookie and tracker consent
  7. What to build, in order
  8. Where Consiva fits
  9. Frequently asked questions

Why e-commerce doesn't have to reason by analogy

Most sectors read a general statute and work out what it means for them. E-commerce is one of three classes written into the Third Schedule to the Rules by name, alongside online gaming and social media intermediaries — each with its own user-count threshold and erasure clock.

The Act also uses online marketplaces in several of its own illustrations, which makes the drafters' intent unusually visible for this sector.

Are you an "e-commerce entity"? The definition excludes more than you'd expect

The Third Schedule's note defines the term by reference to the Consumer Protection Act, 2019: any person who owns, operates or manages a digital facility or platform for e-commerce. And then it carves out something significant:

it does not include a seller offering her goods or services for sale on a marketplace e-commerce entity as defined in that Act.

So the classification splits:

You areThird Schedule item 1?
A marketplace platform (you operate the facility others sell on)Yes, at ≥ 2 crore registered users
A D2C brand selling through your own storefrontYes, if you operate the platform and cross the threshold
A brand selling only as a seller on someone else's marketplaceNo — expressly excluded
A brand doing bothYes for your own storefront; excluded for your marketplace-seller activity

That last row is the common case for Indian D2C, and it means the same company can be inside the Schedule for one channel and outside it for another. The general obligations in Chapter II apply regardless — the Third Schedule adds a time-bound erasure duty on top.

Also note the Schedule's definition of "user" for an e-commerce entity: any person who accesses or avails any computer resource of the entity. That is broader than "customer who has purchased." Registered users who never bought anything still count towards two crore.

What the two crore threshold triggers

Crossing it brings you within Rule 8(1), and three obligations follow.

The three-year clock

You must erase personal data if the Data Principal neither approaches you for performance of the specified purpose nor exercises her rights for three years — unless retention is necessary for compliance with any law.

The clock runs from the later of: the date she last approached you, or the commencement of the Rules. For a dormant customer who last ordered in 2024, the clock effectively starts at commencement rather than at that order.

The two carve-outs that survive

The erasure duty covers all purposes except:

In practice: wallet balances, store credit, gift card value and loyalty points that function as value do not disappear at three years, and neither does the account shell needed to reach them. This is a consumer-protective carve-out and it is narrower than "keep the whole profile" — it covers what is needed for access, not the full order history.

The 48-hour notice

Rule 8(2) requires you to inform the Data Principal at least forty-eight hours before the period completes that her data will be erased, unless she logs in, otherwise initiates contact for the specified purpose, or exercises her rights.

This is the requirement that surprises engineering teams, because it is not a policy — it is a scheduled job running per customer against a per-customer clock, with a notification, a re-engagement listener that resets the clock, and an audit record. At two crore users, a meaningful number of these fire every day.

The retention floor underneath all of it

Rule 8(3) separately requires retention of personal data, associated traffic data and processing logs for a minimum of one year from the date of processing.

The Rules illustrate it with e-commerce specifically: a customer buys an e-book; once delivery completes the specified purpose is served; the platform must still retain order confirmation, payment and delivery records and logs for at least a year even if the customer deletes her account.

So "delete my account" cannot mean "delete my data," and a deletion flow that purges everything is non-compliant in the other direction. → Retention & Erasure

D2C and e-commerce consent architecture fails in a predictable place: the checkout-to-marketing slide.

A customer provides an address to receive an order. Under section 7, personal data voluntarily provided for a specified purpose, where the individual has not indicated objection, may be processed for that purpose. Delivery is that purpose. Marketing is not.

Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, limited to the personal data necessary for the specified purpose. A single tickbox at checkout covering delivery, marketing, analytics and partner sharing is not specific consent, and the part that infringes is invalid to that extent.

Three consequences for the build:

Cookie and tracker consent

D2C storefronts typically run the heaviest tag stack of any sector — analytics, remarketing pixels, affiliate tracking, session recording, A/B testing, chat widgets. Where these process personal data, the Act's consent requirements engage from 13 May 2027.

The failure mode is well known and worth checking today: tags that fire before the consent signal is read. A correctly configured banner sitting on top of tags that load on first paint is a compliance failure with a compliant-looking interface. Verify in a clean browser profile with the network tab open, not by looking at the banner. → Cookie Consent

What to build, in order

  1. Count your registered users on the Schedule's definition — anyone who accesses or avails your computer resource, not just purchasers. Know whether you are above two crore, and how close you are.
  2. Determine your channel classification where you sell both on your own storefront and as a marketplace seller.
  3. Unbundle checkout consent from marketing consent, and fix withdrawal parity.
  4. Fix tag firing order before consent.
  5. Build the retention register — one year floor, plus tax and company law periods, plus the Third Schedule clock.
  6. Build the Rule 8(2) notification job with clock reset on re-engagement.
  7. Start the re-consent programme on your legacy list. It takes longest.

Where Consiva fits

Consiva runs purpose-level consent capture at checkout and across your storefront, cookie and tracker consent with pre-consent firing detection, the Rule 8 clocks with the 48-hour notification, and the retention conflict register. The user-count determination and your channel classification are yours to make.

Start free — 1 domain, 1,000 cookie consents a month, no card. Pro (₹5,999/month plus applicable taxes, or ₹60,000/year plus applicable taxes) adds automated scheduled scanning, 22 languages, automated DSR workflows and the breach tracker. Multi-storefront brands can add domains via the Domain Pack. → Pricing

Frequently asked questions

Does the DPDP Act apply to e-commerce companies?

Yes, and e-commerce entities are additionally named in the Third Schedule to the Rules. Those with not less than two crore registered users in India carry a time-bound erasure duty after three years of customer inactivity, on top of the general Chapter II obligations.

What is the two crore user threshold under the DPDP Rules?

It is the point at which an e-commerce entity or social media intermediary falls within the Third Schedule erasure duty. For online gaming intermediaries the threshold is fifty lakh. "User" means any person who accesses or avails the entity's computer resource, not only purchasers.

Do marketplace sellers fall under the Third Schedule?

No. The Schedule's definition expressly excludes a seller offering goods or services on a marketplace e-commerce entity. A brand that also runs its own storefront is within scope for that storefront if it crosses the threshold.

Can we email customers who bought from us without separate marketing consent?

Data voluntarily provided for a purchase is provided for that purpose. Marketing is a different purpose requiring its own specific consent, unbundled from the transaction and not a condition of it.

Does deleting a customer account delete their order history?

Not for at least a year. Rule 8(3) requires retention of the personal data, traffic data and processing logs for a minimum of one year from processing, and the Rules illustrate this with a customer who deletes her account after an e-book purchase.

Do wallet balances get erased after three years of inactivity?

No. The Third Schedule carves out access to the user account and to a virtual token stored on the platform that can be used to obtain money, goods or services. The carve-out covers what is needed for that access, not the entire customer profile.

Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023, ss. 6, 7, 8(7), 12; DPDP Rules, 2025, Rule 8 and the Third Schedule including its definitional note. Reference material about the law, not legal advice — see /disclaimer.

DPDP compliance built for D2C & E-commerce

Consiva.ai covers every obligation above with pre-configured workflows, templates, and automated jobs — purpose-built for India's data protection law.

Start Free — No Credit Card →