DPDP Audits

DPDP Compliance for E-commerce and D2C Brands

DPDP Act 2023 obligations for e-commerce marketplaces and D2C brands: consent for marketing, cookies and trackers, inactive-account erasure and third-party data sharing.

By Ram Krishan Dudeja, CISA CAIIB · Last reviewed 25 September 2026

E-commerce marketplaces and D2C brands collect personal data at every step: sign-up, browsing, checkout, delivery, returns and reviews. Much of it then flows to payment gateways, logistics partners, ad platforms and analytics tools. Under the Digital Personal Data Protection Act 2023, the brand remains the Data Fiduciary for all of it.

How DPDP applies to e-commerce

Gaps commonly found in e-commerce

Priorities before May 2027

  1. Separate order-fulfilment consent from marketing and personalisation consent.
  2. Audit every tag, pixel and SDK on the site and app, and what data each sends.
  3. Make withdrawal work across all channels, not just email.
  4. Define retention periods and automate erasure for inactive accounts.
  5. Add processor clauses to logistics, payments, support and marketing vendor contracts.

See DPDP Rules 2025 explained for the timeline, and the DPDP audit checklist for a full self-assessment.

Need an independent DPDP audit?

67 controls, auditor-signed findings, and a remediation roadmap you can act on.

Book a Free Consultation

Related guides

This guide is general information, not legal advice. Refer to the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 as notified for the authoritative text.