E-commerce DPDP compliance
tags, dark patterns and three-year erasure.
Online retail carries more third-party tags than any other sector, sells under consumer protection rules that already ban pre-ticked consent, and faces a dark patterns code that reaches the cookie banner. The DPDP Act adds the consent record and, for the largest platforms, a hard erasure clock.
Which laws apply to e-commerce in India?
Online retailers answer to the DPDP Act for personal data and to the Consumer Protection Act 2019 for how they sell, through the Consumer Protection (E-Commerce) Rules, 2020 and the Central Consumer Protection Authority's 2023 dark patterns guidelines. Card payments add RBI's rule that merchants must not store card credentials.
| Law or rule | What it governs | Notes |
|---|---|---|
| DPDP Act 2023 and Rules 2025 | Notice, consent, purpose, erasure, rights, breach reporting | Third Schedule erasure clock for platforms with two crore or more users |
| Consumer Protection (E-Commerce) Rules, 2020 | Disclosures, grievance officer, explicit purchase consent, marketplace duties | G.S.R. 462(E), in force 23 July 2020 |
| Dark patterns guidelines, 2023 | Thirteen specified deceptive design practices | Issued by the CCPA on 30 November 2023 |
| RBI card-on-file rules | Card credentials not stored by merchants | Tokenisation; restated in the 2025 Payment Aggregator Directions |
| TRAI TCCCPR | Commercial SMS and calls: DLT registration, opt-out | See the telecom page |
The obligation e-commerce gets wrong: tags that fire before the banner
Most Indian D2C and marketplace sites load Meta Pixel, Google Ads, GA4 and affiliate scripts on page load, before the visitor has answered the banner. A banner that appears after the tags have fired does not create consent. It records, with a timestamp, that you knew consent was needed and processed anyway.
The mechanism matters more than the banner design. Tag managers are usually configured with triggers on "All pages", and consent integrations are added later as a condition that some tags respect and others do not. Server-side tagging moves the problem rather than solving it: the browser no longer calls Meta, but your server does, with the same personal data, still before consent. The only reliable test is to load the site in a clean browser, record what leaves before any click, then accept and record again. The free two-pass scan does exactly that.
The second exposure is retention. Purchase history is kept legitimately for returns, warranty and tax. Browsing behaviour attached to an identified customer usually has no period at all, and the Third Schedule now supplies one for the largest platforms: erase three years after the person last engaged, with 48 hours' warning.
Where the dark patterns guidelines meet the consent banner
The CCPA's 2023 guidelines list thirteen dark patterns, including confirm shaming, forced action, interface interference, nagging and trick questions. A consent banner that hides Reject, shames the refusal or returns until the visitor agrees is at risk under both the guidelines and the DPDP Act's consent standard.
The thirteen are false urgency, basket sneaking, confirm shaming, forced action, subscription trap, interface interference, bait and switch, drip pricing, disguised advertisement, nagging, trick question, SaaS billing and rogue malware. Several map directly onto consent design. Interface interference is the bright Accept beside a grey text link. Confirm shaming is "No thanks, I don't like saving money" on the newsletter pop-up. Forced action is requiring marketing consent to check out. Nagging is the banner that reappears on each page. Basket sneaking is the pre-added donation or insurance, which Rule 4(9) of the E-Commerce Rules already forbids by requiring explicit, affirmative consent to every purchase and banning pre-ticked boxes.
In June 2025 the CCPA advised e-commerce platforms to self-audit for dark patterns within three months and file self-declarations. Enforcement is by the CCPA under the Consumer Protection Act; the DPDP consequence is separate. A consent obtained through a dark pattern is unlikely to be free, specific, informed and unambiguous under section 6(1), which means the processing that followed had no valid basis.
Marketplaces, sellers and who owes the notice
On a marketplace, the operator and each seller can both be Data Fiduciaries: the operator for accounts, search and advertising, the seller for fulfilment and after-sales. Each owes a notice for its own purposes, and the customer's consent to one is not consent to the other.
The E-Commerce Rules already require marketplaces to show seller details and run a grievance mechanism with a 48-hour acknowledgement and one-month resolution. The DPDP Act adds a data grievance route, and Rule 14 requires the response period to be published and capped at ninety days. Sharing buyer phone numbers with sellers for delivery is a disclosure to a Data Fiduciary or a processor, depending on the contract, and the contract should say which, and what the seller may not do with the number afterwards.
What an online retailer may keep, and for how long
Retention in e-commerce is mostly lawful and mostly undocumented. Tax law, consumer law and warranty obligations justify keeping order records. They do not justify keeping browsing histories, abandoned baskets or marketing profiles for customers who stopped buying years ago.
Order and invoice records are the easy case: GST law requires a registered business to keep its books and records for seventy-two months from the due date of the annual return, and that is retention required by law under section 8(7). Warranty and return windows justify keeping the delivery address and product details for as long as a claim can be made. After that, the justification runs out. For platforms with two crore or more registered users in India, the Third Schedule supplies the outer limit for everything the law does not require: three years after the customer last engaged, then erasure with 48 hours' warning. For smaller retailers, the period is theirs to set, but it has to exist, be stated and be applied. The DPDP retention and erasure guide covers how the Third Schedule counts engagement.
E-commerce control checklist
For online retailers, D2C brands and marketplaces.
| Control | Why | Evidence to hold |
|---|---|---|
| No advertising or analytics tags fire before a choice | DPDP s.6 | Two-pass scan, repeated after each tag change |
| Accept and Reject equally prominent; no re-prompting | Dark patterns guidelines; DPDP s.6(1) | Banner screenshots per release |
| No pre-ticked boxes for purchases, add-ons or marketing | E-Commerce Rules r.4(9) | Checkout review |
| Separate purposes: fulfilment, cart reminders, marketing, personalisation | DPDP s.6(1) | Consent record per purpose |
| Inactivity erasure with 48-hour warning, if two crore or more users | Rule 8; Third Schedule | Scheduled job and warning logs |
| No card credentials stored outside the tokenisation flow | RBI card-on-file rules | PCI scope documentation |
| Grievance officer for consumer and data complaints, with published timelines | E-Commerce Rules; DPDP Rule 14 | Contact published; ticket timestamps |
Where to go next
Start with the scan, then generate a cookie policy from its results. For the law underneath all of it, read the DPDP Act and Rules 2025 guide. To see what your own website does before a visitor answers the banner, run the free two-pass cookie scan. The consent platform holds versioned notices in 22 languages, a hash-chained consent ledger, withdrawal relayed to each processor, and rights requests and breaches on their statutory clocks. The industries overview compares all eight sectors.
The things people ask us
Can an e-commerce site use pre-ticked consent boxes in India?
No. Rule 4(9) of the Consumer Protection (E-Commerce) Rules, 2020 says consent to a purchase must be recorded through an explicit and affirmative action, and not automatically, including by pre-ticked checkboxes. The DPDP Act separately requires consent to be a clear affirmative action, so a pre-ticked marketing box fails both.
Is a cookie banner a dark pattern?
It can be. The CCPA's 2023 dark patterns guidelines list interface interference, confirm shaming, forced action and nagging among thirteen specified patterns. A banner with a bright Accept button, a grey hidden Reject, or a pop-up that returns on every page until the visitor agrees risks being both an unfair trade practice and invalid consent under the DPDP Act.
How long can an e-commerce company keep inactive customers' data?
Large e-commerce entities with two crore or more registered users in India must erase personal data three years after the person last engaged, with 48 hours' notice first, under Rule 8 and the Third Schedule, unless another law requires retention. Tax and warranty records may be kept for their own periods.
Do marketplaces need a grievance officer?
Yes, under two laws. The E-Commerce Rules require a grievance officer who acknowledges a consumer complaint within 48 hours and resolves it within a month. The DPDP Act requires a way to raise data protection grievances, with the response period published and not more than ninety days under Rule 14.
Is cart-abandonment email allowed under the DPDP Act?
Only with a basis for it. Consent to buy, or the data a customer voluntarily gave to complete an order, covers fulfilling that order. Chasing an unfinished basket is a different purpose. It needs its own consent, or a clear notice at the point the email address was captured that it would be used this way.
See which tags fire before anyone clicks.
The scan loads your store twice, before and after consent, and lists every request that left the browser. The platform then holds those tags back until the visitor chooses.