By sector · E-commerce

E-commerce DPDP compliance
tags, dark patterns and three-year erasure.

Online retail carries more third-party tags than any other sector, sells under consumer protection rules that already ban pre-ticked consent, and faces a dark patterns code that reaches the cookie banner. The DPDP Act adds the consent record and, for the largest platforms, a hard erasure clock.

E-Commerce Rules 2020Dark patterns 2023DPDP Third ScheduleRule 4(9)
01

Which laws apply to e-commerce in India?

Online retailers answer to the DPDP Act for personal data and to the Consumer Protection Act 2019 for how they sell, through the Consumer Protection (E-Commerce) Rules, 2020 and the Central Consumer Protection Authority's 2023 dark patterns guidelines. Card payments add RBI's rule that merchants must not store card credentials.

Law or ruleWhat it governsNotes
DPDP Act 2023 and Rules 2025Notice, consent, purpose, erasure, rights, breach reportingThird Schedule erasure clock for platforms with two crore or more users
Consumer Protection (E-Commerce) Rules, 2020Disclosures, grievance officer, explicit purchase consent, marketplace dutiesG.S.R. 462(E), in force 23 July 2020
Dark patterns guidelines, 2023Thirteen specified deceptive design practicesIssued by the CCPA on 30 November 2023
RBI card-on-file rulesCard credentials not stored by merchantsTokenisation; restated in the 2025 Payment Aggregator Directions
TRAI TCCCPRCommercial SMS and calls: DLT registration, opt-outSee the telecom page
02

The obligation e-commerce gets wrong: tags that fire before the banner

Most Indian D2C and marketplace sites load Meta Pixel, Google Ads, GA4 and affiliate scripts on page load, before the visitor has answered the banner. A banner that appears after the tags have fired does not create consent. It records, with a timestamp, that you knew consent was needed and processed anyway.

The mechanism matters more than the banner design. Tag managers are usually configured with triggers on "All pages", and consent integrations are added later as a condition that some tags respect and others do not. Server-side tagging moves the problem rather than solving it: the browser no longer calls Meta, but your server does, with the same personal data, still before consent. The only reliable test is to load the site in a clean browser, record what leaves before any click, then accept and record again. The free two-pass scan does exactly that.

The second exposure is retention. Purchase history is kept legitimately for returns, warranty and tax. Browsing behaviour attached to an identified customer usually has no period at all, and the Third Schedule now supplies one for the largest platforms: erase three years after the person last engaged, with 48 hours' warning.

04

Marketplaces, sellers and who owes the notice

On a marketplace, the operator and each seller can both be Data Fiduciaries: the operator for accounts, search and advertising, the seller for fulfilment and after-sales. Each owes a notice for its own purposes, and the customer's consent to one is not consent to the other.

The E-Commerce Rules already require marketplaces to show seller details and run a grievance mechanism with a 48-hour acknowledgement and one-month resolution. The DPDP Act adds a data grievance route, and Rule 14 requires the response period to be published and capped at ninety days. Sharing buyer phone numbers with sellers for delivery is a disclosure to a Data Fiduciary or a processor, depending on the contract, and the contract should say which, and what the seller may not do with the number afterwards.

05

What an online retailer may keep, and for how long

Retention in e-commerce is mostly lawful and mostly undocumented. Tax law, consumer law and warranty obligations justify keeping order records. They do not justify keeping browsing histories, abandoned baskets or marketing profiles for customers who stopped buying years ago.

Order and invoice records are the easy case: GST law requires a registered business to keep its books and records for seventy-two months from the due date of the annual return, and that is retention required by law under section 8(7). Warranty and return windows justify keeping the delivery address and product details for as long as a claim can be made. After that, the justification runs out. For platforms with two crore or more registered users in India, the Third Schedule supplies the outer limit for everything the law does not require: three years after the customer last engaged, then erasure with 48 hours' warning. For smaller retailers, the period is theirs to set, but it has to exist, be stated and be applied. The DPDP retention and erasure guide covers how the Third Schedule counts engagement.

06

E-commerce control checklist

For online retailers, D2C brands and marketplaces.

ControlWhyEvidence to hold
No advertising or analytics tags fire before a choiceDPDP s.6Two-pass scan, repeated after each tag change
Accept and Reject equally prominent; no re-promptingDark patterns guidelines; DPDP s.6(1)Banner screenshots per release
No pre-ticked boxes for purchases, add-ons or marketingE-Commerce Rules r.4(9)Checkout review
Separate purposes: fulfilment, cart reminders, marketing, personalisationDPDP s.6(1)Consent record per purpose
Inactivity erasure with 48-hour warning, if two crore or more usersRule 8; Third ScheduleScheduled job and warning logs
No card credentials stored outside the tokenisation flowRBI card-on-file rulesPCI scope documentation
Grievance officer for consumer and data complaints, with published timelinesE-Commerce Rules; DPDP Rule 14Contact published; ticket timestamps
07

Where to go next

Start with the scan, then generate a cookie policy from its results. For the law underneath all of it, read the DPDP Act and Rules 2025 guide. To see what your own website does before a visitor answers the banner, run the free two-pass cookie scan. The consent platform holds versioned notices in 22 languages, a hash-chained consent ledger, withdrawal relayed to each processor, and rights requests and breaches on their statutory clocks. The industries overview compares all eight sectors.

Questions

The things people ask us

Can an e-commerce site use pre-ticked consent boxes in India?

No. Rule 4(9) of the Consumer Protection (E-Commerce) Rules, 2020 says consent to a purchase must be recorded through an explicit and affirmative action, and not automatically, including by pre-ticked checkboxes. The DPDP Act separately requires consent to be a clear affirmative action, so a pre-ticked marketing box fails both.

Is a cookie banner a dark pattern?

It can be. The CCPA's 2023 dark patterns guidelines list interface interference, confirm shaming, forced action and nagging among thirteen specified patterns. A banner with a bright Accept button, a grey hidden Reject, or a pop-up that returns on every page until the visitor agrees risks being both an unfair trade practice and invalid consent under the DPDP Act.

How long can an e-commerce company keep inactive customers' data?

Large e-commerce entities with two crore or more registered users in India must erase personal data three years after the person last engaged, with 48 hours' notice first, under Rule 8 and the Third Schedule, unless another law requires retention. Tax and warranty records may be kept for their own periods.

Do marketplaces need a grievance officer?

Yes, under two laws. The E-Commerce Rules require a grievance officer who acknowledges a consumer complaint within 48 hours and resolves it within a month. The DPDP Act requires a way to raise data protection grievances, with the response period published and not more than ninety days under Rule 14.

Is cart-abandonment email allowed under the DPDP Act?

Only with a basis for it. Consent to buy, or the data a customer voluntarily gave to complete an order, covers fulfilling that order. Chasing an unfinished basket is a different purpose. It needs its own consent, or a clear notice at the point the email address was captured that it would be used this way.

Before the banner

See which tags fire before anyone clicks.

The scan loads your store twice, before and after consent, and lists every request that left the browser. The platform then holds those tags back until the visitor chooses.