For online stores, D2C brands and marketplaces
DPDP compliance for e-commerce and D2C brands
Your store runs on customer data: checkout, delivery, ad pixels, abandoned-cart WhatsApps and loyalty emails. The DPDP Act wants a clear choice for each. ConsentKit adds notices and consent to your storefront and passes each customer’s choices to your ads, CRM and messaging tools.
- Marketing and pixels
- Need consent
- Inactive users on large platforms
- Delete after 3 years
- Full compliance
- 13 May 2027
Kaveri Organics asks for your consent
We need your details to deliver your order. The rest is up to you.
Where the DPDP Act touches your store
Every step from the first ad click to the tenth reorder involves customer data. Pick a stage to see which uses need consent.
What changes for your store on 13 May 2027
Most D2C stacks are a platform plus a dozen apps. Each app that touches customer data is part of your compliance.
Ad pixels and tracking need consentSections 5 and 6
Sending browsing and purchase data to ad platforms is a separate purpose from running the store.
A consent banner that controls when pixels and tags load, with a log of every choice.
Marketing needs a free, unticked choiceSection 6
Consent must be specific and an affirmative action. Pre-ticked boxes and “by continuing you agree” do not count.
Per-purpose choices at sign-up and checkout, synced to your CRM and WhatsApp tools.
Withdrawal must reach every toolSection 6(4)
When a customer unsubscribes, your email, SMS, WhatsApp and ad audiences all have to stop.
Webhooks and integrations that push withdrawals to every connected app.
Large platforms must delete inactive usersRule 8 and Third Schedule
E-commerce entities with at least two crore registered users in India must erase data after three years of inactivity, with 48 hours’ notice first.
An inactivity scheduler with automatic notices and a deletion log.
Customers can ask for their dataSections 11 to 14
Customers can request access, correction and erasure, and raise grievances you must answer in time.
A request page in the account area with identity checks and deadlines.
Apps and agencies are your processorsSection 8
Your store platform, apps, courier, payment gateway and marketing agency all process customer data for you.
A vendor register and processor contract checklist.
A plan around your sale calendar
Avoid changing checkout in the festive season. Do the heavy work in the quiet months after it.
Audit apps and pixels
List every app, tag and integration that receives customer data. Change nothing before the festive sales.
Ship the consent banner
Put consent controls on pixels and marketing forms after the festive peak.
Sync choices everywhere
Connect consent to CRM, email, WhatsApp and ad audiences. Clean old lists.
Rights and retention
Add the data-request page and set inactivity deletion rules.
For every kind of online store
Integrations for the platforms you already use.
Shopify and WooCommerce stores
App and plugin install, no developer needed.
Custom-built stores
JavaScript snippet, REST API and webhooks.
Marketplaces
Buyers and sellers, both sides of the data.
Subscription brands
Recurring payments and renewal messages.
Quick commerce
Location data and fast delivery partners.
Omnichannel retailers
Store POS and online data in one consent log.
DPDP compliance for e-commerce brands near you
Local guidance and onboarding in these cities, with support from our team in Kolkata.
Related sectors
Questions e-commerce teams are asking
For the full picture, read our DPDP Act guide or compliance checklist.
Do we need consent for Meta and Google pixels?
Sending customers’ browsing and purchase data to ad platforms is a purpose beyond running the store, so it needs consent. Load pixels only after a customer agrees.
Can we send abandoned-cart messages?
Treat them as marketing. Send them only to customers who agreed to promotional messages, and include an easy opt-out.
Do we have to delete inactive customers?
E-commerce entities with at least two crore registered users in India must erase personal data after three years of inactivity, with 48 hours’ notice. Smaller stores must still delete data once its purpose is over.
Is our store platform responsible for compliance?
No. You are the data fiduciary for your customers. Your platform and apps are processors. You need suitable contracts with each.
Does this apply to customers outside India?
The Act covers personal data processed in India, and data of people in India processed abroad in connection with offering them goods or services.
Get your store ready before May 2027
The readiness check takes about ten minutes and gives you a gap report built for online stores.