Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

Industry guide

DPDP for Ecommerce

High volume consumer data, guest checkouts, marketing consent and platform retention timers make ecommerce one of the most directly affected sectors.

What does the DPDP framework mean for Ecommerce?

High volume consumer data, guest checkout and marketing consent make ecommerce one of the most directly exposed sectors. Notice and consent at checkout is the flow to get right first, then retention timers for dormant accounts and order data, then the breach path for order records. Guardian consent matters wherever minors buy.

How to read this page. The obligations belong to your organisation, not to a role or a sector. Everything here is practical emphasis: which official duties this audience usually leads or feeds into, with links to the official text. Finishing one function's work never makes the company compliant by itself.

Where the framework usually bites first

  • Notice and consent at checkoutRule 3, official text →

    Itemised descriptions and specified purposes must survive real checkout flows, including guest ones.

  • Retention timers for dormant usersRule 8, official text →

    The Third Schedule classes and timers and the 48 hour warning before erasure are operationally significant at ecommerce scale.

  • Order data breachesRule 7, official text →

    Payment adjacent personal data makes the without delay intimation duty a live operational risk.

Tools for this sector

Guides written for this audience