The DPDP Rules are phasing in through 2026 and 2027. Most organisations are working towards full operational compliance by May 2027.

What this means for you

Home / Sectors / Retail and D2C

Retail and direct to consumer

Retail is the sector where the volume of personal data is highest and the controls are usually thinnest, because everything was built for growth and nothing was built for deletion.

The Act applies to every organisation that holds personal data. What reasonable looks like changes a great deal by sector, and this is what it changes to here.

The position

What makes this sector different

An online store holds customer accounts, order history, delivery addresses, phone numbers, payment references and a long trail of browsing behaviour shared with advertising platforms. A brand with a loyalty programme holds considerably more.

The specific problem in this sector is that most of the data leaves. It goes to a courier, a payment provider, a marketing platform, an advertising network and a support tool, and in a surprising number of businesses nobody has written down the full list.

Discovery

Where personal data usually sits

Drawn from engagements and from the questions that come up most often on first calls in this sector.

Retail and direct to consumer
SystemWhat it holdsWhat usually needs attention
Store platformAccounts, order history, delivery addresses, phone numbersCustomers cannot actually delete their account from the interface
Marketing stackEmail lists, WhatsApp broadcast lists, abandoned cart data, segmentsLists imported, bought or scraped with no consent record
Advertising pixelsBrowsing and purchase behaviour shared with advertising platformsTracking fires before anyone agrees to it
Logistics partnersName, address and phone passed to couriers and delivery partnersNo written data terms with the parties receiving it
PaymentsTransaction references, sometimes saved cards and UPI handlesNobody has confirmed what the gateway stores and for how long
Support and returnsComplaints, chat transcripts, call recordings, images customers sendRecordings and transcripts kept forever, with no notice given
Specific risks

What we look at first here

Deletion that is not really deletion. Most store platforms deactivate rather than delete, and the marketing platform keeps its own copy regardless.

Pixels firing before consent. Tracking usually starts on page load, which means it has already happened by the time anyone is asked.

WhatsApp broadcast lists. Built over years from orders, events and imports, with no record of who agreed to what.

The courier layer. Customer name, address and phone go to a logistics partner on every order, and the contract usually covers delivery times and nothing else.

Advertising agency access. Agencies often hold admin access to your advertising accounts and customer lists long after the campaign ended.

The engagement

Which steps carry the most weight

The full sequence is on the engagement page. In this sector, these three usually do the heavy lifting.

Priority

Discovery and mapping

We follow one order from checkout through to delivery and support, and list every system and third party it touches.

Priority

Compliance Support

Consent at the right moment rather than at page load, notices that match what the pixels actually do, and a deletion route that works end to end.

Priority

Implementation support

This sector needs developer work. We give your team or your agency a ticket level plan and review each item as it goes live.

Retail is the sector where a consent tool is most often bought first and mapped later. If you already have one, we will work with it rather than replacing it, and we will tell you plainly where it is configured around guesses.

Other sectors

Not quite your business?

Every engagement is scoped to what you actually run, so none of these pages will match you exactly.

Start here

Thirty minutes, and you will know where you stand.

Tell us what your business runs on. We will tell you which gaps matter most, whether or not you engage us.