DPDP for E-Commerce: A Marketplace Use Case Under the DPDP Act and the 2026 E-Commerce Amendment Rules
As of September 2026, a large Indian e-commerce marketplace is facing three data-and-consent deadlines inside eight months. On 13 November 2026, the Consent Manager framework under Rule 4 of the DPDP Rules, 2025 comes into force. On 1 January 2027, the Consumer Protection (E-Commerce) (Amendment) Rules, 2026 — notified just last week, on 9 September 2026 — take effect, adding a new express-consent requirement for certain uses of consumer information, a mandatory annual dark-pattern self-audit, and tighter grievance timelines. And on 13 May 2027, the substantive DPDP obligations land: notice, consent, security safeguards, breach reporting, children's data, and — uniquely for large e-commerce platforms — a mandatory three-year inactivity erasure rule. These instruments come from two different ministries and were not drafted with each other in mind. This piece works through what each one actually requires of an online marketplace and then walks a single customer journey through all of them, so product, legal and engineering teams can build one consent and data-lifecycle layer instead of three.
The three regimes converging on e-commerce platforms
| Regime | Status (as of September 2026) | What it requires of an e-commerce platform | Effective / deadline |
|---|---|---|---|
| Consumer Protection (E-Commerce) (Amendment) Rules, 2026 (G.S.R. 789(E)) | Final — notified 9 September 2026, not yet in force | Annual dark-pattern self-audit with a prominently displayed certificate; marketplace entities barred from certain uses of collected consumer information (own-brand sales, promoting "associated" sellers) without express and affirmative consumer consent; grievance officer must acknowledge complaints within 48 hours and redress within one month; sponsored listings clearly labelled; no search-result manipulation | 1 January 2027 |
| CCPA Guidelines for Prevention and Regulation of Dark Patterns, 2023, and CCPA Advisory of 5 June 2025 | Guidelines in force since 30 November 2023; advisory issued 5 June 2025 | Prohibits 13 specified dark patterns (e.g. false urgency, basket sneaking, subscription traps); advisory asked platforms to self-audit within three months and file self-declarations | Already applicable; the annual self-audit becomes a binding rule from 1 January 2027 |
| DPDP Act, 2023 and DPDP Rules, 2025 | Enacted; Rules notified 13 November 2025, phased commencement | Itemised notice and free, specific, unambiguous consent; easy withdrawal; reasonable security safeguards; breach reporting to the Data Protection Board within 72 hours; verifiable parental consent for under-18 users and no targeted advertising at children; for e-commerce entities with 2 crore+ registered users, erasure after three years of inactivity with a 48-hour prior warning | Consent Manager framework (Rule 4): 13 November 2026. Substantive obligations: 13 May 2027 |
Two regulators (MeitY's Data Protection Board and the Department of Consumer Affairs' CCPA), three instruments, one checkout page. The rest of this piece takes each in turn, then gets to the use case.
The Consumer Protection (E-Commerce) (Amendment) Rules, 2026
This is the newest instrument and the one most compliance teams haven't yet read in full. The Department of Consumer Affairs notified G.S.R. 789(E) on 9 September 2026, amending the Consumer Protection (E-Commerce) Rules, 2020 under Section 101(2)(zg) of the Consumer Protection Act, 2019. It comes into force on 1 January 2027 — a much shorter runway than DPDP's.
The new consent requirement for marketplace data
A new sub-rule (6) in Rule 5 restricts how a marketplace e-commerce entity may use information it collects. It cannot use that information for the sale of goods bearing a brand or name common with the marketplace's own, or to promote or advertise a seller as being associated with the marketplace, without the express and affirmative consent of the consumers the information pertains to. For any marketplace running private labels or "platform-assured" seller programmes, this is a consumer-protection consent obligation sitting alongside — not replacing — DPDP's consent obligation. It builds on an existing requirement in Rule 4(9) of the 2020 Rules that consent to a purchase be recorded only through explicit, affirmative action, never through pre-ticked boxes.
The annual dark-pattern self-audit
The amendment converts what was an advisory into a rule: every e-commerce entity must comply with the Guidelines for Prevention and Regulation of Dark Patterns, 2023, conduct a yearly self-audit to confirm its platform is free of dark patterns, and prominently display a certificate to that effect. Several dark patterns the CCPA targets — pre-ticked consent, "confirm-shaming" on opt-outs, cancellation flows harder than sign-up flows — are also consent-validity problems under Section 6 of the DPDP Act. A single audit can and should cover both.
Grievance timelines and other changes
The grievance officer must now acknowledge a consumer complaint within 48 hours, give the complainant a copy of the complaint as recorded, and redress it within one month. The amendment also requires sponsored listings to be distinctly identified, prohibits manipulating search results against the user's query, requires "prior price" (the lowest price in the preceding 30 days) to be shown alongside any announced price reduction, and bars marketplaces from charging bundled fees for unrelated services, with a carve-out for loyalty and membership programmes.
The CCPA dark patterns framework already in force
The Guidelines for Prevention and Regulation of Dark Patterns, 2023 were notified on 30 November 2023 and identify 13 prohibited practices. On 5 June 2025 the CCPA issued an advisory asking all e-commerce platforms to self-audit within three months and encouraging self-declarations; by November 2025 the government reported 26 platforms had filed, and media reports indicate the last major marketplace filed in February 2026 after an extension. Until 1 January 2027, the self-audit is advisory in nature; from that date, under the amended E-Commerce Rules, it is an annual legal requirement with a public-facing certificate.
DPDP Act obligations that land hardest on e-commerce
Every e-commerce business that decides why and how customer data is processed is a Data Fiduciary under the DPDP Act. Most of the Act applies to it the same way it applies to a bank or a hospital. Four provisions, however, bite differently on online retail.
Consent at checkout versus consent for marketing
Under Section 6, consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the personal data necessary for the specified purpose. Rule 3 requires the accompanying notice to itemise the personal data and the specified purpose, and to give a communication link for withdrawing consent and exercising rights. Section 6(4) requires withdrawal to be as easy as giving consent. Separately, Section 7(a) treats processing as a "legitimate use" where a person voluntarily provides data for a specified purpose and hasn't indicated she objects. In practice, that is the legal footing for using a delivery address to deliver an order — but not for using it for retargeting, lookalike audiences, or sharing with a brand partner. Those need separate, purpose-specific consent.
The three-year inactivity erasure rule — specific to large platforms
Rule 8(1) read with the Third Schedule applies to only three classes of Data Fiduciary, and an e-commerce entity with at least 2 crore registered users in India is one of them. For such a platform, personal data must be erased once the user has neither approached the platform for the specified purpose nor exercised her rights for three years, measured from her last interaction or the commencement of the Rules, whichever is later — so the clock for already-dormant accounts effectively starts at commencement, not at their last login years ago. The Schedule excepts data needed to let the user access her account and any stored virtual token usable for money, goods or services (think wallet balances and gift cards), so this is purpose-level erasure, not wholesale account deletion. Retention required by another law — GST invoice records, for example — is carved out.
Rule 8(2) then requires the platform to inform the user at least 48 hours before the erasure period completes that her data will be erased unless she logs in, initiates contact, or exercises her rights. Because the warning is tied to each individual's own erasure date, it cannot be satisfied with a single annual batch email. Separately, Rule 8(3) requires every Data Fiduciary to keep personal data, traffic data and processing logs for at least one year from the date of processing — even if the user deletes her account — so the retention schedule has both a floor and a ceiling.
Children's data
The DPDP Act defines a "child" as anyone under 18. Section 9 and Rule 10 require verifiable consent of a parent before processing any child's personal data, with due diligence that the person identifying as the parent is an adult, by reference to reliable identity and age details the platform already holds or that are voluntarily provided, including through a virtual token from an authorised entity. Section 9(3) separately prohibits tracking or behavioural monitoring of children and targeted advertising directed at children. For fashion, gaming-accessory, stationery and electronics marketplaces with meaningful teenage traffic, the recommendation engine is the exposure point, not just the sign-up form.
Breach reporting and processors
Rule 7 requires a Data Fiduciary, on becoming aware of a personal data breach, to inform affected users without delay and to report to the Data Protection Board of India — an initial description without delay, and a detailed report within 72 hours (or such longer period as the Board allows on written request). There is no materiality threshold in the Rules. Under Section 8(2), the platform remains responsible for processing done on its behalf by Data Processors — logistics partners, payment aggregators, customer-support BPOs, analytics SDKs — and must engage them under a valid contract.
Is a large marketplace a Significant Data Fiduciary?
Not yet — no entity has been formally notified as a Significant Data Fiduciary, and Section 10 obligations do not commence before 13 May 2027. MeitY discussed with industry in January 2026 a proposal to compress timelines and fast-track SDF notification, but that proposal has not been gazetted as of this writing, so it should be treated as a possibility to plan for rather than a current requirement.
The actual use case: one customer journey, three rulebooks
Consider an illustrative marketplace — call it "ShopKart" — with 2.6 crore registered users, a private-label apparel brand, a seller "Assured" badge, a wallet, and a quick-commerce arm. Here is one customer, Priya, moving through the platform in mid-2027, and what each regime requires at each step.
Sign-up. Priya registers with her mobile number. DPDP requires an itemised Rule 3 notice and separate, unticked consent toggles for each non-essential purpose (personalised recommendations, marketing messages, sharing with brand partners). The E-Commerce Rules and dark-patterns guidelines require that none of these toggles be pre-ticked and that declining isn't framed with confirm-shaming copy. One consent screen, built once, satisfies both — if the consent record captures exactly which version of the notice she saw and which toggles she chose.
Checkout. Her delivery address and phone number are processed to fulfil the order. That's a Section 7(a) legitimate use and needs no separate consent — but it doesn't extend to feeding the address into a retargeting audience. The consent layer should tag data at collection with the purposes it may flow to, so downstream systems can enforce the difference.
Private-label promotion. ShopKart's merchandising team wants to use Priya's browsing history to push its own apparel brand. From 1 January 2027, Rule 5(6) of the amended E-Commerce Rules requires express and affirmative consent for this use; under DPDP, this is also a distinct purpose needing its own consent. The practical build is a single "promotion of ShopKart's own brands and Assured sellers" purpose in the consent manager, with one consent artifact that evidences compliance for both regulators.
Withdrawal and grievance. Priya later withdraws marketing consent and complains that she's still getting messages. DPDP requires withdrawal to be as easy as giving consent and propagation to processors; the E-Commerce Rules require her complaint to be acknowledged within 48 hours and redressed within a month. A single grievance desk should run to the stricter of the two clocks, with the consent withdrawal event automatically pushed to the SMS vendor rather than waiting for a ticket.
Her teenage cousin. A 16-year-old browses sneakers on a shared family device. If ShopKart knows or should reasonably infer the user is under 18, it needs verifiable parental consent and must switch off behavioural tracking and targeted ads for that profile. Age signals should flow into the recommendation engine, not stop at the account form.
Dormancy. Priya stops using ShopKart. Three years after her last interaction, Rule 8 requires erasure of her personal data for the Third Schedule purposes — except what's needed to keep her account accessible and her ₹340 wallet balance usable, and what GST law requires the platform to retain. At least 48 hours before that date, she must be told her data will be erased unless she logs in. This is a per-user scheduled job driven by a reliable "last approach" timestamp, not a quarterly cleanup script.
Breach. A logistics partner's API leaks delivery addresses. ShopKart, not the partner, owns the DPDP obligation: notify affected users without delay and file a detailed report with the Data Protection Board within 72 hours. Processor contracts signed in 2026 should already require the partner to report incidents to ShopKart within hours, not days.
Built in sequence — a dark-pattern audit in December 2026, a private-label consent patch in January 2027, a DPDP notice-and-retention project in spring 2027 — this becomes three overlapping workstreams touching the same screens and the same data stores. Built once, around a purpose-tagged consent record, a per-user retention clock and a unified grievance desk, it becomes one platform capability that can evidence compliance to the CCPA and the Data Protection Board from the same audit trail.
What's at stake if this goes wrong
On the consumer-protection side, the CCPA has powers under the Consumer Protection Act, 2019 to investigate unfair trade practices, order discontinuation and impose penalties (outside this post's scope). On the DPDP side, once the substantive provisions are in force, the Act's Schedule sets penalty ceilings of up to ₹250 crore for failing to take reasonable security safeguards to prevent a breach under Section 8(5), up to ₹200 crore for failing to notify the Board and affected users of a breach under Section 8(6), up to ₹200 crore for breaching the children's-data obligations under Section 9, and up to ₹50 crore for breaches of other provisions, including consent and retention. These are ceilings the Data Protection Board of India sets case-by-case, not fixed fines, but for a platform processing crores of customer records they define the scale regulators are working with.
Frequently Asked Questions
Does the DPDP Act's three-year erasure rule apply to every e-commerce company?
No — Rule 8(1) and the Third Schedule of the DPDP Rules, 2025 apply the three-year inactivity erasure period only to e-commerce entities with at least 2 crore registered users in India (along with large online gaming and social media intermediaries). Smaller platforms must still erase data once its purpose is served, under Section 8(7), but without a fixed deemed date.
When do the Consumer Protection (E-Commerce) (Amendment) Rules, 2026 come into force?
On 1 January 2027. They were notified by the Department of Consumer Affairs as G.S.R. 789(E) on 9 September 2026.
Do e-commerce platforms need consent to use customer data to promote their own private-label brands?
From 1 January 2027, a marketplace e-commerce entity needs express and affirmative consumer consent before using collected information to sell goods sharing its brand or name, or to promote sellers as associated with it, under the new Rule 5(6) of the amended E-Commerce Rules. Under the DPDP Act, such marketing is also a separate purpose requiring its own specific consent.
Can an e-commerce site show targeted ads to users under 18 under the DPDP Act?
No — Section 9(3) of the DPDP Act prohibits tracking, behavioural monitoring of, and targeted advertising directed at children, defined as anyone under 18, and Rule 10 requires verifiable parental consent before processing a child's personal data. These obligations commence on 13 May 2027.
How quickly must an e-commerce company report a data breach under the DPDP Rules?
Under Rule 7 of the DPDP Rules, 2025, it must inform affected users and the Data Protection Board of India without delay, and file a detailed report with the Board within 72 hours of becoming aware of the breach, unless the Board allows a longer period on written request.
Related Articles & Internal Resources
- IndiaConsent's DPDP Compliance Guide for the E-Commerce Sector
- DPDP Consent Architecture & Implementation in Core Banking
- DPDP in Healthcare: Patient Consent & Data Sharing
- How to Implement Consent Management Under the DPDP Act 2023
- DPDP Compliance Checklist for Enterprises: 7 Critical Steps
Primary Sources Cited
- Digital Personal Data Protection Act, 2023 — Full Text (MeitY Official PDF)
- Digital Personal Data Protection Rules, 2025 — Official Gazette Notification, G.S.R. 846(E)
- Consumer Protection (E-Commerce) (Amendment) Rules, 2026 — Official Gazette Notification, G.S.R. 789(E)
- PIB — CCPA Self-Audit Declarations and Dark Patterns Guidelines, 2023
