The DPDP Act is live. Fines reach ₹250 Cr, and every day matters.Run a free check
D2C & E-COMMERCE

Your growth stack was built before anyone had to ask.

Meta pixel, Google tags, a CDP, WhatsApp broadcasts, SMS blasts, abandoned-cart flows and a customer list assembled over years. Every one of those is processing, and the DPDP Act asks a question none of them were built to answer.

Built for: Direct-to-consumer brands, marketplaces, online retailers and subscription commerce.

WHAT MAKES THIS SECTOR DIFFERENT

The pressure points, specifically

01

Trackers fire before anyone agrees

On most Indian D2C sites the advertising and analytics tags load on first paint, well before a banner appears and regardless of what it is clicked. That is processing without a lawful basis, and it is trivially observable from outside.

02

The list you bought is the list you cannot use

Acquired lists, scraped contacts and consents inherited through an acquisition carry no provable lawful basis. They are also the cheapest revenue in the business, which is what makes this the hardest conversation in the room.

03

WhatsApp and SMS are consent-hungry channels

A promotional WhatsApp message or SMS to a customer needs a consent for marketing on that channel, held per purpose. Platform-level opt-ins are not the same thing as a DPDP consent you can produce.

04

Rights requests arrive at scale

A consumer brand with millions of customers will not handle access and erasure requests by email. The volume makes a workflow with clocks and an audit trail a practical necessity rather than a compliance nicety.

WHAT SAMMATI DOES

The parts that matter here

  • A banner that actually gates the tags

    A consent banner for the storefront plus a scanner that crawls your own site and reports which trackers fire before consent. You find out what you are running the way a regulator would, and the fix is verifiable.

  • Purpose-level consent, not one blanket tick

    Marketing, personalisation, analytics and sharing with delivery or payment partners are separate purposes with their own lawful bases. That granularity is what makes a withdrawal meaningful and a consent defensible.

  • Re-consent the customers you already have

    Import your existing customer base, run a re-consent campaign over email and SMS, and end up with a smaller list you can actually stand behind. The ones who re-consent are worth more than the ones who never asked to be there.

  • Rights at consumer scale

    Self-service access, correction and erasure with the statutory clock tracked per request, automated fulfilment where the data supports it, and a grievance route that satisfies the Act's requirement rather than an inbox nobody reads.

  • Consent from web, app and server

    A server-side API for checkout and account flows, a mobile SDK for the app, and bulk ingestion for historic records, so the storefront and the app write to one ledger instead of two half-truths.

QUESTIONS WE GET ASKED

D2C & e-commerce and the DPDP Act

General information about the DPDP Act, 2023, not legal advice. For a position specific to your organisation, talk to us or read the deep dive: DPDP Compliance for D2C and E-commerce Brands in India.

Where to start

Find out where you actually stand.

The free self-assessment takes a few minutes and gives you a written position on your own setup, not a generic checklist.