Your growth stack was built before anyone had to ask.
Meta pixel, Google tags, a CDP, WhatsApp broadcasts, SMS blasts, abandoned-cart flows and a customer list assembled over years. Every one of those is processing, and the DPDP Act asks a question none of them were built to answer.
Built for: Direct-to-consumer brands, marketplaces, online retailers and subscription commerce.
The pressure points, specifically
Trackers fire before anyone agrees
On most Indian D2C sites the advertising and analytics tags load on first paint, well before a banner appears and regardless of what it is clicked. That is processing without a lawful basis, and it is trivially observable from outside.
The list you bought is the list you cannot use
Acquired lists, scraped contacts and consents inherited through an acquisition carry no provable lawful basis. They are also the cheapest revenue in the business, which is what makes this the hardest conversation in the room.
WhatsApp and SMS are consent-hungry channels
A promotional WhatsApp message or SMS to a customer needs a consent for marketing on that channel, held per purpose. Platform-level opt-ins are not the same thing as a DPDP consent you can produce.
Rights requests arrive at scale
A consumer brand with millions of customers will not handle access and erasure requests by email. The volume makes a workflow with clocks and an audit trail a practical necessity rather than a compliance nicety.
The parts that matter here
A banner that actually gates the tags
A consent banner for the storefront plus a scanner that crawls your own site and reports which trackers fire before consent. You find out what you are running the way a regulator would, and the fix is verifiable.
Purpose-level consent, not one blanket tick
Marketing, personalisation, analytics and sharing with delivery or payment partners are separate purposes with their own lawful bases. That granularity is what makes a withdrawal meaningful and a consent defensible.
Re-consent the customers you already have
Import your existing customer base, run a re-consent campaign over email and SMS, and end up with a smaller list you can actually stand behind. The ones who re-consent are worth more than the ones who never asked to be there.
Rights at consumer scale
Self-service access, correction and erasure with the statutory clock tracked per request, automated fulfilment where the data supports it, and a grievance route that satisfies the Act's requirement rather than an inbox nobody reads.
Consent from web, app and server
A server-side API for checkout and account flows, a mobile SDK for the app, and bulk ingestion for historic records, so the storefront and the app write to one ledger instead of two half-truths.
D2C & e-commerce and the DPDP Act
Yes. Loading an advertising or analytics tracker places and reads data on a user's device and processes their personal data, so it needs a lawful basis, and for advertising and non-essential analytics that basis is consent. In practice this means the tags must not fire until the visitor has agreed, which most Indian D2C sites do not currently implement — a banner that appears while the pixel has already loaded provides no protection.
Not safely. A consent must be freely given, specific, informed and unambiguous, and a list acquired from a third party or through an acquisition will rarely have one that names your company and your purpose. The usual path is a re-consent campaign: contact the list once on the basis you have, ask them to opt in properly, and stop mailing everyone who does not.
Yes. The DPDP Act applies to processing of digital personal data within India regardless of where the company is incorporated, and also reaches processing outside India where it relates to offering goods or services to people in India. Selling only domestically does not narrow the obligation.
Any message whose purpose is marketing rather than servicing a transaction the customer initiated. Order confirmations and delivery updates support the contract the customer entered into; offers, restock nudges and cross-sells are marketing and need a consent recorded for that purpose on that channel.
General information about the DPDP Act, 2023, not legal advice. For a position specific to your organisation, talk to us or read the deep dive: DPDP Compliance for D2C and E-commerce Brands in India.
Find out where you actually stand.
The free self-assessment takes a few minutes and gives you a written position on your own setup, not a generic checklist.