Solutions · Ecommerce & retail

Three years, then delete —
with 48 hours’ notice.

Ecommerce is the one sector the DPDP Rules give a bright-line clock: above two crore registered Indian users, a customer’s data must be erased three years after they last interacted, with at least 48 hours’ notice to each of them first. It is also the sector where that clock collides hardest with everything around it — GST keeps the invoice for seventy-two months, the same order record sits un-clocked with every seller who exported it, and the checkout patterns DPDP will police are already being fined under consumer law.

FROM THE SEPTEMBER 2026 PROBLEM REGISTER · 12 PROBLEMS SWEPT · 4 SHOWN HERE · HOW THIS WAS BUILT

What the ground actually looks like

Four collisions, each read from the instrument.

Each of these is marked confirmed: two independent sources, at least one the instrument itself or a practitioner record. Sources are linked so your counsel can read them.

01 · THE THREE-YEAR CLOCK VS THE INVOICE

Platforms above two crore users must erase a customer’s data three years after last interaction, with a 48-hour notice to each — while GST requires the transaction record for seventy-two months.

Rule 8(1) and the Third Schedule set the clock and the threshold; Rule 8(2) requires the notice. CGST s.36 requires books and records for seventy-two months from the annual-return due date, longer under appeal or investigation. The register’s own read: field-level partial erasure, continuous dormancy tracking, and a notification pipeline firing at tens of millions of lapsed users. NASSCOM called the 48-hour notice “operationally burdensome, requiring automated notification systems tracking deletion schedules.”

SOURCES · DPDP Rules 2025, Rule 8 and Third Schedule (text) · CGST Act s.36 (statute) · NASSCOM feedback on the draft Rules (practitioner)

Confirmed · sweep of 2 Sep 2026 · Rule 8 in force mid-May 2027
02 · THE SELLER HOLDS A COPY WITH NO CLOCK

The Third Schedule deliberately excludes marketplace sellers, so the same order record is under a three-year deletion clock at the platform and under no clock at all at lakhs of sellers holding exports of it.

The ecommerce-entity definition the Schedule imports “does not include a seller offering goods or services on a marketplace e-commerce entity.” Sellers reach buyer details through seller APIs and dashboards; a seller who exports buyer contacts for its own marketing is an independent fiduciary with no privacy tooling. The platform’s mandated erasure does not reach those copies — and if they persist, the platform’s own erasure response is falsifiable, and the complaint names the platform.

SOURCES · Third Schedule definition (text) · A marketplace’s public seller API documentation (the access fact) · A marketplace’s seller data-protection policy update, Nov 2025 (practitioner)

Confirmed for the boundary · the re-papering half is hypothesised
03 · THE CHECKBOX IS ALREADY BEING FINED

Pre-ticked consent and consent-adjacent dark patterns are penalised today under consumer law — two regulators reach the same checkbox, one now and one from 2027.

The Consumer Protection (E-Commerce) Rules 2020, Rule 4(9): consent must be express — “no automatic recording of consent, including in the form of pre-ticked checkboxes.” The Central Consumer Protection Authority has issued a dark-pattern self-audit advisory and penalties across multiple platforms. DPDP s.6(1) will police the same pattern from mid-May 2027. Redesign has not happened voluntarily because it is a conversion-rate cost: measurable opt-in replaces an assumed hundred-per-cent marketable base.

SOURCES · Consumer Protection (E-Commerce) Rules 2020, r.4(9) (instrument) · PIB on CCPA dark-pattern penalties (enforcement record) · CCPA self-audit advisory (context)

Confirmed · enforcement is present-tense, under a different statute
04 · THE TEEN SHOPPER

Under eighteen is a child: verifiable parental consent is required and tracking or targeted advertising at them is flatly prohibited — with no mechanism to even detect a minor.

Section 9(1) requires verifiable parental consent; s.9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children, and consent does not cure it. Most accounts carry no age signal, and personalisation and retargeting run uniformly across all users. Rule 10 specifies the parental-consent process but not minor detection. India’s eighteen-year threshold is the world’s highest; global playbooks written for thirteen or sixteen do not transplant.

SOURCES · DPDP Act s.9 (statute) · MediaNama on teens and the Rules, Nov 2025 (reporting) · NASSCOM feedback (practitioner — operationalising parental consent at scale)

Confirmed · cohort sizes per platform could not be assessed
What the law actually says — and what it doesn’t

Claims we corrected before putting them here.

The register started from AI-drafted hypotheses and kept only what the instruments supported. These are the commerce-specific claims that changed on the way.

The threshold is two crore registered Indian users — and it excludes sellers.

Rule 8(1) and the Third Schedule: two crore registered users for e-commerce (fifty lakh for gaming), anchored to the later of last interaction, last rights exercise, or the Rules’ commencement. “Registered,” not monthly active. The definition expressly excludes a seller on a marketplace.

GST retention is seventy-two months from the return date — not a round number of years.

CGST s.36 as verified: seventy-two months from the due date of the annual return, roughly up to seven and three-quarter years from the transaction, and extended for a year past the disposal of any appeal or investigation.

No ecommerce platform has been designated a Significant Data Fiduciary.

Explainers asserting that the largest marketplaces “are SDFs” are false today: no class has been notified as of 2 September 2026, and none can bind before mid-May 2027. Cross-border is likewise softer than seeded — no restricted-country list exists; RBI’s payment-data localisation is the binding constraint.

Any Indian consent-rate or rights-request number you are quoted today is fabricated.

No data-principal right is in force before mid-May 2027, so no Indian DSR volume or opt-in rate can exist yet. A figure circulating now is either invented or a GDPR transplant. The register projects; it labels the projection; it does not publish one here.

No DPDP penalty can be imposed on anyone today.

The penalty provisions commence in mid-May 2027 and the Board had no members as of 1 August 2026. What is being enforced today is checkout design under consumer law, as collision 03 records. The DPDP penalty schedule is stated plainly here, once.

RULES NOTIFIED MID-NOV 2025 · CONSENT-MANAGER REGISTRATION OPENS MID-NOV 2026 · DUTIES, RIGHTS AND PENALTIES MID-MAY 2027 · DATES STATED AS THE NOTIFICATIONS STATE THEM

Where Consent Tree fits today

A checkbox that cannot be pre-ticked,
and an erasure that actually runs.

Everything below is live today and maps to shipped code — the same rule as every page on this site. Capabilities we are still building are not listed here.

FOR 03 · THE CHECKBOX

Consent per purpose, never pre-ticked — enforced by the widget, not the configuration

Analytics, personalisation, marketing and cart reminders become separate, specified purposes with separate decisions. Non-essential purposes are never pre-checked: the widget enforces that itself rather than trusting an upstream default, so the pattern the consumer regulator penalised cannot be rendered. Withdrawal is as easy as the grant, and a decision is honoured across every property you run.

Live: purpose-by-purpose consent · no pre-ticked non-essential purpose · cross-domain sync
FOR 01 · THE ERASURE

Erasure that reaches the stores where the data lives, and reports what it deleted

A rights request is executed, not ticketed: a parameter-bound delete against the database table and column you nominate, every object under the person’s prefix in your S3-compatible storage, and deletion through each connected SaaS tool’s own API — each returning the count it actually removed. Where a vendor publishes no deletion API, the connector says so and flags a manual filing rather than reporting a success it cannot achieve. The three-year clock and its 48-hour notice are your schedule to run; the erasure at the end of it is what this executes.

Live: erasure connectors for PostgreSQL, Amazon S3, Salesforce, HubSpot, Zoho, Freshdesk, and any HTTP endpoint
FOR 03 AGAIN · SEE IT AS THE REGULATOR WOULD

An outside-in scan of your own checkout, before someone else runs one

The scanner loads your public pages like a stranger would and reports trackers firing before consent, buried reject buttons, pre-ticked boxes and consent walls, whether Global Privacy Control is honoured, and whether your privacy policy substantively covers DPDP duties or gestures at them.

Live: outside-in risk scanner · dark-pattern detection · 70+ tracker signatures
FOR 04 AND ALL OF IT · GUARDIANS AND EVIDENCE

Guardian consent flows for age-gated processing, and a trail a regulator can verify without trusting us

A guardian’s consent is captured as its own record, tied to the minor’s, with the verification method stated — never a stronger claim than the mechanism supports. Every consent, erasure and notice publication is a linked record bound to the one before it, periodically stamped by an independent timestamp authority. Anyone can check the chain. For collision 02, the seller’s copy is the seller’s: we hold your processors and their DPAs as a scored register, and we do not claim to reach into a seller’s export.

Live: guardian consent flows · tamper-evident audit trail · verifiable receipts · processor & DPA register