Ecommerce is the one sector the DPDP Rules give a bright-line clock: above two crore registered Indian users, a customer’s data must be erased three years after they last interacted, with at least 48 hours’ notice to each of them first. It is also the sector where that clock collides hardest with everything around it — GST keeps the invoice for seventy-two months, the same order record sits un-clocked with every seller who exported it, and the checkout patterns DPDP will police are already being fined under consumer law.
FROM THE SEPTEMBER 2026 PROBLEM REGISTER · 12 PROBLEMS SWEPT · 4 SHOWN HERE · HOW THIS WAS BUILT
Each of these is marked confirmed: two independent sources, at least one the instrument itself or a practitioner record. Sources are linked so your counsel can read them.
Rule 8(1) and the Third Schedule set the clock and the threshold; Rule 8(2) requires the notice. CGST s.36 requires books and records for seventy-two months from the annual-return due date, longer under appeal or investigation. The register’s own read: field-level partial erasure, continuous dormancy tracking, and a notification pipeline firing at tens of millions of lapsed users. NASSCOM called the 48-hour notice “operationally burdensome, requiring automated notification systems tracking deletion schedules.”
SOURCES · DPDP Rules 2025, Rule 8 and Third Schedule (text) · CGST Act s.36 (statute) · NASSCOM feedback on the draft Rules (practitioner)
Confirmed · sweep of 2 Sep 2026 · Rule 8 in force mid-May 2027The ecommerce-entity definition the Schedule imports “does not include a seller offering goods or services on a marketplace e-commerce entity.” Sellers reach buyer details through seller APIs and dashboards; a seller who exports buyer contacts for its own marketing is an independent fiduciary with no privacy tooling. The platform’s mandated erasure does not reach those copies — and if they persist, the platform’s own erasure response is falsifiable, and the complaint names the platform.
SOURCES · Third Schedule definition (text) · A marketplace’s public seller API documentation (the access fact) · A marketplace’s seller data-protection policy update, Nov 2025 (practitioner)
Confirmed for the boundary · the re-papering half is hypothesisedThe Consumer Protection (E-Commerce) Rules 2020, Rule 4(9): consent must be express — “no automatic recording of consent, including in the form of pre-ticked checkboxes.” The Central Consumer Protection Authority has issued a dark-pattern self-audit advisory and penalties across multiple platforms. DPDP s.6(1) will police the same pattern from mid-May 2027. Redesign has not happened voluntarily because it is a conversion-rate cost: measurable opt-in replaces an assumed hundred-per-cent marketable base.
SOURCES · Consumer Protection (E-Commerce) Rules 2020, r.4(9) (instrument) · PIB on CCPA dark-pattern penalties (enforcement record) · CCPA self-audit advisory (context)
Confirmed · enforcement is present-tense, under a different statuteSection 9(1) requires verifiable parental consent; s.9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children, and consent does not cure it. Most accounts carry no age signal, and personalisation and retargeting run uniformly across all users. Rule 10 specifies the parental-consent process but not minor detection. India’s eighteen-year threshold is the world’s highest; global playbooks written for thirteen or sixteen do not transplant.
SOURCES · DPDP Act s.9 (statute) · MediaNama on teens and the Rules, Nov 2025 (reporting) · NASSCOM feedback (practitioner — operationalising parental consent at scale)
Confirmed · cohort sizes per platform could not be assessedThe register started from AI-drafted hypotheses and kept only what the instruments supported. These are the commerce-specific claims that changed on the way.
Rule 8(1) and the Third Schedule: two crore registered users for e-commerce (fifty lakh for gaming), anchored to the later of last interaction, last rights exercise, or the Rules’ commencement. “Registered,” not monthly active. The definition expressly excludes a seller on a marketplace.
CGST s.36 as verified: seventy-two months from the due date of the annual return, roughly up to seven and three-quarter years from the transaction, and extended for a year past the disposal of any appeal or investigation.
Explainers asserting that the largest marketplaces “are SDFs” are false today: no class has been notified as of 2 September 2026, and none can bind before mid-May 2027. Cross-border is likewise softer than seeded — no restricted-country list exists; RBI’s payment-data localisation is the binding constraint.
No data-principal right is in force before mid-May 2027, so no Indian DSR volume or opt-in rate can exist yet. A figure circulating now is either invented or a GDPR transplant. The register projects; it labels the projection; it does not publish one here.
The penalty provisions commence in mid-May 2027 and the Board had no members as of 1 August 2026. What is being enforced today is checkout design under consumer law, as collision 03 records. The DPDP penalty schedule is stated plainly here, once.
RULES NOTIFIED MID-NOV 2025 · CONSENT-MANAGER REGISTRATION OPENS MID-NOV 2026 · DUTIES, RIGHTS AND PENALTIES MID-MAY 2027 · DATES STATED AS THE NOTIFICATIONS STATE THEM
Everything below is live today and maps to shipped code — the same rule as every page on this site. Capabilities we are still building are not listed here.
Analytics, personalisation, marketing and cart reminders become separate, specified purposes with separate decisions. Non-essential purposes are never pre-checked: the widget enforces that itself rather than trusting an upstream default, so the pattern the consumer regulator penalised cannot be rendered. Withdrawal is as easy as the grant, and a decision is honoured across every property you run.
Live: purpose-by-purpose consent · no pre-ticked non-essential purpose · cross-domain syncA rights request is executed, not ticketed: a parameter-bound delete against the database table and column you nominate, every object under the person’s prefix in your S3-compatible storage, and deletion through each connected SaaS tool’s own API — each returning the count it actually removed. Where a vendor publishes no deletion API, the connector says so and flags a manual filing rather than reporting a success it cannot achieve. The three-year clock and its 48-hour notice are your schedule to run; the erasure at the end of it is what this executes.
Live: erasure connectors for PostgreSQL, Amazon S3, Salesforce, HubSpot, Zoho, Freshdesk, and any HTTP endpointThe scanner loads your public pages like a stranger would and reports trackers firing before consent, buried reject buttons, pre-ticked boxes and consent walls, whether Global Privacy Control is honoured, and whether your privacy policy substantively covers DPDP duties or gestures at them.
Live: outside-in risk scanner · dark-pattern detection · 70+ tracker signaturesA guardian’s consent is captured as its own record, tied to the minor’s, with the verification method stated — never a stronger claim than the mechanism supports. Every consent, erasure and notice publication is a linked record bound to the one before it, periodically stamped by an independent timestamp authority. Anyone can check the chain. For collision 02, the seller’s copy is the seller’s: we hold your processors and their DPAs as a scored register, and we do not claim to reach into a seller’s export.
Live: guardian consent flows · tamper-evident audit trail · verifiable receipts · processor & DPA register