E-Commerce
Liability Check
E-commerce players must stop Dark Patterns (pre-ticked consent boxes) and ensure Right to Erasure for customer account deletion.
Why E-Commerce is at Risk
E-commerce entails massive data collection (Location, Payment, Preferences). The **Third Schedule of DPDP Rules 2025** mandates that transaction logs be retained for a minimum of 1 year, BUT personal data must be erased once the purpose is served (unless legally required). Balancing retention vs erasure is key.
Common Violations
- 1.Retaining saved cards without explicit consent (Check RBI tokenization rules + DPDP).
- 2.Sharing purchase history with ad networks for retargeting without opt-in.
- 3.Complex or hidden 'Delete Account' processes.
The Immediate Fix
Check your **Data Retention Policy**. Automate the deletion of user data for inactive accounts after a set period (e.g., 3 years as per Schedule III for large entities) . Ensure 'Delete Account' is accessible in 1 click.
Get DPDP Updates for E-Commerce
We'll send you compliance alerts and deadline reminders specific to your area. No spam — unsubscribe anytime.
Projected Compliance Deadline: Immediate
Next step after the audit
The audit shows the gaps. Sanctum closes them. One programme covers legal position, data map, gap analysis, implementation, tooling, training, a written readiness opinion, and breach cover, under one accountable owner. See the all-in-one programme
What Should You Do Next?