DPDP Insights › All sectors › Retail and e-commerce
Retailers and marketplaces hold purchase histories, addresses, payment references and loyalty data for very large numbers of people.
Open the interactive tool for this sectorThis sector is in its core view. The law, guides and seat notes apply in full; the sector pack with role briefs and worked examples is being written.
| Rule | What it says | What it means alongside DPDP | Source |
|---|---|---|---|
| DPDP Rules, Third Schedule | Large e-commerce entities and social media platforms (2 crore or more registered users in India) and online gaming platforms (50 lakh or more) must erase data of users inactive for three years, with 48 hours' notice before erasure. | If you cross these thresholds, build the inactivity clock and the warning message. | MeitY |
| Consumer Protection (E-Commerce) Rules, 2020 | Duties on marketplaces and sellers, including grievance officers. | Align the grievance officer and DPDP contact. | Department of Consumer Affairs |
| CERT-In Directions, 2022 | Report specified cyber incidents within six hours; keep ICT logs 180 days within India. | Applies alongside the DPDP breach steps. | CERT-In |