DPDP for E-commerce and D2C: The Three Year Erasure Clock
One rule names e-commerce explicitly, with a threshold and a clock. Below the threshold the general obligations apply exactly as they do to everyone else.
The named classes
Rule 8(1), read with the Third Schedule, sets a three year erasure clock for three classes:
- An e-commerce entity with not less than two crore registered users in India.
- An online gaming intermediary with not less than fifty lakh registered users in India.
- A social media intermediary with not less than two crore registered users in India.
The clock runs from the date the Data Principal last approached the Data Fiduciary for the specified purpose or exercised her rights, or from commencement of the Rules, whichever is latest.
Below the threshold, the general rule still applies
A D2C brand with fifty thousand customers is not in the Third Schedule, but Rule 8 still requires erasure once the specified purpose is no longer being served. The Schedule fixes a period for named classes; it does not exempt everyone else.
Where e-commerce is usually exposed
- Abandoned carts and dormant accounts. Retained indefinitely by default with no defined purpose.
- Marketing profiles. Behavioural data built for targeting, often on a consent that was never specific to it.
- Delivery and logistics partners. Data Processors requiring the Rule 6(1)(f) clause.
- Under-18 shoppers. Section 9(3) bars targeted advertising directed at children, which conflicts with default retargeting across the whole user base.
The retention clock is not a burden so much as a deadline for a decision you have been deferring: what is a dormant customer record actually for?
Infosek Team
What to do
- Establish whether you cross a Third Schedule threshold, since it fixes your clock.
- Define dormancy and enforce erasure at the boundary, preserving account access and stored value as the Schedule allows.
- Separate marketing profiling from transactional processing so a withdrawal can stop one without breaking the other.
- Exclude accounts you know to be children from behavioural advertising.
Common questions
What is the DPDP retention period for e-commerce companies?
Under Rule 8(1) read with the Third Schedule, a Data Fiduciary that is an e-commerce entity with not less than two crore registered users in India must erase personal data three years from the date the Data Principal last approached it for the specified purpose or exercised her rights, or from commencement of the DPDP Rules 2025, whichever is latest, unless retention is necessary under another law.
Does the Third Schedule apply to small e-commerce businesses?
The specific three year clock applies to the classes named in the Third Schedule, including e-commerce entities with not less than two crore registered users. Smaller businesses remain subject to the general obligation in Rule 8 to erase once the specified purpose is no longer served.
Working out your retention clock?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment