Infosek
INFOSEK

DPDP for E-commerce and D2C: The Three Year Erasure Clock

One rule names e-commerce explicitly, with a threshold and a clock. Below the threshold the general obligations apply exactly as they do to everyone else.

DPDP for E-commerce and D2C: The Three Year Erasure Clock

The named classes

Rule 8(1), read with the Third Schedule, sets a three year erasure clock for three classes:

The clock runs from the date the Data Principal last approached the Data Fiduciary for the specified purpose or exercised her rights, or from commencement of the Rules, whichever is latest.

Below the threshold, the general rule still applies

A D2C brand with fifty thousand customers is not in the Third Schedule, but Rule 8 still requires erasure once the specified purpose is no longer being served. The Schedule fixes a period for named classes; it does not exempt everyone else.

Where e-commerce is usually exposed

The retention clock is not a burden so much as a deadline for a decision you have been deferring: what is a dormant customer record actually for?

Infosek Team

What to do

Common questions

What is the DPDP retention period for e-commerce companies?

Under Rule 8(1) read with the Third Schedule, a Data Fiduciary that is an e-commerce entity with not less than two crore registered users in India must erase personal data three years from the date the Data Principal last approached it for the specified purpose or exercised her rights, or from commencement of the DPDP Rules 2025, whichever is latest, unless retention is necessary under another law.

Does the Third Schedule apply to small e-commerce businesses?

The specific three year clock applies to the classes named in the Third Schedule, including e-commerce entities with not less than two crore registered users. Smaller businesses remain subject to the general obligation in Rule 8 to erase once the specified purpose is no longer served.

Working out your retention clock?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment