The DPDP Audit Tool
Compliance for E-Commerce
🛒
E-Commerce
Liability Check
📦
E-commerce players must stop Dark Patterns (pre-ticked consent boxes) and ensure Right to Erasure for customer account deletion.
Why E-Commerce is at Risk
E-commerce entails massive data collection (Location, Payment, Preferences). The **Third Schedule of DPDP Rules 2025** mandates that transaction logs be retained for a minimum of 1 year, BUT personal data must be erased once the purpose is served (unless legally required). Balancing retention vs erasure is key.
Common Violations
- 1.Retaining saved cards without explicit consent (Check RBI tokenization rules + DPDP).
- 2.Sharing purchase history with ad networks for retargeting without opt-in.
- 3.Complex or hidden 'Delete Account' processes.
The Immediate Fix
Check your **Data Retention Policy**. Automate the deletion of user data for inactive accounts after a set period (e.g., 3 years as per Schedule III for large entities) . Ensure 'Delete Account' is accessible in 1 click.
Projected Compliance Deadline: Immediate