ConsentKit DPDP

For online stores, D2C brands and marketplaces

DPDP compliance for e-commerce and D2C brands

Your store runs on customer data: checkout, delivery, ad pixels, abandoned-cart WhatsApps and loyalty emails. The DPDP Act wants a clear choice for each. ConsentKit adds notices and consent to your storefront and passes each customer’s choices to your ads, CRM and messaging tools.

Marketing and pixels
Need consent
Inactive users on large platforms
Delete after 3 years
Full compliance
13 May 2027
kaveriorganics.inCheckout

Kaveri Organics asks for your consent

We need your details to deliver your order. The rest is up to you.

Withdraw consent anytime
Consent logRecording

    Where the DPDP Act touches your store

    Every step from the first ad click to the tenth reorder involves customer data. Pick a stage to see which uses need consent.

    What changes for your store on 13 May 2027

    Most D2C stacks are a platform plus a dozen apps. Each app that touches customer data is part of your compliance.

    Ad pixels and tracking need consentSections 5 and 6

    Sending browsing and purchase data to ad platforms is a separate purpose from running the store.

    A consent banner that controls when pixels and tags load, with a log of every choice.

    Marketing needs a free, unticked choiceSection 6

    Consent must be specific and an affirmative action. Pre-ticked boxes and “by continuing you agree” do not count.

    Per-purpose choices at sign-up and checkout, synced to your CRM and WhatsApp tools.

    Withdrawal must reach every toolSection 6(4)

    When a customer unsubscribes, your email, SMS, WhatsApp and ad audiences all have to stop.

    Webhooks and integrations that push withdrawals to every connected app.

    Large platforms must delete inactive usersRule 8 and Third Schedule

    E-commerce entities with at least two crore registered users in India must erase data after three years of inactivity, with 48 hours’ notice first.

    An inactivity scheduler with automatic notices and a deletion log.

    Customers can ask for their dataSections 11 to 14

    Customers can request access, correction and erasure, and raise grievances you must answer in time.

    A request page in the account area with identity checks and deadlines.

    Apps and agencies are your processorsSection 8

    Your store platform, apps, courier, payment gateway and marketing agency all process customer data for you.

    A vendor register and processor contract checklist.

    A plan around your sale calendar

    Avoid changing checkout in the festive season. Do the heavy work in the quiet months after it.

    1. Audit apps and pixels

      List every app, tag and integration that receives customer data. Change nothing before the festive sales.

    2. Ship the consent banner

      Put consent controls on pixels and marketing forms after the festive peak.

    3. Sync choices everywhere

      Connect consent to CRM, email, WhatsApp and ad audiences. Clean old lists.

    4. Rights and retention

      Add the data-request page and set inactivity deletion rules.

    For every kind of online store

    Integrations for the platforms you already use.

    Shopify and WooCommerce stores

    App and plugin install, no developer needed.

    Custom-built stores

    JavaScript snippet, REST API and webhooks.

    Marketplaces

    Buyers and sellers, both sides of the data.

    Subscription brands

    Recurring payments and renewal messages.

    Quick commerce

    Location data and fast delivery partners.

    Omnichannel retailers

    Store POS and online data in one consent log.

    Questions e-commerce teams are asking

    For the full picture, read our DPDP Act guide or compliance checklist.

    Do we need consent for Meta and Google pixels?

    Sending customers’ browsing and purchase data to ad platforms is a purpose beyond running the store, so it needs consent. Load pixels only after a customer agrees.

    Can we send abandoned-cart messages?

    Treat them as marketing. Send them only to customers who agreed to promotional messages, and include an easy opt-out.

    Do we have to delete inactive customers?

    E-commerce entities with at least two crore registered users in India must erase personal data after three years of inactivity, with 48 hours’ notice. Smaller stores must still delete data once its purpose is over.

    Is our store platform responsible for compliance?

    No. You are the data fiduciary for your customers. Your platform and apps are processors. You need suitable contracts with each.

    Does this apply to customers outside India?

    The Act covers personal data processed in India, and data of people in India processed abroad in connection with offering them goods or services.

    Get your store ready before May 2027

    The readiness check takes about ten minutes and gives you a gap report built for online stores.