The consent is easy. The erasure clock is the surprise.
18 September 2026
Marketing consent, cookie and SDK tracking, and the Third Schedule's three-year erasure rule for platforms above two crore registered users.
E-commerce comes to the DPDP Act expecting a cookie problem. The consent layer is real work, but it is work the sector already understands. The provision that changes how a platform is built is the one about deleting things.
The Third Schedule clock
For an e-commerce entity with two crore or more registered users, the Third Schedule sets a retention limit: personal data must be erased three years after the Data Principal's last purposeful interaction, or three years from the Rules' commencement, whichever is later. Online gaming intermediaries hit the same rule at fifty lakh users, social media intermediaries at two crore.
Before erasing, the platform must give the person at least 48 hours' notice. If they log in or make contact in that window, the clock resets and the data stays.
Two consequences follow, and neither is a consent-banner problem. The platform needs to know, per customer, when the last purposeful interaction was — which is a definition someone has to write down and defend. And it needs erasure that actually propagates, because deleting a row in the orders table while the same person survives in the warehouse, the recommendation index and the email platform is not erasure.
Marketing, and the bundle at checkout
Most e-commerce marketing permission was collected inside account creation, alongside terms acceptance and transactional messaging. Under Sec. 6(1) that is one consent standing in for several purposes, and Sec. 6(4) requires withdrawal from any one of them to be as easy as giving it was. A person who wants promotional email off but order updates on cannot express that against a single tick.
Unbundling is the fix, and it is also good for the business: the alternative to selective withdrawal is total withdrawal.
Tags, SDKs and the advertising audience
The Act does not mention cookies. It does not need to. Where an analytics tag or an advertising SDK processes personal data, that is processing for a purpose, and it needs its notice and its consent like any other.
The place this leaks is downstream. An audience uploaded to an ad platform last month keeps serving after a withdrawal unless something removes the record, and a warehouse copy rebuilds the segment on its next run. A withdrawal recorded only in the consent store has not been honoured.
Children, if you have them
If under-eighteens can transact, Sec. 9 applies: verifiable parental consent, and no tracking, behavioural monitoring or targeted advertising directed at them. There is no e-commerce exemption in the Fourth Schedule. A platform that cannot tell which accounts belong to children cannot apply the rule, which makes age a data-model question rather than a policy one.
What lands on 13 May 2027
Notice, consent, withdrawal, rights, safeguards, breach reporting, retention and cross-border, together. The retention piece is the one with the longest lead time, because it is the one that requires knowing what you hold, where it went, and when it was last touched.
Questions people ask
- Does the DPDP Act require a cookie banner?
- No provision mentions cookies. What it requires is notice under Sec. 5 and valid consent under Sec. 6(1) for the purposes you process for. Where a tag or SDK processes personal data for advertising or analytics, that is a purpose needing its own notice and its own consent.
- How long can an e-commerce platform keep customer data?
- The Third Schedule reaches an e-commerce entity with at least two crore registered users in India. Personal data is erased three years after she last approached the platform for the specified purpose or exercised her rights, or three years from the commencement of the Rules, whichever is latest, unless a law requires it to be kept. At least 48 hours before erasing, the platform must tell her it will happen unless she logs in, contacts it or exercises her rights.