Quick Answer
D2C (Direct-to-Consumer) brands collect personal data at every touchpoint: website visits, purchase transactions, loyalty programmes, and marketing communications. Under the DPDP Act 2023, each processing purpose requires a separate consent and a clear privacy notice. D2C brands must audit their marketing automation, CRM, and analytics stack for DPDP compliance before enforcement begins in May 2027.
Quick AnswerD2C brands must obtain separate consents for transactional communications and marketing. Retargeting, WhatsApp marketing, and loyalty programs all require explicit opt-ins under DPDP.
DPDP Compliance Checklist
- Audit all marketing consent touchpoints: checkout, pop-ups, WhatsApp opt-in, loyalty registration
- Implement separate consent for: order updates, promotions, personalisation, and third-party sharing
- Review retargeting pixel setup — Meta, Google, and Insider pixels require valid consent
- Implement easy unsubscribe for all marketing channels — one-click for email/SMS
- Build data deletion workflow for customers who request account closure
- Review logistics partner data sharing — only share delivery data, not purchase history
- Train customer success team on DSAR handling — 30-day response
- Publish clear privacy policy covering all data collection and partner integrations
- Implement cookie consent banner — granular choices for analytics vs marketing
- Conduct quarterly DPDP compliance check for new marketing campaigns
Download Full Compliance Guide (Free)
Get the complete sector-specific checklist, risk areas, and 30-day action plan — delivered to your inbox.
Frequently Asked Questions
Does DPDP apply to WhatsApp marketing for D2C brands?+
Yes. WhatsApp marketing requires explicit opt-in consent from each customer. The default messaging consent at checkout is not sufficient for promotional messages.
Can D2C brands use purchase history for personalised recommendations?+
Yes, with consent for personalisation. Most customers accept this — the key is to make consent explicit and provide an easy opt-out.
What is the risk of non-compliance for D2C brands?+
Fines up to ₹250 crore per breach. Customer trust damage is the greater commercial risk — DPDP compliance is increasingly a competitive advantage.
Every Sunday
The Sunday DPDP Brief
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.