Every shipment carries personal data. Consignee names, delivery addresses, GPS coordinates, OTPs — Indian logistics companies process millions of personal data records daily and face DPDP Act 2023 obligations with penalties up to ₹250 Cr per incident.
The DPDP Act 2023 fully applies to logistics companies, courier firms, freight forwarders, last-mile delivery operators, and supply chain tech platforms in India. Every consignee name, delivery address, phone number, OTP, and GPS coordinate is personal data under the Act. Logistics operators must establish a consent framework for recipient communications, execute Data Processing Agreements with e-commerce platform clients (who are the Data Fiduciaries), comply with employee data obligations for driver GPS tracking, and implement security safeguards for the millions of shipment records processed daily. The enforcement deadline is May 13, 2027, and as a Data Processor for e-commerce platforms, your contractual and regulatory liability for data breaches is significant.
Logistics companies sit at the intersection of massive recipient data volumes, employee tracking obligations, multi-party data sharing, and real-time communication data. Here's what you're navigating.
The name, address, and phone number of every consignee is personal data under the DPDP Act 2023. Logistics companies processing lakhs or crores of shipments per month are operating one of the largest personal data pipelines in India — often without an explicit consent framework in place. Unlike a retail platform, the logistics operator frequently has no direct relationship with the consignee and cannot rely on a purchase-event consent. A documented legal basis for processing consignee PII, coupled with appropriate security safeguards for shipment databases, is non-negotiable under DPDP Rules 2025.
Real-time GPS tracking of delivery executives and drivers generates continuous location data for identifiable individuals — personal data under the DPDP Act 2023. Employee location is not exempt simply because tracking occurs during work hours. DPDP applies to employee data, and staff must be informed through a clear, plain-language privacy notice at onboarding. The purpose, scope, and retention period of location data must be documented. Tracking beyond work hours or for purposes beyond route optimisation and proof of delivery requires additional justification and creates material compliance exposure.
B2B logistics operations routinely share consignee data with e-commerce platforms, 3PL partners, customs agents, and clearance brokers. Under the DPDP Act 2023, every entity that receives personal data from you and processes it independently becomes a Data Fiduciary or sub-Processor — and you need documented legal authority (a Data Processing Agreement) to share that data with them. Sharing consignee PII with a customs agent without a DPA, or with a 3PL partner without contractual data protection obligations, is a DPDP violation and creates penalty exposure for both your organisation and your client e-commerce platform.
Delivery OTP confirmation, SMS delivery alerts, and WhatsApp tracking updates are all communication channels that collect and process contact data — phone numbers, message content, and interaction logs. The DPDP Act 2023 requires that a valid legal basis exists for sending communications to recipients. Transactional OTPs for delivery confirmation are likely covered under a legitimate use basis (contract fulfilment), but promotional communications and optional tracking updates require explicit consent. Retention of communication logs must comply with DPDP's purpose-limitation and storage-minimisation principles.
Every category below is personal data under the DPDP Act 2023. Each requires a valid legal basis, purpose documentation, and appropriate security safeguards.
A structured approach built for the data complexity of high-volume logistics and delivery operations — not a generic compliance checklist.
Map every point in the shipment lifecycle where personal data is collected, stored, processed, or transmitted — from order manifest ingestion and consignee data receipt, through delivery attempt logging and OTP capture, to shipment archive and deletion. This includes upstream data received from e-commerce platform clients, downstream data shared with 3PLs, customs agents, and return-logistics providers, and employee data generated by GPS tracking and HR systems. Without a complete data inventory, you cannot build a defensible consent architecture or negotiate accurate DPA terms with your clients. This step also identifies where your data retention schedules conflict with DPDP's storage-minimisation obligations.
Consignees — who receive delivery notifications, OTPs, and tracking updates — are Data Principals under the DPDP Act 2023. As the logistics operator, you must ensure that a valid legal basis exists for every communication sent to them. Transactional delivery communications (OTP, delivery confirmation) can rely on a legitimate use basis tied to the underlying purchase contract between the consignee and the e-commerce platform. However, this basis must be documented and reflected in your privacy notice. Promotional communications, optional real-time tracking links, and post-delivery feedback surveys require explicit consent from the consignee. Design a clear, plain-language recipient privacy notice and embed it in your delivery communication flow — not buried in a terms-of-service page.
In the typical logistics arrangement, the e-commerce platform is the Data Fiduciary — they collected the consignee's data at checkout and are responsible for ensuring lawful processing. You, as the logistics operator, are their Data Processor — processing that consignee data under their instruction to fulfil delivery. The DPDP Act 2023 requires that Data Processors operate under a written contract (Data Processing Agreement) with the Data Fiduciary. Your DPA must specify: the categories of personal data you process, the purposes and duration of processing, the security standards you implement, your breach notification obligations to the platform, and restrictions on sub-processing (sharing with 3PLs or customs agents). Without a DPA, both you and your client are non-compliant — and in a breach scenario, liability allocation is entirely unresolved.
Logistics companies face two critical milestone dates. Given the volume and operational complexity of personal data in the sector, implementation planning must begin now.
Fixed-price tools and expert engagements built for India's logistics and supply chain sector. Start with a free checklist or jump straight to a paid deep-dive.
Tell us about your logistics operation and your biggest DPDP concern. We'll come prepared with observations specific to your data volumes, DPA position with clients, and employee tracking obligations — not generic advice.
Answers to the questions we hear most from logistics operators, courier firms, and supply chain compliance teams.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.