Compliance Guides6 min read

DPDP Purpose Limitation and Secondary Use Risks for E-Commerce

A guide for large D2C and e-commerce compliance heads on managing purpose limitation, unbundling consent, and controlling secondary data use under the DPDP Act 2023 and Rules 2025.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

Overview

With exactly 286 days remaining until the DPDP hard compliance deadline of 13 May 2027, enterprise compliance heads face a critical challenge in controlling how product and growth teams use data. In large direct-to-consumer and e-commerce operations, the line between fulfilling an order and marketing a new product is often blurred. The Digital Personal Data Protection Act, 2023 addresses this by enforcing strict purpose limitation on all processing. If a customer provides a phone number for shipping updates, your marketing team cannot automatically use that number for promotional SMS campaigns. For a Head of Compliance, ensuring that control owners across product and growth teams respect these boundaries requires concrete audit trails, not just policy memos.

What The DPDP Act Says

Section 4 of the DPDP Act states that a Data Fiduciary may process the personal data of a Data Principal only for a lawful purpose. While consent is the primary basis for processing, except where Section 7 legitimate uses apply, strict rules govern how that data is deployed. When relying on consent, the data can only be used for the specified purpose to which the Data Principal agreed. Section 7 clarifies that if a Data Principal voluntarily provides personal data for a specified purpose, such as a pharmacy customer giving a mobile number to receive a payment receipt, the Data Fiduciary may process it only for that receipt. Using that data for secondary promotional purposes without explicit permission violates the core purpose limitation principle.

DPDP Act Vs Rules, 2025: What Changed

The DPDP Rules, 2025 operationalise these principles by introducing strict requirements for itemised notices under Rule 3. These notices must clearly explain what data is collected and for what specific purpose, forcing e-commerce platforms to unbundle their consent requests. You can no longer hide marketing opt-ins inside general terms of service. Furthermore, the Rules require these notices to be accessible in up to 22 regional languages. The Rules also mandate verifiable parental consent mechanics and formalise the breach response process, while adding significant duties for Significant Data Fiduciaries based on volume and risk. Your evidence pack must now prove that a Data Principal in India saw an itemised, translated notice and specifically opted into secondary uses.

What Every Data Fiduciary Must Do Now

Establishing purpose limitation requires creating distinct consent artefacts for different processing activities. Your team must map out exactly which data points are required for core services, such as shipping data, versus secondary growth initiatives, such as marketing data. You need a system that tracks these preferences and pushes them to your downstream marketing platforms. Operating this on spreadsheets works for a pilot phase but breaks rapidly at enterprise scale. When millions of users adjust their preferences daily, manual tracking fails to produce the regulator-ready audit trails required to defend against complaints. If your secondary processing involves sharing data with foreign analytics vendors, note that cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories.

Breach Notification Specifics

If improper secondary use or an external attack exposes personal data, the DPDP Rules, 2025 dictate a precise timeline for response. A Data Fiduciary must send an intimation to affected Data Principals without delay. Simultaneously, you must submit a detailed report to the Data Protection Board of India within 72 hours. This requires your cross-team workflows to identify the breach, assess the compromised consent artefacts, and generate notifications before the 72-hour window closes. Without automated incident response protocols bridging your security and legal teams, hitting this deadline is practically impossible at a large enterprise.

Common Misconceptions

Growth teams often believe that consent is required for everything, but remember that consent is the primary basis for processing, except where Section 7 legitimate uses apply for specific user-initiated actions. However, secondary marketing is never a legitimate use. Another myth is that financial or health data requires extra purpose limitation because it is a special category. The DPDP Act 2023 does not create a formal special category for sensitive information, though the volume and risk of such data can trigger Significant Data Fiduciary obligations. Finally, marketing teams often assume bundling consent into checkout flows is still acceptable, but the Rules explicitly ban this practice.

Implementation Checklist

1. Conduct a Data Protection Impact Assessment to identify all secondary uses of data across marketing and product teams. In-house feasible for policy, requires tooling for continuous discovery.

2. Unbundle consent flows to separate shipping data from marketing data. Tooling assisted to manage frontend user experience and backend consent artefacts.

3. Translate your itemised privacy notices into the 22 languages specified under Rule 3. Tooling assisted to manage updates across multiple regional languages.

4. Integrate consent records with your customer relationship management systems so marketing teams only message opted-in users. Tooling assisted to prevent manual errors.

5. Establish the 72-hour breach reporting workflow required by the Rules, connecting your security operations center to the legal team. In-house feasible for initial protocol design.

Penalties And Enforcement Risk

The Data Protection Board of India holds the authority to levy significant penalties for non-compliance. Failing to adhere to purpose limitation and proper consent mechanics can result in fines up to 250 crore rupees per instance under the DPDP Act. Additionally, failing to meet the strict 72-hour breach reporting deadline adds severe regulatory exposure. The DPBI will demand an evidence trail showing exact consent artefacts and system access logs. If your enterprise relies on a generic compliance dashboard that cannot produce these records, the board reporting risk increases substantially.

How ComplyDP Helps

Many enterprise compliance teams struggle because traditional banking GRC tools are too heavy and do not solve the frontend consent problem. We provide a Consent Unbundler that cleanly separates shipping data from marketing data and automatically translates your notices into regional languages for Tier-2 customers under Rule 3. This ensures your product teams stay agile while giving your legal team an instant, regulator-ready audit trail of every consent artefact and breach workflow. Start scoping your gap assessment today at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act allow us to use checkout data for marketing?

No. Section 4 enforces strict purpose limitation. If a customer provides data specifically for shipping an order, using it for promotional marketing requires a separate, explicit consent artefact.

What is the deadline to comply with the DPDP Act and Rules?

The hard compliance deadline is 13 May 2027. Enterprises have exactly 286 days remaining to align their consent collection, breach response, and itemised notices with the DPDP Rules 2025.

Are we required to translate privacy notices into local languages?

Yes. Under Rule 3 of the DPDP Rules 2025, Data Fiduciaries must provide itemised notices in up to 22 regional languages, allowing the Data Principal in India to make an informed choice.

What is the penalty for violating purpose limitation or consent rules?

The Data Protection Board of India can impose penalties of up to 250 crore rupees per instance for failing to fulfill obligations related to consent and lawful processing under the DPDP Act.

How quickly must we report a data breach under the new Rules?

The DPDP Rules 2025 require you to intimate affected Data Principals without delay and submit a detailed report to the Data Protection Board of India within 72 hours of the incident.