6 mins

Marketplace Section 11: Tracking Which Processors Received Customer Data

Understand how e-commerce marketplaces must track and disclose data shared with third-party processors under Section 11 of the DPDP Act, 2023, and how to manage the legal liability of supply chain data flows.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Direct Answer for Marketplace Section 11 Data Sharing Queries

Under Section 11 of the Digital Personal Data Protection Act, 2023, an e-commerce marketplace must provide a Data Principal with the identities of all Data Processors and third-party Data Fiduciaries who received their personal data. The marketplace is also required to provide a description of the exact data shared with each entity. For a General Counsel managing legal risk in a direct-to-consumer platform, this creates an immediate operational requirement. When a customer submits an access request, the enterprise legal and technical teams have to produce a traceable log. This log shows whether specific contact or payment information went to a regional logistics provider, a payment gateway, or a marketing analytics tool. Failure to maintain these records exposes the enterprise to regulator scrutiny. It also complicates liability allocation if a vendor suffers a data breach. The DPDP Rules, 2025 require verifiable mechanisms to fulfill these Data Principal rights without undue delay. Relying on manual spreadsheet tracking across hundreds of marketplace sellers and supply chain partners creates an unmanageable risk for large retail operators.

Mapping the Liability of E-Commerce Data Flows

The legal architecture of an e-commerce marketplace relies on a complex web of third-party operators. A single transaction triggers data sharing with warehouse management systems, courier services, and customer support helpdesks. Section 11 eliminates the ability to hide behind generic privacy policy statements about sharing data with trusted affiliates. A customer holds the legal right to demand the exact names of those entities. From a defensibility standpoint, the General Counsel needs to verify that every vendor contract includes tight indemnity clauses and specific data processing agreements. These contracts restrict processors to act only on instructions from the marketplace, which operates as the primary Data Fiduciary. Regulator engagement often centers on breach accountability. If a downstream logistics processor loses customer data, the marketplace remains responsible. Under the DPDP Rules, 2025, the enterprise must provide intimation to affected Data Principals without delay. The marketplace also has to submit a detailed report to the Data Protection Board within 72 hours. If the Central Government notifies the marketplace as a Significant Data Fiduciary under Section 10 based on the volume of transaction data processed, the compliance burden increases. The enterprise then has to appoint a Data Protection Officer based in India who reports directly to the Board of Directors.

What to Keep Versus What to Build for Compliance

Preparing for statutory audits requires enterprise legal teams to separate governance tasks from runtime technical enforcement. Legal departments keep control over the governance layer. This involves drafting vendor agreements, defining limitation of liability caps, and setting the legal retention periods for tax or warranty purposes. The legal head retains the authority over what constitutes a lawful purpose under Section 4 of the Act. The runtime enforcement requires technical solutions built or procured by the technology team. A marketplace CTO cannot expect outside counsel to manually compile Section 11 processor sharing reports every time a buyer submits a request. The enterprise needs a systemic registry that automatically maps a specific transaction to the exact logistics vendor that fulfilled it. When a request arrives, the platform queries this registry and exports a compliant summary without requiring hours of privileged legal review. This technical automation reduces outside counsel spend. It guarantees the marketplace meets statutory response timelines predictably.

Acceptance Tests for Procurement Teams

When the legal department evaluates compliance software to manage DPDP obligations, the General Counsel should demand specific acceptance tests. The first test validates the separation of consent purposes. A marketplace cannot force a user to accept marketing emails to complete a checkout. The platform needs to offer a Consent Unbundler that separates shipping data requirements from promotional data access. The second test involves regional language support mandated by the DPDP Rules, 2025. The procurement team evaluates whether the tool automatically presents itemised notices in 22 scheduled languages to serve Tier-2 and Tier-3 city customers effectively. The third test focuses directly on the Section 11 access right. The system has to prove it can instantly generate a report identifying which specific payment processor and courier received a test user data payload. If the software vendor cannot produce an automated, verifiable trail of these disclosures, the marketplace assumes the risk of non-compliance.

Addressing the Common Mistake Around Consent Withdrawal

A recurring error in e-commerce operations is treating a consent withdrawal as a global deletion command. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. If a customer revokes consent for promotional messaging, the marketplace stops sharing their contact details with external advertising processors. The legal team verifies that the underlying data architecture severs this marketing access instantly. This withdrawal does not force the marketplace to erase the entire customer profile. The enterprise retains transaction ledgers, shipping manifests, and payment records to comply with tax laws and manage fraud prevention. Section 4 defines a lawful purpose as any purpose not expressly forbidden by law. A well-configured compliance platform maps the user intent to the specific data purpose. The Chief Marketing Officer stops sending campaigns to that user. At the same time, the finance team safely retains the core purchase history for statutory audits.

Meeting the Statutory Enforcement Deadline

Enterprise legal heads face a strict timeline to enforce vendor accountability across their supply chains. Exactly 230 days remain until the DPDP hard compliance deadline of 13 May 2027. Before this date, a marketplace needs to renegotiate processor agreements, map data flows, and implement the technical scaffolding required to fulfill Section 11 access requests at scale. Waiting until the final quarter guarantees rushed implementations and exposed liability gaps. Regulator defensibility starts with proving that the enterprise has operationalized data rights at the system level. Legal teams evaluate specialized tooling that handles regional language notices and precise processor tracking without imposing massive operational overhead. Start mapping your marketplace data supply chain and explore automated enforcement at https://www.complydp.com/audit-preview today.

Sources

Frequently asked questions

Do we have to list every courier and seller under Section 11 of the DPDP Act?

Yes. Section 11(1)(b) requires a Data Fiduciary to provide the identities of all Data Processors and other fiduciaries who received the personal data. The marketplace must also describe the specific data shared with each of these third parties.

How fast must our marketplace respond to a Section 11 data sharing request?

The DPDP Rules, 2025 mandate that Data Fiduciaries establish verifiable mechanisms to respond to Data Principal requests without undue delay. Legal and technical teams need automated systems to meet these statutory timelines and avoid manual review bottlenecks.

What happens if a vendor loses customer data shared by our marketplace?

The marketplace remains the primary Data Fiduciary. Under the DPDP Rules, 2025, you are required to notify the affected Data Principals without delay and submit a detailed breach report to the Data Protection Board within 72 hours.

Does the DPDP Act allow us to require marketing consent to complete a purchase?

No. E-commerce platforms cannot make consent to promotional marketing a condition for providing shipping or checkout services. Marketplaces have to unbundle these purposes and allow customers to opt out of marketing while still receiving their orders.

When is the final deadline to implement Section 11 data tracking systems?

Enterprises have exactly 230 days remain until the DPDP hard compliance deadline of 13 May 2027. Marketplaces must update vendor contracts and deploy automated data tracing mechanisms before this date to avoid regulator penalties.