The Retailers Association of India (RAI) issues this advisory to guide its members in establishing a legally compliant, operationally sound, and customer-centric framework for obtaining, managing, and enforcing customer consent for the processing of personal data.
(Compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act))
With the enactment of the Digital Personal Data Protection Act, 2023, consent has become a central governance and compliance requirement for retail organizations operating in India. This advisory is to ensure that:
a) Customer data is processed lawfully, transparently, and ethically
b) Core retail operations (sales, service delivery, fulfilment) are not disrupted
c) The organisation remains compliant with the Digital Personal Data Protection Act, 2023 (DPDP Act), applicable Rules, and relevant sectoral regulations.
d) Institutional, operational, and legal risks are effectively mitigated
Under the DPDP Act 2023, consent is the primary lawful basis for processing personal data in India. In the retail context, customer information such as identity details, contact information, transaction history, payment details, and behavioural data qualifies as personal data and attracts statutory compliance obligations.
Members are advised to note that consent is no longer a routine checkbox or marketing formality. It is a core compliance and accountability control that determines:
a) The lawfulness of data processing activities
b) The organisation’s ability to demonstrate regulatory compliance during audits, inspections, or investigations
This advisory applies to all retail functions and business units where customer personal data is collected, processed, stored, or shared, including but not limited to:
a) Physical retail stores and point-of-sale (POS) systems
b) E-commerce platforms and mobile applications
c) Customer relationship management (CRM) systems
d) Loyalty programs and membership schemes
e) Marketing, promotions, and customer engagement initiatives
f) Payments, billing, refunds, and fraud prevention
g) Delivery, logistics, and fulfilment partners
h) Customer support, call centres, and grievance handling
i) Analytics, AI-enabled tools, and personalization engines
j) Third-party service providers handling customer data
Members are advised to ensure that all customer consent obtained meets the following standards:
a) Free – Given voluntarily, without coercion or denial of goods or services
b) Informed – Based on clear, understandable information regarding data usage; if data is shared with group entities or used for allied business interests, this must be explicitly disclosed
c) Specific – Linked to clearly defined and limited purposes
d) Unambiguous – Based on a clear affirmative action by the customer
e) Purpose-limited – Not extendable beyond the stated and agreed purposes
f) Revocable – Withdrawable by the customer at any time
All relevant purposes must be explicitly mentioned. A single blanket consent is insufficient to support multiple, unrelated, or evolving retail data uses.
Consent management is a continuous operational process, not a one-time document or form. It includes:
a) Informing customers, in clear commercial and legal terms, how their data will be used
b) Capturing, storing, and enforcing consent decisions across systems
c) Ensuring data access and processing aligns with the specific consent provided
Members should obtain consent separately, where applicable, for the following purposes:
a) Customer registration and account management
b) Processing sales transactions and order fulfilment
c) Payment processing, billing, refunds, and fraud prevention
d) Delivery, logistics coordination, and order tracking
e) Customer support, complaints, and after-sales service
f) Loyalty programs, reward points, and membership benefits
g) Marketing communications, promotions, and personalized offers
h) Sharing data with payment gateways, logistics partners, and service vendors
i) Processing by third-party platforms, aggregators, or service providers
j) Secondary use including analytics, business intelligence, research, AI-driven insights, and digital innovation
a) Digital mechanisms via websites, mobile applications, POS systems, or CRM platforms (including link-based acceptance or OTP validation)
b) Paper-based consent only where digital capture is not feasible, followed by timely entry into the system
Each consent notice must clearly state all applicable purposes listed in this document. The language shall be plain, consumer-friendly, operationally accurate, and legally precise.
Customers may withdraw consent at any time through:
a) Customer support or helpdesk channels
b) Digital customer portals or mobile applications (where available)
c) Written requests addressed to customer care
Upon Withdrawal:
a) Further processing for the withdrawn purpose must cease
b) Data required to be retained under applicable laws (tax, accounting, fraud prevention, or dispute resolution) shall be preserved
c) No new or secondary use shall occur beyond lawful retention requirements
d) Business continuity and legal compliance shall take precedence where mandated
Consent is not required where processing is necessary for:
a) Compliance with legal or regulatory obligations
b) Court orders or statutory directions
c) Fraud prevention, security incidents, or lawful investigations
d) Public interest or statutory reporting requirements
Members are advised to maintain auditable records evidencing:
a) Date and time of consent
b) Version of the consent notice provided
c) Purpose(s) consented to
d) Records of consent withdrawal, if any
Consent management shall be embedded into:
a) Retail IT systems, POS platforms, CRM, and digital channels
b) Access to customer data shall be governed by role-based and purpose-based controls
c) Systems shall prevent processing inconsistent with recorded consent
Members should clearly define responsibilities, including:
a) Legal & Compliance Team: - Policy oversight, regulatory interpretation, audits
b) IT and Systems Team: – System design, access controls, data security
c) Store Operations and Frontline Teams: – Accurate consent capture and customer communication
d) Marketing and Analytics Teams – Use of data strictly within consented purposes
Mandatory training shall be conducted for both operational and non-operational staff.
This document shall be:
a) Reviewed annually or upon regulatory change
b) Updated to reflect new technologies, business models, or workflows
c) Tested through internal audits, control assessments, and compliance reviews
Failure to implement effective consent management may expose the organization to:
a) Monetary penalties under the DPDP Act (up to INR 250 Crores)
b) Regulatory investigations and enforcement actions
c) Civil, consumer, and contractual litigation
d) Loss of customer trust and reputational damage
RAI advises all members to treat customer personal data protection as a strategic governance priority and to align internal policies, systems, and training programs with the principles outlined in this advisory.
This guidance is intended to support compliance readiness and operational resilience across the retail sector.
This advisory has been reviewed by the Advocacy Committee of the Retailers Association of India.
RAI places on record its sincere appreciation to Mr. G. R. Srikkanth for his valuable inputs, guidance, and support, and for kindly permitting the Association to develop and issue this advisory for the benefit of its members.
Your email address will not be published.