Chapter 32 — Retail, E-Commerce, Advertising and Loyalty Sector Playbook
1. When reuse becomes the business proposal
A purchase establishes a commercial relationship, not unrestricted permission to use everything learned through it. Retail makes that distinction uncomfortable because recommendations, audience creation, loyalty programmes and advertising often draw on the same data pipeline. A useful implementation programme does not simply rename that pipeline “customer experience.” It asks which use the person requested, which additional use is proposed, and what authority supports each.
This chapter retains the purpose matrix and refusal example from the original playbook but rejects its teen-targeting campaign. The central operating principle is that a downstream use needs its own recorded ground decision. That does not mean every transformation is legally a new purpose or needs a separate checkbox. It means the owner must establish whether the transformation remains within the specific authorised purpose rather than assume collection grants unrestricted reuse.
DPDP s4 permits processing for a lawful purpose on consent or the defined legitimate uses, subject to the rest of the Act; it does not supply GDPR’s general legitimate-interests balancing ground (ACT:160–166,269–329).[1] The scoped examples assume the retained core commencement schedule remains unchanged, with core obligations and rights scheduled for 13 May 2027. The Gazette notification, Rules commencement and corrigendum are separate source facts, not evidence that all these duties already operate on the research date (COMM:19,49–59; RULES:1005–1010; CORR:25–38).[2][3][4]
Retail includes businesses whose service can work without behavioural advertising. Avoid treating every retailer as a data broker or every recommendation as inherently unlawful. The practical choice is between a justified use and an unsupported one, not between commerce and privacy. A non-personalised catalogue, a requested receipt and an opt-in adult recommendation feed have different processing requirements and can coexist.
2. Establish the initial ground honestly
Section 7(a) requires that the principal voluntarily provided her personal data for the specified purpose and has not indicated non-consent. Mentioning order fulfilment in a notice is insufficient by itself (ACT:269–284).[1] For the hypothetical requested receipt PUR-007, the adult provides her contact information and asks for that receipt. The fact record contains the request, the purpose and absence of a contrary indication. It does not silently extend that permission to a partner’s lookalike audience.
For a consent-based personalisation flow, s6 requires a free, specific, informed, unconditional and unambiguous affirmative agreement limited to necessary data. Part of a consent that infringes the Act or other law is invalid to that extent (ACT:206–218).[1]
The author-recommended design separates the optional feed from essential account functions and records the notice version, purpose, relevant data, affirmative action and current authority state. The law does not mandate a field literally named consent_hash. A hash can help locate and verify an evidence object; it is not the object and does not prove the interface was understandable.
A legacy feed needs special care. Section 5(2)‘s notice pathway concerns processing for which consent was given before commencement and permits continuation until withdrawal. It does not retrospectively legalise profiles originally collected without consent, and it does not add a new purpose to an old grant (ACT:182–205).[1] The hypothetical retailer segregates documented prior-consent processing from unsupported historical data. It pauses the latter’s use pending a lawful decision. No assumption is made that every customer will agree to the new feed or that the business loses nothing by restricting it.
3. Roles follow the activity, not the vendor category
A Data Fiduciary determines purpose and means, alone or with others; a Data Processor processes on behalf. A valid processor contract is required within s8(2)‘s engagement scope, and the fiduciary retains its own responsibility under s8(1) (ACT:65–81,330–337).[1] The retailer therefore asks the supplier what it actually does with identifiers, segments and inferred interests. The answer cannot be inferred from the words “agency,” “CDP,” “measurement” or “SaaS.”
| Hypothetical activity | Role facts | Decision and recommended evidence |
|---|---|---|
| ENT-101 sets its loyalty purpose and programme rules | Retailer determines purpose and means | Fiduciary; record its ground and accountable owner |
| Hosted points calculation under retailer instructions, no own reuse | Supplier acts on behalf | Processor activity; scoped contract and access controls |
| Agency runs the retailer’s adult campaign only | Agency acts on documented instructions | Processor activity only within those facts; no independent audience product |
| Measurement partner builds its own cross-client model | Partner determines a separate purpose | Separate fiduciary analysis; proposed export refused absent authority |
| Broker offers supposedly anonymous segments | Identifiability is unestablished | Treat as personal data until the assessment supports exclusion; do not approve on the label |
This table is an authored role assessment under stipulated facts, not a statutory vendor taxonomy. A supplier may occupy both roles across activities. An agency’s own reuse cannot be made lawful by inserting a subprocessor clause, and its inability to store a consent hash is not the legal reason a new consent may be needed. The substantive questions are purpose, data, authority, actual recipients and restrictions.
Information about an identifiable individual remains personal data; merely removing names does not establish anonymity (ACT:113–118).[1] If an output is genuinely non-personal, document how that conclusion was reached and the relevant linkage risks. The processing used to create that output still needs its own lawful assessment. The chapter offers no anonymity test or certification; a broker’s assertion alone is a failed evidence gate.
Sharing also affects the access service. For eligible prior-consent processing, s11(1)(b) concerns identities of other fiduciaries and processors and a description of shared personal data; s11(2)‘s specific exception is not blanket secrecy (ACT:441–462).[1] A recipient inventory must include independent recipients as well as processors. The recommended sharing record captures activity, recipient, categories, purpose, authority decision and delivery status. It should not scatter full consent evidence or unnecessary customer identifiers throughout the ad chain merely to prove a linkage.
4. The teen guard is a prohibition gate
A child is below eighteen. Verifiable parental consent under s9(1), the detrimental-effect restriction under s9(2), and the tracking/behavioural-monitoring/targeted-advertising prohibition under s9(3) are separate requirements. Prescribed or notification-based relief under s9(4)/(5) concerns (1)/(3), not (2) (ACT:63–64,386–403).[1] The retailer cannot convert parental agreement into an exception. Nor does s7(b), concerning qualifying State benefits and services, provide an age-group marketing ground (ACT:285–302).[1]
Rule 10 specifies due diligence for checking that the person identifying herself as the parent is an identifiable adult through the stated identity/age routes. An adult identity token does not itself resolve a disputed relationship. Rule 11 concerns the covered disability/lawful-guardian case, not a universal second parental verification step (RULES:1173–1267).[3] The author-recommended implementation keeps the child subject separate from the acting adult and records unresolved authority disputes. It does not require a child’s government identifier simply because the vendor’s default form asks for one.
Rule 12 and the Fourth Schedule supply conditional exceptions. The necessary age-confirmation/due-diligence purpose in Part B6 is not permission to build a marketing profile from verification data (RULES:1269–1275,1744–1746).[3] No child-marketing exception is established for CASE-101. Its policy therefore refuses targeting and behavioural monitoring for children even with a valid parental token. Unknown or disputed age also takes the non-targeted route as a conservative design choice, not a statutory rule that every unknown person is a child.
Short duration is not an escape hatch. A behavioural profile can be prohibited even if it lasts only a session. Deleting an identifier after an hour does not undo tracking during that hour. A push-message disclaimer or guardian opt-out cannot retrospectively authorise a prohibited targeted advertisement. These distinctions shape the replacement campaign and its negative fixtures.
5. Festival sale: adult-only targeting and a separate child path
CASE-101 / ENT-101 is a fictional retail marketplace. SUB-004 is the child; SUB-005 is the claimed parent. The case is separate from CASE-001, which offers no lending or targeted marketing service to children. No live age-classification accuracy or campaign result is available. The former “less than two percent” error threshold is withdrawn rather than presented as a sector requirement.
The business proposes personalised sale recommendations based on purchase history. The new decision record DEC-002 rejects PUR-011 for the child audience despite a stipulated valid parental-consent token. For verified adults, the recommendation route also requires separately valid marketing authority and permitted data and recipients. An adult age result without consent is denied; consent without established adult eligibility is denied. These are two separate gates, not one combined “eligible user” flag.
For child and unresolved-age users, the proposed experience is a general catalogue without behavioural personalisation or advertising trackers. Ordinary purchase/account processing, if offered, still needs its applicable ground, parental-consent or exception assessment and security controls. Calling the page non-targeted does not make all its server logs non-personal or dispense with the child rules. The design recommendation is to keep security-purpose evidence out of advertising features and to avoid unnecessary identifiers in the public catalogue route.
The test specification follows the entire route: first-party feature reads, ad request creation, SDK loading, event transmission, agency export and delayed queues. An interface that hides personalised cards while emitting browsing identifiers still fails. The delivered local fixture tests the decision predicate, not a browser or SDK. Before an actual launch, the owner would need observed network traces and build/configuration evidence across the stated routes. A unit test cannot prove population-wide absence of tracking.
A failed guard is investigated as both a compliance defect and a potential incident. Whether it is a personal-data breach requires the separate s2(u) assessment of unauthorised processing or the listed accidental events compromising confidentiality, integrity or availability. An authorised external disclosure is not automatically a breach; a genuine breach is not excused simply because the guard was intended to work (ACT:115–118,348–350).[1] Where r7 is operative and a breach is established, the initial Board and affected-principal notices are without delay, and the detailed Board update has its distinct seventy-two-hour rule (RULES:1112–1139).[3] The case does not send notifications or claim a penalty has been avoided.
6. Withdrawal, evidence and loyalty value are different objects
A marketing withdrawal is an event by the person, not the calendar end of a promotion. Section 6(4) requires comparable ease; s6(6) requires cessation and processor cessation within a reasonable time, subject to its required/authorised non-consent processing qualification. Prior lawful processing is unaffected (ACT:232–249).[1] An author-recommended immediate marketing gate is a useful operational target, but is not the Act’s literal universal deadline. The renderer should check current authority again for a queued message rather than trust its old audience selection.
Suppose an adult withdraws after audience export but before message dispatch. The specimen sets the marketing authority inactive, denies new dispatch, sends a scoped cessation instruction and leaves completion pending until the relevant processing state is known. A missing processor acknowledgement is not a deletion receipt. An independent recipient’s obligations need their own handling; it cannot be treated as a cancellable internal job merely because the retailer originally supplied the data.
Physical disposal is separately qualified by s8(7), r6(1)(e) and r8(3). The last provision requires a minimum one-year retention of the specified data and processing logs for Seventh Schedule purposes, followed by erasure unless further retention is required under its stated conditions (ACT:351–385; RULES:1101–1106,1153–1166).[1][3] Retained evidence is restricted to its permitted use, not quietly returned to the recommendation store. No universal seven-year banking period is imported into a retail chain. The retention owner must establish the particular commercial, legal and archive classes and where required copies live.
The Third Schedule’s inactivity rule is also not a general marketing retention licence. Its e-commerce class uses the specified registered-user threshold and excludes account-access and virtual-token-access purposes; the period and approach/rights conditions must be read together with r8’s notice and other-law qualifications (RULES:1142–1166,1598–1680).[3] CASE-101 does not assume a threshold classification from the word “major retailer.” The overlay marks that applicability as requiring actual entity counts and activity facts.
Loyalty points are not consent records. The campaign’s end does not by itself mandate clawing back earned points or deleting audit logs. The programme owner must distinguish contractual benefits, monetary/accounting records, marketing projections and evidence. A benefits dispute is routed for its own decision; privacy withdrawal is not used as a punitive shortcut. This is a recommended customer-service safeguard, not an invented DPDP rewards rule.
7. Two decisions with different commercial outcomes
In the first hypothetical walkthrough, an adult recommendation feed has documented authority for the specific purchase and browsing uses. The team limits its feature access, records the approved recipient configuration and supplies a comparable withdrawal route. The proposed launch remains conditional on technical evidence. No statement is made that all historic data is usable, that the feed is statistically effective or that a Board would accept it.
In the second, a partner asks for the loyalty cohort to build its own lookalike product. The original grant covers the retailer’s marketing, not the partner’s independent purpose. The proposed export is refused. A future adult-only, necessary-data collection and consent design may be evaluated, but naming the partner on a screen is not sufficient by itself. It must meet the actual consent standard and any other applicable restriction. The child cohort remains excluded even if the business argues that a new guardian checkbox would recover the lost revenue.
The useful consulting output is not a universal ban or a universal approval. It is a reasoned comparison of the alternatives: a less data-intensive contextual offer; a properly scoped adult opt-in flow; or stopping the proposed partnership. Each has different expected commercial costs, which this chapter does not quantify without evidence. Product owners should record those trade-offs honestly instead of portraying every privacy restriction as costless.
8. Deliverable and exercise
The sector workbook, Q06_DECISIONS.json and local tests are linked from out/sector/README.md. They contain the refusal, adult consent/age distinction, supplier-role branch and separate withdrawal/retention decisions. They are hypothetical records and local decision checks, not vendor capability evidence. The test report states what actually ran; observed SDK, production or campaign results are not supplied.
For the reader exercise, inspect a family-account design in which the parent’s account is adult but the browsing subject is the child. Decide whose data drives the advertisement, which subject identity the gate receives, whether verification is being reused, and which recipient gets the event. Then add a stale queued message after withdrawal and a missing supplier acknowledgement. A satisfactory workpaper cannot answer merely “parent consent present.” It must explain why each use is permitted or denied and what remains unverified.
Remaining application questions are the retailer’s actual age-assurance evidence, any exact exception or later notification it proposes to rely on, its legal retention classes and supplier implementation. The retained Rules’ exemption text is no longer deferred as unread. None of those entity-specific questions permits the rejected teen-targeting flow. Chapter 33 applies the same distinction between helpful intent and actual authority to care and education.
Source locator key
Ranges above are physical newline lines, starting at 1; PDF form feeds do not add lines. Full source URLs follow. The retained text and hashes are indexed in out/remediation/Q06/source-index.json.
- ACT:
research/legal/evidence/01_dpdp_act_2023_gazette.txt. - COMM:
research/legal/evidence/02_gsr_843e_commencement.txt. - RULES:
research/legal/evidence/05_gsr_846e_dpdp_rules_2025.txt. - CORR:
research/legal/evidence/06_gsr_892e_corrigendum.txt.
Sources
[1] https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf — ACT [2] https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf — COMM [3] https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf — RULES [4] https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf — CORR
Contents · Reader guide and citation conventions · Artifact index