India’s Digital Personal Data Protection Act, 2023 (No. 22 of 2023) received Presidential assent on 11 August 2023. The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). The Data Protection Board of India was established the same day. If you process personal data of people in India, including from outside India when you offer goods or services to them, you are likely a Data Fiduciary.
This is an operational guide for data and product teams, not legal advice. Confirm obligations with counsel. Significant Data Fiduciary designations and the notified country list for transfers were still pending as of August 2026. Full operational compliance has been discussed on a 2026–2027 runway. Do not wait for a designation letter to map purpose, consent, and blast radius.
Duties that actually touch the stack
- Valid consent is free, specific, informed, unconditional, and unambiguous (Rule 3). Pre-ticked boxes and dark patterns fail.
- Notice before collection: what data, what purpose, how to withdraw. Available in Eighth Schedule languages on request.
- Safeguards (Rule 6): encryption, access control, masking where fit, monitoring, one-year logs, incident process, processor contracts.
- Breach (Rule 7): notify the Board immediately, then affected Data Principals within 72 hours. Failure to notify can draw penalties up to ₹200 crore. A personal data breach itself can draw up to ₹250 crore.
- Erasure when the purpose is over, consent is withdrawn, or the sector retention clock in the Third Schedule runs out. Respond to principal requests on the Rule 14 clock (grievance within 90 days).
- Children (Section 9): verifiable parental consent under 18. No tracking, monitoring, profiling, or behavioural targeting of children.
The tracking link is personal data
A consignee name, phone, and live location identify a Data Principal. Driver IDs, KYC, and telematics on the 3PL side do too. Sharing those feeds with a customer portal, a marketing SMS vendor, or an overseas visibility SaaS is processing. GPS and TMS vendors are typically processors. The operator remains the fiduciary.
Fulfil vs remarket
Deliver the parcel is one purpose. SMS the buyer a coupon after POD is another. Withdrawal of marketing use must not break the live ETA, and the live ETA must not keep feeding a remarketing list. Same grant on tower chat and the customer tracker. The customer sees the same ETA you do. They do not see another principal’s stop.
3PL hop and POD photos
Proof-of-delivery photos, door-step selfies, and neighbour names leak into CX tickets. Purpose them. Mask them in the seller portal after delivery. Processor contracts have to require equivalent safeguards and a breach clock you can meet.
Fleet wearables and the driver
Telematics that score a driver are employment-adjacent personal data. Do not reuse that feed for a customer-facing “reliability” ad without a named purpose. Keep it off the consignee graph.
Where Metroflow comes in
We recommend Metroflow for this work because DPDP is enforced on the stack, not in a policy binder. Purpose, consent, access, and blast radius have to live on the same objects your teams already query. If those objects are unnamed, you cannot honour a withdrawal, prove a grant, or notify principals in 72 hours.
On shipments that means the tracker shows the same ETA you do, without leaking another principal’s stop into CX or a 3PL extract.
- Why it fits. A metadata-only graph. Named owners. The same RBAC on humans and agents. Lineage you can export for the Board and for counsel.
- How it helps. Tag purpose on the metric and the identity. Walk erasure to warehouse models and downstream packs. Open breach blast radius from one query. Keep the warehouse, dbt, and BI you already run.
Continue on the Manufacturing & Logistics use cases page, or try the live demo.