The Practice |
To fulfil customer orders, the operations team shares customer name, address, phone number, and order details with third-party logistics and delivery partners. Delivery partners retain this data in their own systems well beyond the delivery window, and in some cases the same data is visible to individual delivery personnel through their own mobile apps with no expiry.
Questions Raised for Compliance Review |
- Does sharing customer fulfilment data with logistics partners require anything beyond the standard order-processing relationship under DPDP?
- What risks arise from delivery partner retention practices and delivery-personnel-level access to customer data?
- What is the compliant approach to managing customer data shared with logistics and delivery partners?
Is This Permitted Under DPDP? |
Permissible for the immediate delivery purpose — but current retention and access practices at the partner level exceed what is compliant.
Sharing name, address, and phone number with a delivery partner is a necessary and expected part of order fulfilment, and customers reasonably anticipate this when placing an order. However, DPDP requires that this data be used only for the fulfilment purpose and not retained or accessed beyond what that purpose requires — a requirement the delivery partner's own retention and access practices routinely exceed.
Where the Breach Risks Sit |
- No retention limit imposed on the delivery partner — Once a delivery is complete, the customer's address and contact information typically remains in the logistics partner's systems indefinitely, retained for the partner's own operational or analytical purposes rather than the specific delivery the organisation contracted for.
- Delivery personnel access persists after delivery — Individual delivery personnel, through their own mobile apps, may retain visibility into a customer's address and phone number well after the delivery is complete, with no automatic expiry of that access once the order is closed.
- Sub-contracted delivery networks add an additional layer — Logistics partners frequently operate through their own network of local delivery sub-contractors or gig workers, meaning the organisation's customer data may pass through a chain of parties beyond the primary contracted logistics partner, most of whom have no direct agreement with the organisation.
- No contractual limit on the partner's use of the data for its own purposes — Without specific restriction, a logistics partner may use accumulated customer address and order data for its own analytics, route optimisation modelling, or even cross-selling of its own services, none of which the customer agreed to when placing the order.
The Ideal Compliant Approach |
- Execute a DPDP-specific DPA with every logistics partner. The agreement should define the purpose (fulfilment only), require deletion of customer data within a defined period after delivery, and prohibit use of the data for the partner's own independent purposes.
- Require expiry of delivery-personnel-level access. Work with the logistics partner to ensure delivery personnel's app-level access to a specific customer's address and phone number expires automatically once that delivery is marked complete.
- Extend obligations through the sub-contractor chain. Require the primary logistics partner to flow down the same data handling obligations to any sub-contracted delivery network it uses, and confirm this contractually rather than assuming it occurs by default.
- Share only what fulfilment requires. Limit the data shared with the logistics partner to name, delivery address, and contact number necessary for that delivery — avoiding transfer of full order history, customer account details, or unrelated profile information.
DPDP Risk Summary
| Element | Status | Recommended Action |
|---|---|---|
| No retention limit on logistics partner | Data Retention & Deletion gap | Mandate deletion within defined period post-delivery in DPA |
| Delivery personnel access persists post-delivery | Access Control Failures | Require automatic access expiry on delivery completion |
| Sub-contracted delivery networks receive customer data | Vendor / Processor Risk | Flow down obligations contractually through sub-contractor chain |
| No restriction on partner's independent use of data | Purpose Limitation gap | Restrict use to fulfilment purpose only in DPA |
| Full order/account data shared beyond delivery need | Exceeds necessity | Limit shared data to name, address, contact number only |