Home / Sectors / Retail and D2C
Retail is the sector where the volume of personal data is highest and the controls are usually thinnest, because everything was built for growth and nothing was built for deletion.
The Act applies to every organisation that holds personal data. What reasonable looks like changes a great deal by sector, and this is what it changes to here.
What makes this sector different
An online store holds customer accounts, order history, delivery addresses, phone numbers, payment references and a long trail of browsing behaviour shared with advertising platforms. A brand with a loyalty programme holds considerably more.
The specific problem in this sector is that most of the data leaves. It goes to a courier, a payment provider, a marketing platform, an advertising network and a support tool, and in a surprising number of businesses nobody has written down the full list.
Where personal data usually sits
Drawn from engagements and from the questions that come up most often on first calls in this sector.
| System | What it holds | What usually needs attention |
|---|---|---|
| Store platform | Accounts, order history, delivery addresses, phone numbers | Customers cannot actually delete their account from the interface |
| Marketing stack | Email lists, WhatsApp broadcast lists, abandoned cart data, segments | Lists imported, bought or scraped with no consent record |
| Advertising pixels | Browsing and purchase behaviour shared with advertising platforms | Tracking fires before anyone agrees to it |
| Logistics partners | Name, address and phone passed to couriers and delivery partners | No written data terms with the parties receiving it |
| Payments | Transaction references, sometimes saved cards and UPI handles | Nobody has confirmed what the gateway stores and for how long |
| Support and returns | Complaints, chat transcripts, call recordings, images customers send | Recordings and transcripts kept forever, with no notice given |
What we look at first here
Deletion that is not really deletion. Most store platforms deactivate rather than delete, and the marketing platform keeps its own copy regardless.
Pixels firing before consent. Tracking usually starts on page load, which means it has already happened by the time anyone is asked.
WhatsApp broadcast lists. Built over years from orders, events and imports, with no record of who agreed to what.
The courier layer. Customer name, address and phone go to a logistics partner on every order, and the contract usually covers delivery times and nothing else.
Advertising agency access. Agencies often hold admin access to your advertising accounts and customer lists long after the campaign ended.
Which steps carry the most weight
The full sequence is on the engagement page. In this sector, these three usually do the heavy lifting.
Discovery and mapping
We follow one order from checkout through to delivery and support, and list every system and third party it touches.
Compliance Support
Consent at the right moment rather than at page load, notices that match what the pixels actually do, and a deletion route that works end to end.
Implementation support
This sector needs developer work. We give your team or your agency a ticket level plan and review each item as it goes live.
Retail is the sector where a consent tool is most often bought first and mapped later. If you already have one, we will work with it rather than replacing it, and we will tell you plainly where it is configured around guesses.
Not quite your business?
Every engagement is scoped to what you actually run, so none of these pages will match you exactly.
Thirty minutes, and you will know where you stand.
Tell us what your business runs on. We will tell you which gaps matter most, whether or not you engage us.