Consumer Protection (E-Commerce) (Amendment) Rules, 2026: Recalibrating E-Commerce Compliance Across the Indian Data Privacy Framework

September 17, 2026
Consumer Protection Rule

By Vikrant Rana, Anuradha Gandhi and Rishabh Gupta

Introduction

The Department of Consumer Affairs, Government of India, has amended the Consumer Protection (E-Commerce) Rules, 2020 through the Consumer Protection (E-Commerce) (Amendment) Rules, 2026, with the objective of strengthening consumer protection while facilitating a transparent and balanced regulatory framework for the e-commerce sector.[1]

The Amendment Rules will come into force with effect from January 1, 2027, giving e-commerce entities and marketplace platforms a compliance runway of roughly four months from the date of the notification.

The Amendment Rules substantially recast the disclosure, ranking, pricing, grievance-redressal and data-use obligations placed on e-commerce entities and marketplace e-commerce entities, and for the first time expressly weave the Guidelines for Prevention and Regulation of Dark Patterns, 2023 into a binding rule-based compliance obligation. Several of the changes also have a direct bearing on obligations that will separately arise for these entities as “Data Fiduciaries” under the Digital Personal Data Protection Act, 2023 (“DPDP Act”), and intersect with existing obligations under the Information Technology Act, 2000 (“IT Act”) and the SPDI Rules, 2011.

Key Amendments at a Glance from Data Privacy Perspective

  • Consolidated disclosure obligations [Rule 4(4)]: every e-commerce entity must prominently display its legal name, principal geographic address of its headquarters and all branches, website details, and contact details (e-mail, landline and mobile) of both customer care and the grievance officer.
  • Grievance-redressal timelines [Rule 4(5)]: the grievance officer must acknowledge a consumer complaint within 48 hours, furnish the complainant a copy of the recorded complaint, and redress it within one month of receipt.
  • Dark patterns compliance [new Rule 4(15)]: mandatory compliance with the Guidelines for Prevention and Regulation of Dark Patterns, 2023, a yearly self-audit, and prominent display of a compliance certificate.
  • Restriction on use of consumer data [new Rule 5(6)]: a marketplace e-commerce entity cannot use information it collects to sell goods, directly or indirectly, under a brand or name common with its own, or to project any seller as “associated” with it, without the affected consumer’s express and affirmative consent.

Nexus with the DPDP Act, 2023

The new Rule 5(6) states that, “ No marketplace e-commerce entity shall use information collected by it to promote or advertise any seller as being associated with the marketplace ecommerce entity, unless the marketplace e-commerce entity has obtained the express and affirmative consent for such use from the consumer(s) to whom such information pertains”.

This Rule prohibits an e-commerce marketplace from using a consumer’s data (such as browsing history, search history, or purchase data) to promote or advertise a particular seller as being associated with the marketplace unless the consumer has given express and affirmative consent for that specific use. Since this requirement aligns with the DPDP Act’s consent framework, any consent must be clear, informed, specific, and obtained for that particular marketing purpose. Therefore, if a marketplace uses customer data collected for operating the platform and later repurposes it to market sellers or private-label products without obtaining separate consent, it may face:

  1. Regulatory action under the E-commerce Rules and Consumer Protection Act, 2019 for unfair trade practices – Section 20 of Consumer Protection Act, 2019 empowers the Central Authority to pass orders of discontinuation of practices which are unfair and prejudicial to consumers’ interest. Punishment for failure to comply with such directions is dealt with under section 88 of the Consumer Protection Act, 2019.[2]
  2. Non-compliance under the DPDP Act for violating purpose limitation and consent requirements which may lead to monetary penalties up to INR 50 crore.[3]

Nexus with the IT Act, 2000 and the SPDI Rules, 2011

The amendment strengthens consumer grievance handling and reinforces existing data protection obligations under the IT Act.

  1. Grievance Redressal: The grievance redressal timelines prescribed under the amended E-Commerce Rules differ from those applicable to “Intermediaries” under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. While intermediaries are required to acknowledge complaints within twenty-fours (24) hours and resolve them within seven (7) days of receipt[4], e-commerce entities are required to acknowledge complaints within forty-eight (48) hours, provide a record of the complaint, and redress the grievance within one (1) month.
  2. Practical Impact: A practical challenge may arise for platforms that simultaneously operate as an intermediary and an e-commerce entity, such as Amazon, Flipkart, Myntra etc. since the grievance redressal timelines prescribed under the two regulatory frameworks are not identical. In such cases, as a matter of compliance best practice and regulatory risk mitigation, organizations should align their grievance redressal framework with the stricter standard prescribed under the Intermediary Guidelines to ensure compliance with both regimes.

Further, E-commerce entities should review their data-sharing practices with sellers, payment partners, and logistics providers to ensure that personal data is collected, used, disclosed, and secured only for legitimate purposes.

Nexus with the Dark Patterns Guidelines, 2023

The most significant structural change is the elevation of dark-pattern compliance from a CCPA guideline-based obligation into a binding, rules-based requirement. New Rule 4(15) mandates compliance with the Guidelines for Prevention and Regulation of Dark Patterns, 2023 (“Dark Patterns Guidelines”)[5], a yearly self-audit, and prominent display of a compliance certificate.

The introduction of Rule 4(15) builds upon and significantly strengthens the existing consumer protection framework under the E-Commerce Rules.

This rule has strengthen the earlier provision under the E-commerce Rules, which states that, No e-commerce entity shall – manipulate the price of the goods or services offered on its platform in such a manner as to gain unreasonable profit by imposing on consumers any unjustified price having regard to the prevailing market conditions, the essential nature of the good or service, any extraordinary circumstances under which the good or service is offered, and any other relevant consideration in determining whether the price charged is justified.[6]

Accordingly, e-commerce entities are now expressly required to comply with the Dark Patterns Guidelines, 2023, which defines thirteen types of dark patterns under Annexure 1[7] and undertake annual self-audits, and prominently display a compliance certificate, thereby transforming what was previously a largely principle-based obligation into a codified and auditable compliance requirement.

Compliance Action Points Before January 1, 2027

  • Review consent flows and privacy notices to obtain express, affirmative, purpose-specific consent before re-purposing consumer data for private-label sales or seller-association promotion, and cross-check against DPDP Act consent standards.
  • Revisit data-sharing arrangements with sellers, payment aggregators and logistics partners, and the “reasonable security practices and procedures” maintained under the SPDI Rules, 2011, for the additional personal data and sensitive personal data fields now required to be collected, stored and disclosed under Rules 4 and 5.

Conclusion

While framed as a consumer protection measure, the 2026 Amendment Rules materially deepen the data privacy obligations of e-commerce entities. The new restriction on using consumer information for private-label sales or unauthorised seller-association promotion effectively imports the DPDP Act’s consent standard  directly proportional to the purpose specified, into a Consumer Protection Act enforcement track, ahead of the DPDP Act’s substantive provisions and the Digital Personal Data Protection Rules, 2025 becoming fully operational. E-commerce entities and marketplace platforms should use the runway to January 1, 2027 to align their consent architecture, privacy notices and data-sharing practices under the SPDI Rules, 2011 with DPDP Act standards now, rather than treating DPDP Act readiness as a separate, later exercise.

[1] https://consumeraffairs.gov.in/public/upload/files/E%20Commerce%20Amendment%20Rules%202026_1789127949.pdf

[2] Failure to comply with the direction of the Central Authority under section 20 may lead to imprisonment for a term which may extend to six months or with fine which may extend to twenty lakh rupees, or with both. (Section 88 of Consumer Protection Act, 2019)

[3] DPDP Act 2023, Schedule

[4] Rule 3(2)(i) of Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021

[5] https://ccpa.doca.gov.in/files/The%20Guidelines%20for%20Prevention%20and%20Regulation%20of%20Dark%20Patterns,%202023_1732707717.pdf

[6] Rule 4(11)(a) of Consumer Protection E-commerce Rules, 2020

[7] https://ccpa.doca.gov.in/files/The%20Guidelines%20for%20Prevention%20and%20Regulation%20of%20Dark%20Patterns,%202023_1732707717.pdf

For more information please contact us at : info@ssrana.com