top of page

What to Do When an E-commerce Site Sells Your Data

Sep 11
6 min read

You buy a pair of shoes online. Two days later, a "loan approval" call comes in. Then a WhatsApp message about a "special offer" from a brand you've never heard of. Then five more calls, all from unknown numbers, all somehow knowing your name and that you shop online.

This isn't paranoia. It's one of the most common complaints Indian shoppers have about e-commerce today, and in many cases, it traces back to one thing: a platform selling or leaking your personal data to third parties, data brokers, or "marketing partners" without properly telling you.

If you suspect this has happened to you, here's what actually helps, and what's just noise.


First, figure out if your data was actually sold

It's easy to assume the worst the moment a spam call comes in, but not every unwanted call means a data sale. A few signs point more clearly to your e-commerce data being the source:

  • The calls or messages start soon after you place an order or create an account on a specific platform, and reference details only that platform would know (your order, your product interest, even your delivery address).

  • You used a unique or "tagged" email or phone number for that one site, and now it's getting contacted everywhere.

  • The platform's privacy policy quietly lists dozens of "partners," "affiliates," or "third-party advertisers" it shares data with.

  • A data breach involving that company has actually been reported in the news.

A good trick many people in India use: give a slightly different version of your name or a "+tag" in your email (like yourname+amazon@gmail.com) when signing up on different sites. If spam later arrives addressed to that exact tag, you know exactly which platform leaked it.


Step 1: Stop further damage first

Before you file complaints or send angry emails, plug the leak.

  • Go into the app and revoke permissions you don't actually need — contacts, location, SMS access. Many shopping apps ask for far more than they need to function.

  • Turn off "share data with partners" or "personalised ads" toggles in your account's privacy settings, if the platform offers them.

  • Change your password on that account, and anywhere else you reused it. If your email or phone number was part of the leak, be extra alert for phishing attempts that reference your recent orders.

  • If financial information (card details, UPI ID) might be involved, call your bank's fraud helpline immediately and consider blocking the card temporarily.


Step 2: Collect your evidence before it disappears

Complaints move faster and get taken more seriously with proof attached. Screenshot:

  • The spam calls, SMS, or WhatsApp messages, with timestamps and sender details.

  • The order or account details on the e-commerce platform showing when you signed up or purchased.

  • The platform's privacy policy page (save it as a PDF too, since these pages get edited quietly).

  • Any admission of a breach, if the company has made one publicly.

Keep a simple timeline: date you ordered, date the spam started, what the spam referenced. This becomes useful for every complaint you file next.


Step 3: Raise it directly with the company's Grievance Officer

Every e-commerce platform operating in India is legally required to appoint a Grievance Officer under the IT Rules, and their contact details must be published on the site, usually in the footer or the privacy policy page. This isn't the same as customer support — it's a specific escalation channel for exactly this kind of complaint.

Email them directly, lay out your evidence, and ask two things clearly: what data of yours was shared and with whom, and what action they're taking. Companies are required to respond within a set timeframe. Keep this email, since it becomes your paper trail if you need to escalate further.

If the Grievance Officer doesn't reply or you get a templated non-answer, don't stop here.


Step 4: Report it as a cyber complaint if fraud is involved

If the leaked data has been used for financial fraud, phishing attempts, or serious harassment, treat it as a cybercrime, not just a privacy annoyance.

  • Call 1930, the government's toll-free cyber fraud helpline, run by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs. This is especially important if any money has moved out of your account.

  • File a detailed complaint on cybercrime.gov.in, the National Cyber Crime Reporting Portal. You'll need your evidence from Step 2 for this.

  • If you called 1930 first, you generally have to complete the written complaint on the portal within 24 hours using the acknowledgement number sent by SMS.

Acting quickly matters here. Complaints filed within the first hour give banks and police a real chance to freeze fraudulent transactions before the money moves further.


Step 5: Use India's data protection law

India's Digital Personal Data Protection Act, 2023 (DPDP Act) is now the primary law governing this exact situation, and the DPDP Rules, 2025 were notified in November 2025, giving it a real implementation timeline. Under this law, companies (called "Data Fiduciaries") need your clear consent before sharing your personal data with third parties, and they're required to keep it secure.

A quick reality check as of 2026: the Data Protection Board of India, which will eventually hear individual complaints and issue penalties, has been legally established but isn't yet fully staffed and operational as an adjudicating body — MeitY only invited applications for the Board's Chairperson and Members in mid-2026. So while the law exists, the direct complaint mechanism to the Board is still coming online.

That doesn't leave you without options in the meantime. The older IT Act, 2000 (Section 43A) and the SPDI Rules, 2011 are still in force and already give you the right to seek compensation from a company that fails to maintain "reasonable security practices" for your sensitive personal data — this includes things like financial information, passwords, and health data. Keep an eye on the Data Protection Board's rollout, since once it's hearing complaints, this will become the more direct route for data-specific grievances.


Step 6: File a consumer complaint

Selling your data without consent, or misrepresenting how it would be used, is also a straightforward case of unfair trade practice under the Consumer Protection Act, 2019. You have a few practical routes:

  • National Consumer Helpline: call 1915 or use the UMANG app / consumerhelpline.gov.in to lodge a complaint. This is often faster than people expect, and it's free.

  • e-Daakhil portal (edaakhil.nic.in): file a formal case with the Consumer Disputes Redressal Commission if you want a legal order, and possibly compensation, and not just a resolution.

Consumer forums have, in the past, held e-commerce companies accountable for privacy violations and misuse of customer information, so this route has real teeth, not just symbolic value.


Step 7: Consider legal notice or a lawyer, if the harm is serious

If the leak has caused real financial loss, stalking, harassment, or identity theft, it's worth consulting a lawyer about sending a formal legal notice to the company, or pursuing damages. This is a bigger step, but for serious cases — especially involving financial fraud or safety threats — it's the one that gets companies to actually act instead of stalling with support tickets.


How to protect yourself going forward

You can't fully prevent a company from mishandling your data, but you can make yourself a harder, less useful target:

  • Use unique or "+tagged" emails per platform, so you can trace leaks back to the source.

  • Avoid saving card details on shopping apps; use UPI or pay-on-delivery where practical, or a virtual card with a spending limit.

  • Read the "data sharing" section of privacy policies before signing up on lesser-known platforms, especially ones offering deep discounts that seem too good to be true.

  • Turn off unnecessary app permissions right after installing any shopping app.

  • Check your account's data/privacy settings every few months — these toggles quietly get reset after app updates more often than people realise.


The bottom line

A single spam call isn't proof of anything. A pattern of spam that starts right after you use a specific platform, referencing details only that platform had, is worth acting on. Lock down your account first, gather your evidence, go through the company's own grievance channel, and if that doesn't move, escalate to cybercrime authorities, consumer forums, or a lawyer depending on how serious the harm is. India's data protection law is still filling in its enforcement machinery, but you already have real, working channels — you just have to use the right one for your situation.

Comments


GuidanceHubLegal

​

The law is everywhere. We uncover what often goes unnoticed.

 

Explore laws, rights, legal developments, and overlooked legal questions across India and the United States.

Explore:

​

Home

About

Blog

bottom of page