Overview
Nykaa is Indiaโs leading beauty and personal care e-commerce platform. Unlike general e-commerce, Nykaa collects uniquely personal data: skin type assessments, beauty concern questionnaires, dermatological conditions, hair type profiles, and increasingly, facial geometry data through virtual try-on features. This data crosses into health and biometric territory.
DPDP Readiness: Section-by-Section Analysis
Section 6 โ Consent & Notice ๐ด
Nykaa collects data that borders on health information:
- Skin type questionnaires: Acne-prone, dry, oily, sensitive
- Beauty concerns: Pigmentation, aging, conditions like eczema or rosacea
- Face scanning: AR-powered virtual try-on captures facial geometry
Under DPDP, while โpersonal dataโ is broadly defined, the intimate nature of this data demands higher consent standards than a standard e-commerce platform.
Gap: All data processing is covered by a single consent during account creation. No separate consent for beauty profiling, skin assessments, or facial scanning.
Section 7 โ Certain Legitimate Uses ๐ด
Nykaa uses beauty profile data for:
- Product recommendations (reasonable)
- Third-party brand partnerships (questionable)
- Targeted advertising (should require separate consent)
Gap: Sharing skin condition data with beauty brand partners goes well beyond legitimate use.
Section 8 โ Obligations of Data Fiduciary โ ๏ธ
Standard security measures. However, no specific mention of additional protections for:
- Facial geometry data (biometric-adjacent)
- Health-related beauty data (skin conditions)
- Virtual try-on image processing and storage
Section 9 โ Data Retention ๐ด
No retention timelines for:
- Beauty profile assessments
- Skin type and concern data
- Virtual try-on facial scans
- Purchase history linked to health conditions (e.g., dermatological products)
Critical concern: If a user buys acne medication, is that purchase history โ which reveals health information โ retained indefinitely?
Section 11 โ Rights of Data Principal ๐ด
- No mechanism to delete beauty profiles while keeping the account
- No right to opt out of beauty recommendation algorithms
- No access to understand how skin data influences whatโs shown
- No nomination rights
Section 12 โ Right of Grievance Redressal โ ๏ธ
Basic grievance mechanism without DPB escalation.
Section 16 โ Cross-Border Data Transfer โ ๏ธ
Cloud infrastructure and beauty brand partnerships may involve international data transfer. The policy lacks specificity on which data crosses borders.
Risk Assessment
| Category | Risk Level | Potential Impact |
|---|---|---|
| Regulatory fine | High | Up to โน250 Cr |
| Health-adjacent data handling | Critical | Beauty/skin data borders on health information |
| Facial geometry data | Critical | Virtual try-on captures biometric-adjacent data |
| Brand partnership sharing | High | Skin condition data shared with third-party brands |
| Data retention | High | Health-revealing purchase history retained indefinitely |
The Beauty Data Problem
Nykaa sits in a gray zone between e-commerce and health data:
| Data Type | E-commerce Standard | Health/DPDP Standard | Nykaaโs Practice |
|---|---|---|---|
| Purchase history | Standard | Health-revealing if dermatological | Treated as standard |
| Skin assessments | N/A | Health data equivalent | No extra protection |
| Face scans | N/A | Biometric-adjacent | Handling undefined |
| Beauty concerns | Preference data | Health condition indicators | No separate consent |
Recommendations
- Classify beauty data as sensitive โ Implement enhanced protections for skin type, beauty concerns, and facial scan data
- Separate consent for beauty profiling โ โUse basic product browsing [required]. Share skin profile for personalized recommendations? [optional]โ
- Define facial scan data policy โ โVirtual try-on images are processed locally and never stored on our serversโ or similar clear commitment
- Restrict brand data sharing โ Donโt share individual-level skin condition data with brand partners; use only aggregated, anonymized insights
- Create beauty data deletion tool โ Allow users to clear beauty profiles, skin assessments, and facial scans independently
- Add retention schedules for health-adjacent data โ โBeauty quiz results: 1 year; virtual try-on data: deleted immediately; dermatological purchases: standard retail retentionโ
How Does Your Policy Compare?
๐ Run Your Free DPDP Audit โ
Take the free 60-second DPDP Audit to check your own companyโs liability under the DPDP Act โ 16 quick questions, instant risk report.
Analysis conducted by DPDP Consulting, a Meridian Bridge Strategy initiative. For a comprehensive compliance roadmap, book a free consultation.