DPDP Compliance for Freight Forwarders
Freight forwarders handle massive amounts of personal data, from KYC documents to consignee details. Learn how to comply with India's DPDP Act 2023.
Discuss this page with an LLM
DPDP Action Sheet
Use this before your next workflow goes live. It keeps the useful parts visible and turns DPDP into checks your team can actually answer.
For DPDP Compliance for Freight Forwarders, the DPDP question is how personal data enters the workflow, where it is stored, which tools touch it, what purpose was explained, and how deletion or withdrawal will work.
1. Lead Forms
Check:
- What data are you collecting?
- Is the purpose clear at the point of collection?
- Is marketing consent separate from service communication?
- Can the user withdraw consent later?
Common mistake: one checkbox that silently covers newsletters, sales calls, partner sharing and remarketing.
2. Email and WhatsApp
Check:
- Who is on the list?
- Where did consent come from?
- Is the list imported from a vendor, event, webinar, scrape or old CRM?
- Can you prove the source of consent?
Common mistake: treating every lead as permanently marketable.
3. Ads and Retargeting
Check:
- Are pixels or ad platforms receiving identifiable user behavior?
- Are audiences built from customer lists?
- Are lookalike or remarketing audiences using personal data?
Common mistake: assuming "the ad platform handles it" means your company has no DPDP responsibility.
4. Website Analytics
Check:
- Which tools run on the site?
- Are IP address, device identifiers, session IDs or form fields being captured?
- Is analytics used only for measurement, or also for profiling and targeting?
Common mistake: installing tools first and asking privacy questions later.
5. Vendor List
Make a quick list:
- CRM
- Email platform
- WhatsApp provider
- Analytics
- Ad pixels
- Form tool
- Landing page builder
- Webinar tool
For each vendor, answer: what data goes there, why, who can access it and how deletion works.
6. This Week's Action
Map one campaign from first click to final follow-up. Mark every place personal data is collected, enriched, shared, uploaded or used for targeting.
If your team cannot answer where the data came from and where it goes next, start with a data flow map before rewriting policy copy.
Book a DPDP clarity callWant all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.
Handling Global Agent Transfers
Freight forwarders share shipper and consignee contact details with overseas agents and port authorities daily. Under DPDP, you must verify that your contracts with these foreign partners include specific data processing clauses. This is required even if the destination country lacks its own privacy laws, as you remain responsible for the data you exported from India.
KYC and Customs Retention Conflict
You collect PAN and Aadhaar cards from individual exporters to meet shipping line and customs broker requirements. While DPDP requires deleting personal data once a shipment is delivered, Indian Customs and GST laws often require keeping these records for up to seven years. You must document this legal conflict to justify holding sensitive ID copies beyond the delivery date.
Logistics Staff and Driver Tracking
Tracking driver locations and capturing warehouse visitor logs involves processing personal data. You must limit GPS tracking to active duty hours and ensure biometric attendance data for loaders is encrypted. If you use third-party fleet owners, your agreement must state that they cannot use driver phone numbers for marketing or any purpose other than the specific shipment.
| Workflow | Personal Data Handled | DPDP Compliance Risk |
|---|---|---|
| Bill of Lading Filing | Consignee name, phone, address | Unauthorized sharing with lead aggregators |
| KYC Verification | Individual PAN, Aadhaar, Passport | Storing unmasked ID copies on public cloud folders |
| Driver Dispatch | Real-time GPS, mobile number | Monitoring staff movements outside of working hours |
| Overseas Delivery | Signatory name, ID proof | Sending data to agents in restricted jurisdictions |
This week
Review your last five โHouse Bill of Ladingโ (HBL) digital folders and delete any unmasked Aadhaar or Passport copies for shipments that were completed and cleared over two years ago.
Now think about your work. Where does personal data enter your workflows? Where does it sit? Who else touches it?
Frequently asked questions
Can I share consignee phone numbers with third-party delivery drivers?
Yes, but only for the specific delivery. You must ensure the driver's agency contractually agrees to delete the contact information once the proof of delivery is signed.
How do I handle data for LCL shipments involving multiple individual shippers?
You must keep KYC documents for each shipper in separate digital or physical files. Ensure one shipper cannot see the contact details or ID proofs of others sharing the same container.
Does DPDP apply to the data of foreign consignees?
If you process the personal data of a foreign individual within India to facilitate an export, you must follow DPDP rules for how that data is stored and secured on your local servers.