DPDP NavigatorAct 2023 · Rules 2025
All guides
Sector Deep Dives

DPDP Compliance for Logistics and Delivery Platforms: Location Data at Scale

26 Jul 20269 min read

Delivery platforms track riders in real time and customers by address on every order — two location-data streams that need different justifications.

Rider location tracking is continuous, not transactional

A delivery platform tracks its riders' location continuously through a shift, not just during an active delivery, for dispatch efficiency, safety monitoring, and performance metrics like average speed or idle time. That continuous tracking is a materially different — and more invasive — data flow than tracking a customer's delivery address for a single order, and it deserves its own clear notice to riders about what is logged, for how long, and who inside the company can see it.

Where rider location data feeds performance scoring that affects pay, assignment priority, or account status, the accuracy obligation under Section 8(3) applies directly: a rider penalised by a GPS glitch or a phone left in a bag should have a real path to dispute the reading, not just an algorithmic score with no visible inputs.

Customer address data moves through several parties per order

A single delivery touches the platform, the rider, sometimes a partner fleet operator, and occasionally a merchant fulfilling the order directly — each of whom may see the customer's address, phone number, and delivery instructions. The notice given at checkout needs to reflect that the address is shared with the assigned rider and, where relevant, an aggregator's partner fleet, not just the platform itself.

Delivery instructions sometimes carry incidental sensitive detail — gate codes, notes about who is home, landmark descriptions tied to a specific person's daily pattern — and retaining that verbatim after delivery serves little purpose beyond the transaction, making it a reasonable candidate for prompt deletion rather than indefinite storage in an order history table.

Live tracking dashboards and third-party mapping vendors

Real-time tracking links shared with customers, and internal dashboards showing fleet-wide rider locations, both depend on mapping and routing vendors who receive live location feeds as processors. Those vendor contracts need the same Section 8(2) coverage as any other processor, with particular attention to how long the mapping vendor is permitted to retain historical route data once a delivery completes.

Aggregated heat-map style location analytics — used for warehouse placement or demand forecasting — can often be built from de-identified or aggregated data rather than raw individual location trails, and doing so reduces both regulatory exposure and the blast radius of any future incident.

Retention limits for a data set that grows fast

Location and delivery data accumulates quickly at logistics scale, and a platform without a clear retention schedule ends up storing years of granular movement history with no defined purpose past the immediate delivery and any short dispute-resolution window. Section 8(7) requires erasure once the purpose is served, so a documented retention period — long enough for delivery disputes and fraud investigation, no longer — is worth setting explicitly rather than defaulting to “keep everything.”

Where to go next

The Data Flow Mapper is particularly suited to logistics, since a single order genuinely does move through several distinct parties in sequence. Follow it with the Retention Planner to set defensible limits on raw location trail storage.