On September 18, 2026, MediaNama reported on a three-hour, closed-door consultation under Chatham House Rules on e-commerce, AI and illicit trade. Brand owners, law firms, customs and enforcement officials, intergovernmental agencies and researchers attended. No e-commerce platform did. Participants backed continuous, risk-weighted seller KYC in place of a one-time onboarding check. They also wanted shared alerts on removed sellers, and enforcement outcomes tied to commercial privileges such as advertising and buy-box eligibility. The organisers plan to send findings to the Controller General's office and DPIIT. A working group of brand owners will pilot shared seller and KYC data formats, according to MediaNama.
This is not a government app mandate. No such mandate has been verified in the last 60 days, and no rule has been proposed here. But it is the nearest live example of the design pattern that sank the last one: a compliance architecture drafted by the people who want it, for a party who was not consulted.
The strongest case for the proposal
The complaint is serious. Speakers said registered seller addresses turn out, on inspection, to be empty plots or not to exist. They described networks of intermediaries that help flagged sellers get back onto platforms. They noted that a seller with infringement complaints can still buy ads and win the buy-box, while the platform earns commission on the sale either way. Existing law is thin on this point. Rule 5 of the Consumer Protection (E-Commerce) Rules, 2020 requires marketplaces to display seller details and obtain an accuracy undertaking. It also requires them to keep records that identify sellers who repeatedly offered goods previously removed under IP laws. As summarised by consumerprotection.in, the rule does not require the platform to terminate those repeat offenders. Rights holders reasonably ask why a record-keeping duty has no consequence attached.
Where the design goes wrong
First, the record is one-sided. MediaNama itself notes that the case was made "in full, and unopposed". The same report says platforms show limited voluntary appetite for data sharing. That is a fact worth knowing, but it is no substitute for hearing what platforms would say about false positives, due process for sellers, or the cost of continuous checks. A second round including platforms is planned. It should not be a formality.
Second, a shared blacklist of "removed sellers" is a powerful instrument. Removal today follows a complaint, and complaints can be mistaken or abusive. Genuine resellers, parallel importers and small sellers who lawfully sell branded goods are the likeliest casualties. If a removal on one platform triggers alerts and lost ad and buy-box access on every other, an unadjudicated allegation becomes a market-wide penalty. Pro-innovation regulation asks for a route to contest that outcome, and a standard of evidence before a flag propagates.
Third, shared KYC data formats invite scope creep. Continuous verification of every seller, held in formats designed for cross-platform matching, builds a large identity dataset. It should be treated as personal data with a defined purpose, retention limit and access rule. None of that is on the reported agenda.
Fourth, tying enforcement to buy-box and ad placement moves the state into ranking design. That is a commercial decision platforms make for many reasons. A targeted penalty for adjudicated repeat infringers is defensible. A general obligation to reshape ranking around brand-owner complaints is not, and it would hand complainants leverage over competitors' listings.
What Sanchar Saathi teaches
The parallel is procedural. On December 2, 2025, the Department of Telecommunications directed handset makers and importers to pre-install the Sanchar Saathi app, with implementation within 90 days and a report within 120 days. The stated purpose was to verify genuine handsets, prevent purchase of counterfeit devices and enable reporting of telecom misuse. The goal was legitimate, and it too was framed around counterfeits and fraud. The order also required that the app's functions not be disabled or restricted. Within days it drew criticism from opposition politicians, privacy advocates and handset makers.
On December 3, 2025, the government announced that it would not make pre-installation mandatory. It cited the app's "increasing acceptance", about 1.4 crore downloads, and said citizens could remove the app whenever they wished. The reversal is instructive. The tool's voluntary uptake was strong enough that the mandate added little except distrust. Where a system is useful, it can win adoption without compulsion.
The same logic applies to seller verification. If continuous KYC and shared alerts reduce counterfeits, platforms and legitimate sellers have strong reasons to adopt them. A voluntary, pilot-based standard, tested with platforms and published for comment, would show whether the benefits are real. Mandating a format that only one side of the market designed would repeat the sequence of December 2025: a well-meant order, a backlash, a retreat.
A proportionate path
- Bring platforms and seller representatives into the working group before any format is sent to DPIIT.
- Limit shared alerts to adjudicated or counter-noticed-and-unanswered removals, with a notice-and-appeal step for the seller.
- Apply continuous verification by risk, as participants themselves suggested, not to every small seller.
- Set purpose limits, retention limits and access controls on any shared KYC data.
- Use the existing Rule 5 record-keeping duty as the base. Add a graduated consequence for proven repeat infringers before creating new architecture.
Counterfeits harm consumers and honest sellers alike, and the enforcement gap is real. The remedy should be tested on both sides of the market before it is written into a mandate.