DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr

Quick Answer

What DPDP Act 2023 obligations apply to e-commerce companies? E-commerce platforms collect and process personal data at multiple touchpoints — account registration, browsing behaviour, purchase history, payment details, and delivery addresses — making them high-exposure Data Fiduciaries under the DPDP Act 2023. Key obligations include collecting only the minimum data necessary for each transaction, obtaining granular consent for marketing communications, enabling customers to access, correct, or delete their account data, maintaining robust payment data security, and signing DPAs with all logistics, payment, and analytics vendors.

⚐ Enforcement Deadline: May 2027

DPDP Compliance for E-Commerce — Customer Data & Consent Requirements

What D2C brands, online marketplaces, and Shopify stores must do under India's Digital Personal Data Protection Act 2023

Get Free Assessment Download Checklist
₹250 Cr Maximum penalty per violation
72 Hours Breach notification window
90 Days Rights response SLA

What Personal Data Does Your Store Handle?

Every data point your e-commerce business processes falls under DPDP 2023

🛍Order History & Purchase Records

Transaction details, order IDs, and purchase patterns linked to customer identity

💳Payment & Card Data

Payment method details, billing information processed at checkout

📦Delivery Addresses & Contact Details

Shipping addresses, phone numbers, and email required for fulfillment

🖱Browsing & Cart Abandonment Data

Product views, wish lists, and cart activity tracked for retargeting

🎁Loyalty Points & Customer Profiles

Reward balances, tier status, and purchase history in CRM systems

🔄Returns & Refund Data

Return reasons, refund status, and product feedback data

💬Customer Support Chat Logs

Support conversations containing personal details, complaints, and order information

📧Marketing Preferences & Opt-ins

Email, SMS, and WhatsApp consent records and campaign engagement data

5 DPDP Obligations Every E-Commerce Business Must Meet

 

1

Consent at Checkout

Every checkout page must display a DPDP Rule 3 notice before data collection. Pre-ticked consent boxes are illegal under the DPDP Act. Purpose-specific consent is required — one tick for delivery does not cover marketing communications.

2

Customer Data Rights

Customers can demand access to their data, request corrections, or ask for complete deletion within 90 days. You need a working rights-request mechanism — a dedicated contact form or email address is the minimum requirement.

3

Payment Data Safeguards

DPDP 2023 overlaps with PCI DSS. Tokenise card data, never store raw CVV, and communicate your data retention period at checkout. Tokenisation satisfies both PCI and DPDP data minimisation requirements.

4

Delivery Partner Data Sharing

Every logistics partner — Delhivery, Blue Dart, Xpressbees, Shadowfax — receives your customers' personal data. A signed Data Processing Agreement (DPA) is mandatory under DPDP before sharing any personal data with processors.

5

Marketing Consent

WhatsApp, SMS, and email marketing each require a separate, explicit opt-in. Bundling marketing consent into Terms & Conditions acceptance is non-compliant. Log every consent with a timestamp and consent version.

DPDP Risks Specific to Online Retail

 

⚠️ Meta Pixel & Google Tag

Behavioural tracking via third-party pixels requires disclosure in your DPDP notice. Customers must know their browse data is shared with Meta/Google for advertising purposes.

⚠️ Review Platforms

Displaying customer names, photos, or location tags in product reviews without explicit consent may violate DPDP data minimisation and purpose limitation principles.

⚠️ Gift Recipient Data

When customers send gifts, the recipient's personal data is collected without their consent. You need a legal basis for processing data of people who haven't agreed to your terms.

⚠️ Third-Party Payment Gateways

Razorpay, PayU, and Stripe are Data Processors. DPAs with each are mandatory. Check if your current gateway contract already includes DPDP-compliant DPA language — many don't.

⚠️ Returns Revealing Sensitive Purchases

A return of health supplements, medical devices, or personal care products in the order history constitutes sensitive personal data. Extra safeguards and access restrictions apply under DPDP.

⚠️ WhatsApp Order Bots

Automated WhatsApp messages for order updates and delivery notifications require prior explicit consent to contact the customer on WhatsApp. This opt-in must be separate from order placement.

E-Commerce DPDP Compliance Checklist

How does your store measure up? Tick off what you've completed.

Need help completing this checklist? Get a free assessment →

Niti Bharat E-Commerce Compliance Services

 

DPDP Gap Assessment

₹25,000

Comprehensive audit of your data flows, checkout consent, vendor contracts, and current compliance gaps. Deliverable: gap report with prioritised remediation roadmap.

Duration: 1–2 weeks

Policy & Notice Suite

₹35,000

DPDP-compliant privacy policy, Rule 3 consent notices for checkout, DPA templates for logistics partners, and marketing consent records.

Duration: 1 week

Full Compliance Programme

₹75,000

Everything in Gap Assessment + Policy Suite, plus staff training, Grievance Officer appointment support, and 12 months of ongoing compliance monitoring.

Duration: 4–6 weeks

Prices indicative. Book a free call for a custom quote.

Get a Free DPDP Readiness Assessment for Your E-Commerce Business

Our compliance team will review your store and send you a personalised checklist within 48 hours — no cost, no commitment.

Thank you! We'll send your personalised checklist within 48 hours.

Frequently Asked Questions

 

Does DPDP apply to my Shopify/WooCommerce store? +
Yes. If your store collects personal data from customers in India — which includes names, email addresses, phone numbers, and payment details — the DPDP Act 2023 applies regardless of which platform you use. Shopify, WooCommerce, Magento, and custom stores are all covered. The Act applies to the Data Fiduciary (you, the store owner), not the platform.
Do I need a DPA with Razorpay/PayU? +
Yes. Payment gateways process your customers' financial personal data on your behalf, making them Data Processors under DPDP 2023. A Data Processing Agreement is mandatory before sharing customer data with any processor. Check your current gateway contract — some providers have already added DPA language, but many older contracts predate DPDP and need an addendum.
What happens if a customer requests deletion of their order history? +
You must respond within 90 days. However, DPDP allows you to retain data where a legal or regulatory obligation requires it — for example, GST rules require transaction records for 8 years. You can retain the minimum financial records legally required while deleting all other personal data. Communicate this clearly in your response to the customer.
Can I still use Meta Pixel and Google Analytics? +
Yes, but with disclosure and consent. Your DPDP Rule 3 notice must inform customers that browsing behaviour and device data are shared with Meta/Google for analytics and advertising purposes. If you use Meta's retargeting features, the purpose must be specifically stated and consented to. A generic "analytics" consent is not sufficient for cross-platform ad targeting.
When does enforcement start? +
The DPDP Act 2023 was notified in August 2023. The DPDP Rules 2025 were published in January 2025. Enforcement is expected to begin after the Data Protection Board of India is constituted and operational, which is expected by May 2027. However, the legal obligation exists now — waiting until enforcement begins leaves you exposed to retrospective penalties.
Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPDP Compliance for EdTech Platforms IndiaDPDP Compliance for FMCG & Consumer Brands IndiaDPDP Compliance for GCCs & Captive Units IndiaDPDP Employee Awareness Programme KitSee all By Sector tools →📝 DPDP Compliance Healthcare Hospitals📝 DPDP for IT Companies