What DPDP Act 2023 obligations apply to e-commerce companies? E-commerce platforms collect and process personal data at multiple touchpoints — account registration, browsing behaviour, purchase history, payment details, and delivery addresses — making them high-exposure Data Fiduciaries under the DPDP Act 2023. Key obligations include collecting only the minimum data necessary for each transaction, obtaining granular consent for marketing communications, enabling customers to access, correct, or delete their account data, maintaining robust payment data security, and signing DPAs with all logistics, payment, and analytics vendors.
What D2C brands, online marketplaces, and Shopify stores must do under India's Digital Personal Data Protection Act 2023
Every data point your e-commerce business processes falls under DPDP 2023
Transaction details, order IDs, and purchase patterns linked to customer identity
Payment method details, billing information processed at checkout
Shipping addresses, phone numbers, and email required for fulfillment
Product views, wish lists, and cart activity tracked for retargeting
Reward balances, tier status, and purchase history in CRM systems
Return reasons, refund status, and product feedback data
Support conversations containing personal details, complaints, and order information
Email, SMS, and WhatsApp consent records and campaign engagement data
Every checkout page must display a DPDP Rule 3 notice before data collection. Pre-ticked consent boxes are illegal under the DPDP Act. Purpose-specific consent is required — one tick for delivery does not cover marketing communications.
Customers can demand access to their data, request corrections, or ask for complete deletion within 90 days. You need a working rights-request mechanism — a dedicated contact form or email address is the minimum requirement.
DPDP 2023 overlaps with PCI DSS. Tokenise card data, never store raw CVV, and communicate your data retention period at checkout. Tokenisation satisfies both PCI and DPDP data minimisation requirements.
Every logistics partner — Delhivery, Blue Dart, Xpressbees, Shadowfax — receives your customers' personal data. A signed Data Processing Agreement (DPA) is mandatory under DPDP before sharing any personal data with processors.
WhatsApp, SMS, and email marketing each require a separate, explicit opt-in. Bundling marketing consent into Terms & Conditions acceptance is non-compliant. Log every consent with a timestamp and consent version.
Behavioural tracking via third-party pixels requires disclosure in your DPDP notice. Customers must know their browse data is shared with Meta/Google for advertising purposes.
Displaying customer names, photos, or location tags in product reviews without explicit consent may violate DPDP data minimisation and purpose limitation principles.
When customers send gifts, the recipient's personal data is collected without their consent. You need a legal basis for processing data of people who haven't agreed to your terms.
Razorpay, PayU, and Stripe are Data Processors. DPAs with each are mandatory. Check if your current gateway contract already includes DPDP-compliant DPA language — many don't.
A return of health supplements, medical devices, or personal care products in the order history constitutes sensitive personal data. Extra safeguards and access restrictions apply under DPDP.
Automated WhatsApp messages for order updates and delivery notifications require prior explicit consent to contact the customer on WhatsApp. This opt-in must be separate from order placement.
How does your store measure up? Tick off what you've completed.
Need help completing this checklist? Get a free assessment →
Comprehensive audit of your data flows, checkout consent, vendor contracts, and current compliance gaps. Deliverable: gap report with prioritised remediation roadmap.
Duration: 1–2 weeksDPDP-compliant privacy policy, Rule 3 consent notices for checkout, DPA templates for logistics partners, and marketing consent records.
Duration: 1 weekEverything in Gap Assessment + Policy Suite, plus staff training, Grievance Officer appointment support, and 12 months of ongoing compliance monitoring.
Duration: 4–6 weeksPrices indicative. Book a free call for a custom quote.
Our compliance team will review your store and send you a personalised checklist within 48 hours — no cost, no commitment.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.