What must a retail privacy policy in India cover under DPDP? An Indian retail privacy policy must cover both online and in-store data collection: phone numbers captured at the point-of-sale counter, CCTV surveillance notices required at store entrances, WhatsApp and SMS marketing consent, CRM profile-building from purchase history, and — critically for omnichannel retailers — a clear disclosure of how online and offline (in-store) customer records are merged into a single profile. Most retail privacy policies only address the website and ignore the store-floor data points, which is where DPDP gaps are most common. This generator builds a policy covering both channels.
For retailers with both online stores and physical outlets. Covers POS data capture, CCTV notices, WhatsApp/SMS consent, CRM use, and online-offline data merging — in one policy.
If your billing counter asks customers for a phone number — for the receipt, for a loyalty scan, or simply because staff have been trained to collect it — that is personal data collection subject to the same DPDP notice and purpose-limitation requirements as anything captured online. Based on your answer, if phone numbers are captured for every transaction rather than only loyalty members, the policy must disclose this as a standard checkout practice, state the specific purpose (transaction record, order lookup, marketing if separately consented), and make clear that providing the number is not a condition of completing the purchase unless it is genuinely required for the transaction itself.
The most common retail DPDP gap here is using the phone number collected 'just for the receipt' to later add the customer to a WhatsApp marketing list without a separate consent step. The generated policy language explicitly separates the transactional purpose (receipt/warranty lookup) from any marketing use, and the marketing-consent section (unlocked in the full document) builds the correct opt-in flow for that handoff.
Stores running CCTV — for security, loss prevention, or footfall analytics — are processing personal data (visual identity) of every customer who enters, and DPDP's transparency principle expects a clear, visible notice at store entrances stating that surveillance is in operation, the purpose, and how long footage is retained. Based on your CCTV selection, this section generates entrance-signage text and a corresponding policy clause. If you operate across multiple outlets, the same notice language should be posted consistently at every location that runs CCTV — 'select outlets' answers still need the disclosure at every outlet where cameras are actually installed.
Where CCTV is combined with any form of facial recognition, footfall counting linked to loyalty profiles, or in-store analytics that ties camera data to an identified customer, this significantly raises the processing's sensitivity and should be flagged separately in your policy rather than folded into a generic 'security cameras in use' line — the full document's CRM and data-merging sections address this handoff specifically.
Sections prioritised for your retail operation:
Most Indian retail privacy policies were written for the website alone — often adapted from an e-commerce template — and say nothing about the store floor, where a large share of actual data collection happens: phone numbers at billing, CCTV at the entrance, and loyalty enrolment at the counter. Under the DPDP Act 2023, personal data is personal data regardless of channel, and a policy that only addresses online collection leaves the physical-store data flow entirely undocumented. With DPDP Rules 2025 notified and enforcement expected around May 2027, this gap is one of the first things a retail-sector DPDP audit surfaces.
The risk compounds for omnichannel brands that merge online and in-store customer records into a single CRM profile without disclosing the merge — a practice that is operationally common (it's exactly what makes a good loyalty programme work) but rarely documented anywhere the customer can see. Niti Bharat's fixed-price DPDP engagements (₹75,000–₹3.2 lakh) routinely start with exactly this fix for retail clients — email hello@nitibharat.com to scope your outlets and channels.
CCTV surveillance is one of the most visible and easiest-to-verify compliance gaps a Data Protection Board investigator (or a walk-in customer filing a complaint) can point to — either the entrance notice exists or it doesn't. Retailers that treat this as a physical-security matter rather than a data-protection disclosure obligation are exposed to the same penalty framework as any other DPDP violation: up to ₹250 crore for failure of reasonable security safeguards, and up to ₹50 crore for other violations, enforced by the Data Protection Board.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.