What the DPDP Act covers
The Digital Personal Data Protection Act, 2023 governs how businesses handle personal data in digital form. Your store collects plenty of it. Names, phone numbers, addresses, emails and order history all count. Under the Act, you are a Data Fiduciary, and each buyer is a Data Principal. The rules that put it into practice, the DPDP Rules, 2025, were notified on 13 November 2025. Most duties for a store switch on later, as the last section explains.
Consent at signup and checkout
The Act says consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. That rules out pre-ticked boxes. But you do not need a consent box just to deliver an order. The Act lets you use data a buyer gives you for the purpose they gave it, like shipping their parcel. Ask for separate consent for anything extra. Keep each request in clear, plain language.
Marketing messages
Offers on WhatsApp, SMS or email go beyond delivering an order. So ask for them separately, with an unticked box at signup or checkout. The Act also says buyers can withdraw consent at any time. Withdrawing must be as easy as giving consent was. In practice, every message needs a simple way to opt out, and your list must respect it quickly.
Keeping and deleting data
The Act asks you to erase personal data once a buyer withdraws consent, or once the purpose is clearly over. Other laws can still require you to keep some records, such as tax invoices. The Rules also ask you to keep personal data and processing logs for at least one year, for security checks. You must protect the data with reasonable safeguards, such as encryption, access control and backups. Failing to take reasonable security safeguards can cost up to ₹250 crore.
A small-store checklist
- List every piece of personal data you collect, and why you collect it.
- Remove any pre-ticked boxes from signup and checkout.
- Add a separate, unticked opt-in for marketing messages.
- Make opting out as easy as opting in, in every message.
- Limit who on your team can see buyer data, and turn on backups.
- Publish a contact for data questions on your website.
- Write down what you will do if data leaks, including telling buyers and the Data Protection Board.
What your privacy policy must say
Under the Rules, your notice must stand on its own and use clear, plain language. It should list the personal data you collect, item by item, and the purpose for each. It must explain how a buyer can withdraw consent, use their rights, and complain to the Data Protection Board of India. You also need to publish the business contact details of a person who can answer questions about the data.
When it applies
The Act's main duties, including consent, notice and security, come into force 18 months after 13 November 2025. That is May 2027. The Rules on notices, security, breach reporting and data retention start on the same date. After that, if data leaks, you must tell affected buyers without delay. You must also give the Board a detailed report within 72 hours. That gives a small store time to prepare, not a reason to wait. The Storemate adds a privacy request page to every store, where buyers can ask to see, export or delete their data. For anything complex, check with a lawyer.