Skip to content
    The Storemate
    • How it works
    • Features
    • Included
    • Pricing
    Compliance

    The DPDP Act and your small online store: a plain-English checklist

    India's data protection law reaches every online store that collects a phone number. What the DPDP Act and Rules ask of a small store, and when each duty starts.

    Illustration: data protection duties for a small online store
    Yashh Mittal
    Yashh Mittal
    Founder
    12 Aug 2026 · 4 min read
    Topic: Business setup & legal
    In short

    The DPDP Act for ecommerce stores means clear consent for anything beyond delivering the order, easy opt-outs, reasonable security, a plain-language privacy notice and a contact for data questions. Most duties start in May 2027, 18 months after the Rules were notified.

    What the DPDP Act covers

    The Digital Personal Data Protection Act, 2023 governs how businesses handle personal data in digital form. Your store collects plenty of it. Names, phone numbers, addresses, emails and order history all count. Under the Act, you are a Data Fiduciary, and each buyer is a Data Principal. The rules that put it into practice, the DPDP Rules, 2025, were notified on 13 November 2025. Most duties for a store switch on later, as the last section explains.

    Consent at signup and checkout

    The Act says consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. That rules out pre-ticked boxes. But you do not need a consent box just to deliver an order. The Act lets you use data a buyer gives you for the purpose they gave it, like shipping their parcel. Ask for separate consent for anything extra. Keep each request in clear, plain language.

    Marketing messages

    Offers on WhatsApp, SMS or email go beyond delivering an order. So ask for them separately, with an unticked box at signup or checkout. The Act also says buyers can withdraw consent at any time. Withdrawing must be as easy as giving consent was. In practice, every message needs a simple way to opt out, and your list must respect it quickly.

    Keeping and deleting data

    The Act asks you to erase personal data once a buyer withdraws consent, or once the purpose is clearly over. Other laws can still require you to keep some records, such as tax invoices. The Rules also ask you to keep personal data and processing logs for at least one year, for security checks. You must protect the data with reasonable safeguards, such as encryption, access control and backups. Failing to take reasonable security safeguards can cost up to ₹250 crore.

    A small-store checklist

    1. List every piece of personal data you collect, and why you collect it.
    2. Remove any pre-ticked boxes from signup and checkout.
    3. Add a separate, unticked opt-in for marketing messages.
    4. Make opting out as easy as opting in, in every message.
    5. Limit who on your team can see buyer data, and turn on backups.
    6. Publish a contact for data questions on your website.
    7. Write down what you will do if data leaks, including telling buyers and the Data Protection Board.

    What your privacy policy must say

    Under the Rules, your notice must stand on its own and use clear, plain language. It should list the personal data you collect, item by item, and the purpose for each. It must explain how a buyer can withdraw consent, use their rights, and complain to the Data Protection Board of India. You also need to publish the business contact details of a person who can answer questions about the data.

    When it applies

    The Act's main duties, including consent, notice and security, come into force 18 months after 13 November 2025. That is May 2027. The Rules on notices, security, breach reporting and data retention start on the same date. After that, if data leaks, you must tell affected buyers without delay. You must also give the Board a detailed report within 72 hours. That gives a small store time to prepare, not a reason to wait. The Storemate adds a privacy request page to every store, where buyers can ask to see, export or delete their data. For anything complex, check with a lawyer.

    Frequently asked questions

    When does the DPDP Act apply to online stores?

    Most duties, including consent, notices and security, start 18 months after the DPDP Rules were notified on 13 November 2025, which is May 2027.

    Do I need consent to ship an order?

    Usually not separately. The Act lets you use data a buyer voluntarily gives you for that purpose. Marketing messages are different and need clear, separate consent.

    What is the penalty under the DPDP Act?

    It depends on the breach. Failing to take reasonable security safeguards can attract a penalty of up to ₹250 crore, and most other breaches up to ₹50 crore.

    Sources

    • MeitY - The Digital Personal Data Protection Act, 2023
    • MeitY - Digital Personal Data Protection Rules, 2025
    • MeitY - DPDP Act enforcement timeline notification

    Keep reading

    • ComplianceThe legal pages your Indian online store needs, and what each must say
    • MarketingWhatsApp marketing for Indian stores: rules, tools and templates
    • MarketingEmail marketing for online stores: the flows that make money
    ← Back to all posts
    The Storemate

    The complete e-commerce platform. Create, manage, and grow your online store from a single dashboard.

    Product
    • Features
    • Themes
    • Pricing
    • FAQs
    Company
    • About
    • How it works
    • Blog
    • Contact
    © 2026 The Storemate. Brewed with chai and built with ♥️ in India.
    PrivacyTermsCookies