DPDP 2023 for Indian Ecommerce Sellers: What Actually Changes
The Digital Personal Data Protection Act 2023 is now enforced. Here's the practical checklist every marketplace seller needs to survive an audit — and the 6 things most miss.
DPDP 2023 for Indian Ecommerce Sellers: What Actually Changes
The Digital Personal Data Protection Act, 2023 is India's first standalone data protection law. Enforcement started in phases through 2025, and by Q1 2026, penalties for non-compliance can reach ₹250 crore per breach.
If you're selling on Amazon / Flipkart / Meesho / your own D2C site — you are a Data Fiduciary under DPDP. This is a plain-English breakdown.
Are you covered?
DPDP applies if you:
- Collect or store any personal data of Indian citizens
- Process customer names, phone numbers, addresses, emails, PIN codes, order histories, IP addresses, device IDs
Every ecommerce seller triggers this on day one. There is no small-business exemption.
The 6 obligations most sellers miss
1. Notice-and-consent at collection
Every place you collect personal data must show a clear, plain-language notice at the point of collection. Pre-checked boxes are illegal. If you use marketplace channels, the marketplace handles this — but if you resell contact info or run a WhatsApp broadcast list, YOU need consent.
2. Purpose limitation
You can only use the data for the purpose stated at collection. Sending marketing WhatsApps to a customer who bought once, without their consent to marketing, is a violation.
3. Data minimization
Only collect what you strictly need. If you're running a Shopify checkout that asks for DOB "just in case" — remove it. Data you never needed is now a liability.
4. The right to erase
Customers can ask you to delete their data. You have 30 days to comply. If you outsource fulfillment or use 3rd-party CRMs, deletion must cascade — and you must have written data-processing agreements with them proving this.
5. Breach notification
A breach must be reported to the Data Protection Board (DPB) within 72 hours. "Breach" includes ransomware, misconfigured S3 buckets, laptop theft with unencrypted customer data, and rogue employees exporting order sheets.
6. Data Protection Officer (DPO)
If you're a "Significant Data Fiduciary" (large volume + sensitive data), you need a designated DPO. Threshold guidance is still evolving — but any seller doing >5,000 orders/month with customer contact data should proactively designate one.
The practical checklist
Print this and tick it off:
- Privacy policy live on every customer-facing surface
- Point-of-collection notice on every form (checkout, newsletter, contact)
- Consent recorded with timestamp + IP + version of policy accepted
- Data inventory: what you collect, why, where it's stored, retention period
- Vendor contracts with all data processors (Shopify, Zoho, Freshworks, your BPO)
- Encryption-at-rest for customer data (Fernet, AES-256, or equivalent)
- Encryption-in-transit (HTTPS everywhere — no plain HTTP forms)
- Access logs for customer data — who accessed what, when
- 72-hour breach response plan documented
- Customer request (access / erase / correct) intake channel published
- Employee training log (at least annually)
The 3 things ecommerce sellers get wrong
-
Excel sheets on personal laptops. Downloading order data with customer PII to a personal spreadsheet is a violation the moment it happens. Use audited tools with role-based access.
-
WhatsApp broadcast lists without consent. The moment you added that number to a broadcast because they ordered from you once, you crossed a consent line. Use double-opt-in.
-
Retaining data forever. Retention limits must be documented and enforced. "We keep everything forever, just in case" is a fine waiting to happen.
What SellerPapa does about DPDP
Since v1.0, SellerPapa has been DPDP-first:
- All marketplace credentials encrypted with Fernet at rest
- httpOnly session cookies + CSRF-nonce OAuth
- Every DB read is scoped by tenant (
org_id) — no cross-tenant leaks by design - Access logs on every customer data read
- Right-to-erasure endpoint that cascades across orders, invoices, tickets
Compliance isn't a checklist you do once. It's how you architect. But if your current stack fails 5+ items on the checklist above, DPDP is an existential risk.
Start with the checklist. If you're building on the wrong foundation, SellerPapa can be that foundation — with the compliance baked in.