All posts
ComplianceDPDPLegalIndia

DPDP 2023 for Indian Ecommerce Sellers: What Actually Changes

The Digital Personal Data Protection Act 2023 is now enforced. Here's the practical checklist every marketplace seller needs to survive an audit — and the 6 things most miss.

10 February 2026 10 min readBy Yesuraj G

DPDP 2023 for Indian Ecommerce Sellers: What Actually Changes

The Digital Personal Data Protection Act, 2023 is India's first standalone data protection law. Enforcement started in phases through 2025, and by Q1 2026, penalties for non-compliance can reach ₹250 crore per breach.

If you're selling on Amazon / Flipkart / Meesho / your own D2C site — you are a Data Fiduciary under DPDP. This is a plain-English breakdown.

Are you covered?

DPDP applies if you:

  • Collect or store any personal data of Indian citizens
  • Process customer names, phone numbers, addresses, emails, PIN codes, order histories, IP addresses, device IDs

Every ecommerce seller triggers this on day one. There is no small-business exemption.

The 6 obligations most sellers miss

1. Notice-and-consent at collection

Every place you collect personal data must show a clear, plain-language notice at the point of collection. Pre-checked boxes are illegal. If you use marketplace channels, the marketplace handles this — but if you resell contact info or run a WhatsApp broadcast list, YOU need consent.

2. Purpose limitation

You can only use the data for the purpose stated at collection. Sending marketing WhatsApps to a customer who bought once, without their consent to marketing, is a violation.

3. Data minimization

Only collect what you strictly need. If you're running a Shopify checkout that asks for DOB "just in case" — remove it. Data you never needed is now a liability.

4. The right to erase

Customers can ask you to delete their data. You have 30 days to comply. If you outsource fulfillment or use 3rd-party CRMs, deletion must cascade — and you must have written data-processing agreements with them proving this.

5. Breach notification

A breach must be reported to the Data Protection Board (DPB) within 72 hours. "Breach" includes ransomware, misconfigured S3 buckets, laptop theft with unencrypted customer data, and rogue employees exporting order sheets.

6. Data Protection Officer (DPO)

If you're a "Significant Data Fiduciary" (large volume + sensitive data), you need a designated DPO. Threshold guidance is still evolving — but any seller doing >5,000 orders/month with customer contact data should proactively designate one.

The practical checklist

Print this and tick it off:

  • Privacy policy live on every customer-facing surface
  • Point-of-collection notice on every form (checkout, newsletter, contact)
  • Consent recorded with timestamp + IP + version of policy accepted
  • Data inventory: what you collect, why, where it's stored, retention period
  • Vendor contracts with all data processors (Shopify, Zoho, Freshworks, your BPO)
  • Encryption-at-rest for customer data (Fernet, AES-256, or equivalent)
  • Encryption-in-transit (HTTPS everywhere — no plain HTTP forms)
  • Access logs for customer data — who accessed what, when
  • 72-hour breach response plan documented
  • Customer request (access / erase / correct) intake channel published
  • Employee training log (at least annually)

The 3 things ecommerce sellers get wrong

  1. Excel sheets on personal laptops. Downloading order data with customer PII to a personal spreadsheet is a violation the moment it happens. Use audited tools with role-based access.

  2. WhatsApp broadcast lists without consent. The moment you added that number to a broadcast because they ordered from you once, you crossed a consent line. Use double-opt-in.

  3. Retaining data forever. Retention limits must be documented and enforced. "We keep everything forever, just in case" is a fine waiting to happen.

What SellerPapa does about DPDP

Since v1.0, SellerPapa has been DPDP-first:

  • All marketplace credentials encrypted with Fernet at rest
  • httpOnly session cookies + CSRF-nonce OAuth
  • Every DB read is scoped by tenant (org_id) — no cross-tenant leaks by design
  • Access logs on every customer data read
  • Right-to-erasure endpoint that cascades across orders, invoices, tickets

Compliance isn't a checklist you do once. It's how you architect. But if your current stack fails 5+ items on the checklist above, DPDP is an existential risk.

Start with the checklist. If you're building on the wrong foundation, SellerPapa can be that foundation — with the compliance baked in.

Ready to stop leaking money?

Try SellerPapa free for 30 days

27 live marketplace connectors. TrueProfit per-order margin. PapaProof SHA-256 fraud chain. Reconciliation engine. Claude 4.5 Copilot. No credit card required.

See pricing