India’s Digital Personal Data Protection Act (DPDP), passed in 2023, is now the framework for how you handle buyer personal data. If you are a D2C seller running a Shopify store, an AJIO account, and a customer-service WhatsApp, this affects you. The headlines made it sound scarier than it is. Here is the practical version.
The five things you need to do
1. Notice. Tell people what you collect, why, and how long you keep it. This is what your privacy policy is for. If you have a Shopify store, your privacy policy needs an India-specific section.
2. Consent. Do not auto-opt-in to marketing. Do not default the WhatsApp checkbox to checked. Get explicit, granular, withdrawable consent.
3. Purpose limitation. If you collected an email for shipping confirmations, do not use it for promotions without separate consent.
4. Retention limits. Do not keep buyer data forever. Set a retention window per category and delete after.
5. Breach notification. If something leaks, notify the Data Protection Board (the regulator) within seventy-two hours. Notify affected users without undue delay.

What you do not need to do (yet)
Some things in DPDP coverage that do not apply to most early-stage D2C sellers:
- Data Protection Officer (DPO). Required for “significant data fiduciaries” — not you, unless you are processing very large volumes or sensitive data.
- Data Protection Impact Assessment (DPIA). Required for high-risk processing — most D2C sellers are below the threshold.
- Cross-border data transfer restrictions. Some are coming via secondary rules; for now, most transfers under standard processing agreements are fine.

What Robnu does about this
Robnu is DPDP-aligned by design:
- Data residency. Buyer PII (names, addresses, phone numbers) flowing through Robnu stays in India-residency regions. We do not move PII outside India for processing.
- Token vault. Marketplace credentials encrypted with a per-seller DEK, under a KMS-managed master key. Audit log on every credential read.
- Audit log. Sellers can read their own audit trail of credential access.
- Breach posture. If something happens, we follow the DPDP seventy-two hour timeline — and we would notify you faster than that.
- Data subject requests. Buyer access, erasure, and correction requests can flow through Robnu’s admin UI to the right place.

What you still have to do
DPDP applies to you, not just to your tools. So:
- Privacy policy. Update for DPDP. Generic templates from 2022 are not good enough.
- Consent UI. WhatsApp opt-in checkboxes need to be unchecked by default. Email marketing consent needs to be separate from transactional consent.
- Retention. Pick a retention window for buyer data (we recommend five years for orders, one year for marketing data). Delete on schedule.
- Records. Keep records of consents and processing activities. The DPDP rules require you to be able to demonstrate compliance.
Spend an hour with the Act itself — it is surprisingly readable. Pair it with the Robnu data posture, decide your retention windows, and fix your consent UI. None of it is glamorous, and all of it is the boring infrastructure that keeps a small Indian brand out of trouble.

