Skip to content
Robnu
Field NotesField Notes5 min read

DPDP for Indian D2C sellers — what actually changes for your data

India's DPDP Act is now the framework for how you handle buyer personal data. The headlines made it sound scarier than it is. Here is the practical version — the five duties, what does not apply yet, and what Robnu handles versus what you still own.

Hiren Bhuva
Co-founder, Onviqa Inc. · Robnu
TL;DR
  • DPDP is law. The compliance bar is real, but it is not as scary as the headlines make it sound.
  • The big duties: notice plus consent, purpose limitation, retention limits, breach notification, and data principal rights.
  • Robnu is DPDP-aligned by design — but you still need your own compliance posture for buyer data outside Robnu.

India’s Digital Personal Data Protection Act (DPDP), passed in 2023, is now the framework for how you handle buyer personal data. If you are a D2C seller running a Shopify store, an AJIO account, and a customer-service WhatsApp, this affects you. The headlines made it sound scarier than it is. Here is the practical version.

The five things you need to do

1. Notice. Tell people what you collect, why, and how long you keep it. This is what your privacy policy is for. If you have a Shopify store, your privacy policy needs an India-specific section.

2. Consent. Do not auto-opt-in to marketing. Do not default the WhatsApp checkbox to checked. Get explicit, granular, withdrawable consent.

3. Purpose limitation. If you collected an email for shipping confirmations, do not use it for promotions without separate consent.

4. Retention limits. Do not keep buyer data forever. Set a retention window per category and delete after.

5. Breach notification. If something leaks, notify the Data Protection Board (the regulator) within seventy-two hours. Notify affected users without undue delay.

The five DPDP duties for a D2C seller: notice, consent, purpose limitation, retention limits, and breach notification within seventy-two hours to the Data Protection Board.
Figure 1 — The five DPDP duties in plain words: notice, consent, purpose limitation, retention limits, and breach notification. What a D2C seller actually has to do (illustrative, not legal advice).

What you do not need to do (yet)

Some things in DPDP coverage that do not apply to most early-stage D2C sellers:

  • Data Protection Officer (DPO). Required for “significant data fiduciaries” — not you, unless you are processing very large volumes or sensitive data.
  • Data Protection Impact Assessment (DPIA). Required for high-risk processing — most D2C sellers are below the threshold.
  • Cross-border data transfer restrictions. Some are coming via secondary rules; for now, most transfers under standard processing agreements are fine.
What applies now versus not yet under DPDP. Now: a DPDP-updated privacy policy, unchecked consent, retention windows, seventy-two hour breach notice, and data principal requests. Not yet for most: a Data Protection Officer, a Data Protection Impact Assessment, and cross-border transfer restrictions.
Figure 2 — What applies now versus what does not yet apply for most early-stage sellers: a DPO, a DPIA, and cross-border restrictions are above most sellers' threshold today (illustrative, not legal advice).

What Robnu does about this

Robnu is DPDP-aligned by design:

  • Data residency. Buyer PII (names, addresses, phone numbers) flowing through Robnu stays in India-residency regions. We do not move PII outside India for processing.
  • Token vault. Marketplace credentials encrypted with a per-seller DEK, under a KMS-managed master key. Audit log on every credential read.
  • Audit log. Sellers can read their own audit trail of credential access.
  • Breach posture. If something happens, we follow the DPDP seventy-two hour timeline — and we would notify you faster than that.
  • Data subject requests. Buyer access, erasure, and correction requests can flow through Robnu’s admin UI to the right place.
Split of DPDP responsibilities. Robnu by design: India-residency PII, a per-seller encrypted token vault under a KMS master key, an audit log on credential reads, a seventy-two hour breach posture, and routed data-subject requests. Seller still owns: a DPDP privacy policy, unchecked consent UI, retention windows, and records of consents.
Figure 3 — The split: what Robnu handles by design versus what the seller still owns. A tool is a useful primitive, not a compliance posture (illustrative, not legal advice).

What you still have to do

DPDP applies to you, not just to your tools. So:

  • Privacy policy. Update for DPDP. Generic templates from 2022 are not good enough.
  • Consent UI. WhatsApp opt-in checkboxes need to be unchecked by default. Email marketing consent needs to be separate from transactional consent.
  • Retention. Pick a retention window for buyer data (we recommend five years for orders, one year for marketing data). Delete on schedule.
  • Records. Keep records of consents and processing activities. The DPDP rules require you to be able to demonstrate compliance.

Spend an hour with the Act itself — it is surprisingly readable. Pair it with the Robnu data posture, decide your retention windows, and fix your consent UI. None of it is glamorous, and all of it is the boring infrastructure that keeps a small Indian brand out of trouble.

Tags:compliancedpdpsecurityprivacy

Frequently asked questions

  • Yes. India's Digital Personal Data Protection Act, passed in 2023, is now the framework for how any business handles buyer personal data. If you run a Shopify store, an AJIO account, and a customer-service WhatsApp, you are handling personal data and DPDP applies to you. The practical bar is lower than the headlines suggested, but it is not zero.

Start Robnu free

See where you're losing rupees on Ajio

Robnu walks every Ajio order from open through manifest, flags every silent deduction, and watches every SLA. Free during early access. No caps. No card. No trial timer.

  • Ajio order processing — every stage covered
  • Free for ≤ 25 orders/day — forever
  • 11-stage flow, document pipeline, SLA watchdog

Sources & further reading

  1. Digital Personal Data Protection Act, 2023 — official text and framework
    Ministry of Electronics and Information Technology, Government of IndiaAccessed July 2026
Hiren Bhuva
Co-founder, Onviqa Inc. · Robnu

Hiren has spent over a decade shipping commerce software for Indian sellers and runs Onviqa Inc., the parent company behind Robnu. He writes about marketplace ops, deduction defense, and the boring infrastructure that decides whether a small Indian brand keeps its money.

Related reading

All posts
build e7713058ee9ee67dffe938623a3f859dcb157b2a · 2026-07-24T12:14:00+05:30