BLOG · DPDP ACT 2023 · DPDP RULES 2025
DPDP Act compliance guide for small businesses and e-commerce
LAST UPDATED SEPTEMBER 29, 2026
If your website has a contact form, a newsletter sign-up, a checkout or even Google Analytics, you collect personal data — and India’s Digital Personal Data Protection Act (DPDP Act) applies to you. From 13 May 2027, the DPDP Rules 2025 set clear rules for how you do that. This DPDP compliance guide explains what the law says, the deadlines that matter, and what a small business or e-commerce store needs to fix — in plain language.
What is the DPDP Act 2023?
The Digital Personal Data Protection Act, 2023 (the “DPDP Act” or “DPDPA”) is India’s data protection law. The DPDP Rules, 2025, published on 13 November 2025, fill in the practical details. Together they decide how businesses may collect, use, store and delete personal data.
Personal data means any data about a person who can be identified from it: name, email, phone number, address, order history, IP address, device ID and so on. The law covers personal data in digital form, including paper records you later digitise.
It uses three roles you should know:
- Data Principal— your visitor or customer, the person the data is about. For a child under 18, this includes the parent.
- Data Fiduciary— you, the business that decides why and how data is used. You are responsible for compliance.
- Data Processor— any vendor that handles data for you: your hosting, website builder, payment gateway, email or SMS tool. You stay responsible for what they do with your customers’ data.
Does the DPDP Act apply to small businesses and e-commerce?
Almost certainly, yes. The Act applies to personal data processed in India, and to businesses outside India that offer goods or services to people in India. There is no general exemption for small businesses. The government mayexempt some startups from some duties in future, but none has been notified — so plan as if the full law applies to you.
DPDP Act implementation timeline and deadlines
11 AUG 2023DPDP Act passed
The Digital Personal Data Protection Act, 2023 becomes law. Most of it waits for the Rules.
13 NOV 2025DPDP Rules notified
Definitions and the Data Protection Board come into force. The countdown starts.
13 NOV 2026Consent Managers go live
Consent Managers can register with the Board. Your users may start giving or withdrawing consent through them.
13 MAY 2027Almost everything else applies
Notices, security safeguards, breach reporting, data retention and erasure, children's data, user rights and grievance handling all become enforceable.
18 months sounds like a lot. It isn’t, if your forms, checkout and database need changing. Retrofitting consent and deletion into a live store is slower and costlier than building it in now. Keep an eye on government notifications, since timelines can change.
DPDP compliance checklist: 11 steps before 13 May 2027
01Map the personal data you collect
List every form, checkout field, cookie, plugin and third-party app on your site. For each one, write down what data it collects, why, where it is stored, who it is shared with and when it is deleted. If you don’t need a field, stop collecting it.
02Show a DPDP privacy notice where you collect data
Before or when you ask for consent, show a short notice that stands on its own — not just a link to a long privacy policy. It must list the data you collect and the purpose of each, and tell people how to withdraw consent, how to use their rights and how to complain to the Data Protection Board. People can ask for it in English or any of the 22 languages in the Eighth Schedule of the Constitution.
03Get valid consent (DPDP consent requirements)
- One unticked checkbox per purpose — for example, “send me offers” separate from “process my order”.
- No “by using this site you agree” and no pre-ticked boxes.
- Your store must still work if someone says no to marketing.
- Keep a record of who agreed to what, and when. If challenged, you must prove it.
04Use a DPDP-compliant cookie consent banner
Analytics, ad pixels and marketing tags usually rely on consent. Use a consent banner that keeps them switched off until the visitor agrees.
05Make withdrawing consent as easy as giving it
If it took one click to sign up, it should take one click to opt out. After someone withdraws, stop processing their data and make your vendors stop too.
06Put reasonable security safeguards in place
Rule 6 sets a minimum: encryption or masking of personal data, access control, logs and monitoring of who accessed data, backups, and security terms in your contracts with vendors. Keep those logs for at least one year.
07Prepare for data breach reporting (72 hours)
Any leak, loss or unauthorised access to personal data is a breach, however small. You must tell every affected customer without delay, send the Board a first report without delay, and a detailed report within 72 hours of finding out. Decide now who does what.
08Set data retention and deletion rules
Erase personal data once its purpose is served or consent is withdrawn, unless another law makes you keep it (tax and accounting records, for example). But keep order records and processing logs for at least one year, even if the customer deletes their account. Very large platforms (e-commerce with 2 crore or more registered users) must also delete data of users inactive for three years, with 48 hours’ notice.
09Handle data principal rights requests
Customers can ask to see a summary of their data, correct or update it, erase it, nominate someone to act for them, and raise a grievance. Publish how to make a request and who to contact, and reply within your published time limit — no more than 90 days.
10Get parental consent for children’s data
Anyone under 18 is a child under the Act. You need verifiable consent from a parent before processing a child’s data, and you must not track children or show them targeted ads. If you sell to young people, add an age check.
11Sign data processing contracts with vendors
Your website builder, host, payment gateway, courier, email and analytics tools all handle your customers’ data. Make sure each contract covers security, breach reporting and deletion.
DPDP Act penalties for non-compliance
The Data Protection Board can impose penalties of up to (per breach):
These are maximums. The Board looks at how serious and how long the breach was, the type of data, and what you did to limit the harm. Showing you took reasonable steps matters.
How Uvera helps with DPDP compliance
We are a software team, so we fix the technical side — the forms, banners, databases and workflows the law depends on.
01Free audit
Start with a free scan at dpdp-audit.in. It shows the trackers, forms and notices on your site that need attention.
02Data map and gap report
We list every place your site collects personal data — forms, checkout, cookies, plugins, payment and email tools — and match each one to what the law requires.
03Consent and notices
We add a consent banner that keeps analytics and marketing tags off until visitors agree, clear notices on every form, unticked per-purpose checkboxes, and a consent log you can show the Board. Wix sites can use our DPDP Banner app.
04User rights and grievances
We build simple flows for customers to see, correct or delete their data, withdraw consent and raise a complaint, with a tracker so no request passes the 90-day limit.
05Security hardening
HTTPS everywhere, encryption, strong admin access with two-factor login, access logs kept for a year, tested backups, and no personal data leaking into logs or URLs.
06Retention and breach readiness
Automatic clean-up jobs that delete data when it is no longer needed (while keeping the one-year records the Rules ask for), plus a breach plan and ready-to-send notices for the 72-hour window.
Free DPDP compliance tools
- Free DPDP audit — Scan your website and get a plain-language report of the gaps — consent, notices, trackers and security basics.
- DPDP Banner for Wix — A DPDP-ready consent banner for Wix sites and Wix stores. Optional tracking stays off until your visitor says yes.
DPDP Act FAQs
01What is the DPDP Act 2023?
The Digital Personal Data Protection Act, 2023 (DPDP Act or DPDPA) is India's data protection law. It sets rules for how businesses collect, use, store and delete digital personal data, and gives people rights over their data. The DPDP Rules, 2025, notified on 13 November 2025, explain how to comply.
02When does the DPDP Act come into force?
In phases. The DPDP Rules were notified on 13 November 2025, the Consent Manager rules apply from 13 November 2026, and most compliance duties — notice, consent, security, breach reporting, data retention, children's data and user rights — apply from 13 May 2027.
03Does the DPDP Act apply to small businesses?
Yes. There is no general exemption based on size. If your website or online store collects personal data such as names, emails, phone numbers or addresses from people in India, the DPDP Act applies. The government may exempt some startups from some duties in future, but no such exemption has been notified.
04What is the penalty under the DPDP Act?
The Data Protection Board can impose penalties of up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for not reporting a personal data breach or breaking the rules on children's data, and up to ₹50 crore for other breaches of the Act or Rules.
05Do I need a cookie consent banner under the DPDP Act?
The Act does not mention cookies by name, but analytics and marketing cookies, pixels and trackers that collect personal data generally need consent. A consent banner that keeps them switched off until the visitor agrees is the practical way to comply.
06How soon must a data breach be reported under the DPDP Rules?
Without delay to each affected person and to the Data Protection Board, followed by a detailed report to the Board within 72 hours of becoming aware of the breach. There is no minimum size — every personal data breach must be reported.
07What is the difference between the DPDP Act and GDPR?
Both protect personal data, but the DPDP Act covers only digital personal data, has no separate 'sensitive data' category, relies on consent plus a short list of 'legitimate uses' instead of GDPR's broader legal bases such as legitimate interests, and sets fixed penalty caps (up to ₹250 crore) instead of a percentage of turnover.
08What is a Data Fiduciary under the DPDP Act?
The business or person that decides why and how personal data is processed — the equivalent of a 'data controller' under GDPR. If you run a website or online store, you are the Data Fiduciary for your customers' data.
Talk to the Uvera team
Not sure where your site stands? Tell us about it and we’ll walk you through what needs to change.
OR EMAIL INFO@UVERA.TECH
This guide is general information based on the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. It is not legal advice. For decisions about your business, please consult a lawyer.
← BACK TO HOME