BLOG · DPDP ACT 2023 · DPDP RULES 2025

DPDP Act compliance guide for small businesses and e-commerce

LAST UPDATED SEPTEMBER 29, 2026

If your website has a contact form, a newsletter sign-up, a checkout or even Google Analytics, you collect personal data — and India’s Digital Personal Data Protection Act (DPDP Act) applies to you. From 13 May 2027, the DPDP Rules 2025 set clear rules for how you do that. This DPDP compliance guide explains what the law says, the deadlines that matter, and what a small business or e-commerce store needs to fix — in plain language.

What is the DPDP Act 2023?

The Digital Personal Data Protection Act, 2023 (the “DPDP Act” or “DPDPA”) is India’s data protection law. The DPDP Rules, 2025, published on 13 November 2025, fill in the practical details. Together they decide how businesses may collect, use, store and delete personal data.

Personal data means any data about a person who can be identified from it: name, email, phone number, address, order history, IP address, device ID and so on. The law covers personal data in digital form, including paper records you later digitise.

It uses three roles you should know:

  • Data Principal— your visitor or customer, the person the data is about. For a child under 18, this includes the parent.
  • Data Fiduciary— you, the business that decides why and how data is used. You are responsible for compliance.
  • Data Processor— any vendor that handles data for you: your hosting, website builder, payment gateway, email or SMS tool. You stay responsible for what they do with your customers’ data.

Does the DPDP Act apply to small businesses and e-commerce?

Almost certainly, yes. The Act applies to personal data processed in India, and to businesses outside India that offer goods or services to people in India. There is no general exemption for small businesses. The government mayexempt some startups from some duties in future, but none has been notified — so plan as if the full law applies to you.

DPDP Act implementation timeline and deadlines

11 AUG 2023

DPDP Act passed

The Digital Personal Data Protection Act, 2023 becomes law. Most of it waits for the Rules.

13 NOV 2025

DPDP Rules notified

Definitions and the Data Protection Board come into force. The countdown starts.

13 NOV 2026

Consent Managers go live

Consent Managers can register with the Board. Your users may start giving or withdrawing consent through them.

13 MAY 2027

Almost everything else applies

Notices, security safeguards, breach reporting, data retention and erasure, children's data, user rights and grievance handling all become enforceable.

18 months sounds like a lot. It isn’t, if your forms, checkout and database need changing. Retrofitting consent and deletion into a live store is slower and costlier than building it in now. Keep an eye on government notifications, since timelines can change.

DPDP compliance checklist: 11 steps before 13 May 2027

01

Map the personal data you collect

List every form, checkout field, cookie, plugin and third-party app on your site. For each one, write down what data it collects, why, where it is stored, who it is shared with and when it is deleted. If you don’t need a field, stop collecting it.

02

Show a DPDP privacy notice where you collect data

Before or when you ask for consent, show a short notice that stands on its own — not just a link to a long privacy policy. It must list the data you collect and the purpose of each, and tell people how to withdraw consent, how to use their rights and how to complain to the Data Protection Board. People can ask for it in English or any of the 22 languages in the Eighth Schedule of the Constitution.

03

Get valid consent (DPDP consent requirements)

  • One unticked checkbox per purpose — for example, “send me offers” separate from “process my order”.
  • No “by using this site you agree” and no pre-ticked boxes.
  • Your store must still work if someone says no to marketing.
  • Keep a record of who agreed to what, and when. If challenged, you must prove it.
04

Use a DPDP-compliant cookie consent banner

Analytics, ad pixels and marketing tags usually rely on consent. Use a consent banner that keeps them switched off until the visitor agrees.

05

Make withdrawing consent as easy as giving it

If it took one click to sign up, it should take one click to opt out. After someone withdraws, stop processing their data and make your vendors stop too.

06

Put reasonable security safeguards in place

Rule 6 sets a minimum: encryption or masking of personal data, access control, logs and monitoring of who accessed data, backups, and security terms in your contracts with vendors. Keep those logs for at least one year.

07

Prepare for data breach reporting (72 hours)

Any leak, loss or unauthorised access to personal data is a breach, however small. You must tell every affected customer without delay, send the Board a first report without delay, and a detailed report within 72 hours of finding out. Decide now who does what.

08

Set data retention and deletion rules

Erase personal data once its purpose is served or consent is withdrawn, unless another law makes you keep it (tax and accounting records, for example). But keep order records and processing logs for at least one year, even if the customer deletes their account. Very large platforms (e-commerce with 2 crore or more registered users) must also delete data of users inactive for three years, with 48 hours’ notice.

09

Handle data principal rights requests

Customers can ask to see a summary of their data, correct or update it, erase it, nominate someone to act for them, and raise a grievance. Publish how to make a request and who to contact, and reply within your published time limit — no more than 90 days.

10

Get parental consent for children’s data

Anyone under 18 is a child under the Act. You need verifiable consent from a parent before processing a child’s data, and you must not track children or show them targeted ads. If you sell to young people, add an age check.

11

Sign data processing contracts with vendors

Your website builder, host, payment gateway, courier, email and analytics tools all handle your customers’ data. Make sure each contract covers security, breach reporting and deletion.

DPDP Act penalties for non-compliance

The Data Protection Board can impose penalties of up to (per breach):

Not taking reasonable security safeguards₹250 crore
Not reporting a personal data breach to the Board and to affected users₹200 crore
Breaking the extra rules for children's data₹200 crore
Any other breach of the Act or Rules (for example, invalid consent or notices)₹50 crore

These are maximums. The Board looks at how serious and how long the breach was, the type of data, and what you did to limit the harm. Showing you took reasonable steps matters.

How Uvera helps with DPDP compliance

We are a software team, so we fix the technical side — the forms, banners, databases and workflows the law depends on.

01

Free audit

Start with a free scan at dpdp-audit.in. It shows the trackers, forms and notices on your site that need attention.

02

Data map and gap report

We list every place your site collects personal data — forms, checkout, cookies, plugins, payment and email tools — and match each one to what the law requires.

03

Consent and notices

We add a consent banner that keeps analytics and marketing tags off until visitors agree, clear notices on every form, unticked per-purpose checkboxes, and a consent log you can show the Board. Wix sites can use our DPDP Banner app.

04

User rights and grievances

We build simple flows for customers to see, correct or delete their data, withdraw consent and raise a complaint, with a tracker so no request passes the 90-day limit.

05

Security hardening

HTTPS everywhere, encryption, strong admin access with two-factor login, access logs kept for a year, tested backups, and no personal data leaking into logs or URLs.

06

Retention and breach readiness

Automatic clean-up jobs that delete data when it is no longer needed (while keeping the one-year records the Rules ask for), plus a breach plan and ready-to-send notices for the 72-hour window.

Free DPDP compliance tools

  • Free DPDP audit — Scan your website and get a plain-language report of the gaps — consent, notices, trackers and security basics.
  • DPDP Banner for Wix — A DPDP-ready consent banner for Wix sites and Wix stores. Optional tracking stays off until your visitor says yes.

DPDP Act FAQs

01

What is the DPDP Act 2023?

The Digital Personal Data Protection Act, 2023 (DPDP Act or DPDPA) is India's data protection law. It sets rules for how businesses collect, use, store and delete digital personal data, and gives people rights over their data. The DPDP Rules, 2025, notified on 13 November 2025, explain how to comply.

02

When does the DPDP Act come into force?

In phases. The DPDP Rules were notified on 13 November 2025, the Consent Manager rules apply from 13 November 2026, and most compliance duties — notice, consent, security, breach reporting, data retention, children's data and user rights — apply from 13 May 2027.

03

Does the DPDP Act apply to small businesses?

Yes. There is no general exemption based on size. If your website or online store collects personal data such as names, emails, phone numbers or addresses from people in India, the DPDP Act applies. The government may exempt some startups from some duties in future, but no such exemption has been notified.

04

What is the penalty under the DPDP Act?

The Data Protection Board can impose penalties of up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for not reporting a personal data breach or breaking the rules on children's data, and up to ₹50 crore for other breaches of the Act or Rules.

05

Do I need a cookie consent banner under the DPDP Act?

The Act does not mention cookies by name, but analytics and marketing cookies, pixels and trackers that collect personal data generally need consent. A consent banner that keeps them switched off until the visitor agrees is the practical way to comply.

06

How soon must a data breach be reported under the DPDP Rules?

Without delay to each affected person and to the Data Protection Board, followed by a detailed report to the Board within 72 hours of becoming aware of the breach. There is no minimum size — every personal data breach must be reported.

07

What is the difference between the DPDP Act and GDPR?

Both protect personal data, but the DPDP Act covers only digital personal data, has no separate 'sensitive data' category, relies on consent plus a short list of 'legitimate uses' instead of GDPR's broader legal bases such as legitimate interests, and sets fixed penalty caps (up to ₹250 crore) instead of a percentage of turnover.

08

What is a Data Fiduciary under the DPDP Act?

The business or person that decides why and how personal data is processed — the equivalent of a 'data controller' under GDPR. If you run a website or online store, you are the Data Fiduciary for your customers' data.

Talk to the Uvera team

Not sure where your site stands? Tell us about it and we’ll walk you through what needs to change.

OR EMAIL INFO@UVERA.TECH

This guide is general information based on the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. It is not legal advice. For decisions about your business, please consult a lawyer.

← BACK TO HOME