Who this page is for
Brands that sell from their own online store, on Shopify, Wix or WordPress, to customers across India. It does not cover selling only through marketplaces.
The personal data a store usually holds
These are typical for a store. Yours may differ, and your data record (step 03) is where you list what is true for you.
| What a store typically holds | Where it comes from | What the Act says |
|---|---|---|
| Customer name, phone number, delivery address, email | Checkout, account sign-up, enquiry forms | Personal data is any data about an identifiable individual. |
| Order and payment references | Your store admin and the payment gateway | The Rules' own worked example for an online purchase keeps the order details, personal data and logs, such as order confirmation, payment and delivery events, for at least one year from the transaction. |
| Cookie and analytics identifiers | Store themes, analytics and advertising tools | List them in your data record (step 03); where consent is your basis, give a notice and ask for consent. |
| Newsletter, WhatsApp and support contacts | Sign-up forms, chat, email | Each needs a lawful purpose: consent with a notice that states it, or a legitimate use such as data a person volunteers for a stated purpose. |
| Customer details held by your processors | Store platform, payment gateway, courier, email tool | You stay responsible for processing done on your behalf, and a processor may act only under a valid contract. |
Which documents to start with
- Step 01: Start here. Confirm the Act applies and see which duties you already cover.
- Step 03: Know your data. List every item above, where it sits and which vendor holds it.
- Step 05: Ask properly. The notice shown with or before a consent request: itemised data, a specific purpose, how to withdraw and complain.
- Step 04: Set the rules. The policy behind it.
- Step 06: Keep only as long as needed. Erasure when the purpose ends, unless a law requires keeping it, and the one-year retention of logs.
- Step 07: Answer people on time. Customers asking for their data or a correction; grievance replies within the period you publish, 90 days at most.
- Step 09: Control your vendors. Your store platform, gateway, courier and email tool.
- Step 09b: Sign the vendor contract. The contract with each one.
- Step 11: When something goes wrong. A breach: tell the Board and each affected customer.
If any of your tools keep data outside India, add step 10: the Act restricts transfers only to countries the Central Government notifies, and the Rules let the Government set requirements by order for making data available to a foreign State. If you sell to children, the Act needs verifiable parental consent and bars tracking, behavioural monitoring and targeted advertising aimed at them, apart from narrow exemptions in the Rules.
The Rules set fixed retention periods for e-commerce entities with not less than two crore registered users in India. Check whether you are near that size.
When it applies, and the penalty ceiling
Duties and the Board’s power to penalise apply from 13 May 2027. The ceiling for failing to take reasonable security safeguards is up to ₹250 crore, and a penalty is imposed only after an inquiry finds a significant breach, after you have been given an opportunity of being heard.
The sections and rules behind these lines are in the free duties list, on How we arrived here, and in the articles.
The documents are a drafting aid. Get legal advice for your situation.