If you take orders via Instagram DMs, Stories, or Link-in-Bio — you're collecting personal data and DPDP applies to you.
Every time a customer sends you their name, address, phone number, or payment details via Instagram DM, that message contains personal data under Section 3(a)(i) of the DPDP Act. You become a Data Fiduciary the moment you store, process, or use that information.
Most Instagram sellers don't have a consent notice, don't have a process for data deletion requests, and don't have an incident response plan. This is a violation — even if you're a solo seller with 500 followers.
| No. | Data source | What's collected |
|---|---|---|
| 01 | DM orders | Customer name, address, phone via chat |
| 02 | Stories & polls | Customer preferences and interactions |
| 03 | Google Form orders | Name, email, address, item selection |
| 04 | Payment details | UPI IDs forwarded via DM |
| 05 | Highlight viewer data | Instagram provides analytics on viewers |
| 06 | CRM/spreadsheet | If you log customer orders anywhere |
Send a consent notice
Before or at the point of collecting their address/phone, send them a message explaining what you collect and why. EasyDP automates this.
Log the consent
You need proof that consent was given. A screenshot isn't enough — it needs to be timestamped and stored securely.
Handle erasure requests
If a customer asks "delete my data", act within the response time you have published (Rule 14) — many businesses commit to 30 days. This includes removing them from your WhatsApp lists and spreadsheets, except records other laws require you to keep.
Secure your data
Customer details in a plain spreadsheet or WhatsApp group are high risk. Encrypt and restrict access.
Our Instagram add-on (available on Growth+ plans) auto-handles DM compliance:
Takes 2 minutes. Get your exact obligations and penalty exposure.