Everything Shopify store owners need to know about India's Digital Personal Data Protection Act 2023.
Yes — if your Shopify store collects personal data from Indian customers (names, addresses, phone numbers, email addresses, payment details), you are a Data Fiduciary under Section 2(i) of the DPDP Act 2023. This applies regardless of your store size.
| No. | Data source | What's collected |
|---|---|---|
| 01 | Checkout data | Name, email, phone, shipping address |
| 02 | Payment data | Razorpay / Stripe transaction references |
| 03 | Account data | Customer login, order history, wishlist |
| 04 | Analytics | IP addresses, device IDs, browsing behaviour |
| 05 | Third-party apps | Review apps, loyalty programs, chat widgets |
| 06 | Shipping processors | Shiprocket, Delhivery — processor liability |
Add a DPDP-compliant consent notice at checkout
Must state what data is collected, why, and for how long. Cannot be pre-ticked. Must be in the customer's preferred language.
Handle customer data requests on your published timelines
Customers can request access to their data, correction, or complete erasure. Publish how fast you respond and meet it (Rule 14) — many businesses commit to 30 days.
Sign Data Processing Agreements with your processors
Razorpay, Shiprocket, Delhivery, and every third-party app are your Data Processors. You are responsible for their compliance.
Report breaches on the legal clock
Inform affected customers and the Data Protection Board without delay, and file the detailed breach report with the Board within 72 hours (Rule 7).
Maintain an audit log
Keep records of every consent event and data request — security logs for at least one year (Rule 6), consent records for as long as you rely on them (Section 6).
EasyDP's Shopify app installs in 10 minutes. Join early access free.