DPDP Roles, explained simply

India's Digital Personal Data Protection Act. Who is who.

‹ Sector wise readiness

Sector wise readiness

E-commerce: the 2 crore user line that changes everything

One misconception I keep seeing when e-commerce startups read DPDP checklists: they assume every box applies from day one. It does not.

A D2C store on its first 5,000 customers is not expected to operate like Amazon or Flipkart. A small marketplace does not need every compliance product a national platform buys. A sector map is a superset, not a launch checklist.

What applies from the start, whatever your size

What may not apply to you yet

Keep the three triggers straight

There are three different lines, and people blur them. The 2 crore mark triggers the Third Schedule retention rules automatically. SDF status is separate and needs Government notification. And the 1 year transaction log duty applies to everyone from day one, even on deleted accounts. Three triggers, three mechanisms. Confusing them is how teams either over build or miss a basic.

A warning auditors look for

Do not game the threshold. Splitting into multiple branded entities, or narrowing how you count "registered users" to stay under 2 crore, is the first thing an auditor probes. Group structure and your definition of "registered user" get scrutinised under Section 8.

The better question

The better question is not "does e-commerce have this requirement?"

It is "have I actually triggered this requirement?"

Law creates obligations. Scale and risk influence implementation. Confusing the two is how e-commerce startups spend on tools they do not need while missing the basics.

Which obligation do you see e-commerce startups over implementing most? Drop it in the comments.

Next in this series: SaaS and cloud ›

#DPDP #DataProtection #Ecommerce #DataPrivacy #Privacy #RetailTech

Be DPDP ready before the deadline

We are preparing more than a dozen ready to use templates, including the Privacy Notice, Consent Notice, Data Retention and Erasure Policy, Security Safeguards Policy, Breach Response Procedure, Children's Data Policy, and the Data Processing Agreement. Drop your email and we will notify you when the assessment and templates go live.