DPDP Roles, explained simply

India's Digital Personal Data Protection Act. Who is who.

‹ Sector wise readiness

Sector wise readiness

E-commerce: the 2 crore user line that changes everything

What changes for an e-commerce business at 2 crore users?
Crossing 2 crore registered users triggers the Third Schedule retention rules automatically. That is separate from Significant Data Fiduciary status, which needs Government notification, and separate again from the one year transaction log duty that applies to everyone from day one.
Who this affects
D2C stores, marketplaces and online retailers at any size.
What to do about it
Keep the three triggers distinct, and do not game the threshold. Splitting entities or narrowing how you count registered users is the first thing an auditor probes.

One misconception I keep seeing when e-commerce startups read DPDP checklists: they assume every box applies from day one. It does not.

A D2C store on its first 5,000 customers is not expected to operate like Amazon or Flipkart. A small marketplace does not need every compliance product a national platform buys. A sector map is a superset, not a launch checklist.

What applies from the start, whatever your size

What may not apply to you yet

Keep the three triggers straight

There are three different lines, and people blur them. The 2 crore mark triggers the Third Schedule retention rules automatically. SDF status is separate and needs Government notification. And the 1 year transaction log duty applies to everyone from day one, even on deleted accounts. Three triggers, three mechanisms. Confusing them is how teams either over build or miss a basic.

A warning auditors look for

Do not game the threshold. Splitting into multiple branded entities, or narrowing how you count "registered users" to stay under 2 crore, is the first thing an auditor probes. Group structure and your definition of "registered user" get scrutinised under Section 8.

The better question

The better question is not "does e-commerce have this requirement?"

It is "have I actually triggered this requirement?"

Law creates obligations. Scale and risk influence implementation. Confusing the two is how e-commerce startups spend on tools they do not need while missing the basics.

Which obligation do you see e-commerce startups over implementing most?

Next in this series: SaaS and cloud ›

#DPDP #DataProtection #Ecommerce #DataPrivacy #Privacy #RetailTech

Get DPDP ready in hours, not weeks

Take the readiness assessment and generate your compliance documents from your answers.

Assess My Readiness