Sector wise readiness
Retail and omnichannel: the sale needs a payment, not a face
- Do physical shops fall under DPDP?
- Yes. Cameras counting footfall and increasingly analysing faces, a loyalty card tied to every basket, and a POS holding card details make a physical store a data operation with a shopfront attached.
- Who this affects
- Retail chains, supermarkets, and any store running loyalty schemes or camera analytics.
- What to do about it
- Collect what the sale actually needs. The sale needs a payment. It does not need a face.
A misconception I keep seeing when retail chains and supermarkets read DPDP checklists: "we are a physical shop, the data rules are for online businesses."
Walk your own store. Cameras counting footfall and, increasingly, analysing faces. A loyalty card tied to every basket. A POS holding card details. You are running a data operation with a shopfront attached.
The auditor's observation here is blunt: in store camera analytics and loyalty profiling routinely collect far more than the sale actually needs. The sale needs a payment. It does not need a face.
A sector map is a superset, not a launch checklist.
What applies from the start, whatever your size
- ✅ Notice
- ✅ Consent and easy withdrawal
- ✅ Security safeguards
- ✅ Rights handling
- ✅ Grievance mechanism
- ✅ Processor contracts
- ✅ Breach response
What retail carries from day one
- ✅ Loyalty profiling needs consent. Completing the transaction is one purpose. Marketing and profiling on that basket data is another, and it needs its own consent.
- ✅ CCTV and footfall analytics need a basis and notice. Facial analytics is high risk. Minimise it, and be able to justify why you need identity rather than a headcount.
- ✅ POS and payment security. Tokenise card and UPI data at the till. A day one duty, with no size gate.
- ✅ Loyalty retention. Erase loyalty data on inactivity, reconciled against tax and warranty needs. A dormant account from 2019 is not a live purpose.
What may not apply yet
- ❌ SDF obligations. Large chains are plausible candidates to assess, but Significant Data Fiduciary status comes only on Government notification, not from store count.
- ❌ A mandatory Data Protection Officer, annual DPIAs and independent audits. These attach to SDF status once notified.
The better question
The better question is not "do online rules apply to a physical store?"
It is "everything our cameras and loyalty programme collect, does the sale actually need it?"
Law creates obligations. Scale and risk influence implementation. But minimisation and POS security apply from your first till. Neither waits for scale.
If you run retail, could you justify your facial analytics to an auditor tomorrow?