DPDP Compliance for E-commerce
Payment Data Security
- Never store full credit card numbers; use tokenization
- Retain payment data only 90 days for refunds
- Encrypt all financial data at-rest (AES-256)
Cookies & Tracking
- Obtain explicit consent BEFORE setting non-essential cookies
- Implement granular cookie consent (analytics, marketing, functional)
- Allow users to reject tracking
Third-Party Vendors
- Signed DPAs with payment gateways (Razorpay, Stripe)
- Signed DPAs with analytics (Google Analytics)
- Signed DPAs with email services
Customer Data Rights
- Enable data download/deletion for customers
- Respond to requests within 30 days
- Provide data in machine-readable format
Disclaimer: General informational article. Consult legal counsel. dpdp compliance case study ecommerce
Get Compliant: Start your free DPDP compliance assessment dpdp compliance fintech dpdp compliance healthtech DPDP for E-commerce