Pandectes GDPR Compliance - 3,000+ Verified ⭐⭐⭐⭐⭐ 5/5 Reviews Worldwide - #1 on Shopify 🏅

India Digital Personal Data Protection Act (DPDPA) Compliance

Pandectes GDPR Compliance helps Shopify stores meet DPDPA requirements by collecting consent before non-essential cookies, scanning and classifying cookies, and keeping consent records.

Start Free
DPDPA India

The #1 cookie consent app for Shopify, trusted by 185k stores

  • Nike Strength
  • Reebok
  • Ted Baker
  • Juicy Couture
  • Aje
  • Casely
  • Oracle Red Bull Racing
  • KFC
  • Flying Tiger Copenhagen
  • Sennheiser
  • Susanne Kaufmann
  • Aldo
  • Victoria Beckham
  • Scalpers
  • UGREEN

What is DPDPA?

The Digital Personal Data Protection Act, 2023 (DPDPA) is India’s first comprehensive data protection law. It governs how businesses, which the Act calls “Data Fiduciaries”, process the digital personal data of individuals, called “Data Principals”. The Digital Personal Data Protection Rules, 2025 (DPDP Rules) set out the practical details, such as what a consent notice must contain and how to respond to requests.

Key requirements of the DPDPA include:

  • Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data needed for the stated purpose.
  • Each request for consent must come with a clear notice explaining what data is collected and why. Individuals can ask for the notice in English or in any of the languages listed in the Eighth Schedule to the Constitution.
  • Individuals can withdraw consent at any time, and withdrawing must be comparably easy to giving consent.
  • Processing a child’s data (anyone under 18) needs verifiable consent from a parent or guardian, and tracking, behavioral monitoring and targeted advertising directed at children are prohibited.
  • Individuals have rights to access, correct, update and erase their data, and requests must be answered within 90 days.
  • Data Fiduciaries must protect data with reasonable security safeguards and report personal data breaches.

Who does the DPDPA apply to?

The DPDPA applies to digital personal data processed in India. It also applies to processing outside India when it is connected to offering goods or services to people in India, so an online store based elsewhere that sells to customers in India is covered.

What happens if I don’t comply with the DPDPA?

The DPDPA is enforced by the Data Protection Board of India, which can inquire into breaches of the law and impose financial penalties. The maximum penalties are set in a schedule to the Act:

  • Up to ₹250 crore for failing to take reasonable security safeguards to prevent a personal data breach.
  • Up to ₹200 crore for failing to notify the Board and affected individuals of a personal data breach.
  • Up to ₹200 crore for breaching the additional obligations for children’s data.
  • Up to ₹50 crore for other breaches of the Act or the Rules by a Data Fiduciary.

The Board decides each penalty based on factors such as the nature, gravity and duration of the breach. Appeals against its decisions go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

When will the DPDPA go into effect?

The DPDPA received presidential assent on August 11, 2023, and the DPDP Rules were notified in November 2025. The provisions setting up the Data Protection Board took effect immediately, the rules for registered Consent Managers apply from November 2026, and the main obligations on businesses, including notice, consent, children’s data and data subject rights, apply from May 2027.

Complying with the DPDPA

Shopify stores that sell to customers in India should use the remaining time before May 2027 to prepare. Where cookies and tracking tools process personal data, the visitor’s consent must be a clear affirmative action, so pre-ticked boxes or treating continued browsing as consent will not meet the standard. The consent notice must stand on its own, list the data collected and each specific purpose in plain language, and visitors must be able to withdraw it as easily as they gave it. If your store may be used by children, take particular care with tracking and targeted advertising.

The DPDPA does not require a specific mechanism for transferring data abroad, but the government can restrict transfers to countries it notifies, so keep an eye on any such list. You should also publish contact details for privacy questions and set up a process to answer access, correction and erasure requests on time.

A Consent Management Platform (CMP) like Pandectes GDPR Compliance helps with the parts of this that happen on your storefront. It shows a cookie banner and blocks non-essential cookies until the visitor consents, automatically scans and classifies the cookies on your store, and generates a cookie declaration for your policy. It keeps consent logs as proof of consent, helps you handle data subject requests, and lets you configure banner settings by region using geolocation, so visitors from India can see a banner suited to the DPDPA.

Because the DPDPA is new and guidance from the Board is still developing, review your setup with legal counsel where appropriate.

Make your Shopify Store's use of cookies and online tracking compliant today

Try for free