News Analysis4 mins

DPDP Act Shifts Privacy to the Boardroom: E-Commerce Compliance Expsoure

The DPDP Act elevates data privacy from IT operations to a boardroom governance mandate. E-commerce compliance heads face new risks around unbundled consent, 22-language notices, and 72-hour breach reporting rules.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What happened

On July 28, 2026, ETLegalWorld published an analysis detailing how the Digital Personal Data Protection Act, 2023 elevates data privacy from a back-office IT function to a critical boardroom governance issue. Author Varun Singh notes that Indian companies historically relegated data privacy to IT staff, compliance officers, or outside counsel. The analysis traces this constitutional shift back to the Supreme Court's 2017 ruling in K.S. Puttaswamy (Retd.) v. Union of India, which established privacy as a fundamental right. For corporate boards, this transition means privacy failures now carry direct governance consequences rather than operational IT risks alone. The report highlights that organizations must manage this alongside sectoral demands from regulators such as the RBI, IRDAI, and the National Digital Health Mission framework.

Does the DPDP Act apply here?

This boardroom escalation directly applies to large D2C and E-commerce enterprises processing digital personal data. The Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. For high-volume platforms, transaction scale often triggers Significant Data Fiduciary designation under the Act. Once classified as an SDF, the compliance burden shifts upwards, requiring the appointment of a Data Protection Officer based in India who reports directly to the Board of Directors or governing body. The Head of Compliance must provide the board with regulator-ready evidence packs demonstrating that the enterprise meets obligations across both the DPDP Act and overlapping sectoral frameworks.

Legal implications under DPDP

Under the DPDP Act and the Rules, 2025, consent is the primary basis for processing, except where Section 7 legitimate uses apply. For E-commerce compliance heads, this fundamentally alters how marketing data is collected, as Section 6 requires consent to be free, specific, informed, unconditional, and unambiguous. Rule 3 mandates providing itemised notices in up to 22 scheduled languages, an operational hurdle for customer-facing brands. Regarding global operations, the Act permits cross-border transfers generally unless the Central Government restricts transfer to notified countries or territories. In the event of a failure, the Rules, 2025 dictate exact breach response timelines, requiring intimation to affected Data Principals without delay and a detailed report to the Data Protection Board within 72 hours.

Could this happen to you

If your CMO relies on pre-ticked boxes or bundled terms of service to build email marketing lists, your enterprise is highly exposed. When the Data Protection Board of India investigates a consumer complaint, they will not ask your IT team for a general policy document. They will demand that the Head of Compliance produce verifiable consent artefacts tied to specific users and explicit processing purposes. The boardroom risk is a penalty ceiling of up to 250 crore rupees for failing to implement reasonable security safeguards, and up to 200 crore rupees for breaching consent obligations. You need specialized tooling that separates shipping data from marketing data and auto-translates notices, ensuring your CTO and CMO can operate without dragging the enterprise into compliance failures.

What companies should do in the next 30 days

1. Conduct a board-level briefing where the Head of Compliance presents a DPDP risk matrix, quantifying exposure in terms of potential penalties and enterprise-deal risks.

2. Unbundle your consent flows by partnering with the CTO to audit all customer checkout forms, ensuring separate opt-ins for delivery and marketing.

3. Implement a translation protocol to serve itemised notices in 22 regional languages as mandated by the Rules, 2025, storing the exact version the Data Principal agreed to.

4. Establish a 72-hour breach workflow that maps the exact chain of command from the control owner identifying an anomaly to the Board and the DPBI.

5. Review vendor contracts to ensure all data processors have contractual obligations to report breaches to you immediately, enabling you to meet regulatory timelines.

What to watch

As established under Sections 18 and 19 of the DPDP Act, the Central Government is operationalising the Data Protection Board of India to enforce these exact provisions. Compliance heads must monitor the DPBI's initial enforcement actions to understand how strictly the 72-hour breach reporting window and SDF board oversight mandates will be penalized in practice. The overlapping regulatory environment requires watching for harmonisation guidelines between the DPBI and sectoral regulators like the RBI. There are exactly 285 days remaining until the DPDP hard compliance deadline of 13 May 2027. Do not wait for an auditor to expose gaps in your consent trails or language capabilities. Evaluate your enterprise exposure today with a free scan at freescan.complydp.com to identify gaps in your RoPA and consent architecture.

Sources

Frequently asked questions

Does the DPDP Act apply to our D2C e-commerce operations?

Yes. The Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. High transaction volumes may also classify your enterprise as a Significant Data Fiduciary, requiring board-level oversight.

Can we continue bundling marketing consent with shipping terms?

No. Under Section 6 of the DPDP Act, consent must be free, specific, informed, unconditional, and unambiguous. Consent is the primary basis for processing, except where Section 7 legitimate uses apply, meaning marketing opt-ins must be separated from operational shipping data.

How long do we have to report a data breach under the new framework?

The Rules, 2025 mandate exact timelines for data breach response. Enterprises must provide intimation to affected Data Principals without delay and submit a detailed report to the Data Protection Board of India within 72 hours.

What is the penalty for failing to obtain proper consent or secure data?

The DPDP Act establishes a penalty ceiling of up to 250 crore rupees for failing to implement reasonable security safeguards. Breaching consent obligations can result in penalties up to 200 crore rupees, making compliance a critical boardroom issue.

Do we need to restrict cross-border data transfers entirely?

No, the Act permits cross-border transfers generally. Transfers are only restricted if the Central Government places a specific country or territory on a notified negative list.