5 mins
DPDP 2023 Guide for Paris D2C Brands Serving Indian Markets
Map your existing privacy program to the Digital Personal Data Protection Act 2023. Understand extraterritorial scope, cross-border transfers, and how to unbundle consent for Indian buyers before the May 2027 deadline.
Last updated:
Extraterritorial Scope Reaches Paris Operations
Section 3 applies to processing outside India if it connects to offering goods or services to Data Principals within India. A Paris-based e-commerce brand ships directly to buyers in Delhi or Bengaluru. That physical delivery and digital transaction trigger compliance duties under the law. Accepting Indian Rupees or running targeted ads on local platforms establishes this connection. You do not need a physical office in India to fall under regulatory scope.
Mapping CNIL and GDPR to DPDP Deltas
Your existing privacy program covers much of the foundational work. You already maintain data maps and vendor contracts. The gap lies in specific operational mechanics required under the DPDP Act and the new Rules 2025. Generic global privacy suites miss the localized workflows required for Indian compliance. Heavy banking tools create unnecessary friction for consumer brands.
The law relies on volume and risk to determine obligations. Formal categories of data do not drive the compliance baseline. A D2C brand processes standard contact info and shipping addresses. You assess risk by the scale of the operation to determine if the company meets the threshold for a Significant Data Fiduciary. High volume processing triggers additional duties. Appointing an India-based Data Protection Officer and conducting periodic Data Protection Impact Assessments become necessary at that level.
Consent operates under strict structural rules for D2C companies. Section 4 establishes that consent is the primary basis for processing, except where Section 7 legitimate uses apply. European brands often bundle marketing consent into general terms of service. The law prohibits this practice. Separating shipping data consent from promotional email consent is a core requirement. Rule 3 of the DPDP Rules 2025 requires companies to provide privacy notices in English and the 22 regional languages listed in the Eighth Schedule of the Constitution. A generic English notice fails compliance when selling into Tier-2 Indian cities. The notice specifies the personal data collected, the precise purpose of processing, and the mechanisms for users to exercise their right to withdraw consent. Translating and presenting these itemised notices effectively validates the data collection.
Cross-border transfers function differently under Section 16 of the Act. The law permits transfers outside India unless the Central Government restricts specific countries through a notified negative list. You do not wait for a formal approval of the destination country. Data flows freely until a restriction is published. Section 16 also states that sectoral laws demanding higher protection remain valid. The Reserve Bank of India mandates localization for payment system data. Your payment gateways need to comply with those specific sectoral rules. The brand is the Data Fiduciary. Your company bears full legal responsibility for any failures by logistics providers or cloud hosts acting as Data Processors.
Breach notification timelines require a split workflow under the Rules 2025. The Rules mandate intimation to affected Data Principals without delay. Submitting a detailed report to the Data Protection Board within 72 hours is the next step. Your current incident response plan requires mapping to these exact triggers. The financial consequences for ignoring these rules are severe. The Data Protection Board has the authority to impose penalties up to INR 250 crore for failing to take reasonable security safeguards. Failing to notify the Board and affected individuals carries a penalty of up to INR 200 crore. These fines apply per breach event.
The 90-Day India-Ready Plan
1. Audit your current Indian user footprint to confirm applicability under Section 3.
2. Implement a consent unbundler to separate transactional shipping data from marketing lists.
3. Translate your itemised privacy notices into the required regional languages specified in the Eighth Schedule.
4. Publish the contact details of your Data Protection Officer or grievance contact person.
5. Update vendor agreements with your logistics and payment gateways to enforce breach reporting timelines.
Procurement Proofing for Enterprise Partnerships
Indian enterprise buyers now require DPDP posture evidence during security reviews. A claim of general European compliance no longer clears procurement. Buyers ask for localized consent logs and proof of itemised notice delivery. Producing data maps showing data flows into and out of India proves readiness. Generating these artifacts on demand secures the deal and shortens the sales cycle.
Cost of Waiting and Next Steps
Exactly 217 days remain until the 13 May 2027 compliance deadline. Retrofitting a global architecture at the last minute increases engineering costs. Build these rules into your current sprint cycles instead of disrupting future product releases.
Scan your India-facing stack and get a gap report before your next Indian enterprise deal review. Assess how ComplyDP handles consent unbundling and automatic regional translations compared to generic GRC tools. Start your evaluation at https://www.complydp.com/audit-preview today.
Sources
Frequently asked questions
Does the DPDP Act apply to our e-commerce brand based in Paris?
Yes. Section 3 applies to processing outside India if it connects to offering goods or services to Data Principals in India. Selling and shipping to Indian buyers brings your company into scope.
Can we continue bundling email marketing consent with our shipping terms?
No. The DPDP Act requires specific, clear consent for each purpose. Separating shipping data from marketing lists is a strict requirement. Consent is the primary basis for processing, except where Section 7 legitimate uses apply.
How do cross-border data transfers work under the new Indian privacy law?
Under Section 16, transfers outside India are generally permitted. The Central Government regulates this through a negative list of restricted countries or territories. Sectoral rules like RBI data localization still apply.
What is the deadline to comply with the DPDP Act 2023?
Companies have exactly 217 days until the compliance deadline on 13 May 2027. Meeting this date requires updating consent flows and notice translations well in advance.
Do we have to translate our privacy notice into multiple languages?
Yes. Rule 3 of the DPDP Rules 2025 requires providing the itemised notice in English and the 22 languages specified in the Eighth Schedule of the Constitution.
ComplyDP