# Retail & e-commerce security compliance in India — the TechBag guide

> For Indian store-led retailers (supermarket, fashion, electronics and pharmacy chains; QSR and franchise networks) and online sellers (marketplaces, D2C brands, quick commerce). Every obligation carries its source and the date it was verified. Last reviewed 2026-10-05. General information, not legal advice.

Web version: https://www.thetechbag.com/industries/retail · Obligations: https://www.thetechbag.com/industries/retail/obligations · Controls: https://www.thetechbag.com/industries/retail/controls

## The core point: one incident, several clocks — the law's, and your contracts' own

- **CERT-In FAQ, Q13** (on the Directions of 28 April 2022): "Any entity which notices the cyber security incident, shall report to CERT-In. The obligation of reporting of cyber incident is neither transferrable nor indemnified or dispense with." A retailer cannot hand its six-hour duty to its e-commerce agency or SaaS vendor.
- **ONDC Network Policy, 8.2.2:** a network participant "must alert ONDC of such Data Breach or cyber security incident within 6 hours of being aware", and files a yearly certificate from an ONDC- or CERT-In-empanelled auditor.
- **Amazon Selling Partner API Data Protection Policy, 1.6.3:** "notify Amazon … within twenty four (24) hours of detecting a Security Incident" — binding a seller’s own integration too.
- **Payment gateways:** Cashfree's merchant terms ask for suspected security events within 12 hours; Razorpay's for breaches within 24.

### The reporting clocks one incident can start

- **CERT-In** — 6 hours from the moment you notice it, to CERT-In.
- **ONDC** — 6 hours from becoming aware of a breach, to ONDC.
- **Payment gateway** — 12–24 hours from a suspected security event, to your payment gateway.
- **Amazon** — 24 hours from detecting a security incident, to Amazon.
- **NIS2** — 24 hours from becoming aware of a significant incident, to the national CSIRT (early warning).
- **DPDP** — 72 hours from a personal-data breach (from May 2027), to the Data Protection Board.
- **GDPR** — 72 hours from becoming aware of a breach, to the EU / UK supervisory authority.

## The industry

Stores: 20,169 Reliance Retail stores; 963 Zudio stores; 500 DMart stores; 2,455 Domino’s India stores. Online: ~$60bn online retail, 2024; 270M+ online shoppers; 2,443 Blinkit dark stores; 85.5% of payments by volume on UPI. Sources: Company filings and results (Reliance Retail Q1 FY27, Trent FY26, Avenue Supermarts 31 March 2026, Jubilant FoodWorks, Eternal Q1 FY27); Bain & Company with Flipkart, March 2025; RBI Payment System Report, H2 2025.

## Deadlines (2025–2027)

- 2025-03-31 — Checkout-script rules mandatory (PCI DSS)
- 2025-06-05 — Dark-pattern self-audit advised (Dark patterns)
- 2025-09-15 — PA Master Direction issued (RBI PA rules)
- 2025-11-13 — DPDP Rules notified (DPDP)
- 2026-02-20 — 7-day grievance resolution (Intermediary Rules)
- 2026-04-01 — Dynamic factor for online card pay (RBI 2FA rules)
- 2026-04-21 — E-mandate Framework issued (E-mandates)
- 2026-04-22 — Amended COPPA compliance date (COPPA)
- 2026-09-09 — E-Commerce amendment notified (E-Commerce Rules)
- 2026-09-15 — Existing merchants re-checked (RBI PA rules)
- 2026-09-18 — TRAI spam-rules amendment issued (TRAI spam rules)
- 2026-11-13 — Consent Managers begin (DPDP)
- 2027-01-01 — E-Commerce amendment in force (E-Commerce Rules)
- 2027-01-01 — Yearly dark-pattern self-audit required (Dark patterns)
- 2027-01-01 — CCPA automated-decision rules (CCPA)
- 2027-05-13 — DPDP operational duties apply (DPDP)
- 2027-05-13 — SPDI Rules fall away (IT Act 43A)

## The 26 obligations

### Indian law & regulators

What binds every Indian retailer, or every retailer doing a particular kind of selling.

#### CERT-In Directions under section 70B(6), 28 April 2022

- **Issuer:** CERT-In (MeitY) · **Force:** Regulator · **For:** Every retailer
- **Who it reaches:** Always. The Directions bind every “body corporate” — every incorporated retailer, store-led or online — and name “attacks on applications such as e-commerce” as a reportable incident.
- **Status:** In force since June 2022 (September 2022 for MSMEs). No amendment as of October 2026.
- **What it requires:**
  - Report listed incidents — data breach, data leak, website intrusion, attacks on e-commerce applications, DDoS, fake apps, attacks on digital payment systems — within six hours of noticing them.
  - Keep logs of all ICT systems for a rolling 180 days: firewall, web, database, application, VPN — successful and failed events.
  - Synchronise clocks to NIC or NPL time, or a source traceable to them.
  - Name a point of contact for CERT-In.
- **Reporting clock:** 6 hours from the moment you notice it, to CERT-In.
- **What people get wrong:** The duty cannot be handed to your e-commerce agency, MSP or SaaS vendor. CERT-In’s FAQ (Q13) answers exactly the “consumer-facing business and its back-end partner” case: “The obligation of reporting of cyber incident is neither transferrable nor indemnified”. Logs may sit outside India if they can be produced in reasonable time (Q35).
- **Source:** [CERT-In Directions and FAQ (May 2022)](https://www.cert-in.org.in/PDF/FAQs_on_CyberSecurityDirections_May2022.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#cert-in-directions

#### Digital Personal Data Protection Act 2023 and DPDP Rules 2025

- **Issuer:** Parliament; Rules by MeitY · **Force:** Law · **For:** Every retailer
- **Who it reaches:** Always. Every retailer is a Data Fiduciary for its customers’ data — loyalty, POS, CRM, app sign-ups, delivery addresses — and for its staff’s.
- **Status:** Rules notified 13 November 2025. Consent Managers from 13 November 2026; the operational duties from 13 May 2027. A proposal to bring that forward was consulted on in early 2026 but has not been notified.
- **What it requires:**
  - Security safeguards at the minimum: encryption, masking or tokens; access control; logged and reviewed access; backups (Rule 6).
  - Keep order details, personal data and processing logs for at least one year — even if the customer deletes the account (Rule 8(3)).
  - Notices a customer can understand on their own, and withdrawal as easy as giving consent (Rule 3).
  - Tell affected customers and the Board without delay, with a detailed report to the Board within 72 hours (Rule 7). No materiality threshold.
  - Publish a contact for data questions; resolve grievances within 90 days.
- **Reporting clock:** 72 hours from a personal-data breach (from May 2027), to the Data Protection Board.
- **What people get wrong:** The 72 hours is the detailed report to the Board — customers must be told “without delay”. Penalties run to ₹250 crore for failing to keep safeguards and ₹200 crore for failing to notify a breach.
- **Source:** [DPDP Rules 2025, G.S.R. 846(E)](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#dpdp

#### DPDP Rules, Third Schedule: erasure by large e-commerce platforms

- **Issuer:** MeitY · **Force:** Law · **For:** Online sellers
- **Who it reaches:** If you are an e-commerce entity with at least two crore registered users in India. Marketplace sellers are excluded; a multi-channel retailer whose app or site crosses two crore is in.
- **Status:** Enforceable with the operational duties on 13 May 2027. When the three years starts counting is ambiguous in the text — take advice.
- **What it requires:**
  - Erase a user’s personal data three years after they last engaged — except what keeps their account, wallet, gift card or loyalty balance usable.
  - Warn the user at least 48 hours before erasure, so they can log in to keep the account.
- **Source:** [DPDP Rules 2025, Third Schedule](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#dpdp-erasure

#### DPDP Act section 9 and Rule 10: children’s data

- **Issuer:** Parliament; Rules by MeitY · **Force:** Law · **For:** Online sellers
- **Who it reaches:** If any of your customers or app users may be under 18 — toys, kids’ fashion, baby care, school supplies, gaming accessories, or simply an app minors use.
- **Status:** From 13 May 2027, with the operational duties.
- **What it requires:**
  - Verifiable consent from a parent who is an identifiable adult before processing a child’s data.
  - No tracking, behavioural monitoring or targeted advertising directed at children.
- **What people get wrong:** A child is anyone under 18 — not 13 or 16. None of the Fourth Schedule exemptions is a retail exemption.
- **Source:** [DPDP Act 2023, section 9; DPDP Rules 2025, Rule 10](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#dpdp-children

#### IT Act section 43A and the SPDI Rules 2011

- **Issuer:** MeitY · **Force:** Law · **For:** Every retailer
- **Who it reaches:** Always, until the DPDP Act replaces it — for any retailer handling card or bank details, passwords or health data.
- **Status:** Still in force. The DPDP Act omits section 43A from 13 May 2027, and the SPDI Rules fall away with it.
- **What it requires:**
  - Reasonable security practices for sensitive personal data — financial information, passwords, health and biometrics.
  - ISO/IEC 27001 is the standard the Rules name as one way to show them.
- **Source:** [DPDP commencement, G.S.R. 843(E) (via ICAI and taxmann)](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#it-act-43a

#### Consumer Protection Act 2019, section 2(47)(ix)

- **Issuer:** Parliament; enforced by the CCPA · **Force:** Law · **For:** Every retailer
- **Who it reaches:** Always — offline stores included.
- **Status:** In force.
- **What it requires:**
  - Disclosing a customer’s personal information given in confidence, other than as the law allows, is an “unfair trade practice”.
- **Source:** [Consumer Protection Act 2019 (Gazette)](https://egazette.gov.in/WriteReadData/2019/210422.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#consumer-protection-act

#### Consumer Protection (E-Commerce) Rules 2020, as amended in 2026

- **Issuer:** Ministry of Consumer Affairs · **Force:** Law · **For:** Online sellers
- **Who it reaches:** If you sell online — marketplace, inventory or D2C, including multi-channel single-brand retailers — or sell on a marketplace as a seller.
- **Status:** In force since 23 July 2020. The Amendment Rules 2026 (G.S.R. 789(E), notified 9 September 2026) come into force on 1 January 2027.
- **What it requires:**
  - Record a purchase consent only through an explicit, affirmative action — no pre-ticked boxes (Rule 4(9)).
  - A grievance officer who acknowledges complaints within 48 hours and resolves them within a month.
  - Tell customers about the security of your payment methods and the payment provider’s contact (Rules 5 and 7).
  - From 2027: no manipulated search results; sponsored listings clearly labelled; a discount must show the lowest price of the previous 30 days.
  - From 2027: a marketplace may not use customer data to sell its own-brand goods, or to promote sellers as associated with it, without the customer’s express consent (Rule 5(6)).
- **What people get wrong:** The 2021 draft’s flash-sale ban, fall-back liability and Chief Compliance Officer were never notified — the 2026 amendment omits all of them.
- **Source:** [E-Commerce (Amendment) Rules 2026, G.S.R. 789(E)](https://egazette.gov.in/WriteReadData/2026/276125.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#consumer-ecommerce

#### Guidelines for Prevention and Regulation of Dark Patterns, 2023

- **Issuer:** Central Consumer Protection Authority · **Force:** Regulator · **For:** Online sellers
- **Who it reaches:** If you run a platform, advertise or sell online in India — the Guidelines bind platforms, advertisers and sellers.
- **Status:** In force since 30 November 2023 and being enforced (penalties in June 2026). A yearly self-audit has been an advisory since June 2025; it becomes a rule for e-commerce entities on 1 January 2027, with a certificate displayed on the site.
- **What it requires:**
  - None of the 13 patterns: false urgency, basket sneaking, confirm shaming, forced action, subscription trap, interface interference, bait and switch, drip pricing, disguised ads, nagging, trick questions, SaaS billing, rogue malware.
  - No forcing customers to share personal data they don’t need to buy — and no cookie or notification prompts without a way to say no.
- **Source:** [CCPA Dark Patterns Guidelines 2023](https://ccpa.doca.gov.in/files/The%20Guidelines%20for%20Prevention%20and%20Regulation%20of%20Dark%20Patterns,%202023_1732707717.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#dark-patterns

#### IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, as amended

- **Issuer:** MeitY · **Force:** Law · **For:** Online sellers
- **Who it reaches:** If you run a marketplace — its safe harbour is tied to these Rules by the E-Commerce Rules.
- **Status:** In force; amended four times, most recently in February 2026.
- **What it requires:**
  - Keep a user’s registration data for 180 days after they close the account.
  - Acknowledge grievances in 24 hours and resolve them in 7 days; act on court or government takedowns within 3 hours.
  - Secure your computer resource to the SPDI Rules’ standard, and report cyber incidents to CERT-In.
  - Answer an authorised agency’s written request, including for cyber incidents, within 72 hours.
- **Source:** [IT Rules 2021, consolidated to 10 February 2026](https://www.meity.gov.in/static/uploads/2026/02/550681ab908f8afb135b0ad42816a1c9.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#it-intermediary

#### TRAI Telecom Commercial Communications Customer Preference Regulations, as amended

- **Issuer:** Telecom Regulatory Authority of India · **Force:** Regulator · **For:** Every retailer
- **Who it reaches:** If you send OTPs, order updates, or promotional SMS and calls — every such message makes you a registered Sender.
- **Status:** In force; amended February 2025 and again on 18 September 2026. The 2026 amendment phases in 30, 60 and 90 days after Gazette publication — from late October 2026.
- **What it requires:**
  - Send only from registered headers and templates; self-certify them every year or face automatic suspension.
  - Give an opt-out in every promotional message. Re-acquire a revoked consent only after 90 days.
  - From the 2026 amendment: message on the strength of an enquiry only within 7 days, and keep the enquiry in a verifiable written or digital form; declare automated calls in advance.
- **What people get wrong:** The rupee penalties fall on telecom operators. A sender found sending unsolicited messages has every telecom resource barred for 15 days — and is disconnected and blacklisted the second time.
- **Source:** [TCCCPR Third Amendment 2026](https://www.trai.gov.in/sites/default/files/2026-09/Regulation_18092026.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#trai-tcccpr

#### Companies (Accounts) Rules 2014, rule 3(5), as amended in 2022

- **Issuer:** Ministry of Corporate Affairs · **Force:** Law · **For:** Every retailer
- **Who it reaches:** Always — every Indian company, including the Indian arm of a foreign retailer.
- **Status:** Daily-backup amendment in force since 5 August 2022.
- **What it requires:**
  - Back up electronically kept books of account daily to servers physically located in India.
  - Keep the books accessible in India at all times.
- **Source:** [Companies (Accounts) Amendment Rules 2022 (via AZB, Grant Thornton)](https://www.mca.gov.in/) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#companies-accounts

#### GST e-invoicing: the 30-day reporting limit

- **Issuer:** GSTN / CBIC · **Force:** Regulator · **For:** Every retailer
- **Who it reaches:** If you issue B2B invoices — marketplace commissions, franchise supplies, wholesale, distributors — with an aggregate turnover of ₹10 crore or more. Retail B2C sales are not e-invoiced.
- **Status:** The 30-day limit has applied since 1 April 2025.
- **What it requires:**
  - Report e-invoices, credit notes and debit notes to the Invoice Registration Portal within 30 days — later ones are rejected.
  - Keep GST records with backups that can be restored in reasonable time.
- **Source:** [GSTN advisory, 5 November 2024](https://www.mahagst.gov.in/public/uploads/gstnadvisory/1760531580_293%20Advisory%20Time%20Limit%20for%20Reporting%20e%20Invoice%20on%20the%20IRP%20Portal%20%20Lowering%20of%20Threshold%20to%20AATO%2010%20Crores%20and%20Above.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#gst-einvoice

### Payments & card data

The card industry’s standard and the RBI’s rules — most of which reach you through your payment aggregator.

#### PCI DSS v4.0.1

- **Issuer:** PCI Security Standards Council; enforced by the card brands and acquirers · **Force:** Card-industry standard · **For:** Every retailer
- **Who it reaches:** If you accept cards — at a store terminal or on your own website or app. The card brands and your acquirer decide your merchant level and how you prove compliance.
- **Status:** v4.0.1 is the only version. Its future-dated requirements became mandatory on 31 March 2025. No successor version or date has been announced.
- **What it requires:**
  - Online: inventory, authorise and integrity-check every script on your payment page (6.4.3), and detect unauthorised changes to it at least weekly (11.6.1).
  - Online, on SAQ A: you are eligible only if your site is protected against script attacks — by you or your payment provider (PCI SSC FAQ 1588).
  - MFA for all non-console access into the card environment (8.4.2) — a POS login that sees one card at a time is exempt; the back office is not.
  - Anti-phishing protection for staff with access to in-scope systems (5.4.1); 12-character passwords (8.3.6).
- **What people get wrong:** Redirecting customers to the gateway’s own page takes the SAQ A script test off you; an embedded iframe does not.
- **Source:** [PCI SSC: SAQ A update (30 Jan 2025) and FAQ 1588](https://blog.pcisecuritystandards.org/important-updates-announced-for-merchants-validating-to-self-assessment-questionnaire-a) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#pci-dss

#### RBI card-on-file tokenisation: merchants may not store card data

- **Issuer:** Reserve Bank of India · **Force:** Regulator · **For:** Every retailer
- **Who it reaches:** If you take card payments — for saved cards, one-click checkout, loyalty or reconciliation.
- **Status:** In force since 30 September 2022, after two extensions; restated in the 2025 Payment Aggregator Master Direction.
- **What it requires:**
  - Store no actual card data. Keep only the last four digits and the card issuer’s name, for tracking and reconciliation.
  - Use network tokens for saved cards, and let customers de-register a token.
- **What people get wrong:** Tokenisation does not stop a skimmer reading what a shopper types on a page you host — that is what the PCI checkout-script rules are for.
- **Source:** [RBI circular, 7 September 2021 (CoFT)](https://rbi.org.in/Scripts/NotificationUser.aspx?Id=12159) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#rbi-card-storage

#### RBI (Regulation of Payment Aggregators) Directions 2025

- **Issuer:** Reserve Bank of India — reaching you through your payment aggregator · **Force:** Regulator · **For:** Every retailer
- **Who it reaches:** If you take payments through a payment aggregator — online, or at the store through a POS aggregator.
- **Status:** Issued 15 September 2025, consolidating the 2020–2023 rules. Merchants onboarded before 2026 had to be re-checked by 15 September 2026.
- **What it requires:**
  - Your aggregator must ensure your infrastructure meets PCI DSS, review your PCI status at onboarding, and assess your security baseline (para 9(a); Annexure 1).
  - Customer card credentials may not be stored in any database or server you access.
  - Merchant due diligence and background checks; a marketplace may take payments only for sellers onboarded to it.
- **What people get wrong:** No Indian law aims PCI DSS at merchants directly. It reaches you through the aggregator — which is why its contract asks for proof every year.
- **Source:** [RBI PA Master Direction, 15 September 2025](https://rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12896) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#rbi-pa-direction

#### RBI Cyber Resilience Directions for non-bank PSOs: card terminals at merchants

- **Issuer:** Reserve Bank of India — reaching you through your PSO · **Force:** Regulator · **For:** Store-led retailers
- **Who it reaches:** If you take cards on terminals in your stores.
- **Status:** Master Direction of 30 July 2024, in force.
- **What it requires:**
  - Terminals that capture card details must be validated against PCI P2PE; PIN-entry terminals must be PCI PTS approved.
  - Handhelds and mPOS devices that take cards sit inside the same card environment — managed and locked down like the tills.
- **Source:** [RBI Cyber Resilience MD for non-bank PSOs (via payments register)](https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#rbi-pos-terminals

#### RBI (Authentication Mechanisms for Digital Payment Transactions) Directions 2025

- **Issuer:** Reserve Bank of India — through your gateway and issuers · **Force:** Regulator · **For:** Online sellers
- **Who it reaches:** If customers pay online by card — the duty sits on payment providers, and reaches you through your checkout flow.
- **Status:** Issued 25 September 2025; compliance from 1 April 2026.
- **What it requires:**
  - Two factors for every digital payment unless exempted — and for non-card-present payments, at least one factor must be dynamic.
- **Source:** [RBI Authentication Directions, 25 September 2025](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12898) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#rbi-authentication

#### RBI Digital Payments — E-mandate Framework 2026

- **Issuer:** Reserve Bank of India — through your acquirer · **Force:** Regulator · **For:** Online sellers
- **Who it reaches:** If you run subscriptions, memberships or auto-replenishment on cards, prepaid instruments or UPI.
- **Status:** Issued 21 April 2026, consolidating eight earlier circulars; in force.
- **What it requires:**
  - Authenticate the customer at registration and on the first debit; send a pre-debit notice at least 24 hours before, naming you.
  - Recurring debits run without extra authentication only up to ₹15,000 a transaction.
- **Source:** [RBI E-mandate Framework, 21 April 2026](https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=13374) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#rbi-e-mandate

### What your platforms & partners demand

Not law — but the gateway, the marketplace and the network write it into the agreement, with breach clocks of 6 to 24 hours that run alongside CERT-In’s.

#### Payment gateway merchant terms (Razorpay, Cashfree)

- **Issuer:** Your payment aggregator · **Force:** Your platforms & partners · **For:** Every retailer
- **Who it reaches:** If you take payments through an Indian payment gateway — online, or at stores through its POS.
- **Status:** Razorpay’s terms effective 1 January 2026; Cashfree’s last updated 10 March 2026. Read your own agreement — windows differ.
- **What it requires:**
  - Report a suspected security event within 12 hours (Cashfree) or an actual or suspected breach within 24 hours (Razorpay).
  - Never store full card credentials — “irrespective of the Merchant being PCI-DSS compliant” (Cashfree).
  - Submit proof of PCI DSS compliance every year, and accept security audits at any time (Razorpay).
- **Reporting clock:** 12–24 hours from a suspected security event, to your payment gateway.
- **Source:** [Cashfree terms (and Razorpay terms)](https://www.cashfree.com/tnc/) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#gateway-terms

#### Amazon Selling Partner API Data Protection Policy

- **Issuer:** Amazon · **Force:** Your platforms & partners · **For:** Online sellers
- **Who it reaches:** If you connect to Amazon through its Selling Partner API — including a seller’s own private integration, not just software vendors.
- **Status:** Current policy; breach can suspend or terminate your API access.
- **What it requires:**
  - MFA for every user account; 12-character passwords; API keys encrypted and rotated yearly.
  - Encrypt customer data at rest (AES-128 or stronger) and in transit (TLS 1.2+); endpoint protection and DLP.
  - Notify Amazon within 24 hours of detecting a security incident.
  - Keep customer PII no longer than 30 days after delivery; scan for vulnerabilities every 30 days; penetration-test every year.
- **Reporting clock:** 24 hours from detecting a security incident, to Amazon.
- **Source:** [Amazon Data Protection Policy](https://sellercentral.amazon.com/mws/static/policy?documentType=DPP&locale=en_US) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#amazon-dpp

#### ONDC Network Policy: technology governance, data and grievances

- **Issuer:** Open Network for Digital Commerce · **Force:** Your platforms & partners · **For:** Online sellers
- **Who it reaches:** If you are an ONDC network participant — a seller app or buyer app. A small retailer selling through a seller app receives these obligations through it.
- **Status:** Chapter 8 v2.1 (5 December 2024) and Chapter 7 v1.0, in force for network participants.
- **What it requires:**
  - A documented security programme no less rigorous than ISO/IEC 27001 and COBIT — extended to your technology service providers.
  - Alert ONDC within 6 hours of becoming aware of a data breach or cyber incident.
  - A yearly certificate from an ONDC- or CERT-In-empanelled auditor; ONDC may audit you without notice after a major breach.
  - Explicit consent from buyers and sellers; acknowledge issues within 120 minutes and resolve grievances within 96 hours.
- **Reporting clock:** 6 hours from becoming aware of a breach, to ONDC.
- **Source:** [ONDC Network Policy, Chapter 8](https://ondc-static-website-media.s3.ap-south-1.amazonaws.com/ondc-website-media/downloads/governance-and-policies/CHAPTER+%5B8%5D+Network+Technology+Governance,+Certification+and+Audit.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#ondc

### If you sell abroad

EU, UK and US rules that reach an Indian retailer through the customers it ships to.

#### EU GDPR and UK GDPR

- **Issuer:** European Union; UK · **Force:** Law · **For:** Online sellers
- **Who it reaches:** If you offer goods to customers in the EU or UK — EU-currency checkout, delivery there, ads aimed there. Being reachable is not enough; shipping there regularly is.
- **Status:** In force. A proposal to move breach notice to 96 hours (the Digital Omnibus) is still in committee — 72 hours remains the law.
- **What it requires:**
  - Appoint a representative in the EU and the UK — a D2C brand shipping there regularly will not fit the “occasional” exemption.
  - Notify the supervisory authority within 72 hours of becoming aware of a breach.
- **Reporting clock:** 72 hours from becoming aware of a breach, to the EU / UK supervisory authority.
- **Source:** [Regulation (EU) 2016/679](https://eur-lex.europa.eu/eli/reg/2016/679/oj) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#gdpr

#### EU Digital Services Act: online marketplaces

- **Issuer:** European Union · **Force:** Law · **For:** Online sellers
- **Who it reaches:** If you run a marketplace that targets EU consumers (unless micro or small). D2C sellers on EU marketplaces must supply the same trader data.
- **Status:** Applies from 17 February 2024.
- **What it requires:**
  - A legal representative in the EU who can be held liable.
  - Collect and check each trader’s identity, contact, payment and registration details before they sell to EU consumers.
- **Source:** [Regulation (EU) 2022/2065](https://eur-lex.europa.eu/eli/reg/2022/2065/oj) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#eu-dsa

#### EU NIS2 Directive: online marketplaces

- **Issuer:** European Union · **Force:** Law · **For:** Online sellers
- **Who it reaches:** If you run a medium-sized or larger online marketplace offering services in the EU. A D2C brand selling only its own goods is not a marketplace.
- **Status:** Applies from 18 October 2024; national transposition still uneven.
- **What it requires:**
  - Appoint an EU representative; ten minimum measures including supply-chain security and multi-factor authentication.
  - An early warning within 24 hours of a significant incident, and a notification within 72.
- **Reporting clock:** 24 hours from becoming aware of a significant incident, to the national CSIRT (early warning).
- **Source:** [Directive (EU) 2022/2555](https://eur-lex.europa.eu/eli/dir/2022/2555/oj) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#nis2

#### California Consumer Privacy Act, as amended

- **Issuer:** California · **Force:** Law · **For:** Online sellers
- **Who it reaches:** If you do business in California and have annual gross revenue above $26,625,000 (from 2025), or trade the data of 100,000+ consumers.
- **Status:** New regulations in force from 1 January 2026; cybersecurity-audit certifications due from 2028 by revenue band.
- **What it requires:**
  - Honour Californians’ privacy rights; from 2028–2030, certify an annual cybersecurity audit.
- **Source:** [California Privacy Protection Agency](https://www.cppa.ca.gov/regulations/cpi_adjustment.html) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#ccpa

#### US COPPA Rule, as amended in 2025

- **Issuer:** US Federal Trade Commission · **Force:** Law · **For:** Online sellers
- **Who it reaches:** Only if you sell to or collect data from US children under 13 — toy, kids’ apparel or ed-tech brands.
- **Status:** Amended rule effective 23 June 2025; compliance from 22 April 2026.
- **What it requires:**
  - A written information security programme, with yearly risk assessments and vendor due diligence.
- **Source:** [Amended COPPA Rule, 16 CFR 312](https://downloads.regulations.gov/FTC-2024-0003-0281/content.htm) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/retail/obligations#coppa

## The 29 controls, and what answers each

### Every retailer

Store-led or online, every retailer needs these.

#### Detect and report inside six hours

- **What it is:** Endpoint detection and response, or a managed service that watches it 24×7.
- **Why it matters here:** CERT-In and ONDC both start a six-hour clock at the moment you notice — and you cannot report in six hours what you find in six days. Verizon’s 2026 retail data: 61% of breaches were system intrusion.
- **What a gateway, marketplace or auditor asks to see:** Coverage on every POS back-office PC, server and laptop; 24×7 monitoring (in-house or MDR); dated detection-to-report times from your last incidents or drills.
- **Required by:** CERT-In, Amazon, ONDC, NIS2
- **What answers it:** [Endpoint protection guide](https://www.thetechbag.com/browse/security/endpoint-protection), [Managed detection & response guide](https://www.thetechbag.com/browse/security/managed-detection-response)

#### Keep 180 days of logs — and a year for personal data

- **What it is:** Central log collection with retention matched to the law: 180 days for CERT-In, a year under DPDP from May 2027.
- **Why it matters here:** CERT-In can ask for 180 days of firewall, web, database and application logs; DPDP Rule 8(3) wants order and processing logs kept a year — even after a customer deletes the account.
- **What a gateway, marketplace or auditor asks to see:** A retention policy citing both rules, and proof you can pull a given day’s logs from six months ago.
- **Required by:** CERT-In, DPDP, Intermediary Rules
- **What answers it:** [SIEM & log management guide](https://www.thetechbag.com/browse/security/siem-log-management)

#### Phishing-resistant MFA and SSO for staff

- **What it is:** Single sign-on with strong multi-factor authentication for head office, warehouse and store-manager accounts.
- **Why it matters here:** Amazon’s seller-API policy and PCI DSS 8.4.2 both demand MFA; the Snowflake-linked retail breaches of 2024 used stolen passwords on accounts without it.
- **What a gateway, marketplace or auditor asks to see:** MFA coverage across admin, back-office and cloud consoles; which factors are phishing-resistant; how shared store logins are handled.
- **Required by:** PCI DSS, Amazon, NIS2
- **What answers it:** [IAM, SSO & MFA guide](https://www.thetechbag.com/browse/identity-access/iam-sso-mfa)

#### Email security, DMARC and lookalike-site takedown

- **What it is:** Filter phishing aimed at staff; publish DMARC so no one can mail as you; find and take down fake stores and apps using your brand.
- **Why it matters here:** Fake DMart, JioMart and Flipkart sites circulate every sale season, and CERT-In’s festive advisory names fake shopping sites. PCI DSS 5.4.1 requires anti-phishing for staff in scope.
- **What a gateway, marketplace or auditor asks to see:** DMARC at enforcement; phishing-filter coverage; how lookalike domains and apps are found and taken down.
- **Required by:** TRAI spam rules, PCI DSS
- **What answers it:** [Email security guide](https://www.thetechbag.com/browse/security/email-security), [Infoblox Exposure Management](https://www.thetechbag.com/infoblox/infoblox-exposure-management), [Check Point External Risk Management](https://www.thetechbag.com/checkpoint/checkpoint-external-risk-management)
- **Catalogue coverage:** Email filtering and DMARC are well covered; dedicated brand-takedown services are thin — two products, no Indian takedown specialist yet.

#### Backups you can restore — offline, and in India for the books

- **What it is:** Immutable and offline backups of ERP, POS and storefront data, tested by restore; daily backups of the books on servers in India.
- **Why it matters here:** Ransomware stopped Raymond’s supply chain while its stores stayed open, and emptied Co-op’s shelves. The Companies Act wants the books backed up daily in India.
- **What a gateway, marketplace or auditor asks to see:** Restore tests with dates and outcomes — not backup success reports — and where the books’ daily copy sits.
- **Required by:** DPDP, Companies Act, GST e-invoice
- **What answers it:** [Backup & recovery guide](https://www.thetechbag.com/browse/backup-cyber-resilience/backup-recovery), [Cyber recovery guide](https://www.thetechbag.com/browse/backup-cyber-resilience/cyber-recovery), [SaaS backup guide](https://www.thetechbag.com/browse/backup-cyber-resilience/saas-backup)

#### Patch what is exposed first

- **What it is:** Continuous scanning of what faces the internet — storefront, APIs, VPNs — with critical fixes on a clock.
- **Why it matters here:** Exploited vulnerabilities opened 42% of retail breaches in Verizon’s 2026 data, the top way in. Amazon wants scans every 30 days and a yearly penetration test.
- **What a gateway, marketplace or auditor asks to see:** An external attack-surface inventory, scan cadence, and time-to-fix for critical findings.
- **Required by:** IT Act 43A, Amazon, ONDC
- **What answers it:** [Vulnerability management guide](https://www.thetechbag.com/browse/security/vulnerability-management)

#### Encrypt and tokenise customer data

- **What it is:** Encryption at rest and in transit, tokens in place of card and identity data, and discovery of where customer data actually sits.
- **Why it matters here:** DPDP Rule 6 names encryption, masking and tokens as the minimum; the leaked BigBasket, Domino’s and boAt databases were customer data at rest.
- **What a gateway, marketplace or auditor asks to see:** A data map of where customer data lives, what is encrypted, and how keys are managed.
- **Required by:** DPDP, DPDP erasure, IT Act 43A, Consumer Act, No card storage, RBI PA rules, Payment gateway, Amazon, GDPR, CCPA
- **What answers it:** [Encryption & rights management guide](https://www.thetechbag.com/browse/data-security-privacy/encryption-rights), [DSPM & data discovery guide](https://www.thetechbag.com/browse/data-security-privacy/dspm)

#### Consent, notices and erasure under DPDP

- **What it is:** Capture and record consent at every sign-up and checkout, honour withdrawals, and erase on schedule.
- **Why it matters here:** DPDP wants notices a customer can understand alone and withdrawal as easy as consent; the E-Commerce Rules forbid pre-ticked boxes; large platforms must erase inactive users after three years.
- **What a gateway, marketplace or auditor asks to see:** Consent records tied to purposes, withdrawal handling, and the erasure job with its 48-hour warning.
- **Required by:** DPDP, DPDP erasure, DPDP children, E-Commerce Rules, Dark patterns, TRAI spam rules, GDPR, CCPA, COPPA
- **What answers it:** [OneTrust Consent & Preferences](https://www.thetechbag.com/onetrust/onetrust-consent-preferences), [OneTrust Privacy Automation](https://www.thetechbag.com/onetrust/onetrust-privacy-automation), [Securiti Data Privacy Automation](https://www.thetechbag.com/securiti/securiti-data-privacy), [Mitigata Dranta](https://www.thetechbag.com/mitigata/mitigata-dranta)
- **Catalogue coverage:** Four consent and privacy products, no decision guide yet — and no registered DPDP Consent Manager in our catalogue.

#### Know which vendors hold your customers

- **What it is:** An inventory of every agency, SaaS tool and processor that touches customer data, with security checks proportionate to what they hold.
- **Why it matters here:** Third parties were involved in 68% of retail breaches in Verizon’s 2026 data. Dunzo was entered through a third party’s server; Juspay held many merchants’ card metadata.
- **What a gateway, marketplace or auditor asks to see:** A vendor register with data held, last assessment date, and the contract’s breach-notice clause.
- **Required by:** DPDP, ONDC, NIS2, COPPA
- **What answers it:** [OneTrust Third-Party Management](https://www.thetechbag.com/onetrust/onetrust-third-party-management), [MetricStream Cyber GRC](https://www.thetechbag.com/metricstream/metricstream-cyber-grc), [Optro IT & Cyber Risk](https://www.thetechbag.com/optro/optro-it-cyber-risk), [Mitigata Compliance / GRC](https://www.thetechbag.com/mitigata/mitigata-compliance-grc)
- **Catalogue coverage:** GRC suites are covered; dedicated vendor-risk ratings (SecurityScorecard, BitSight) and Indian compliance automation (Sprinto, Scrut) are not in our catalogue yet.

#### Limit what store and support staff can take

- **What it is:** Data loss prevention and least-privilege access for customer-service, store and warehouse staff who see customer records.
- **Why it matters here:** Swiggy’s 2023 incident was a former employee reaching test systems; return fraud at Meesho ran through a colluding seller. The Consumer Protection Act treats leaking a customer’s data as an unfair trade practice.
- **What a gateway, marketplace or auditor asks to see:** Who can export customer lists, what is monitored, and how access ends when people leave.
- **Required by:** Consumer Act
- **What answers it:** [DLP & insider risk guide](https://www.thetechbag.com/browse/data-security-privacy/dlp-insider-risk)

### Stores

For chains, franchises and anyone with tills, terminals and a store network.

#### Lock down POS and back-office machines

- **What it is:** Application allow-listing and hardening on POS terminals and store back-office PCs, so only approved software runs.
- **Why it matters here:** Store POS malware — Target, Wendy’s, Wawa — ran on machines that would run anything. Allow-listing stops it at the till.
- **What a gateway, marketplace or auditor asks to see:** Which store machines run allow-listing or EDR, and how exceptions are approved.
- **Required by:** POS terminals
- **What answers it:** [Endpoint protection guide](https://www.thetechbag.com/browse/security/endpoint-protection), [Broadcom Carbon Black App Control](https://www.thetechbag.com/broadcom/broadcom-carbon-black-app-control), [Heimdal Application Control](https://www.thetechbag.com/heimdal/heimdal-application-control)

#### Manage handhelds, kiosks and rugged devices

- **What it is:** Mobile device management with kiosk lockdown for scanners, mPOS, self-checkout and delivery-partner devices.
- **Why it matters here:** A store runs dozens of shared Android devices handled by seasonal staff — lost, swapped and rarely updated. They carry customer and payment apps.
- **What a gateway, marketplace or auditor asks to see:** An inventory of store devices, lockdown profiles, update status, and remote wipe.
- **Required by:** POS terminals
- **What answers it:** [UEM & MDM guide](https://www.thetechbag.com/browse/endpoint-management/uem-mdm), [Esper Foundation](https://www.thetechbag.com/esper/esper-foundation), [SOTI XSight](https://www.thetechbag.com/soti/soti-xsight), [42Gears SureLock](https://www.thetechbag.com/42gears/42gears-surelock)

#### Segment the store network and the card environment

- **What it is:** Branch firewalls or SD-WAN/SASE that keep POS, guest Wi-Fi, CCTV and back office apart — so the card environment stays small.
- **Why it matters here:** Target’s attackers moved from an HVAC vendor’s access to the POS. Segmentation is also what keeps PCI DSS scope — and its cost — contained.
- **What a gateway, marketplace or auditor asks to see:** A network diagram showing the card environment’s boundary, and the rules between store zones.
- **Required by:** PCI DSS
- **What answers it:** [Firewall & network security guide](https://www.thetechbag.com/browse/network-security-sase/firewall-network-security), [SASE & SSE guide](https://www.thetechbag.com/browse/network-security-sase/sase-sse)
- **Catalogue coverage:** Firewalls and SD-WAN are well covered; store Wi-Fi and network access control (Meraki, Aruba, Forescout) are thin.

#### Filter web and DNS at every store

- **What it is:** DNS and web filtering on store networks and devices, blocking known-bad sites and lookalikes.
- **Why it matters here:** Store staff browse, click and download on shared machines; one infected back-office PC can reach the POS. Protective DNS is the cheapest layer across hundreds of sites.
- **What a gateway, marketplace or auditor asks to see:** Filtering coverage across stores and roaming devices, and the block reports.
- **What answers it:** [Secure web & DNS guide](https://www.thetechbag.com/browse/network-security-sase/secure-web-dns)

#### Control vendor and franchise access to stores

- **What it is:** Privileged access management and recorded, time-boxed remote sessions for POS vendors, IT contractors and franchise support.
- **Why it matters here:** Wendy’s franchise POS malware came through “certain service providers’ remote access credentials”; Target’s came through an HVAC contractor’s.
- **What a gateway, marketplace or auditor asks to see:** Who can reach store systems remotely, how sessions are approved and recorded, and when access expires.
- **What answers it:** [Privileged access management guide](https://www.thetechbag.com/browse/identity-access/privileged-access-management), [Remote access & support guide](https://www.thetechbag.com/browse/endpoint-management/remote-access)

### Online

For marketplaces, D2C brands and anyone with a checkout, an app or a seller API.

#### Web application and API protection, and DDoS

- **What it is:** A WAF or WAAP in front of the storefront and its APIs, with DDoS protection for sale days.
- **Why it matters here:** Basic web-application attacks are one of the three patterns behind 95% of retail breaches (Verizon 2026), and PCI DSS 6.4.2 wants an automated control in front of public web apps.
- **What a gateway, marketplace or auditor asks to see:** What sits in front of the storefront and the APIs, which rules are in blocking mode, and the sale-day DDoS plan.
- **Required by:** PCI DSS
- **What answers it:** [Cloudflare Application Security](https://www.thetechbag.com/cloudflare/cloudflare-application-security), [Akamai App & API Protector](https://www.thetechbag.com/akamai/akamai-app-api-protector), [F5 Distributed Cloud WAAP](https://www.thetechbag.com/f5/f5-distributed-cloud-waap), [Fortinet FortiWeb](https://www.thetechbag.com/fortinet/fortinet-fortiweb), [Akamai API Security](https://www.thetechbag.com/akamai/akamai-api-security), [Akamai Prolexic](https://www.thetechbag.com/akamai/akamai-prolexic)
- **Catalogue coverage:** Strong products from six vendors, but no decision guide yet; Imperva and India’s Indusface are not in our catalogue.

#### Stop bots and account takeover

- **What it is:** Bot management against credential stuffing, scalping and fake sign-ups, with account-takeover detection on logins.
- **Why it matters here:** Meesho blocked 13 lakh bot orders in a year and pursued account-takeover cases; The North Face reported a credential-stuffing attack in 2025.
- **What a gateway, marketplace or auditor asks to see:** Login-abuse rates, how bots are told from shoppers, and what happens on a suspicious login.
- **What answers it:** [Akamai Bot Manager](https://www.thetechbag.com/akamai/akamai-bot-manager), [Akamai Account Protector](https://www.thetechbag.com/akamai/akamai-account-protector), [F5 Distributed Cloud Bot Defense](https://www.thetechbag.com/f5/f5-distributed-cloud-bot-defense)
- **Catalogue coverage:** Thin: three dedicated products. HUMAN, Kasada and DataDome are not in our catalogue.

#### Watch every script on the checkout page

- **What it is:** An inventory, authorisation and integrity check for each payment-page script, with alerts when one changes — PCI DSS 6.4.3 and 11.6.1.
- **Why it matters here:** Web skimmers read what a shopper types before the card is ever tokenised; the ICO fined British Airways £20 million for one. Since March 2025 PCI DSS requires this control.
- **What a gateway, marketplace or auditor asks to see:** The script inventory with a reason for each, the integrity mechanism, and change alerts at least weekly.
- **Required by:** PCI DSS, No card storage, RBI 2FA rules
- **What answers it:** [Akamai Client-Side Protection](https://www.thetechbag.com/akamai/akamai-client-side-protection), [Cloudflare Application Security (Page Shield)](https://www.thetechbag.com/cloudflare/cloudflare-application-security)
- **Catalogue coverage:** Thin: one dedicated product, plus Cloudflare’s module. Jscrambler, Feroot and c/side are not in our catalogue.

#### Secure customer logins

- **What it is:** Customer identity (CIAM) with passwordless or risk-based multi-factor login for shoppers and loyalty members.
- **Why it matters here:** Swiggy customers were taken over through fake IVR calls and charged on linked BNPL; RBI wants a dynamic factor for online card payments from April 2026.
- **What a gateway, marketplace or auditor asks to see:** How customers authenticate, what triggers step-up, and how a takeover is reversed.
- **Required by:** RBI 2FA rules, E-mandates
- **What answers it:** [IAM, SSO & MFA guide](https://www.thetechbag.com/browse/identity-access/iam-sso-mfa), [Okta Customer Identity (Auth0)](https://www.thetechbag.com/okta/okta-customer-identity), [miniOrange CIAM](https://www.thetechbag.com/miniorange/miniorange-ciam)
- **Catalogue coverage:** Two dedicated customer-identity products; Ping Identity and LoginRadius are not in our catalogue.

#### Verify sellers, riders and partners

- **What it is:** Identity verification and KYC for marketplace sellers, delivery partners and new merchants.
- **Why it matters here:** Meesho lost ₹5.5 crore to a seller who faked buyers and returns. The RBI’s aggregator rules and the EU DSA both require knowing who the trader is.
- **What a gateway, marketplace or auditor asks to see:** Seller onboarding checks, re-verification triggers, and how fake accounts are found.
- **Required by:** RBI PA rules, EU DSA
- **What answers it:** [HyperVerge Onboarding & KYC](https://www.thetechbag.com/hyperverge/hyperverge-onboarding-kyc), [HyperVerge Fraud Prevention](https://www.thetechbag.com/hyperverge/hyperverge-fraud-prevention), [Signzy Onboarding & KYC](https://www.thetechbag.com/signzy/signzy-onboarding-kyc)
- **Catalogue coverage:** KYC is covered; e-commerce order-fraud scoring (Riskified, Forter, SEON) for refund, coupon and cash-on-delivery abuse is not in our catalogue.

#### Stay up on sale day

- **What it is:** Real-user monitoring, synthetic checks and a CDN that see a checkout slowdown before customers do.
- **Why it matters here:** Victoria’s Secret took its site down for three days and put the online-sales hit at about $20 million; Krispy Kreme’s online ordering was disrupted for weeks.
- **What a gateway, marketplace or auditor asks to see:** Checkout availability and latency at the last sale peak, and the alerting that fired.
- **Required by:** GST e-invoice
- **What answers it:** [Observability & APM guide](https://www.thetechbag.com/browse/devops/observability-apm), [Cloudflare CDN & Performance](https://www.thetechbag.com/cloudflare/cloudflare-cdn-performance), [Akamai Ion](https://www.thetechbag.com/akamai/akamai-ion)

### What no software answers

Procedure, design, contracts and policy — where the 2024–26 retail attacks got in.

#### Verify the caller before any reset

- **What it is:** A help-desk procedure that proves who is calling before a password or MFA reset — especially for admin accounts.
- **Why it matters here:** M&S said attackers impersonated someone and tricked a third party into a reset; the UK NCSC told every firm to review how its help desk authenticates staff.
- **What a gateway, marketplace or auditor asks to see:** The written verification procedure, who is allowed to override it, and a test of it.
- **Not answered by software:** This is a procedure, not a tool. Self-service resets with strong verification help, but the control is who the help desk will and won’t believe.

#### Decide your PCI scope on purpose

- **What it is:** Choose how card data flows — redirect, iframe, or your own form; P2PE terminals or not — knowing what each puts in scope.
- **Why it matters here:** A redirect to the gateway removes the SAQ A script test; an iframe keeps it; your own form puts your whole site in scope. Segmented stores keep the card environment small.
- **What a gateway, marketplace or auditor asks to see:** The data-flow diagram for every payment channel, and the SAQ or report it supports.
- **Required by:** PCI DSS, RBI PA rules, Payment gateway
- **Not answered by software:** A design decision with your gateway and acquirer. Products then protect whatever you left in scope.

#### The six-hour runbook

- **What it is:** Who tells CERT-In, the gateway, Amazon, ONDC and customers — in what order, inside which clock.
- **Why it matters here:** One incident can start several clocks at once — law, network, gateway and platform — and filing one does not discharge another. Without a runbook the shortest is missed while the team investigates.
- **What a gateway, marketplace or auditor asks to see:** The runbook, its contact list, and the timestamps from the last drill.
- **Required by:** CERT-In, Intermediary Rules, Payment gateway, Amazon, ONDC, GDPR, NIS2
- **Not answered by software:** A plan and a rehearsal. Detection tools start the clock; people meet it.

#### Read the breach clauses you have signed

- **What it is:** Know the notice windows, audit rights and data rules in your gateway, marketplace, logistics and agency contracts — and write your own into vendors’.
- **Why it matters here:** Cashfree asks for 12 hours, Razorpay and Amazon 24, ONDC 6 — and your agency’s contract decides whether you hear in time.
- **What a gateway, marketplace or auditor asks to see:** A table of every partner’s notice clock and audit right, and the matching clause in your vendor contracts.
- **Required by:** DPDP, Payment gateway, EU DSA
- **Not answered by software:** A legal and procurement exercise. No software signs a contract.

#### Design refunds and returns against abuse

- **What it is:** Return, refund and cash-on-delivery rules that make organised abuse expensive — limits, holds, evidence and pattern checks.
- **Why it matters here:** Myntra filed a ₹1.1 crore refund-fraud complaint; Meesho lost ₹5.5 crore to faked returns. Both were business logic working as designed.
- **What a gateway, marketplace or auditor asks to see:** Refund rules, limits per account and address, and the alerts that caught the last abuse.
- **Not answered by software:** Policy design. Fraud tools score the orders, but the rules decide what a fraudster can extract.

#### Audit checkout and consent for dark patterns

- **What it is:** A yearly review of sign-up, checkout and consent screens against the 13 dark patterns — required for e-commerce entities from 2027.
- **Why it matters here:** The CCPA fined platforms in June 2026 for pre-selected add-ons and forced data capture; from 1 January 2027 the self-audit certificate goes on your site.
- **What a gateway, marketplace or auditor asks to see:** The self-audit, the fixes it led to, and the displayed certificate.
- **Required by:** DPDP children, E-Commerce Rules, Dark patterns, E-mandates
- **Not answered by software:** A review of your own screens. Consent tools record choices; they do not decide whether your design is fair.

#### Hold franchisees to a minimum

- **What it is:** A security baseline in the franchise agreement — terminals, POS access, patching, who their IT vendor is — and a way to check it.
- **Why it matters here:** Wendy’s POS malware hit franchised restaurants through franchisees’ service providers, not company stores. Visa counts franchisee volume separately when it isn’t processed by the corporate entity.
- **What a gateway, marketplace or auditor asks to see:** The franchise security schedule, attestations from franchisees, and the vendors they use.
- **Not answered by software:** A contract and an attestation programme. Tools can be mandated in it, but the agreement is the control.

#### Use validated card terminals

- **What it is:** Card terminals validated under PCI P2PE, and PIN pads approved under PCI PTS — supplied through your payment provider.
- **Why it matters here:** The RBI requires payment operators to install exactly these at merchants; point-to-point encryption takes card data off your store network entirely.
- **What a gateway, marketplace or auditor asks to see:** The terminal models in each store and their P2PE and PTS listings.
- **Required by:** POS terminals
- **Not answered by software:** Hardware from your payment operator, not software we sell. Ask your PSO for the validated models.

## How retailers actually get breached

### The help desk resets the attacker’s password (Store-led retailers)

A caller impersonates someone with the right details, a help desk resets their password and MFA, and ransomware follows. Path: Caller poses as staff → Desk resets password + MFA → Ransomware follows.

- **Marks & Spencer (UK)** (April 2025): Attackers impersonated one of the people who work with M&S and tricked a third party into a reset; online orders stopped for weeks. M&S first guided about £300 million off profit before mitigation and insurance. Press named its service-desk supplier TCS, which says “no TCS systems or users were compromised”. Source: [UK Parliament evidence; BleepingComputer](https://bleepingcomputer.com/news/security/mands-confirms-social-engineering-led-to-massive-ransomware-attack)
- **Co-op Group (UK)** (April 2025): Data on all 6.5 million members was copied; shutting systems down early prevented encryption but still emptied shelves. Reported to have started with help-desk resets. Source: [BleepingComputer](https://www.bleepingcomputer.com/news/security/co-op-confirms-data-theft-after-dragonforce-ransomware-claims-attack/)
- **UK NCSC** (May 2025): After the retail attacks, told every organisation to review how its IT help desk authenticates staff before resetting passwords, especially for admins. Source: [NCSC](https://www.ncsc.gov.uk/news/retailers-incident)
- **India:** No public Indian case found — the mechanism needs only a help desk and a convincing caller.
- **Stops it:** Verify the caller before any reset, Phishing-resistant MFA and SSO for staff, Detect and report inside six hours, Backups you can restore — offline, and in India for the books

### Ransomware stops the supply, not the stores (Store-led retailers)

Attackers get a foothold, spread to ERP and warehouse systems, and encrypt them — stores stay open with nothing to sell. Path: Foothold, then spread → ERP and warehouse encrypted → Supply stops.

- **Raymond Lifestyle** (February 2025): Its exchange filing said store operations were unaffected. Its Q4 FY25 results then attributed part of a ₹45 crore loss to “a ransomware attack that led to system outages and supply chain disruptions”. Source: [IndiaRetailing](https://www.indiaretailing.com/2025/05/13/raymond-lifestyle-posts-rs-45-crore-loss-in-q4)
- **Haldiram’s** (October 2020): An FIR in Noida records servers encrypted and financial, HR and sales data taken; police said the allegations were found true. Source: [Deccan Herald / PTI](https://www.deccanherald.com/india/haldiram-s-crucial-data-stolen-hackers-demand-rs-750-lakh-to-release-info-903069.html)
- **Mithaas** (October 2020): A second Noida food-retail chain reported ransomware within two weeks: “complete data has become useless for us”. Source: [Tribune / PTI](https://www.tribuneindia.com/news/nation/ransomware-attack-on-restaurant-chain-mithaas-probe-on-161417/amp)
- **Stops it:** Backups you can restore — offline, and in India for the books, Detect and report inside six hours, Patch what is exposed first, Filter web and DNS at every store

### A vendor’s remote access becomes POS malware (Store-led retailers)

A POS vendor’s, contractor’s or franchisee’s remote-access credentials are stolen, and malware lands on the tills. Path: Vendor’s remote access → Into store systems → Malware on the tills.

- **Wendy’s (US)** (2015–16): POS malware at franchised restaurants, installed using “compromised third-party vendor credentials”; company-operated restaurants were not affected. Source: [Wendy’s 8-K](https://www.sec.gov/Archives/edgar/data/0000030697/000119312516617956/d121680dex991.htm)
- **Target (US)** (2013): Attackers used an HVAC contractor’s credentials, moved through the network and put malware on POS systems; 40 million cards were taken. Source: [Dark Reading](https://www.darkreading.com/cyberattacks-data-breaches/target-breach-hvac-contractor-systems-investigated)
- **India:** No public Indian case found. Indian franchise disclosures do not show franchisor security clauses either.
- **Stops it:** Control vendor and franchise access to stores, Hold franchisees to a minimum, Lock down POS and back-office machines, Segment the store network and the card environment, Use validated card terminals

### An old key or an open bucket, and the customer database walks out (Online sellers)

A stale access key, a stolen password without MFA or a misconfigured cloud store gives direct access to the customer database. Path: Old key or misconfiguration → Into the data store → Customer data exported.

- **Juspay** (August 2020): “An old unrecycled AWS access key was exploited”; Juspay said 3.5 crore masked-card records were taken from the payments partner of several large merchants. A researcher put the figure at about 10 crore; Juspay disputed it. Source: [Business Today](https://www.businesstoday.in/technology/news/story/amazon-swiggy-payments-partner-juspay-suffers-data-breach-35-crore-records-compromised-283598-2021-01-05)
- **RentoMojo** (April 2023): Its CEO told customers attackers exploited a cloud misconfiguration; the leaked data included government ID and passport numbers. Source: [MediaNama](https://www.medianama.com/2023/04/223-rentomojo-data-breach-customer-personal-data/)
- **BigBasket, Domino’s India, ABFRL, boAt** (2020–2024): Customer databases verified by Have I Been Pwned at 2.45 crore, 2.25 crore, 55 lakh and 75 lakh email addresses. None of the companies disclosed how the attackers got in. Source: [MediaNama (BigBasket)](https://www.medianama.com/2020/11/223-bigbasket-data-breach/)
- **Snowflake customers** (2024): About 165 organisations’ data stores were accessed with stolen credentials and no MFA — Advance Auto Parts reported 23 lakh people affected. Source: [Google / Mandiant](https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion)
- **Stops it:** Encrypt and tokenise customer data, Patch what is exposed first, Know which vendors hold your customers, Keep 180 days of logs — and a year for personal data, Phishing-resistant MFA and SSO for staff

### Customers’ accounts are taken over and spent (Online sellers)

Reused passwords or a fake support call hand over a customer’s account — and its wallet, BNPL line or loyalty points. Path: Reused password or fake call → Account taken over → Wallet or BNPL spent.

- **Swiggy customers** (February 2024): Delhi Police arrested two men who used fake IVR calls to take over accounts and placed ₹97,197 of orders on one victim’s linked BNPL account. Source: [Siasat](https://www.siasat.com/hackers-place-order-of-over-rs-97k-from-victims-swiggy-account-two-held-2980014/)
- **Meesho** (2024): Its own trust report: 13 lakh bot orders blocked in a year, and nine cases filed for account-takeover fraud. Source: [Outlook Business](https://www.outlookbusiness.com/corporate/meesho-acts-against-22-crore-suspicious-transactions-lodges-12-cases-in-a-year)
- **The North Face (US)** (April 2025): VF called it a “small-scale credential stuffing attack”; 2,861 customers’ names, addresses and order histories were visible to the attackers. Source: [Maine Attorney General filing](https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/c1f0f661-11e0-4103-a365-389293a09cef.html)
- **Stops it:** Stop bots and account takeover, Secure customer logins

### A script on the checkout page copies every card (Online sellers)

Attackers inject or hijack a script on the payment page, and it reads what the shopper types before the card is ever tokenised. Path: Script injected → Checkout input copied → Card data leaves.

- **British Airways (UK)** (2018; fined 2020): The UK regulator fined BA £20 million after its payment page was skimmed for about 4.3 lakh customers and staff. Source: [The Register](https://www.theregister.com/2020/10/16/british_airways_ico_fine_20m/)
- **Ticketmaster UK** (Fined 2020): Fined £1.25 million over a third-party chatbot script on its payment page. Source: [SCL](https://www.scl.org/12122-ticketmaster-chatbots-and-the-ico-fine-what-lessons-can-we-learn/)
- **CosmicSting (Adobe Commerce / Magento)** (2024): Sansec counted 4,275 online stores hacked through one vulnerability — about 5% of all Adobe Commerce and Magento stores. Source: [Sansec](https://sansec.io/research/cosmicsting-fallout)
- **India:** No public Indian web-skimming case found, 2019–2026 — not the same as “it doesn’t happen here”.
- **Stops it:** Watch every script on the checkout page, Web application and API protection, and DDoS, Patch what is exposed first, Decide your PCI scope on purpose

### Refunds, returns and coupons are farmed (Online sellers)

Fake buyers, colluding sellers or insiders exploit refund and return rules that work exactly as designed. Path: Fake buyers or sellers → False return claims → Refunds drained.

- **Myntra** (2024): Filed a ₹1.1 crore complaint with Bengaluru police over false “item missing” refund claims on about 5,529 orders. Source: [Business Today](https://businesstoday.in/technology/news/story/myntra-rs11-crore-refund-scam-heres-how-a-jaipur-based-gang-pulled-it-off-456827-2024-12-10)
- **Meesho** (2024): Police arrested a seller and agent who faked buyer accounts and returns to take ₹5.5 crore. Source: [Deccan Herald](https://www.deccanherald.com/india/karnataka/bengaluru/gang-registers-as-seller-with-e-commerce-company-exploits-returns-policy-swindles-rs-5-5-crore-3302465)
- **Swiggy** (February 2023): Its IPO document discloses a former employee who gained access to test systems; an FIR was filed. Source: [Storyboard18 (Swiggy DRHP)](https://www.storyboard18.com/brand-makers/swiggy-admits-to-data-breaches-says-business-is-vulnerable-to-cyberattacks-43408.htm)
- **Stops it:** Design refunds and returns against abuse, Verify sellers, riders and partners, Limit what store and support staff can take, Stop bots and account takeover

### A supplier is breached, and your customers or shelves pay (Every retailer)

An agency, SaaS platform or service provider holding your data or running your operations is compromised. Path: A supplier is breached → Into your data or operations → Orders or data hit.

- **Dunzo** (July 2020): The attacker “compromised the servers of a third party that the company works with”; 34.6 lakh email addresses were later verified. Source: [MediaNama](https://www.medianama.com/2020/07/223-dunzo-data-breach/)
- **Blue Yonder** (November 2024): Ransomware in one supply-chain SaaS provider disrupted Starbucks’ staff scheduling and warehouse systems at UK grocers Morrisons and Sainsbury’s. Source: [CyberScoop](https://cyberscoop.com/termite-ransomware-blue-yonder-disruption/)
- **UNFI (US)** (June 2025): Whole Foods’ main distributor took systems offline and estimated $350–400 million of lost sales. Source: [UNFI results (SEC)](https://www.sec.gov/Archives/edgar/data/1020859/000102085925000038/julyfy25-earningsreleasefo.htm)
- **Harrods (UK)** (September 2025): An external supplier was breached: about 4.3 lakh customers’ loyalty and contact records. Source: [The Register](https://www.theregister.com/2025/09/29/harrods_blames_thirdparty_supplier_after)
- **Stops it:** Know which vendors hold your customers, Read the breach clauses you have signed, Backups you can restore — offline, and in India for the books, Detect and report inside six hours

### Fake stores and apps use your name (Every retailer)

Lookalike sites, apps and support numbers use your brand at sale time, and your customers pay or log in to them. Path: Fake store or app → Shoppers pay or log in → Money and data lost.

- **CERT-In advisory CIAD-2024-0050** (October 2024): CERT-In’s festive-season advisory warns of fake e-commerce sites and cash-on-delivery scams run through fake online stores. Source: [CERT-In](https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES02&VLCODE=CIAD-2024-0050)
- **Meesho** (2024): Its trust report: 130 fake websites and apps and 18,000 fake social-media accounts taken down in a year. Source: [Outlook Business](https://www.outlookbusiness.com/corporate/meesho-acts-against-22-crore-suspicious-transactions-lodges-12-cases-in-a-year)
- **Stops it:** Email security, DMARC and lookalike-site takedown, Secure customer logins

## What a breach costs a retailer

- **₹25.5 cr** — Average cost of a data breach in India — the highest IBM has recorded ([IBM Cost of a Data Breach, India 2026](https://in.newsroom.ibm.com/India-Records-its-Highest-Average-Cost-of-a-Data-Breach-2026))
- **68%** — Share of retail breaches that involved a third party ([Verizon DBIR 2026, retail](https://www.verizon.com/business/resources/T5d1/reports/2026-dbir-retail-snapshot.pdf))
- **42%** — Share of retail breaches that began with an exploited vulnerability — the top way in ([Verizon DBIR 2026, retail](https://www.verizon.com/business/resources/T5d1/reports/2026-dbir-retail-snapshot.pdf))
- **$1M** — Median ransom paid by retailers whose data was encrypted — 58% paid ([Sophos State of Ransomware in Retail 2025](https://www.sophos.com/blog/the-state-of-ransomware-in-retail-2025))
- **₹45 cr** — Raymond Lifestyle’s Q4 FY25 loss — attributed in part to a ransomware attack that disrupted its supply chain ([IndiaRetailing](https://www.indiaretailing.com/2025/05/13/raymond-lifestyle-posts-rs-45-crore-loss-in-q4))
- **£300m** — What M&S first guided its 2025 attack would take off operating profit, before insurance and mitigation ([The Record](https://therecord.media/marks-spencer-profits-wiped-out-cyberattack))
- **$20m** — Online sales Victoria’s Secret put down to taking its website offline for three days in 2025 ([Victoria’s Secret results (SEC)](https://www.sec.gov/Archives/edgar/data/1856437/000185643725000044/ex991vscoq32025earningsrel.htm))
- **£20m** — UK regulator’s fine on British Airways after its payment page was skimmed ([The Register](https://www.theregister.com/2020/10/16/british_airways_ico_fine_20m/))

## What the market gets wrong

- "Our e-commerce agency reports the breach, not us." — CERT-In: whoever notices it reports it, and the duty is “neither transferrable nor indemnified”.
- "DPDP is in force now." — Only the Board is. The operational duties start on 13 May 2027; Consent Managers on 13 November 2026.
- "DPDP gives us 72 hours to tell customers." — Customers must be told “without delay”. The 72 hours is the detailed report to the Board.
- "RBI mandates PCI DSS for every merchant." — It reaches you through your payment aggregator, which must check your infrastructure — no rule is aimed at merchants directly.
- "SAQ A means we can ignore checkout scripts." — SAQ A dropped 6.4.3 and 11.6.1 but added a test: your site must be protected against script attacks — by you or your provider.
- "We can store encrypted card numbers." — No entity other than issuers and networks may store card data. You may keep the last four digits and the issuer’s name.
- "Large marketplaces are Significant Data Fiduciaries." — None has been notified, and the section only commences on 13 May 2027. There is no user-count threshold.
- "All e-commerce must delete data after three years." — Only platforms with two crore or more registered users, and not marketplace sellers — from May 2027.
- "The 2021 e-commerce draft banned flash sales." — That draft was never notified, and the September 2026 amendment omits it.
- "The dark-pattern self-audit is already law." — It is an advisory until 1 January 2027, when it becomes a rule — with a certificate on your site.
- "CERT-In logs must stay in India." — CERT-In’s FAQ allows storage abroad if logs can be produced in reasonable time.
- "Every retailer needs a yearly CERT-In-empanelled audit." — Not by law — CERT-In’s 2025 audit guidelines are guidance. ONDC does require one of its participants.
- "A child is anyone under 13." — Under DPDP a child is anyone under 18 — and targeted ads to children are banned.
- "UPI collect requests are banned." — Only person-to-person collect ended; merchant collect continues for verified merchants.

## Frequently asked questions

### If our e-commerce agency or SaaS vendor detects a breach, who reports it to CERT-In?

Whoever notices it. CERT-In's FAQ on its 2022 Directions answers exactly the case of a consumer-facing business and its back-end partner: the duty to report within six hours is neither transferable nor indemnifiable by contract.

### How fast must a retailer report a breach to its payment gateway, Amazon or ONDC?

Faster than most expect, and by contract rather than law. Cashfree's merchant terms ask for suspected security events within 12 hours and Razorpay's for breaches within 24; Amazon's seller-API policy wants 24 hours; ONDC's network policy wants 6. CERT-In's own clock is 6 hours. They run in parallel.

### Does PCI DSS apply if we use a hosted checkout from Razorpay or Cashfree?

It depends on how the checkout is built. If you redirect shoppers to the gateway's own page, the SAQ A script test does not apply to you. If you embed the gateway's form in an iframe on your page, you are eligible for SAQ A only if your page is protected against script attacks — by you or your provider (PCI SSC FAQ 1588, 2025).

### Can we store customers' card numbers for one-click checkout?

No. Since 30 September 2022 the RBI has barred everyone except card issuers and networks from storing card data. A merchant may keep the last four digits and the issuer's name for reconciliation, and use network tokens for saved cards.

### When does the DPDP Act start applying to retailers?

The operational duties — notices, security safeguards, breach notification, erasure, children's data — apply from 13 May 2027. Consent Managers start on 13 November 2026. Customers must be told of a breach without delay; the detailed report to the Data Protection Board is due within 72 hours.

### What changes for e-commerce on 1 January 2027?

The Consumer Protection (E-Commerce) Amendment Rules 2026 come into force: a yearly dark-pattern self-audit with a certificate displayed on the site, clearly labelled sponsored listings, no manipulated search results, a 30-day prior-price rule for discounts, and — for marketplaces — express consent before using customer data to sell own-brand goods.

### Must large e-commerce platforms delete inactive users' data?

Yes, from May 2027, but only e-commerce entities with at least two crore registered users in India, and not marketplace sellers. They must erase a user's data after three years of inactivity, with 48 hours' warning, keeping what is needed for the account and wallet or loyalty balances.

### Do retailers need a yearly audit by a CERT-In-empanelled auditor?

Not by law — CERT-In's 2025 audit guidelines are guidance for private companies. But ONDC requires a yearly certificate from an ONDC- or CERT-In-empanelled auditor from its network participants, and payment gateways ask for annual proof of PCI DSS compliance.

## Questions about the obligations

### Which obligations bind every Indian retailer?

The CERT-In Directions (six-hour reporting, 180 days of logs, clock sync); the DPDP Act, whose operational duties apply from 13 May 2027; IT Act section 43A until then; the Consumer Protection Act's rule against disclosing customers' personal information; and the Companies Act rule to back up electronic books daily to servers in India.

### Does PCI DSS legally apply to Indian merchants?

Not directly: no Indian law aims PCI DSS at merchants. The RBI's Payment Aggregator Directions of 15 September 2025 require your aggregator to ensure your infrastructure meets PCI DSS and to review your status at onboarding; the card brands and your acquirer set your merchant level.

### Do the dark-pattern guidelines apply to D2C brands and sellers?

Yes. The CCPA's 2023 guidelines bind platforms, advertisers and sellers, list 13 patterns from false urgency to basket sneaking, and are being enforced: the CCPA fined platforms in June 2026. From 1 January 2027 every e-commerce entity must also self-audit yearly and display a certificate.

### Do TRAI's rules apply to a retailer's SMS and calls?

Yes. Every OTP, order update or promotional message makes you a registered Sender. Send only from registered headers and templates, give an opt-out in every promotional message, and from the September 2026 amendment message on an enquiry only within seven days, keeping the enquiry in a verifiable form.

### Does GDPR apply to an Indian D2C brand?

If you offer goods to customers in the EU or UK (EU-currency checkout, delivery there, ads aimed there), yes, and a brand shipping there regularly will need a representative in the EU and the UK. Breaches go to the supervisory authority within 72 hours.

### How long must a marketplace keep a user's data after they close their account?

Under the IT intermediary rules, 180 days after the account is closed. From 13 May 2027 the DPDP Rules also require order details and processing logs to be kept for at least a year, even if the customer deletes the account.

## Questions about the controls

### Which security controls should a retail chain start with?

The ones every retailer needs (Detect and report inside six hours; Keep 180 days of logs — and a year for personal data; Phishing-resistant MFA and SSO for staff; Email security, DMARC and lookalike-site takedown; Backups you can restore — offline, and in India for the books; Patch what is exposed first; Encrypt and tokenise customer data; Consent, notices and erasure under DPDP; Know which vendors hold your customers; Limit what store and support staff can take), then the store ones: Lock down POS and back-office machines; Manage handhelds, kiosks and rugged devices; Segment the store network and the card environment; Filter web and DNS at every store; Control vendor and franchise access to stores.

### What does an online seller need beyond a payment gateway?

A gateway handles the card, not your site. Online sellers also need: Web application and API protection, and DDoS; Stop bots and account takeover; Watch every script on the checkout page; Secure customer logins; Verify sellers, riders and partners; Stay up on sale day.

### How do we meet PCI DSS 6.4.3 and 11.6.1 on our checkout?

Keep an inventory of every script on the payment page with a reason for each, authorise and integrity-check them, and alert on unauthorised changes to the page and its security headers at least weekly. Redirecting shoppers to the gateway's own page takes the SAQ A script test off you; an embedded iframe does not.

### Which retail security controls can't be bought as software?

Verify the caller before any reset; Decide your PCI scope on purpose; The six-hour runbook; Read the breach clauses you have signed; Design refunds and returns against abuse; Audit checkout and consent for dark patterns; Hold franchisees to a minimum; Use validated card terminals. Procedures, design decisions, policies and contracts: where many 2024 to 2026 retail attacks got in.

---

TechBag — software discovery for Indian businesses. Talk to us: https://www.thetechbag.com/discovery-call?ref=retail
