26 security obligations on Indian retailers, and where each comes from
Indian law and regulators, the card industry and the RBI, what your gateway, marketplace and network write into the contract, and foreign law if you sell abroad. Every card carries its source and the date we checked it.
- 26obligations, in four groups
- 7carry a reporting clock
- 17dated milestones, 2025–2027
- 18read from the primary text
The deadlines still ahead
From today, in order. Everything already in force is folded underneath. Click one to open its card.
Already in force — 11 milestones since 31 Mar 2025
Showing 26 of 26
Indian law & regulators
12What binds every Indian retailer, or every retailer doing a particular kind of selling.
CERT-In Directions under section 70B(6), 28 April 2022
6 hoursAlways. The Directions bind every “body corporate” — every incorporated retailer, store-led or online — and name “attacks on applications such as e-commerce” as a reportable incident.
CERT-In Directions under section 70B(6), 28 April 2022
6 hoursAlways. The Directions bind every “body corporate” — every incorporated retailer, store-led or online — and name “attacks on applications such as e-commerce” as a reportable incident.
Who it reaches
Status
What it requires
- Report listed incidents — data breach, data leak, website intrusion, attacks on e-commerce applications, DDoS, fake apps, attacks on digital payment systems — within six hours of noticing them.
- Keep logs of all ICT systems for a rolling 180 days: firewall, web, database, application, VPN — successful and failed events.
- Synchronise clocks to NIC or NPL time, or a source traceable to them.
- Name a point of contact for CERT-In.
The clock
What people get wrong
The duty cannot be handed to your e-commerce agency, MSP or SaaS vendor. CERT-In’s FAQ (Q13) answers exactly the “consumer-facing business and its back-end partner” case: “The obligation of reporting of cyber incident is neither transferrable nor indemnified”. Logs may sit outside India if they can be produced in reasonable time (Q35).
The controls it drives
CERT-In (MeitY). Source: CERT-In Directions and FAQ (May 2022). Read from the primary text, verified 2026-10-05.
Digital Personal Data Protection Act 2023 and DPDP Rules 2025
72 hoursAlways. Every retailer is a Data Fiduciary for its customers’ data — loyalty, POS, CRM, app sign-ups, delivery addresses — and for its staff’s.
Digital Personal Data Protection Act 2023 and DPDP Rules 2025
72 hoursAlways. Every retailer is a Data Fiduciary for its customers’ data — loyalty, POS, CRM, app sign-ups, delivery addresses — and for its staff’s.
Who it reaches
Status
What it requires
- Security safeguards at the minimum: encryption, masking or tokens; access control; logged and reviewed access; backups (Rule 6).
- Keep order details, personal data and processing logs for at least one year — even if the customer deletes the account (Rule 8(3)).
- Notices a customer can understand on their own, and withdrawal as easy as giving consent (Rule 3).
- Tell affected customers and the Board without delay, with a detailed report to the Board within 72 hours (Rule 7). No materiality threshold.
- Publish a contact for data questions; resolve grievances within 90 days.
The clock
What people get wrong
The 72 hours is the detailed report to the Board — customers must be told “without delay”. Penalties run to ₹250 crore for failing to keep safeguards and ₹200 crore for failing to notify a breach.
The controls it drives
Parliament; Rules by MeitY. Source: DPDP Rules 2025, G.S.R. 846(E). Read from the primary text, verified 2026-10-05.
DPDP Rules, Third Schedule: erasure by large e-commerce platforms
OnlineIf you are an e-commerce entity with at least two crore registered users in India. Marketplace sellers are excluded; a multi-channel retailer whose app or site crosses two crore is in.
DPDP Rules, Third Schedule: erasure by large e-commerce platforms
OnlineIf you are an e-commerce entity with at least two crore registered users in India. Marketplace sellers are excluded; a multi-channel retailer whose app or site crosses two crore is in.
Who it reaches
Status
What it requires
- Erase a user’s personal data three years after they last engaged — except what keeps their account, wallet, gift card or loyalty balance usable.
- Warn the user at least 48 hours before erasure, so they can log in to keep the account.
The controls it drives
MeitY. Source: DPDP Rules 2025, Third Schedule. Read from the primary text, verified 2026-10-05.
DPDP Act section 9 and Rule 10: children’s data
OnlineIf any of your customers or app users may be under 18 — toys, kids’ fashion, baby care, school supplies, gaming accessories, or simply an app minors use.
DPDP Act section 9 and Rule 10: children’s data
OnlineIf any of your customers or app users may be under 18 — toys, kids’ fashion, baby care, school supplies, gaming accessories, or simply an app minors use.
Who it reaches
Status
What it requires
- Verifiable consent from a parent who is an identifiable adult before processing a child’s data.
- No tracking, behavioural monitoring or targeted advertising directed at children.
What people get wrong
A child is anyone under 18 — not 13 or 16. None of the Fourth Schedule exemptions is a retail exemption.
The controls it drives
Parliament; Rules by MeitY. Source: DPDP Act 2023, section 9; DPDP Rules 2025, Rule 10. Read from the primary text, verified 2026-10-05.
IT Act section 43A and the SPDI Rules 2011
Always, until the DPDP Act replaces it — for any retailer handling card or bank details, passwords or health data.
IT Act section 43A and the SPDI Rules 2011
Always, until the DPDP Act replaces it — for any retailer handling card or bank details, passwords or health data.
Who it reaches
Status
What it requires
- Reasonable security practices for sensitive personal data — financial information, passwords, health and biometrics.
- ISO/IEC 27001 is the standard the Rules name as one way to show them.
The controls it drives
MeitY. Source: DPDP commencement, G.S.R. 843(E) (via ICAI and taxmann). Two or more reputable secondary sources, verified 2026-10-05.
Consumer Protection Act 2019, section 2(47)(ix)
Always — offline stores included.
Consumer Protection Act 2019, section 2(47)(ix)
Always — offline stores included.
Who it reaches
Status
What it requires
- Disclosing a customer’s personal information given in confidence, other than as the law allows, is an “unfair trade practice”.
The controls it drives
Parliament; enforced by the CCPA. Source: Consumer Protection Act 2019 (Gazette). Read from the primary text, verified 2026-10-05.
Consumer Protection (E-Commerce) Rules 2020, as amended in 2026
OnlineIf you sell online — marketplace, inventory or D2C, including multi-channel single-brand retailers — or sell on a marketplace as a seller.
Consumer Protection (E-Commerce) Rules 2020, as amended in 2026
OnlineIf you sell online — marketplace, inventory or D2C, including multi-channel single-brand retailers — or sell on a marketplace as a seller.
Who it reaches
Status
What it requires
- Record a purchase consent only through an explicit, affirmative action — no pre-ticked boxes (Rule 4(9)).
- A grievance officer who acknowledges complaints within 48 hours and resolves them within a month.
- Tell customers about the security of your payment methods and the payment provider’s contact (Rules 5 and 7).
- From 2027: no manipulated search results; sponsored listings clearly labelled; a discount must show the lowest price of the previous 30 days.
- From 2027: a marketplace may not use customer data to sell its own-brand goods, or to promote sellers as associated with it, without the customer’s express consent (Rule 5(6)).
What people get wrong
The 2021 draft’s flash-sale ban, fall-back liability and Chief Compliance Officer were never notified — the 2026 amendment omits all of them.
The controls it drives
Ministry of Consumer Affairs. Source: E-Commerce (Amendment) Rules 2026, G.S.R. 789(E). Read from the primary text, verified 2026-10-05.
Guidelines for Prevention and Regulation of Dark Patterns, 2023
OnlineIf you run a platform, advertise or sell online in India — the Guidelines bind platforms, advertisers and sellers.
Guidelines for Prevention and Regulation of Dark Patterns, 2023
OnlineIf you run a platform, advertise or sell online in India — the Guidelines bind platforms, advertisers and sellers.
Who it reaches
Status
What it requires
- None of the 13 patterns: false urgency, basket sneaking, confirm shaming, forced action, subscription trap, interface interference, bait and switch, drip pricing, disguised ads, nagging, trick questions, SaaS billing, rogue malware.
- No forcing customers to share personal data they don’t need to buy — and no cookie or notification prompts without a way to say no.
The controls it drives
Central Consumer Protection Authority. Source: CCPA Dark Patterns Guidelines 2023. Read from the primary text, verified 2026-10-05.
IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, as amended
OnlineIf you run a marketplace — its safe harbour is tied to these Rules by the E-Commerce Rules.
IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, as amended
OnlineIf you run a marketplace — its safe harbour is tied to these Rules by the E-Commerce Rules.
Who it reaches
Status
What it requires
- Keep a user’s registration data for 180 days after they close the account.
- Acknowledge grievances in 24 hours and resolve them in 7 days; act on court or government takedowns within 3 hours.
- Secure your computer resource to the SPDI Rules’ standard, and report cyber incidents to CERT-In.
- Answer an authorised agency’s written request, including for cyber incidents, within 72 hours.
The controls it drives
MeitY. Source: IT Rules 2021, consolidated to 10 February 2026. Read from the primary text, verified 2026-10-05.
TRAI Telecom Commercial Communications Customer Preference Regulations, as amended
If you send OTPs, order updates, or promotional SMS and calls — every such message makes you a registered Sender.
TRAI Telecom Commercial Communications Customer Preference Regulations, as amended
If you send OTPs, order updates, or promotional SMS and calls — every such message makes you a registered Sender.
Who it reaches
Status
What it requires
- Send only from registered headers and templates; self-certify them every year or face automatic suspension.
- Give an opt-out in every promotional message. Re-acquire a revoked consent only after 90 days.
- From the 2026 amendment: message on the strength of an enquiry only within 7 days, and keep the enquiry in a verifiable written or digital form; declare automated calls in advance.
What people get wrong
The rupee penalties fall on telecom operators. A sender found sending unsolicited messages has every telecom resource barred for 15 days — and is disconnected and blacklisted the second time.
The controls it drives
Telecom Regulatory Authority of India. Source: TCCCPR Third Amendment 2026. Read from the primary text, verified 2026-10-05.
Companies (Accounts) Rules 2014, rule 3(5), as amended in 2022
Always — every Indian company, including the Indian arm of a foreign retailer.
Companies (Accounts) Rules 2014, rule 3(5), as amended in 2022
Always — every Indian company, including the Indian arm of a foreign retailer.
Who it reaches
Status
What it requires
- Back up electronically kept books of account daily to servers physically located in India.
- Keep the books accessible in India at all times.
The controls it drives
Ministry of Corporate Affairs. Source: Companies (Accounts) Amendment Rules 2022 (via AZB, Grant Thornton). Two or more reputable secondary sources, verified 2026-10-05.
GST e-invoicing: the 30-day reporting limit
If you issue B2B invoices — marketplace commissions, franchise supplies, wholesale, distributors — with an aggregate turnover of ₹10 crore or more. Retail B2C sales are not e-invoiced.
GST e-invoicing: the 30-day reporting limit
If you issue B2B invoices — marketplace commissions, franchise supplies, wholesale, distributors — with an aggregate turnover of ₹10 crore or more. Retail B2C sales are not e-invoiced.
Who it reaches
Status
What it requires
- Report e-invoices, credit notes and debit notes to the Invoice Registration Portal within 30 days — later ones are rejected.
- Keep GST records with backups that can be restored in reasonable time.
The controls it drives
GSTN / CBIC. Source: GSTN advisory, 5 November 2024. Read from the primary text, verified 2026-10-05.
Payments & card data
6The card industry’s standard and the RBI’s rules — most of which reach you through your payment aggregator.
PCI DSS v4.0.1
If you accept cards — at a store terminal or on your own website or app. The card brands and your acquirer decide your merchant level and how you prove compliance.
PCI DSS v4.0.1
If you accept cards — at a store terminal or on your own website or app. The card brands and your acquirer decide your merchant level and how you prove compliance.
Who it reaches
Status
What it requires
- Online: inventory, authorise and integrity-check every script on your payment page (6.4.3), and detect unauthorised changes to it at least weekly (11.6.1).
- Online, on SAQ A: you are eligible only if your site is protected against script attacks — by you or your payment provider (PCI SSC FAQ 1588).
- MFA for all non-console access into the card environment (8.4.2) — a POS login that sees one card at a time is exempt; the back office is not.
- Anti-phishing protection for staff with access to in-scope systems (5.4.1); 12-character passwords (8.3.6).
What people get wrong
Redirecting customers to the gateway’s own page takes the SAQ A script test off you; an embedded iframe does not.
The controls it drives
PCI Security Standards Council; enforced by the card brands and acquirers. Source: PCI SSC: SAQ A update (30 Jan 2025) and FAQ 1588. Read from the primary text, verified 2026-10-05.
RBI card-on-file tokenisation: merchants may not store card data
If you take card payments — for saved cards, one-click checkout, loyalty or reconciliation.
RBI card-on-file tokenisation: merchants may not store card data
If you take card payments — for saved cards, one-click checkout, loyalty or reconciliation.
Who it reaches
Status
What it requires
- Store no actual card data. Keep only the last four digits and the card issuer’s name, for tracking and reconciliation.
- Use network tokens for saved cards, and let customers de-register a token.
What people get wrong
Tokenisation does not stop a skimmer reading what a shopper types on a page you host — that is what the PCI checkout-script rules are for.
The controls it drives
Reserve Bank of India. Source: RBI circular, 7 September 2021 (CoFT). Read from the primary text, verified 2026-10-05.
RBI (Regulation of Payment Aggregators) Directions 2025
If you take payments through a payment aggregator — online, or at the store through a POS aggregator.
RBI (Regulation of Payment Aggregators) Directions 2025
If you take payments through a payment aggregator — online, or at the store through a POS aggregator.
Who it reaches
Status
What it requires
- Your aggregator must ensure your infrastructure meets PCI DSS, review your PCI status at onboarding, and assess your security baseline (para 9(a); Annexure 1).
- Customer card credentials may not be stored in any database or server you access.
- Merchant due diligence and background checks; a marketplace may take payments only for sellers onboarded to it.
What people get wrong
No Indian law aims PCI DSS at merchants directly. It reaches you through the aggregator — which is why its contract asks for proof every year.
The controls it drives
Reserve Bank of India — reaching you through your payment aggregator. Source: RBI PA Master Direction, 15 September 2025. Read from the primary text, verified 2026-10-05.
RBI Cyber Resilience Directions for non-bank PSOs: card terminals at merchants
StoresIf you take cards on terminals in your stores.
RBI Cyber Resilience Directions for non-bank PSOs: card terminals at merchants
StoresIf you take cards on terminals in your stores.
Who it reaches
Status
What it requires
- Terminals that capture card details must be validated against PCI P2PE; PIN-entry terminals must be PCI PTS approved.
- Handhelds and mPOS devices that take cards sit inside the same card environment — managed and locked down like the tills.
The controls it drives
Reserve Bank of India — reaching you through your PSO. Source: RBI Cyber Resilience MD for non-bank PSOs (via payments register). Two or more reputable secondary sources, verified 2026-10-05.
RBI (Authentication Mechanisms for Digital Payment Transactions) Directions 2025
OnlineIf customers pay online by card — the duty sits on payment providers, and reaches you through your checkout flow.
RBI (Authentication Mechanisms for Digital Payment Transactions) Directions 2025
OnlineIf customers pay online by card — the duty sits on payment providers, and reaches you through your checkout flow.
Who it reaches
Status
What it requires
- Two factors for every digital payment unless exempted — and for non-card-present payments, at least one factor must be dynamic.
The controls it drives
Reserve Bank of India — through your gateway and issuers. Source: RBI Authentication Directions, 25 September 2025. Read from the primary text, verified 2026-10-05.
RBI Digital Payments — E-mandate Framework 2026
OnlineIf you run subscriptions, memberships or auto-replenishment on cards, prepaid instruments or UPI.
RBI Digital Payments — E-mandate Framework 2026
OnlineIf you run subscriptions, memberships or auto-replenishment on cards, prepaid instruments or UPI.
Who it reaches
Status
What it requires
- Authenticate the customer at registration and on the first debit; send a pre-debit notice at least 24 hours before, naming you.
- Recurring debits run without extra authentication only up to ₹15,000 a transaction.
The controls it drives
Reserve Bank of India — through your acquirer. Source: RBI E-mandate Framework, 21 April 2026. Read from the primary text, verified 2026-10-05.
What your platforms & partners demand
3Not law — but the gateway, the marketplace and the network write it into the agreement, with breach clocks of 6 to 24 hours that run alongside CERT-In’s.
Payment gateway merchant terms (Razorpay, Cashfree)
12–24 hoursIf you take payments through an Indian payment gateway — online, or at stores through its POS.
Payment gateway merchant terms (Razorpay, Cashfree)
12–24 hoursIf you take payments through an Indian payment gateway — online, or at stores through its POS.
Who it reaches
Status
What it requires
- Report a suspected security event within 12 hours (Cashfree) or an actual or suspected breach within 24 hours (Razorpay).
- Never store full card credentials — “irrespective of the Merchant being PCI-DSS compliant” (Cashfree).
- Submit proof of PCI DSS compliance every year, and accept security audits at any time (Razorpay).
The clock
The controls it drives
Your payment aggregator. Source: Cashfree terms (and Razorpay terms). Read from the primary text, verified 2026-10-05.
Amazon Selling Partner API Data Protection Policy
Online24 hoursIf you connect to Amazon through its Selling Partner API — including a seller’s own private integration, not just software vendors.
Amazon Selling Partner API Data Protection Policy
Online24 hoursIf you connect to Amazon through its Selling Partner API — including a seller’s own private integration, not just software vendors.
Who it reaches
Status
What it requires
- MFA for every user account; 12-character passwords; API keys encrypted and rotated yearly.
- Encrypt customer data at rest (AES-128 or stronger) and in transit (TLS 1.2+); endpoint protection and DLP.
- Notify Amazon within 24 hours of detecting a security incident.
- Keep customer PII no longer than 30 days after delivery; scan for vulnerabilities every 30 days; penetration-test every year.
The clock
The controls it drives
Amazon. Source: Amazon Data Protection Policy. Read from the primary text, verified 2026-10-05.
ONDC Network Policy: technology governance, data and grievances
Online6 hoursIf you are an ONDC network participant — a seller app or buyer app. A small retailer selling through a seller app receives these obligations through it.
ONDC Network Policy: technology governance, data and grievances
Online6 hoursIf you are an ONDC network participant — a seller app or buyer app. A small retailer selling through a seller app receives these obligations through it.
Who it reaches
Status
What it requires
- A documented security programme no less rigorous than ISO/IEC 27001 and COBIT — extended to your technology service providers.
- Alert ONDC within 6 hours of becoming aware of a data breach or cyber incident.
- A yearly certificate from an ONDC- or CERT-In-empanelled auditor; ONDC may audit you without notice after a major breach.
- Explicit consent from buyers and sellers; acknowledge issues within 120 minutes and resolve grievances within 96 hours.
The clock
The controls it drives
Open Network for Digital Commerce. Source: ONDC Network Policy, Chapter 8. Read from the primary text, verified 2026-10-05.
If you sell abroad
5EU, UK and US rules that reach an Indian retailer through the customers it ships to.
EU GDPR and UK GDPR
Online72 hoursIf you offer goods to customers in the EU or UK — EU-currency checkout, delivery there, ads aimed there. Being reachable is not enough; shipping there regularly is.
EU GDPR and UK GDPR
Online72 hoursIf you offer goods to customers in the EU or UK — EU-currency checkout, delivery there, ads aimed there. Being reachable is not enough; shipping there regularly is.
Who it reaches
Status
What it requires
- Appoint a representative in the EU and the UK — a D2C brand shipping there regularly will not fit the “occasional” exemption.
- Notify the supervisory authority within 72 hours of becoming aware of a breach.
The clock
The controls it drives
European Union; UK. Source: Regulation (EU) 2016/679. Two or more reputable secondary sources, verified 2026-10-05.
EU Digital Services Act: online marketplaces
OnlineIf you run a marketplace that targets EU consumers (unless micro or small). D2C sellers on EU marketplaces must supply the same trader data.
EU Digital Services Act: online marketplaces
OnlineIf you run a marketplace that targets EU consumers (unless micro or small). D2C sellers on EU marketplaces must supply the same trader data.
Who it reaches
Status
What it requires
- A legal representative in the EU who can be held liable.
- Collect and check each trader’s identity, contact, payment and registration details before they sell to EU consumers.
The controls it drives
European Union. Source: Regulation (EU) 2022/2065. Two or more reputable secondary sources, verified 2026-10-05.
EU NIS2 Directive: online marketplaces
Online24 hoursIf you run a medium-sized or larger online marketplace offering services in the EU. A D2C brand selling only its own goods is not a marketplace.
EU NIS2 Directive: online marketplaces
Online24 hoursIf you run a medium-sized or larger online marketplace offering services in the EU. A D2C brand selling only its own goods is not a marketplace.
Who it reaches
Status
What it requires
- Appoint an EU representative; ten minimum measures including supply-chain security and multi-factor authentication.
- An early warning within 24 hours of a significant incident, and a notification within 72.
The clock
The controls it drives
European Union. Source: Directive (EU) 2022/2555. Two or more reputable secondary sources, verified 2026-10-05.
California Consumer Privacy Act, as amended
OnlineIf you do business in California and have annual gross revenue above $26,625,000 (from 2025), or trade the data of 100,000+ consumers.
California Consumer Privacy Act, as amended
OnlineIf you do business in California and have annual gross revenue above $26,625,000 (from 2025), or trade the data of 100,000+ consumers.
Who it reaches
Status
What it requires
- Honour Californians’ privacy rights; from 2028–2030, certify an annual cybersecurity audit.
The controls it drives
California. Source: California Privacy Protection Agency. Two or more reputable secondary sources, verified 2026-10-05.
US COPPA Rule, as amended in 2025
OnlineOnly if you sell to or collect data from US children under 13 — toy, kids’ apparel or ed-tech brands.
US COPPA Rule, as amended in 2025
OnlineOnly if you sell to or collect data from US children under 13 — toy, kids’ apparel or ed-tech brands.
Who it reaches
Status
What it requires
- A written information security programme, with yearly risk assessments and vendor due diligence.
The controls it drives
US Federal Trade Commission. Source: Amended COPPA Rule, 16 CFR 312. Two or more reputable secondary sources, verified 2026-10-05.
14 things the market gets wrong
Each of these circulates in vendor decks, contracts or commentary. Each was checked against the source.
- “Our e-commerce agency reports the breach, not us.”CERT-In: whoever notices it reports it, and the duty is “neither transferrable nor indemnified”.
- “DPDP is in force now.”Only the Board is. The operational duties start on 13 May 2027; Consent Managers on 13 November 2026.
- “DPDP gives us 72 hours to tell customers.”Customers must be told “without delay”. The 72 hours is the detailed report to the Board.
- “RBI mandates PCI DSS for every merchant.”It reaches you through your payment aggregator, which must check your infrastructure — no rule is aimed at merchants directly.
- “SAQ A means we can ignore checkout scripts.”SAQ A dropped 6.4.3 and 11.6.1 but added a test: your site must be protected against script attacks — by you or your provider.
- “We can store encrypted card numbers.”No entity other than issuers and networks may store card data. You may keep the last four digits and the issuer’s name.
- “Large marketplaces are Significant Data Fiduciaries.”None has been notified, and the section only commences on 13 May 2027. There is no user-count threshold.
- “All e-commerce must delete data after three years.”Only platforms with two crore or more registered users, and not marketplace sellers — from May 2027.
- “The 2021 e-commerce draft banned flash sales.”That draft was never notified, and the September 2026 amendment omits it.
- “The dark-pattern self-audit is already law.”It is an advisory until 1 January 2027, when it becomes a rule — with a certificate on your site.
- “CERT-In logs must stay in India.”CERT-In’s FAQ allows storage abroad if logs can be produced in reasonable time.
- “Every retailer needs a yearly CERT-In-empanelled audit.”Not by law — CERT-In’s 2025 audit guidelines are guidance. ONDC does require one of its participants.
- “A child is anyone under 13.”Under DPDP a child is anyone under 18 — and targeted ads to children are banned.
- “UPI collect requests are banned.”Only person-to-person collect ended; merchant collect continues for verified merchants.
Compiled and verified by TechBag research. General information, not legal advice — confirm applicability and current status with your counsel. If we have read something wrongly, write to info@thetechbag.com.
Retail obligations, answered
Short answers, each backed by the sources on this page.
Which obligations bind every Indian retailer?
The CERT-In Directions (six-hour reporting, 180 days of logs, clock sync); the DPDP Act, whose operational duties apply from 13 May 2027; IT Act section 43A until then; the Consumer Protection Act's rule against disclosing customers' personal information; and the Companies Act rule to back up electronic books daily to servers in India.
Does PCI DSS legally apply to Indian merchants?
Not directly: no Indian law aims PCI DSS at merchants. The RBI's Payment Aggregator Directions of 15 September 2025 require your aggregator to ensure your infrastructure meets PCI DSS and to review your status at onboarding; the card brands and your acquirer set your merchant level.
Do the dark-pattern guidelines apply to D2C brands and sellers?
Yes. The CCPA's 2023 guidelines bind platforms, advertisers and sellers, list 13 patterns from false urgency to basket sneaking, and are being enforced: the CCPA fined platforms in June 2026. From 1 January 2027 every e-commerce entity must also self-audit yearly and display a certificate.
Do TRAI's rules apply to a retailer's SMS and calls?
Yes. Every OTP, order update or promotional message makes you a registered Sender. Send only from registered headers and templates, give an opt-out in every promotional message, and from the September 2026 amendment message on an enquiry only within seven days, keeping the enquiry in a verifiable form.
Does GDPR apply to an Indian D2C brand?
If you offer goods to customers in the EU or UK (EU-currency checkout, delivery there, ads aimed there), yes, and a brand shipping there regularly will need a representative in the EU and the UK. Breaches go to the supervisory authority within 72 hours.
How long must a marketplace keep a user's data after they close their account?
Under the IT intermediary rules, 180 days after the account is closed. From 13 May 2027 the DPDP Rules also require order details and processing logs to be kept for at least a year, even if the customer deletes the account.