Your online shop collects more data than you think — here's what to do.
You got 50 orders last week. Great! But did you know each order shared your customer's phone number, address, and payment details with 4 or 5 other companies? Your delivery partner got it. Your payment app got it. Your WhatsApp marketing tool got it. Most small D2C sellers have no idea this is happening. Under India's new DPDPA law, YOU are responsible for all of it.
Say you run a small D2C brand on Instagram. A customer orders a kurta. You share their phone number with Shiprocket or Delhivery. You send them a WhatsApp message via a bulk tool. You add them to a loyalty list. That is four places their information now lives. If any one of them misuses it, the customer can complain — and the law points back to you. You must know where your customers' information goes. You must have their permission before using it for marketing.
List every app or partner that gets your customer's phone number or address.
Stop sending WhatsApp marketing without customer permission — ask first.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“Every order creates a data trail not just a revenue line.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.