Your D2C brand collects more customer info than you think.
You packed the order. You shipped it. Done, right? Not really. That one order collected your customer's name, phone number, home address, and payment details. Now multiply that by every order you have ever shipped. That is a lot of people's information sitting in your system. Under India's new data law, you are responsible for all of it.
Think about your last 100 orders. Each one has a customer's phone number and home address. Your support team chats on WhatsApp — those messages have names and complaints. Your loyalty programme knows who buys what. Your returns sheet has bank account details for refunds. All of this is people's information. India's new data law says you must protect it. If something goes wrong, you are responsible.
List every place you store customer names, phones, and addresses.
Tell your support team: do not share customer details on personal WhatsApp.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“Every order is also a data event.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.