More people touch your customer data than you think.
You think only you have your customer's phone number. But think again. Your delivery partner has it. Your WhatsApp marketing agency has it. Your warehouse team has it. Your CRM tool has it. Under the new DPDPA law, YOU are responsible for all of them. If any one of them misuses your customer's information, the problem comes back to you.
Say a customer orders from your brand. Your warehouse team packs it. A delivery partner like Delhivery or Shiprocket gets the address. Your CRM tool saves the phone number. Your agency uses the email for a sale campaign. Your finance team sees the order for GST records. That is six places with one customer's details. DPDPA says you must track all six. You must make sure none of them misuse that information. If they do, you are in trouble — not them.
Write down every tool and team that sees customer orders.
Ask your agency and delivery partner how they store customer data.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“The customer record is usually spread across tools not stored in one place.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.