Most D2C brands collect info they never use. That's a problem now.
You sell online. Customers fill your form. They give their name, phone, address, date of birth, and sometimes even their PAN number. But do you really need all of that just to deliver a kurta or a protein shake? Under the new DPDPA law, collecting extra information is not allowed. If you run a D2C brand — even a small one — this applies to you today.
Say you run a skincare brand. Your checkout form asks for date of birth and WhatsApp number. Your Meta ads agency also has access to your full customer list. Your delivery partner gets customer phone numbers too. That is three places where people's information is sitting. Under DPDPA, you must know who has this data and why. You must only collect what you truly need. Old campaign lists with thousands of names? Delete them. They are a risk, not an asset.
Open your order form and remove every field you do not truly need.
List all agencies and apps that can see your customer data right now.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“The fastest privacy win in D2C is often deleting useless data.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.