Blog
September 3, 2026
5 mins
Privacy Laws
Shopify

India DPDP Compliance for Shopify: What Merchants Need to Do Before May 2027

August 2026 made India’s DPDP timeline concrete: Consent Manager rules in November 2026, and core business obligations in May 2027. This guide shows Shopify merchants what to fix now, where a cookie banner helps, and what still sits outside a CMP.
Prepare your Shopify store for India’s DPDP requirements with Consentmo

TLDR

  • India’s Digital Personal Data Protection (DPDP) regime is phased. Core merchant-facing duties (notices, consent, Data Principal rights, security, breach handling, retention) are set for 13 May 2027.
  • Consent Manager provisions arrive earlier, around 13 November 2026.
  • August 2026 locked the public story: a Lok Sabha reply restated the May 2027 window, and the Cabinet Secretary pushed ministries and states to file time-bound implementation plans.
  • A cookie banner / CMP is necessary for tracking consent on Shopify. It does not make a store fully DPDP-compliant on its own.

The DPDP timeline Shopify merchants should know

According to reporting on the government’s Lok Sabha position and detailed practitioner guides:

  1. From Rules notification (13 Nov 2025): Institutional pieces such as the Data Protection Board framework begin to operate.
  2. Around 13 November 2026: Consent Manager registration and related Rule 4 machinery.
  3. Around 13 May 2027 (18 months after Rules notification): Core fiduciary obligations that ecommerce teams feel day to day: notice content, consent mechanics, reasonable security safeguards, breach notification, retention and erasure, grievance contact, and Data Principal rights workflows.

Important clarification for Consentmo readers: main business obligations are not “everything is fully enforceable against every Shopify store as of today.” Some institutional provisions are already in motion. The heavy merchant checklist (notices, consent proof, rights handling, security, breaches, retention) is timed for May 2027. Waiting until April 2027 still leaves you late, because store data maps, app inventories, and legal text rarely finish in a weekend.

Consentmo DPDP compliance timeline for India

Does DPDP apply to your Shopify store?

Treat yourself as in scope if you:

  • Sell to people in India, or target the India market
  • Collect personal data (name, email, phone, address, order history, support chats, IP, device identifiers, marketing profiles)
  • Run cookies, pixels, analytics, ads, or personalization scripts on the storefront
  • Share personal data with apps, agencies, ESPs, CRMs, or processors outside India

DPDP is built around Data Principals (individuals) and Data Fiduciaries (organizations that determine purpose and means of processing).

On Shopify, you are typically the fiduciary for customer data you decide to collect and use. Apps and service providers often act as processors under your instructions, which still leaves you accountable for contracts, purpose limits, and oversight.

For a product-level overview of how Consentmo frames India on Shopify, see our India (DPDP) compliance page.

What “DPDP compliance” means on a real storefront

1. Clear notices before or at collection

Explain, in plain language:

  • What personal data you collect
  • The purpose of each use (orders, support, marketing, analytics, fraud checks)
  • How long you keep it (or the criteria you use)
  • Rights and how to exercise them
  • How to contact you (and any grievance channel you publish)

Checkout, account creation, newsletter popups, and quiz funnels are collection moments. A buried privacy policy link is weak notice design.

2. Consent that is free, specific, informed, unconditional, and clear

For processing that relies on consent (especially marketing and many tracking technologies):

  • Separate consent from unrelated terms
  • Tie consent to a purpose, not a vague “improve experience”
  • Record what the person agreed to, when, and how
  • Make withdrawal as easy as giving consent

Order fulfilment and other limited non-consent bases may apply in some cases. Do not stretch “necessary for the order” to cover every pixel and lookalike audience. When in doubt, isolate marketing consent.

3. Purpose limitation

If someone consented to order updates, that is not a free pass for partner advertising. Map each app and flow to a purpose. Kill orphan scripts.

4. Data Principal rights

Build a path for access, correction, erasure, and withdrawal requests. Shopify admin tools, support macros, and a privacy request page need a named owner and a response SLA. Logging matters as much as the form.

5. Processors and third parties

List every app that sees personal data: email, SMS, reviews, loyalty, helpdesk, analytics, ads. Update DPAs or vendor terms where needed. Know where data leaves India. A CMP does not rewrite your app stack for you.

6. Retention and deletion

Define how long you keep abandoned carts, ticket attachments, and marketing lists after last purchase. Align Shopify customer data, ESP lists, and warehouse exports. Deletion is a process, not a slogan.

7. Security and breach readiness

“Reasonable security safeguards” means access control, least privilege on staff accounts, MFA, vendor offboarding, and a written breach playbook: detect, contain, notify the Board and affected people on the timelines the Rules prescribe, document decisions.

8. Children and sensitive flows (if relevant)

If you sell to or market toward minors, treat age gates and parental consent as a separate workstream. Default adult fashion stores still need honest age claims if you collect DOB.

Cookie banner vs full DPDP: draw the line clearly

DPDP is broader than cookie compliance.

A consent management platform on Shopify is still one of the highest-leverage front-door controls because most stores leak personal data through scripts long before checkout.

A CMP / cookie banner helps with Still on you (policy, process, vendors)
Presenting choice before non-essential tags fire Full privacy / notice text and purpose mapping
Blocking analytics and ads until consent Handling access, correction, erasure tickets end to end
Logging consent events for accountability App inventory, contracts, cross-border transfers
Geotargeting India visitors with a stricter experience Retention schedules outside the browser
Preference center / withdraw on-site Security programme and breach notification ops
Supporting Consent Mode-style tag behaviour where configured Decisions on Consent Managers vs direct consent collection
Consentmo CMP coverage vs merchant DPDP responsibilities

Shopify merchant checklist before May 2027

Use this as a working backlog, not a guarantee of legal advice.

Now (implementation year kickoff)

  • Confirm whether you sell to or market to India
  • Export a full app and pixel inventory
  • Decide marketing vs necessary processing for each data use
  • Publish or refresh privacy notice language for India visitors
  • Turn on a consent layer that blocks non-essential scripts pre-consent for India traffic
  • Assign a rights-request owner and a simple ticket template

Before November 2026 (Consent Manager window)

  • Decide if you will rely only on direct storefront consent or also integrate registered Consent Manager patterns when the ecosystem matures
  • Standardize consent records (purpose, timestamp, version of notice, channel)
  • Stress-test withdraw flows on banner, account, and email preference center

Before May 2027 (core obligations)

  • Complete processor / vendor contract pass
  • Retention and deletion runbooks for Shopify + ESP + support tools
  • Security baseline: staff access, MFA, offboarding
  • Breach tabletop exercise with who calls whom
  • Evidence pack: policies, logs, DPIA-style notes if your counsel recommends them, training records

Practical next steps with Consentmo

  1. Enable or audit your consent banner for India geotargeting. Get started with the Consentmo Cookie Banner.
  2. Scan cookies and block marketing/analytics until opt-in where required using the Consentmo Tracker Manager.
  3. Enable consent logging and a path for privacy requests.
  4. Align banner copy with your actual privacy notice purposes.
  5. Walk the rest of the checklist with counsel or a privacy consultant for processor terms, retention, and security.

Prepare your Shopify store for DPDP compliance with Consentmo

Get ready for India’s DPDP requirements with region-aware consent, tracker control, consent logging, preference management, and privacy request tools built for Shopify.

Install Consentmo on Shopify →

DPDP rewards stores that treat personal data as an operating system, not a popup. Start with consent and scripts, then close the gaps a banner cannot touch.

This article is general information for Shopify merchants, not legal advice. Confirm obligations with qualified counsel for your facts and the latest government notifications.

Mariya Petrova
Growth & Product Marketing
With over 7 years of experience in advertising across agencies and e-commerce brands, Mariya has made marketing her core element. Today, she supports Consentmo users by guiding them through the realms of compliance, Shopify, and all things marketing.