DPDPA consent and data rights for Indian Shopify stores
Consenfy gates tracking against what the shopper actually chose, and keeps an uneditable, notice-stamped record of it in your own Shopify store.
Free for everything the law requires. Pro is $7/month. Not legal advice.
What just got recorded
S6(10)Try it. This is the decision logic, running in your browser. Nothing is sent anywhere.
Built against the Digital Personal Data Protection Act, 2023 — not a GDPR checklist with Indian labels stuck on.
Choices run through Shopify's Customer Privacy API, so managed pixels are actually gated. Essential processing stays locked on — checkout is not a cookie toggle.
Every decision written once, never edited, stamped with the notice version on screen at the time. Emails and IPs stored as keyed hashes, not plain text.
A storefront form covering all six rights, feeding a queue you can work. Erasure logs its own proof.
Publishing a change creates a new immutable version, so past consents stay tied to the wording actually shown.
Record what happened and keep a timeline. It won't decide whether an incident is notifiable, and it can't file with the Board for you.
Reads your settings and states what applies to you. Where we haven't asked, it says so rather than assuming.
Compliance records go into your own Shopify store as metafields and metaobjects, under a namespace reserved to the app. We read and write them through Shopify's API — we don't keep a second copy of your customers.
If you never pay, you can still collect consent, enforce it, keep the evidence, and answer every rights request — including erasure. You pay only when doing it by hand starts to hurt.
Free
$0 forever, for the part that keeps you compliant
Consenfy Pro
$7 / month
Submission is in progress. We won't fake an "Install now" button that goes nowhere — here's where things actually stand.
Consenfy is going through Shopify's app review. Once approved, you'll install it directly from the Shopify App Store. Shopify has to separately approve Protected Customer Data access before the app can show some customer fields by name — that's their rule, not a Consenfy paywall.
Free plan on install. Pro is billed through Shopify at $7 USD / 30 days.
In ordinary English, with citations. Not a substitute for the Gazette text or for a lawyer.
There is no revenue, size, or order-volume threshold in the Act. S3(a) covers digital data collected in India, including paper you later type in. S3(b) reaches processing outside India when it serves people in India.
No "accept or you can't browse" wall.
Not one box for analytics, ads and profiling together.
The notice was shown before they decided.
Not bundled inside T&C acceptance.
Silence and scrolling are not a yes.
They acted on purpose. Pre-ticks fail.
There is no GDPR-style legitimate-interest test — S7 is a closed list. Taking the order, charging and shipping run on S7(a), so don't ask permission for those.
Only grievance has a number: respond within no more than 90 days Rule 14(3). Access, correction and erasure have no numeric deadline in the Rules — erasure is "upon receipt". Any tool printing a GDPR-style "30 days" against those is describing a different statute.
| Breach | Section | May extend to |
|---|---|---|
| Reasonable security safeguards | S8(5) | ₹250 crore |
| Failure to notify a breach | S8(6) | ₹200 crore |
| Children's-data obligations | S9 | ₹200 crore |
| Significant Data Fiduciary duties | S10 | ₹150 crore |
| Any other provision — including consent and notice | n/a | ₹50 crore |
S33(2) requires the Board to weigh mitigation and how promptly you acted. Records are evidence you tried; they are not a shield on their own.
Notice, consent, rights and penalties defined.
DPDP Rules, 2025 and the Board are live. Breach intimation already applies.
Phased in by notification. The record you'll want then is the one you start keeping now.
Consenfy covers consent on your storefront. Marketplace and quick-commerce checkouts aren't yours to collect for; WhatsApp and SMS lists built elsewhere are still your consent problem, plus India's DLT rules. Security, breach reporting and erasure follow the data across every system you hold it in. Anyone selling a banner as whole-business compliance is overselling it.
Usually not. Most banners record a click without gating trackers, and most are GDPR tools whose categories don't map onto this Act. The harder gap is S6(10): an "accepted" flag with no notice version is weak proof.
It must not, and Consenfy locks essential processing on. Orders, payment, and delivery run on S7(a), not on cookie consent.
A formal DPO is an S10 duty for a notified Significant Data Fiduciary. Almost every store instead needs a published contact person under S8(9) who can answer questions about processing. Those are different jobs.
No. It can collect valid consent, enforce known trackers, keep evidence, and run a rights queue. It can't decide what is lawful for your business, write policies you can rely on without review, or take responsibility for the rest of your stack. You remain the Data Fiduciary.
Compliance records live in your store's reserved namespace, inside your own Shopify store — not ours. Shopify's uninstall/redact webhooks are how the session data tied to your install is removed from our host. Deleting the app does not rewrite the Act.
No. DPDPA has one uniform category of personal data, no data-portability right, no legitimate-interest balancing test, and only one numeric grievance ceiling. An app that offers "portability" or "legitimate interest" as if they were Indian-law features is describing a different statute.