The Complete Compliance Checklist for D2C and E-Commerce Brands
D2C and e-commerce brands in India need DPDP, GST/TCS, Legal Metrology, Consumer Protection E-commerce Rules and POSH compliance. Full checklist here.
D2C and e-commerce brands sit under some of the fastest-moving compliance areas in India right now: data protection, marketplace tax collection, and packaging disclosure rules, all layered on top of standard employer law.
Key facts at a glance
- Full DPDP Act substantive obligations (notice, consent, security safeguards, breach reporting) become enforceable from 13 May 2027, with penalties of up to Rs 250 crore per instance for security failures.
- The DPDP Consent Manager framework becomes operational on 13 November 2026.
- E-commerce operators must collect GST TCS on payments to sellers on their platform.
- Legal Metrology declarations (MRP, net quantity, manufacturer details) are mandatory on the online product listing, not just the physical package.
- Consumer Protection E-commerce Rules require clear seller details, country of origin, and grievance officer contact on every listing.
- A POSH Internal Committee is mandatory once a brand has 10 or more employees across offices and warehouses.
- FSSAI licensing applies to any D2C brand selling food or beverage products, regardless of whether it sells only online.
DPDP: the biggest compliance shift for D2C brands
Every D2C and e-commerce business runs on customer data: names, addresses, phone numbers, order history, and often payment details. This makes essentially every such brand a data fiduciary under the DPDP Act. While the Data Protection Board's provisions took effect immediately and the Consent Manager registration framework becomes operational on 13 November 2026, the substantive obligations that actually change how brands must collect and handle data (clear notice, verifiable consent, reasonable security safeguards, breach reporting, and honouring data-principal rights like access and erasure) become enforceable on 13 May 2027, with no stated grace period after that date. Brands should treat 2026 as the build-out window for consent flows, privacy notices and breach-response processes, not wait until the deadline.
GST and TCS on marketplace sales
Brands selling through marketplaces need to track two GST-related flows: their own output GST liability on sales, and TCS that the marketplace operator collects and deposits on their behalf. Reconciling TCS credit against monthly GST returns is a common operational gap, especially for brands selling across multiple marketplaces with different reporting formats. Brands selling direct-to-consumer through their own website handle GST directly, without the TCS layer, but still need to register once turnover crosses the applicable threshold.
Legal Metrology: declarations belong on the listing, not just the box
A frequently missed requirement is that mandatory packaging declarations, MRP, net quantity, manufacturer or importer details, and a consumer care contact, must appear on the online product listing itself, in addition to the physical package. Many D2C brands get the physical packaging right but omit these details from their website or marketplace listing, which is a distinct violation even if the product itself is correctly labelled.
Consumer Protection E-commerce Rules
These rules require e-commerce entities (including D2C brands selling through their own platforms) to disclose seller identity and contact details, country of origin for each product, a named grievance officer with response timelines, and clear return, refund and cancellation terms. The rules also prohibit specific unfair practices such as fake urgency indicators ("only 2 left") that do not reflect actual stock, and manipulated search or ranking results that favour a brand's own products without disclosure.
Compliance areas at a glance
| Area | Key requirement | Governing law |
|---|---|---|
| Data protection | Notice, consent, security safeguards | DPDP Act, 2023 (full force 13 May 2027) |
| Tax | GST registration and TCS reconciliation | GST law |
| Packaging | MRP, quantity, manufacturer details on listing | Legal Metrology (Packaged Commodities) Rules |
| Consumer protection | Seller details, grievance officer, fair listing practices | Consumer Protection (E-commerce) Rules |
| Food products | FSSAI licence/registration | Food Safety and Standards Act |
| Employer | POSH, EPF, ESI | Respective labour laws |
Standard employer compliance still applies
Behind the storefront, a D2C brand is also an employer running offices, warehouses and fulfilment operations. Once headcount reaches 10 employees, a POSH Internal Committee becomes mandatory; EPF applies at 20+ employees and ESI at 10+ employees, counting warehouse and logistics staff alongside office employees.
If you are not sure where your D2C or e-commerce brand stands on data protection compliance, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.
Sources
- Ministry of Electronics and Information Technology (DPDP) - meity.gov.in
- GST Council / gst.gov.in
- Department of Consumer Affairs (Legal Metrology, E-commerce Rules) - consumeraffairs.nic.in
- FSSAI - fssai.gov.in
- EPFO - epfindia.gov.in
- ESIC - esic.gov.in
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- Does the DPDP Act apply to D2C and e-commerce brands?
- Yes. Any brand collecting customer data such as name, address, phone number or payment details through its website or app is a data fiduciary under the DPDP Act, and full substantive obligations become enforceable from 13 May 2027.
- What penalty can a D2C brand face under DPDP for a data breach?
- Penalties for failing to implement reasonable security safeguards can reach up to Rs 250 crore per instance under the DPDP Act, making data security a board-level risk, not just an IT task.
- Does GST TCS apply to D2C brands selling through marketplaces?
- Yes, e-commerce operators are required to collect tax at source (TCS) on payments made to sellers on their platform, and D2C brands selling through marketplaces like Amazon or Flipkart should reconcile this TCS credit against their GST liability.
- What is the Legal Metrology declaration requirement for e-commerce?
- Pre-packaged goods sold online must carry mandatory declarations, including MRP, net quantity, manufacturing/import details and consumer care contact, on the product listing itself, not just the physical package, under the Legal Metrology (Packaged Commodities) Rules.
- What do the Consumer Protection E-commerce Rules require?
- These rules require e-commerce entities to display seller details, country of origin, grievance officer contact information, and clear return/refund/cancellation policies, and prohibit unfair trade practices like fake urgency claims or manipulated search rankings.
- Does POSH apply to a D2C brand's warehouse and office staff?
- Yes, a POSH Internal Committee is mandatory once the brand has 10 or more employees across its offices and warehouses combined, the same threshold that applies to any employer.
- Do D2C brands need FSSAI if they sell food or beverage products?
- Yes, any D2C brand manufacturing, packaging or selling food or beverage products needs an FSSAI licence or registration depending on turnover, in addition to its general e-commerce compliance obligations.
Check your status
DPDP Gap Assessment
A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.