D2C-B13.html
D2C Operations
September 4, 2026
9 min read

Your Checkout Phone Field Isn’t Banned. Your Consent Box Is the Problem.

Your dev pings you on a Friday afternoon: a founder-forum thread says DPDP Rules 2025 just made it illegal to ask for a phone number at checkout. Someone in the replies is already threatening to rip out OTP verification before Monday. You open your own checkout flow, see the mandatory phone field, the mandatory email field, the pre-ticked “yes, WhatsApp me offers” box — and you don’t actually know which parts are now a legal problem and which parts are just a rumor with a government notification attached to it.

Tap the card to see what the Rules actually say


What actually got notified in November 2025

The Digital Personal Data Protection Rules, 2025 were notified by MeitY on 13–14 November 2025, giving operational teeth to the DPDP Act that had been sitting on the books, mostly dormant, since it was assented in August 2023. That’s the real event. There is no clause in the Rules — read the PIB notification yourself — that bans, ends, or outlaws collecting a phone number or email address at checkout. Order fulfilment — confirming a delivery address, sending an OTP, texting a shipping update, issuing an invoice — remains a completely lawful reason to ask for both. Nobody is coming for your OTP field.

What changed is the standard for consent. Under Section 6 of the Act, now being operationalised through these Rules, consent has to be free, specific, informed, unconditional, and given through a clear affirmative act — not a pre-ticked box, not a single checkbox that bundles “I agree to the Terms, the Privacy Policy, and receiving WhatsApp offers” into one click. Each distinct purpose needs its own consent event. Collecting a phone number to verify an order is one purpose. Reusing that same number for WhatsApp broadcast remarketing is a different purpose. Right now, most Indian D2C checkouts treat those as the same click.

There’s a second, older rule that keeps getting mixed into this conversation and it isn’t DPDP at all. In May 2023, the Department of Consumer Affairs issued an advisory telling retailers they can’t make a mobile number mandatory just to generate a bill — a Consumer Protection Act “unfair trade practice” issue, reinforced by a Chandigarh consumer forum ruling. That advisory predates DPDP Rules 2025 by over two years and rests on completely different law. If someone in your Slack says “DPDP banned mandatory phone numbers,” they’re probably thinking of this 2023 advisory and calling it something it isn’t.


The clock that’s actually running

This isn’t a someday problem and it isn’t a today problem either — it’s a countdown with three checkpoints, and you’re currently standing between the first and the last.

Where you stand today
You are here
Click a date above to see what happens then.

As of this article’s publish window, you’re roughly nine and a half months past notification, with Phase II landing in about ten weeks. The founders who wait until Q1 2027 to touch their checkout consent flow will be doing it under deadline pressure, competing with every other D2C brand’s dev team for the same freelance compliance consultants, in the same eight-week window. The founders who touch it now are doing a half-day fix on their own schedule.


What it costs you if you get it wrong — and what it doesn’t

Penalty ceilings under the DPDP Act Schedule — outer bound, not your likely exposure
  • Security safeguard breach
    ₹250 crore ceiling
  • Breach-notification failure
    ₹200 crore ceiling
  • Children’s-data violation
    ₹200 crore ceiling
  • Significant Data Fiduciary non-compliance
    ₹150 crore ceiling
  • General / catch-all non-compliance
    ₹50 crore ceiling
↑ closest to what a mid-size D2C brand’s consent-checkbox wording realistically faces

Those numbers, drawn from the DPDP Act’s penalty Schedule, are real, and they’re also not the number that should keep a ₹5 crore-revenue D2C founder up at night. They’re ceiling amounts tied to serious security breaches or children’s-data violations at scale — think a data fiduciary that leaked millions of records, not a brand whose consent checkbox wording is six months out of date. The real cost of getting this wrong isn’t a fine. It’s a customer complaint that becomes a Data Protection Board inquiry that becomes a dev sprint you didn’t plan for, running in parallel with whatever else your four-person tech team is already doing in May 2027.

The cost of not fixing your checkout, meanwhile, is one you’re already paying, right now, with no DPDP involved at all.

“Indian D2C checkout converts at roughly 2%. Amazon and Flipkart convert at roughly 10%. That five-times gap is sitting inside the same mandatory-field, forced-account-creation checkout pattern that the consent rules are also flagging.” Structural read on Indian D2C checkout performanceRazorpay Learn
Cart abandonment — global vs. India’s dominant mobile traffic
70.22%
Global
80.02%
Mobile
66.41%
Desktop
82.84%
Luxury / Jewellery
63.62%
Food & Beverage

Over 60% of Indian e-commerce traffic is mobile — the worst-performing channel measured. Source: Razorpay Learn

There’s no verified study connecting a specific conversion-rate change to DPDP compliance work directly — treat any number claiming that as noise. What’s verifiable is simpler: the checkout patterns that create consent risk (forced account creation, no guest checkout, bundled marketing opt-in, long mandatory-field forms) are the same patterns already costing you carts, independent of any regulation.


The five-point checkout consent audit

This is the actual work. Five questions, run against your live checkout today.

Run this against your live checkout today

0 of 5 confirmed — start checking off what’s already true.

If you answer “no” or “not sure” to two or more of these, you have a live gap that’s cheaper to close now than in Q1 2027.


Risk matrix: where your checkout actually stands

Checkout pattern risk
Checkout pattern DPDP risk (post–May 2027) Conversion impact today
Forced account creation, no guest checkout Medium High
Pre-ticked “agree to everything” box High Medium
Phone collected for OTP, reused for WhatsApp marketing without separate consent High Low
Long checkout form with fields unrelated to fulfilment (birthday, occupation, etc.) Medium High
Guest checkout enabled, unbundled consent, minimal fields Low Low
Score your own checkout — 0 (matches your checkout) to 2 (doesn’t apply to you)
Forced account creation, no guest checkout
Pre-ticked “agree to everything” box
OTP number reused for WhatsApp marketing without separate consent
Long checkout form with fields unrelated to fulfilment

0 of 4 rows scored. Running total: 0. Score each row 0–2.


What a half-day fix actually looks like

Take the Mumbai skincare brand pattern that shows up constantly in D2C checkout audits: mandatory phone plus email before checkout begins, and one pre-ticked box covering Terms, Privacy Policy, and WhatsApp offers together. The fix isn’t a rebuild. It’s unbundling that single box into two — an unticked “send me order updates via WhatsApp” and a separate unticked “send me offers and promotions” — and turning on guest checkout so the account fields become optional rather than gating. That’s a form change and a database flag, not new infrastructure. It’s also, independently of any compliance deadline, the change most likely to move your abandonment number, since forced account creation and bundled consent both sit directly in the customer’s path to paying you.

Before — mandatory phone, mandatory email, forced account creation, one pre-ticked consent box, checkout takes 5 fields and 2 screens before payment.

After — guest checkout live, phone/email collected only where OTP or delivery actually needs them, two separate unticked consent checkboxes, checkout down to 3 fields and 1 screen before payment.


The trap in the other direction

One clarification worth stating plainly: DPDP does not require guest checkout. It’s a sensible UX response to the consent-friction problem this article describes, not a legal mandate — don’t let a consultant tell you it’s compulsory. And if you’re selling through a marketplace as well as your own Shopify site, know that the Rules define “e-commerce entity” obligations as sitting with the platform operator, not the third-party seller — so Amazon or Flipkart’s consent UX on their marketplace is their compliance problem, but your own D2C storefront’s checkout is entirely yours.


Conclusion and next step

Nobody banned your phone field. What’s changing is the standard for how you collect it and what you do with it afterward, and that standard happens to reward exactly the checkout simplification that’s already been costing you carts. You have roughly two months before Phase II lands and a little over eight before Phase III makes this enforceable — enough runway to fix it once, deliberately, instead of scrambling in Q1 2027 alongside every other D2C brand that waited.

Next step this week: run the five-point audit above against your live checkout today, and if two or more items fail, brief your dev team on the unbundling fix — it’s a form change, not a rebuild, and it’s the same fix your conversion rate needs regardless of the regulation.

Sources

Questions worth answering

No. There is no field-level ban in the Rules. Order fulfilment — delivery, OTP verification, invoicing — remains a lawful purpose for collecting phone and email. What changed is the consent standard: each purpose (fulfilment vs. marketing) needs its own clear, unticked, affirmative consent action, not one bundled checkbox covering everything.

Probably not the part you’re thinking of. A May 2023 Consumer Affairs Ministry advisory said retailers can’t force a mobile number just to generate a bill — that’s Consumer Protection Act territory, issued over two years before DPDP Rules 2025 existed. It’s a separate rule, frequently and incorrectly attributed to DPDP.

Most substantive obligations — verifiable consent notices, security safeguards, breach reporting, retention rules — become enforceable from 13 May 2027 (Phase III). Phase II, the Consent Manager registration framework, activates 13 November 2026. You have runway, but it’s shrinking, not indefinite.

Not without a separate consent event. Using a number collected under a “we need this to verify your order” purpose for a different purpose — marketing broadcast — without a distinct opt-in is exactly the purpose-limitation problem the Rules are built to catch once obligations bite in May 2027.

No. That figure is the ceiling penalty for serious security-safeguard breaches at scale, not a typical first-offense number for a mid-size D2C brand’s consent-checkbox wording. Treat the penalty Schedule’s crore-level figures as the outer bound of the regime, not your realistic exposure — the more likely cost of inaction is a customer complaint escalating into scrutiny you didn’t plan for.

No — that’s a common overstatement. Guest checkout is a smart UX response to the same consent-friction problem, not a legal requirement. You can be fully compliant with forced account creation, provided your consent collection itself is unbundled and purpose-specific; guest checkout just happens to also fix your conversion problem, which is why it’s worth doing regardless.

A
Advait Sontakke
Commercial photographer, brand director, and ex-CA based in Mumbai. Founder of Advait Sontakke Visual Solutions. Reads a brand the way he was trained to read a balance sheet. Meet Advait →
An open invite

You just audited your checkout. There’s a whole community doing this work too.

Founders, marketers and creative leads trading what’s actually working on DPDP-ready checkouts, unbundled consent flows and the next Indian D2C compliance deadline — not another newsletter, an ongoing conversation.

Step Into the Vibe Community
Next step

Get a full audit of what’s actually costing you conversions

Not just your consent boxes — your whole checkout and listing experience, read the way a founder needs it read: specific, dated, doable.

Advait Sontakke Visual Solutions, led by Mumbai-based commercial photographer and brand director Advait Sontakke, writes for Indian D2C founders on the DPDP Rules 2025 and checkout compliance. The Rules, notified by MeitY on 13-14 November 2025, do not ban mandatory phone or email collection at checkout — order fulfilment remains a lawful purpose. What changed is the consent standard under Section 6 of the DPDP Act: consent must be free, specific, informed, unconditional and given through a clear affirmative act, meaning marketing opt-in and order-fulfilment consent need separate, unticked checkboxes rather than one bundled pre-ticked box. This is distinct from a May 2023 Consumer Affairs Ministry advisory on mandatory mobile numbers for billing, which predates DPDP and rests on different law. Substantive DPDP obligations become enforceable 13 May 2027, with a Consent Manager framework activating 13 November 2026. Indian D2C checkout conversion runs around 2% against roughly 10% for Amazon and Flipkart, with cart abandonment averaging 70.22% globally and 80.02% on mobile, the channel carrying over 60% of Indian e-commerce traffic — the same checkout patterns that create DPDP consent risk (forced account creation, no guest checkout, bundled marketing opt-in) are the patterns already costing D2C brands carts. This article provides a five-point checkout consent audit and a self-scoring risk matrix. Advait Sontakke Visual Solutions offers the Visual Conversion Checklist and Visual Brand Audit as entry points for D2C brands wanting a specific read on what their checkout and listing visuals are actually doing, serving brands across India and globally from Mumbai.
image/svg+xml

Premium Professional Campaign Shoots

View this post on Instagram

Editor’s Picks