Consult Now

Business & Compliance

E-Commerce Legal Compliance Checklist For Indian Businesses

This article is also available in: हिन्दी | मराठी

Feature Image for the blog - E-Commerce Legal Compliance Checklist For Indian Businesses

E-commerce businesses in India must navigate a comprehensive regulatory landscape covering business registration, tax mandates (GST, TCS, TDS), consumer protection standards, digital data privacy laws, payment processing, product licences, and enforceable contracts. Compliance obligations vary significantly based on your business model (inventory vs. marketplace), product categories, and target scale.

Setting up and operating an e-commerce platform in India requires adherence to statutory requirements across multiple operational areas. Use this full checklist to review your business setup:

  • Business & Tax Registration: Formal corporate entity incorporation, PAN, TAN, and Goods and Services Tax (GST) registration.
  • E-Commerce & Consumer Compliance: Statutory platform disclosures, nodal contact details, and mandatory grievance officer appointments under the Consumer Protection (E-Commerce) Rules, 2020.
  • GST & Invoicing: Tax Collection at Source (TCS) handling, Tax Deducted at Source (TDS), e-invoicing, and HSN/SAC code mapping.
  • Payments, Refunds & Cancellations: Integration with RBI-authorized payment aggregators, tokenization, clear auto-reversal timelines, and transparent cancellation workflows.
  • Data Protection & Privacy: Granular consent mechanisms, privacy notices, data security protocols, and breach reporting under the Digital Personal Data Protection (DPDP) Act, 2023 and DPDP Rules, 2025.
  • Product-Specific Licences: Category-based approvals such as FSSAI for food items, Legal Metrology (LMPC) for pre-packaged goods, and BIS certifications for electronics.
  • Advertising & Marketing: Adherence to the Advertising Standards Council of India (ASCI) code, Central Consumer Protection Authority (CCPA) guidelines on misleading ads, and influencer endorsement rules.
  • Intellectual Property (IP): Trademark filings, copyright protection for media, and intermediary take-down protocols for counterfeit prevention.
  • Business Contracts: User-facing policies (Terms & Conditions, Privacy Policy, Return Policy) and vendor/B2B agreements (Vendor Onboarding, Logistics SLAs, NDAs).

Also Read: How to claim Intellectual property rights

Primary Governing Statutes:

  • Consumer Protection Act, 2019 & Consumer Protection (E-Commerce) Rules, 2020
  • Central Goods and Services Tax (CGST) Act, 2017 & Income Tax Act, 1961
  • Digital Personal Data Protection (DPDP) Act, 2023 & DPDP Rules, 2025
  • Information Technology Act, 2000 (Section 79 Intermediary Guidelines)

What Business Registration and Tax Compliance Is Required?

Before listing products or collecting online payments, an e-commerce venture must establish its legal structure and register with tax authorities.

Appropriate Business Structure

Choose a legal structure based on funding requirements, liability exposure, and operational scale:

  • Private Limited Company (Pvt Ltd): Preferred for scaling platforms, raising venture capital, and limiting shareholder liability.
  • Limited Liability Partnership (LLP): Offers operational flexibility with limited partner liability; ideal for co-founded boutique platforms.
  • Sole Proprietorship / Partnership: Common for micro-businesses, though it offers no personal asset protection.

PAN and TAN Registration

  • PAN (Permanent Account Number): Mandatory for entity bank account opening and corporate tax filing.
  • TAN (Tax Deduction Account Number): Required to deduct Tax Deducted at Source (TDS) on vendor payouts, software licenses, and employee compensation.

GST Registration Framework

Under Section 24 of the CGST Act, 2017, traditional rules mandated GST registration for all e-commerce suppliers regardless of turnover. However, per CBIC Notification No. 34/2023-Central Tax, small e-commerce sellers with aggregate turnover below the standard threshold (₹40 Lakhs for goods / ₹20 Lakhs for services; ₹20 Lakhs / ₹10 Lakhs in Special Category States) are exempt from mandatory GST registration, provided they:

  • Make only intra-state supplies (no inter-state sales).
  • Operate in only one State or Union Territory.
  • Hold a valid PAN and generate an enrolment number on the GST portal prior to selling.

TDS and TCS Requirements

  • Tax Collection at Source (TCS - Section 52, CGST Act): Marketplace operators facilitating sales must collect 1% TCS (0.5% CGST + 0.5% SGST, or 1% IGST) on the net value of taxable supplies made by third-party sellers.
  • Tax Deducted at Source (TDS - Section 194O, Income Tax Act): E-commerce operators deducting payment on behalf of resident sellers must withhold 1% TDS on the gross transaction amount.

What E-commerce Rules Apply to Online Businesses?

The Consumer Protection (E-Commerce) Rules, 2020 enforce specific operational mandates on all digital commerce entities operating in or selling to consumers in India:

  • Model Classification: Businesses must declare whether they operate as an Inventory-based Model (owning stock directly) or a Marketplace Model (providing an electronic platform for independent sellers).
  • Seller Disclosures: Marketplace operators must display key seller details directly on product listing pages, including legal entity names, principal geographic addresses, customer service numbers, and seller ratings.
  • Product and Price Disclosures: Every product listing must show the Maximum Retail Price (MRP) with a line-item breakdown of taxes, delivery charges, and mandatory details such as the Country of Origin.
  • Grievance Redressal Mechanism: Platforms must prominently display the name, designation, and contact details of a appointed Grievance Officer. The platform must send an acknowledgment receipt within 48 hours and resolve consumer complaints within 1 month of receipt.
  • Unfair Trade Practice Restrictions: E-commerce operators cannot manipulate product search algorithms to privilege specific sellers, generate fake consumer reviews, or charge discriminatory cancellation fees.

What Consumer Protection Requirements Must E-commerce Businesses Follow?

The Consumer Protection Act, 2019 prohibits unfair trade practices and protects consumer rights in digital transactions.

  • Product & Service Disclosures: Descriptions must match the actual product specifications, including dimensions, materials, color shades, weight, and usage instructions.
  • Clear Fee Structures: All fees, including convenience fees, shipping costs, and assembly charges, must be disclosed prior to checkout. Unannounced fees added at the payment step violate consumer norms.
  • Warranties & Guarantees: Manufacturers or seller-backed warranty details, including claim procedures and service center contact info, must be stated upfront.
  • Non-Discriminatory Refunds: Platforms cannot impose higher penalties for order cancellation than the actual operational loss incurred.

What Privacy and Data Protection Compliance Does an E-commerce Business Need?

With the notification of the Digital Personal Data Protection (DPDP) Rules, 2025 enforcing the DPDP Act, 2023, e-commerce businesses operating as Data Fiduciaries must align their digital operations with statutory data privacy requirements:

  • Consent & Standalone Notices (Rule 3): Before collecting personal data (e.g., name, delivery address, phone number, payment details), platforms must issue an itemized, standalone privacy notice detailing what data is collected and its exact processing purpose. Notices must be available in English and 22 languages specified in the Eighth Schedule to the Constitution.
  • Customer Rights Management: Users (Data Principals) hold statutory rights to review, correct, update, or demand complete erasure of their personal data once the processing purpose is completed or consent is withdrawn.
  • Data Security & Technical Measures (Rule 6): Platforms must implement technical safeguards, including end-to-end data encryption, access controls, activity log tracking, and secure database architecture.
  • Data Breach Handling (Rule 7): In the event of a personal data breach, Data Fiduciaries must notify the Data Protection Board of India (DPB) and affected users without undue delay.
  • Data Retention & Minimal Storage Limits: Personal data must not be stored indefinitely. Platforms must configure automated data purging policies when a customer closes their account or remains inactive for a statutory period.

What Licences Are Required to Sell Products Online?

There is no single universal e-commerce licence in India. Required approvals depend on the product vertical:

Industry / Product Vertical

Mandatory Licence / Regulatory Compliance

Food & Beverages

FSSAI Registration or Licence under the Food Safety and Standards Act, 2006. Marketplace platforms require an FSSAI Central Licence.

Pre-Packaged Goods

Legal Metrology (LMPC) Registration under the Packaged Commodities Rules, 2011, governing mandatory label disclosures such as MRP, net quantity, and manufacturer/importer address.

Drugs & Cosmetics

Retail Drug Licence (Form 20/21) for pharmacy items; CDSCO approval and manufacturing compliance for cosmetic lines.

Electronics & Hardware

BIS Certification (Bureau of Indian Standards) and EPR (Extended Producer Responsibility) authorizations for e-waste management.

Imported Physical Goods

Importer Exporter Code (IEC) issued by the Directorate General of Foreign Trade (DGFT).

What Payment, Refund and Cancellation Rules Apply?

Online checkout security and funds flow are governed by the Reserve Bank of India (RBI) and the Consumer Protection (E-Commerce) Rules, 2020:

  • Payment Collection Architecture: Platforms must partner with RBI-authorized Payment Aggregators (PAs) and enforce strict PCI-DSS compliance. Storing raw debit/credit card details or CVVs on merchant databases is prohibited; tokenization protocols must be used.
  • Failed Transaction Reversals: In cases of transaction failure where funds are debited from the customer's account, automated reconciliation mechanisms must reverse the funds back to the original source within RBI-mandated settlement timelines (typically T+1 days).
  • Invoicing & Tax Details: Tax invoices showing HSN/SAC codes, itemized GST rates (CGST, SGST, IGST), platform details, and transaction numbers must be issued for every successful order.
  • Refund Processing Channels: Refunds must be remitted back to the customer’s original payment instrument unless the customer explicitly consents to receive store credit or wallet balances.

To protect against legal liability, define operational terms, and maintain enforceability under the Indian Contract Act, 1872, deploy this core documentation stack:

  • Terms and Conditions (Terms of Use): The primary binding electronic agreement establishing site access rules, user eligibility, payment conditions, platform liability caps, and jurisdiction for dispute resolution.
  • Privacy Policy: A mandatory document under the DPDP Act, 2023 and IT Act, 2000 detailing data processing scopes, cookie usage, analytics sharing, and customer privacy rights.
  • Shipping & Delivery Policy: Explicit rules establishing estimated delivery timelines, logistics coverage areas, shipping fee calculation rules, and risk-of-loss transfer points.
  • Return, Exchange & Refund Policy: Clear instructions detailing return windows (e.g., 7 days from delivery), product condition checks, pickup arrangements, and refund settlement timelines.
  • Vendor / Merchant Agreements: B2B contracts for marketplaces outlining platform commission percentages, listing quality standards, delivery SLAs, and indemnification against counterfeit goods.
  • Non-Disclosure Agreements (NDAs): Essential agreements protecting proprietary algorithms, vendor lists, software source code, and business models when engaging contractors or software developers.

What IP and Advertising Compliance Should E-commerce Businesses Follow?

Protecting intellectual property and adhering to truth-in-advertising guidelines prevents regulatory action and legal claims.

  • Trademark Registration: Register brand names, trade dress, and platform logos across relevant classes under the Trade Marks Act, 1999 to establish legal ownership and prevent counterfeiters from misusing brand identifiers.
  • Copyright Compliance: Ensure website graphics, custom layout code, video content, and original product copy are protected under the Copyright Act, 1957. Using uncredited stock imagery or third-party content without explicit licensing constitutes infringement.
  • Safe Harbour Intermediary Protection: Marketplace platforms claiming safe harbour immunity under Section 79 of the Information Technology Act, 2000 must maintain a Notice-and-Takedown Protocol. Infringing listings or counterfeit products must be removed upon receiving valid rights-holder notifications.
  • Truthful Advertising & Influencer Rules: Under CCPA and ASCI rules, marketing campaigns must avoid deceptive product claims. Paid media collaborations and influencer promotions must carry clear, visible disclosures.

What Changes for Marketplace vs. Inventory-Based E-commerce?

Legal responsibility, tax liability, and contract structures differ depending on your e-commerce operational model:

Compliance Area

Marketplace Model

Inventory-Based Model

Inventory Control

Owned by independent third-party sellers.

Owned and stocked directly by the e-commerce business.

Seller Onboarding

Primary focus: KYC verification, vendor onboarding, and seller agreements.

Not applicable; business sources inventory directly via supply contracts.

TCS / TDS Withholding

Mandatory: Collects 1% TCS under GST and deducts 1% TDS (Section 194O) on seller payouts.

Standard: Collects and remits standard GST on direct sales to end consumers.

Product Quality & Defect Responsibility

Shared/role-dependent; platform acts as an intermediary under Section 79 of the IT Act.

Direct Liability: Primary responsibility for product defects, safety, and warranties.

Consumer Obligations

Facilitates platform-level dispute management between customer and seller.

Direct legal obligation to fulfil orders, issue refunds, and honour warranties.

What Are the Most Common E-commerce Compliance Mistakes?

Avoiding these frequent compliance pitfalls can prevent regulatory fines, platform takedowns, or legal disputes:

  • Missing Mandatory Disclosures: Failing to publish the Grievance Officer's details, legal entity address, or Country of Origin information on product pages.
  • Incorrect GST Handling: Operating without required GST registrations when shipping across state borders, or failing to deduct and deposit TCS on marketplace seller payouts.
  • Vague Refund and Return Policies: Relying on ambiguous "no-refund" terms that contradict mandatory return rights established under consumer protection regulations.
  • Misleading Product Photography or Claims: Publishing edited product images that distort actual dimensions or colors, or making unverified health or functional claims.
  • Inadequate Data Privacy Frameworks: Using generic, copy-pasted privacy notices that fail to meet standalone notice and explicit consent standards under the DPDP Act, 2023.
  • Selling Regulated Items Without Licences: Distributing packaged food items, cosmetics, or electronic products without obtaining valid FSSAI, LMPC, or BIS approvals.
  • Unlicensed Third-Party Content Usage: Copying product images, banner graphics, or descriptive text directly from competitors or brand websites without licensing.

Explore More Legal Guides

Exiting a contract without paying damages is possible when the termination is supported by a valid contractual or legal ground. Mutual rescission, termination clauses, material breach, frustration, fraud, or misrepresentation may allow a lawful exit. However, wrongful termination, failure to follow notice requirements, or abandoning obligations without justification can trigger compensation claims. Before terminating, carefully review the agreement, document the grounds, follow prescribed procedures, and seek legal advice for complex or high-value contracts.

Disclaimer: This blog is for informational purposes only. If you need legal consultation, please contact an experienced Corporate Lawyer.

Frequently Asked Questions

Q1. Is GST registration mandatory for every e-commerce business?

Not for all sellers. Under CBIC Notification No. 34/2023-Central Tax, small intra-state sellers with an aggregate turnover under the standard threshold (₹40 Lakhs/₹20 Lakhs) are exempt from mandatory GST registration, provided they operate in a single State and register via PAN on the GST portal. However, inter-state sellers and marketplace operators must obtain GST registration.

Q2. Is a privacy policy mandatory for an e-commerce website?

Yes. Publishing a comprehensive Privacy Policy is required under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000. The policy must outline what customer data is collected, processing scopes, retention timelines, and user privacy rights.

Q3. What licences are required to sell products online?

Licensing requirements depend on the product category. Common examples include an FSSAI Licence for food items, Legal Metrology (LMPC) Registration for pre-packaged commodities, BIS Certification for regulated electronics, and an Importer Exporter Code (IEC) for imported goods.

Q3. What are the main e-commerce rules in India?

Key frameworks include the Consumer Protection (E-Commerce) Rules, 2020, Section 79 of the Information Technology Act, 2000 (Intermediary Rules), the Digital Personal Data Protection Act, 2023, CGST Act, 2017 (TCS provisions), and the Legal Metrology Rules, 2011.

Q4. Is FSSAI required to sell food online?

Yes. Any entity manufacturing, packaging, storing, or listing food products online must hold a valid FSSAI Licence or Registration under the Food Safety and Standards Act, 2006. E-commerce platforms facilitating food distribution require an FSSAI Central Licence.

About the Author
Adv. Jyoti Dwivedi Tripathi
Adv. Jyoti Dwivedi Tripathi Writer | Researcher View More

Jyoti Dwivedi Tripathi, Advocate, completed her L.L.B from Chhatrapati Shahu Ji Maharaj University, Kanpur, and her LL.M from Rama University, Uttar Pradesh. She registered with the Bar Council of India in 2015 and specialised in IPR as well as civil, criminal, and corporate law. Jyoti writes research papers, contributes chapters to pro bono publications, and pens articles and blogs to break down complex legal topics. Her goal through writing is to make the law clear, accessible, and meaningful for all.

My Cart

Services

Sub total

₹ 0