If your website collects names, email addresses, phone numbers or payment details, data protection law applies to you. For Indian website owners that means India's Digital Personal Data Protection Act, 2023 (the DPDP Act), and the EU's General Data Protection Regulation (GDPR) as well if you offer goods or services to people in the EU. This guide explains in plain terms what each law asks of a small website, what a good privacy policy contains, and how data protection affects your domain's WHOIS record.
The DPDP Act covers personal data you collect in digital form in India, and it also reaches offerings to people in India from abroad; GDPR can apply to you if you target people in the EU. Both expect you to collect only what you need, tell people why in a clear privacy notice, get valid consent where it is your basis, keep data secure and honour requests to access or delete it. For .in domains, personal registrant details are not shown in public WHOIS; this is free and automatic. This article is general information, not legal advice.
Data protection law depends on your business, your customers and where they are. Use this guide to understand the basics, and ask a qualified lawyer before you rely on it for your own compliance.
1. Which law applies to your website
| Law | Who it protects | When it applies to you |
|---|---|---|
| DPDP Act 2023 (India) | Individuals whose personal data you process in digital form | You process personal data in India, or you offer goods or services to people in India from outside |
| GDPR (EU) | People in the EU | You are established in the EU, or you offer goods or services to people in the EU or monitor their behaviour |
| Other laws | For example California's CCPA or Canada's PIPEDA | You target customers in those places |
An Indian shop that sells only within India mainly needs to think about the DPDP Act. If the same shop ships to Germany, prices in euros or runs ads aimed at EU visitors, GDPR can apply too. Simply being reachable from the EU is usually not enough on its own.
The DPDP Rules, which set out how the Act works in practice, were notified in November 2025. Most obligations phase in over the following 18 months, so now is a good time to get your site in order.
2. The principles both laws share
Although the details differ, the DPDP Act and GDPR rest on the same ideas:
Under the DPDP Act you are a data fiduciary, and the person is the data principal. Under GDPR the same roles are called controller and data subject.
3. Practical steps for a small website
- List the data you collect.Contact forms, sign-ups, orders, comments, analytics and chat widgets all collect personal data. Note what each collects and why.
- Cut what you don't need.Remove optional form fields and plugins you don't use.
- Get consent properly.Use an unticked checkbox or a clear action, separate from your terms, and keep a record of it. Pre-ticked boxes are not valid consent.
- Publish a privacy notice.Link it from every page footer and from each form (see section 4).
- Secure the site.Use HTTPS, keep your CMS and plugins updated, use strong passwords with two-factor login, and restrict who can see customer data.
- Check your service providers.Payment gateways, email tools and analytics process data for you. Read their data protection terms, and sign a data processing agreement where they offer one.
- Plan for requests and breaches.Decide who answers access and deletion requests, and what you will do and whom you will notify if data leaks. The DPDP Act requires you to inform the Data Protection Board and affected people of a breach; GDPR generally requires notice to the regulator within 72 hours.
4. What a privacy policy should contain
A privacy notice should be short, specific and honest. At minimum, cover:
- who you are and how to contact you;
- what personal data you collect, and from where;
- why you collect it, and your legal basis (for example consent);
- who you share it with, such as your payment gateway, courier or email provider;
- how long you keep it;
- how people can access, correct or erase their data and withdraw consent;
- how to complain: under the DPDP Act, give the contact for grievances and mention that people can approach the Data Protection Board of India;
- cookies and tracking, if you use analytics or advertising tools.
Privacy policy generators give you a starting point, but edit the result so it describes what your site really does. A generic policy that doesn't match your practices can cause more trouble than it solves. For an example of the structure, see Domain India's own privacy policy.
5. Cookies, analytics and third-party tools
Analytics scripts, advertising pixels, embedded videos, chat widgets and social buttons can all collect visitors' data. For EU visitors, non-essential cookies need consent before they are set, which is why many sites show a cookie banner with a real "reject" option. Under the DPDP Act, consent must also be free, specific and informed, and withdrawable at any time.
Good habits:
- load analytics and marketing tools only after consent where required;
- turn on the privacy options your tools offer, such as IP anonymisation or shorter data retention;
- remove plugins and embeds that you don't need.
6. WHOIS and domain privacy
Every domain has a public registration record, served through WHOIS and its newer replacement, RDAP. Since GDPR took effect in 2018, registrars and registries have hidden much of the personal data in these records.
For .in and its second-level extensions (.co.in, .net.in, .org.in and others), personal registrant details are not shown in public WHOIS. This is free and automatic; there is nothing to switch on. Company or organisation names may still appear.
For .com, .net, .org and most other extensions, Domain India offers WHOIS privacy as an optional add-on at ₹300 a year per domain, excluding 18% GST, at Domain India list prices on 19 September 2026. You enable it from the domain's page in the client area. Full details are in how to enable privacy protection for your domain.
Whatever is shown publicly, the registrar must still hold accurate contact details for you. Keep them current: they are how you receive renewal notices and prove that the domain is yours.
7. Penalties, in brief
Both laws have serious penalties. Under GDPR, fines can reach €20 million or 4% of worldwide annual turnover, whichever is higher. Under the DPDP Act, the Data Protection Board can impose penalties of up to ₹250 crore for a single breach, for example for failing to take reasonable security safeguards. Regulators generally weigh how serious the failure was and what you did about it, which is why a documented, good-faith approach matters even for a small business.
8. Where Domain India fits
Domain India is a NIXI-accredited .IN registrar. Every .in domain you register with us has personal details hidden in public WHOIS at no extra cost, and our hosting plans include free SSL certificates, so your forms and checkout run over HTTPS. Our privacy policy explains how we handle your own account data.
If you find personal data being misused on a website we host, for example a phishing page, report it to [email protected] with the web address and details. Domain India customers asking about their own account should use live chat or a support ticket.
Frequently asked questions
Does GDPR apply to an Indian website?
It can. GDPR applies to a business outside the EU if it offers goods or services to people in the EU or monitors their behaviour there. An Indian site that only serves Indian customers is mainly covered by India's DPDP Act 2023 instead.
What is the DPDP Act?
The Digital Personal Data Protection Act, 2023 is India's data protection law. It covers personal data processed in digital form, requires a lawful purpose and clear notice, gives individuals rights to access, correct and erase their data, and is enforced by the Data Protection Board of India. Its rules were notified in November 2025 and phase in over about 18 months.
Does my small website need a privacy policy?
If it collects any personal data, such as through a contact form, sign-up, order or analytics, you should publish a clear privacy notice explaining what you collect, why, who you share it with, how long you keep it and how people can use their rights.
Are .in domain owners' details public in WHOIS?
No. For .in and its second-level extensions such as .co.in, personal registrant details are not shown in public WHOIS. This is free and automatic, and there is nothing to switch on. Company or organisation names may still appear.
How much does WHOIS privacy cost for a .com domain at Domain India?
₹300 a year per domain, excluding 18% GST, at Domain India list prices on 19 September 2026. It is an optional add-on enabled from the domain's page in the client area.
Is this article legal advice?
No. It is general information to help you understand the basics. For decisions about your own business, consult a qualified lawyer.
Ready to protect your visitors and your domain? Register a .in domain with personal details hidden in WHOIS, read about WHOIS privacy for other extensions, or open a support ticket with questions about your account.
Personal details on .in domains are hidden in public WHOIS at no extra cost.
Search domains