The Digital Personal Data Protection Act is the first Indian law that treats your customer chat logs, phone numbers, and order histories as legally protected personal data - and it applies to a two-person Shopify store just as much as to a bank. The good news: for most SMBs, compliance is less about lawyers and more about choosing tools that were built correctly.
The three obligations that touch your support stack
First, purpose limitation: data collected to answer a support query should be used for that, not quietly repurposed. Second, security safeguards: you're expected to take "reasonable" measures - encryption, access control - to protect personal data you hold. Third, erasure: when data is no longer needed or a customer asks, you must be able to actually delete it.
Notice that every one of these lands on your tools, not your intentions. If your support platform can't tell you where a customer's transcripts live or delete them on request, you can't comply no matter how good your privacy policy sounds.
Compliance isn't a document you write. It's a property of the tools you chose.
Questions to ask any support vendor
Where is my data stored, and is it isolated from other customers? Is it encrypted at rest, not just in transit? Can I export or delete a specific customer's conversations? Does the AI train on my data or anyone else's? A vendor who answers these crisply has done the work; a vendor who forwards you to a generic trust page has not.
Tenant isolation deserves special attention with AI tools: your documents and transcripts should be walled off per business, so your price list can never leak into someone else's chatbot answer.
The upside nobody mentions
Indian customers are increasingly wary of where their data goes. Being able to say "your chats are encrypted, stored with tenant isolation, and deletable on request" isn't legal overhead - it's a trust signal your competitors mostly can't make. The DPDP Act sets a floor; treat it as a selling point.