There is no single “online business licence” in India. Your compliance stack depends on the legal entity, physical and employee footprint, transaction model, product or service, customer location, payment flow and personal data handled. Start by mapping those facts. Then apply entity, tax, consumer, privacy, platform, intellectual-property and sector rules to the actual flow—not to the label “e-commerce”.
Digital delivery does not create one legal category
A website can be only a marketing channel, a shop selling its own inventory, a marketplace connecting third parties, a subscription product, an app, or infrastructure used by other businesses. Each model shifts responsibility.
The central question is not whether the business is “digital”. It is who makes the offer, owns the product, accepts the order, collects payment, issues the invoice, determines how personal data is used, handles complaints and controls third-party content.
A compliant launch therefore begins with a transaction map and evidence: entity documents, registrations, seller contracts, product licences, tax positions, data flows, website disclosures, customer communications and incident records.
Six facts decide the compliance stack
Who operates?
Record the proprietor, firm, LLP or company that owns the site, signs contracts, employs staff and receives revenue.
Who sells?
Separate own-inventory sales, marketplace facilitation, subscriptions, software, content and regulated professional services.
Where is activity?
Map offices, homes, warehouses, employees, sellers and customers. State and local duties may follow the footprint.
What is collected?
List identifiers, payments, device data, communications, children’s data and vendor access; state each purpose.
Who charges and settles?
Trace invoices, gateway settlement, commissions, refunds, TCS/TDS, foreign receipts and tax responsibility.
What is regulated?
Food, finance, health, education, imports, telecom, gaming and other sectors add rules beyond general e-commerce law.
Follow what the business actually does
Register the operator, then test the footprint
Business identity
- Choose the entity based on ownership, liability, capital and governance.
- Use the same legal name, address and identifiers across contracts, invoices and disclosures.
- Keep bank and payment-gateway onboarding aligned with the contracting entity.
Location layer
- Test shops and establishments, professional tax, trade licence and labour duties state by state.
- A home office, warehouse or distributed workforce may still create a local footprint.
- Do not display registrations the business does not hold.
Activity layer
- Check FSSAI for food, DGFT/IEC for imports or exports, and the relevant regulator for controlled activities.
- Product standards, labelling and legal-metrology duties can apply before the first listing goes live.
- Marketplace onboarding is not a substitute for a licence.
For entity selection, use TargoLegal’s business-structure guide. Verify live incorporation and licence requirements on the relevant authority’s portal before filing.
Make the offer, seller and remedy clear
The Consumer Protection Act, 2019 covers e-commerce, including digital products. The Consumer Protection (E-Commerce) Rules, 2020 distinguish marketplace and inventory models and require model-specific disclosures and grievance arrangements.
Before checkout
Show the true seller, total price components, material product or service characteristics, delivery terms, cancellation and return position, and applicable warranty information.
After the order
Provide confirmation, invoices or receipts, fulfilment records, refund handling and an accessible grievance route. Promises made in ads and product pages must match delivery.
Marketplace evidence
Maintain seller onboarding, contract, disclosure and complaint records. Do not blur platform responsibility with the third-party seller’s role.
Claims and reviews
Substantiate price comparisons, performance claims, endorsements and environmental claims. Avoid manipulated reviews, hidden conditions and dark-pattern design.
Electronic contracts are recognised under the Information Technology Act, 2000, but enforceability still depends on valid consent, authority, lawful terms and usable evidence. A checkbox cannot cure an unfair or inaccurate term.
Build for the final framework without misstating today’s law
The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 with staged commencement. As at 21 July 2026, some institutional provisions are in force; Rule 4 is scheduled for 13 November 2026, while the main operational rules—covering notices, security safeguards, breach intimation, retention, rights and other duties—are scheduled for 13 May 2027.
Inventory
Record each data field, source, purpose, system, access group, recipient and retention period.
Notice and choice
Write notices around actual purposes and build consent or other permitted processing routes where the applicable law requires them.
Security and vendors
Set access controls, logs, backups, patching, contractual controls and a tested breach escalation path.
Rights and deletion
Design a verified request route, legal-hold exceptions, correction and deletion workflow, and evidence of action.
Do not reduce online GST to one threshold
Determine who supplies what, from where, to whom, and through which operator. Then test turnover registration, compulsory-registration categories, section 9(5), tax collection by an e-commerce operator under section 52, place of supply, invoicing, input tax credit and return obligations. Current notifications may create exceptions for particular suppliers or models.
Direct seller
Map turnover, supply location, product or service classification, invoicing, returns, credit notes and state registrations.
Marketplace operator
Test whether the operator collects consideration, TCS applies, section 9(5) shifts liability, and seller reports reconcile with settlements.
Cross-border digital
Test export conditions, place of supply, foreign-currency evidence, OIDAR where relevant, withholding, FEMA and income-tax nexus.
GST registration and filing positions should be checked on the official GST portal. For related planning, see TargoLegal’s GST registration checklist for 2026.
A platform may carry more than e-commerce duties
If users or sellers upload listings, reviews, messages, files or other content, test whether the service is an intermediary under the Information Technology Act and the current Intermediary Guidelines and Digital Media Ethics Code Rules. Safe-harbour questions depend on the service, the role played and compliance with applicable due diligence—not on calling the business a “technology platform”.
- Define prohibited activity and enforcement in clear platform terms.
- Publish the required grievance contact and build a ticket-and-evidence trail.
- Preserve and disclose information only under applicable law and valid process.
- Document seller verification, repeat abuse, takedowns and reinstatement decisions.
- Recheck the consolidated rules and amendments; MeitY published an updated supersession text in February 2026.
One weak control can cross several legal layers
Intellectual-property controls belong in this map. Confirm ownership or licences for code, copy, photographs, product catalogues, fonts and user content; search key brands before launch; and document assignments from founders, employees and contractors. TargoLegal’s 2026 trademark registration guide explains the registration route.
Build controls in the order evidence is created
Freeze the operating map
Identify the legal operator, products, sellers, customers, locations, staff, money flow and data systems.
Create the obligation register
List each central, state, local and sector duty; record owner, evidence, due date and official source.
Align customer documents
Make listings, checkout, terms, privacy notice, delivery, refunds and grievance information consistent.
Contract the supply chain
Allocate seller, vendor, gateway, cloud, fulfilment, security, tax, IP, confidentiality and incident responsibilities.
Test real journeys
Run purchase, cancellation, refund, complaint, data request, takedown and incident scenarios from a phone.
Set review triggers
Recheck whenever the model, state footprint, product, payment route, data use, regulator or law changes.
Common online-compliance mistakes
A template describing practices the business does not follow can create evidence against it.
Unclear roles distort invoices, disclosures, refunds, product liability and GST analysis.
Turnover, section 9(5), TCS, place of supply and current notifications must be tested separately.
The 2025 Rules have staged commencement. Operational design and legal-effective dates must be distinguished.
Warehouses, employees, home offices and fulfilment locations may trigger state or local duties.
A payment provider does not determine the business’s consumer, tax, FEMA or record obligations.
Payment alone may not produce the assignment needed for code, creative work or brand assets.
Automation cannot fix an undefined business model, inaccurate data map or unassigned responsibility.
When this guide is not enough
This framework does not determine permissions for banking, lending, insurance, securities, payments, medicines, medical advice, food, alcohol, gaming, telecom, education credentials, broadcasting, defence goods, children-focused services or another controlled activity. Nor does it settle a live breach, regulator notice, consumer dispute, infringement claim or tax assessment.
Cross-border sales require a country-by-country test for consumer, tax, customs, foreign-exchange, sanctions, export-control and privacy rules. An Indian legal entity does not prevent foreign law from applying when customers, staff, goods, servers or targeted activities are elsewhere.
Related TargoLegal guides
Turn the online model into a workable compliance plan
Review the operating entity, transaction flow, registrations, consumer documents, GST position, data controls, platform contracts, intellectual property and recurring compliance before launch or a material change.
Request a digital compliance reviewFrequently asked questions
Must an online business register in every Indian state where it has customers?
Not automatically. Entity registration is different from GST, shops and establishments, professional tax, trade-licence and sector registrations. Physical presence, employees, warehouses, turnover, supplies and local activity determine which state-level registrations apply.
Is a privacy policy enough for Indian data-protection compliance?
No. A privacy notice is only one control. A business also needs an accurate data inventory, a lawful processing workflow, appropriate notices and consent where required, vendor controls, security safeguards, retention rules, rights handling and an incident-response process.
Are the DPDP Rules fully operational in July 2026?
No. The Digital Personal Data Protection Rules, 2025 use staged commencement. Some institutional rules commenced on 13 November 2025, Rule 4 is scheduled for 13 November 2026, and the principal operational rules are scheduled for 13 May 2027. Businesses should check the live commencement position before relying on a deadline.
Does every seller on an e-commerce marketplace need GST registration?
No single answer applies to every seller. Registration depends on turnover, the type and place of supply, whether the operator is liable under section 9(5) or collects tax under section 52, and current exemptions or notifications. Test the actual transaction flow on the GST portal or with a tax professional.
Which legal pages should an Indian business website have?
The required set depends on the model. Common documents include terms of use or sale, a privacy notice, cancellation and refund terms, shipping or service-delivery terms, grievance details and mandated seller or entity disclosures. Each page must reflect actual operations rather than a generic template.
What is the difference between a marketplace and an inventory e-commerce entity?
A marketplace provides a digital platform that facilitates transactions between buyers and sellers, while an inventory model owns the goods or services offered for sale directly to consumers. The Consumer Protection (E-Commerce) Rules assign different responsibilities to each model.
Does an online business still need trade or sector licences?
Often yes. Selling online does not displace licences tied to the product, service, premises or profession. Food, payments, health, education, imports, telecom, financial services and other regulated activities can trigger separate central, state or local requirements.
Primary sources to check
- India Code: Consumer Protection Act, 2019 — consumer rights, unfair trade practices, product liability and e-commerce rule-making.
- Department of Consumer Affairs: Consumer Protection (E-Commerce) Rules, 2020 — marketplace, inventory, seller, disclosure and grievance duties. Check amendments with the Department.
- MeitY Gazette: Digital Personal Data Protection Rules, 2025 — final rules and staged commencement dates.
- MeitY: Digital Personal Data Protection Act, 2023 — statutory framework; check section-by-section commencement.
- India Code: Information Technology Act, 2000 — electronic records, electronic contracts and intermediary framework.
- MeitY: Information Technology Intermediary Rules, consolidated supersession text, February 2026 — current platform due-diligence reference.
- Goods and Services Tax portal — registration, returns, notifications and taxpayer services.
- Ministry of Corporate Affairs portal — live entity incorporation and company or LLP filing services.