Quick Answer
E-commerce businesses operating in India must comply with a multi-layer regulatory framework covering the Consumer Protection (E-Commerce) Rules 2020 (amended 2023), FDI policy, the DPDP Act, GST TCS obligations, and CCI antitrust rules. Non-compliance exposes platforms and sellers to penalties, operational restrictions, and regulatory investigations.
India’s e-commerce market is projected to reach USD 350 billion by 2030, making it one of the fastest-growing digital retail economies in the world. It is also one of the most regulated. Platforms, marketplace operators, D2C brands, and individual online sellers all operate within a compliance environment that spans consumer protection law, foreign direct investment policy, data privacy, competition law, and GST.
CCPA enforcement has intensified significantly since 2022. The Competition Commission of India has pursued active investigations against major platforms. And the Digital Personal Data Protection Act (DPDP Act) is set to bring a new enforcement layer by May 2027. The window to build compliant operations from the ground up is now.
This guide covers every critical compliance obligation for e-commerce businesses in India in 2026: what the law requires, what the penalties are, and what your operations need to reflect.
FDI Rules for E-Commerce in India: The Critical Distinction
Foreign investment in Indian e-commerce is permitted, but only within a tightly defined structure. The regulatory line between a permitted marketplace model and a prohibited inventory model is the single most consequential compliance question for any foreign-invested platform.
What is the Marketplace Model, and Why Does 100% FDI Apply?
Under the marketplace model, a foreign-invested entity operates a technology platform that connects buyers and independent sellers. The platform does not own the goods, does not stock inventory, and does not control pricing. 100% FDI is permitted under the automatic route.
However, the marketplace model comes with binding operational restrictions:
- The platform cannot hold inventory of goods and cannot permit its group companies to sell on the platform
- No single vendor or vendor group may account for more than 25% of total platform sales (gross merchandise value) in a financial year
- The platform cannot directly or indirectly influence the selling price of goods
- The platform cannot offer preferential treatment to any seller, including through exclusive arrangements on logistics, warehousing, or advertising
The 25% GMV cap on single-vendor concentration is a hard compliance threshold. Platforms must monitor vendor sales share actively and maintain documented records for DPIIT review.
Inventory Model: Why Foreign Ownership Is Not Permitted
Under the inventory model, the e-commerce entity sources, stocks, and sells goods directly to consumers. This structure is not available to foreign-invested companies. FDI is not permitted in inventory-based e-commerce in India.
The practical risk is misclassification. Several platforms have structured themselves as marketplaces while exercising operational control over inventory, pricing, and logistics in ways that functionally replicate inventory-based selling. Both DPIIT and the CCI have investigated such arrangements. Misclassification exposes a platform to Enforcement Directorate scrutiny and potential unwinding of the FDI structure.
See our FDI in India guide for a complete table of permitted routes and conditions across all sectors.
Single-Brand E-Commerce: 100% FDI With Conditions
A single-brand retail entity may operate an e-commerce channel with 100% FDI permitted under the government route (above 49%). The 30% local sourcing obligation from Indian MSMEs applies where FDI exceeds 51%. Sourcing compliance is monitored annually by DPIIT and must be documented in purchase invoices and vendor certifications.
Consumer Protection (E-Commerce) Rules 2020: What the 2023 Amendments Require
The Consumer Protection (E-Commerce) Rules, 2020, amended in 2023, apply to every entity operating an e-commerce platform in India including cross-border sellers accessing Indian consumers. These rules sit within the framework of the Consumer Protection Act, 2019 (CPA), which holds platforms and sellers directly liable for violations. See our full Consumer Protection compliance guide for the CPA framework in detail.
Mandatory Seller Disclosures
Every seller operating through an e-commerce platform must display the following on their product listing:
- Legal name of the seller
- Principal geographic address of the seller
- Contact details (email address and phone number)
- Country of origin of the product
- Details of any imported goods, including importer information
- Pre-purchase disclosure of all applicable fees, charges, and taxes
These disclosures cannot be buried in terms and conditions. They must be visible and accessible at the product listing level before the consumer completes a purchase.
No Preferred Sellers and No Exclusivity
E-commerce platforms cannot enter into exclusive arrangements with sellers or engage in practices that artificially preference certain sellers on the platform. This prohibition covers:
- Exclusive product launches tied to a single platform
- Logistics or warehousing arrangements that confer structural advantages on related-party sellers
- Advertising placements or search ranking adjustments that favor specific vendors without transparent commercial basis
Platforms operating seller services divisions including fulfilment, advertising, and analytics products must maintain clear structural separation between those services and marketplace operations.
Pricing: No Manipulation Permitted
Platforms must not manipulate prices either directly or through algorithmic mechanisms. Practices that artificially inflate the original price to make a discount appear larger, or that use personalized dynamic pricing to disadvantage specific consumer segments, constitute a violation of the E-Commerce Rules and may attract CCPA action.
Return and Refund Policy: Transparency Required
Every e-commerce entity must display a clear, accessible return and refund policy before the point of sale. The policy must:
- State the timeframe within which returns are accepted
- Specify the process for initiating a return
- Disclose any product categories excluded from return
- Confirm the refund timeline and method
Ambiguous or difficult-to-access refund policies are treated as a consumer protection violation and can serve as the basis for CCPA suo motu enforcement.
Grievance Officer and Nodal Contact: Both Are Mandatory
E-commerce entities must appoint two named individuals and publish their contact details on the platform:
- Grievance Officer responsible for consumer complaints; must acknowledge complaints within 48 hours and resolve them within one month
- Nodal Officer responsible for coordinating with law enforcement and government authorities
Non-appointment of either officer is an independent compliance violation, regardless of whether any consumer complaints have been filed.
Dark Patterns: Prohibited Under CCPA Guidelines 2023
The Central Consumer Protection Authority issued Guidelines for Prevention and Regulation of Dark Patterns in 2023. These guidelines apply to all platforms and sellers operating in Indian e-commerce and designate the following practices as explicitly prohibited:
- False urgency: Countdown timers or stock scarcity messages that are artificial or misleading
- Basket sneaking: Adding products, subscriptions, or donations to a consumer’s cart without their explicit action
- Confirm shaming: Framing the opt-out or decline option in a way that pressures the consumer through guilt or shame
- Forced action: Requiring consumers to purchase additional products, sign up for subscriptions, or create accounts as a precondition to completing a primary purchase
- Subscription trap: Making it easy to subscribe but deliberately difficult to cancel, or obscuring recurring charge disclosures
- Bait and switch: Advertising one product or price and substituting another at checkout
- Hidden charges: Disclosing mandatory fees, surcharges, or taxes only at the final stage of checkout rather than at the point of product listing
The CCPA can take suo motu cognizance of dark pattern violations without requiring a consumer complaint. Penalties apply to both the platform and the individual seller. Platforms must audit their UX flows, checkout sequences, and subscription management interfaces against all seven prohibited categories.
DPDP Act Compliance for E-Commerce Platforms
The Digital Personal Data Protection Act, 2023 (DPDP Act) classifies large e-commerce platforms as significant data fiduciaries, subjecting them to an elevated compliance regime. Phase III enforcement commences in May 2027, but the compliance architecture must be built now.
Key obligations for e-commerce platforms under the DPDP Act include:
- Consent for order and purchase data: Platforms must obtain clear, specific, and informed consent before collecting personal data for order processing, marketing, and analytics purposes. Bundled consents covering multiple purposes are not compliant.
- Targeted advertising: Using personal data for targeted advertising requires separate, explicit consent from the data principal. Pre-ticked consent boxes and implied consent are not valid.
- Payment data security: Payment data must be processed with appropriate technical and organizational safeguards. Platforms that retain tokenized payment data must do so under documented retention policies.
- Children’s data: Platforms must implement age-verification mechanisms and obtain verifiable parental consent before processing data of children under 18.
- Data retention: Personal data cannot be retained beyond the period necessary for the purpose for which it was collected. Platforms must establish documented retention schedules and deletion protocols.
- Breach notification: Data breaches must be reported to the Data Protection Board of India within prescribed timeframes. The platform must also notify affected data principals.
For a full analysis of DPDP Act obligations and implementation steps, see our DPDP Act compliance guide.
CCI Antitrust Scrutiny of E-Commerce Platforms
The Competition Commission of India has placed e-commerce platforms under sustained antitrust scrutiny. The CCI initiated investigations against both Amazon and Flipkart following allegations of preferential treatment for select sellers, exclusive brand arrangements, and deep discounting practices that distort competition.
The Competition Amendment Act, 2023 introduced a deal value threshold: mergers and acquisitions with a transaction value exceeding ₹2,000 crore must now be notified to the CCI, even if the target does not meet the traditional asset or turnover thresholds. This threshold directly affects acquisitions of high-value e-commerce companies and D2C brands by larger platforms.
The Amendment Act also introduced the concept of Significant Digital Enterprises (SDEs). Platforms designated as SDEs face obligations relating to:
- Self-preferencing restrictions
- Data portability requirements
- Interoperability standards
- Fair access for third-party sellers and service providers
For a complete analysis of the Competition Amendment Act 2023 and its implications for digital businesses, see our Competition Law advisory guide.
GST for E-Commerce: TCS Mechanism and Filing Obligations
Every e-commerce operator in India that facilitates the supply of goods or services by third-party sellers is required to collect Tax Collected at Source (TCS) at 1% of the net value of seller sales made through the platform.
Key TCS compliance obligations:
- Rate: 1% (0.5% CGST + 0.5% SGST, or 1% IGST for interstate transactions)
- Filing: Platforms must file GSTR-8 monthly, disclosing the aggregate value of supplies made through the platform and the TCS collected
- Seller credit: TCS collected is reflected in the seller’s electronic cash ledger and can be claimed as credit against their GST liability
E-commerce sellers including individual sellers operating through platforms like Amazon or Flipkart must register for GST regardless of annual turnover. The standard ₹40 lakh threshold does not apply to e-commerce sellers.
Cross-border e-commerce imports are subject to import duties, IGST at the applicable product rate, and, where applicable, the OIDAR (Online Information Database Access and Retrieval) rules for digital services imported into India.
Marketplace Liability for Seller Products
Under the Consumer Protection Act, 2019, e-commerce platforms are not automatically insulated from liability for products sold by third-party sellers. Platform liability attaches where:
- The platform had knowledge that the product was defective or non-compliant and failed to act
- The platform modified, altered, or repackaged the product
- The platform made express endorsements or warranties regarding the product’s quality or fitness
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 further affect marketplace liability. Platforms that actively participate in curating, modifying, or selecting content lose safe harbour protection under Section 79 of the IT Act. A marketplace that exercises editorial or algorithmic control over product listings in a way that goes beyond neutral facilitation may no longer qualify for intermediary safe harbour.
The combined effect: platforms must maintain clear operational separation between neutral facilitation and active commercial participation. Vendor indemnification clauses in seller agreements are essential, but they do not substitute for platform-level structural compliance.
Frequently Asked Questions: E-Commerce Legal Compliance India
Q1: Can a foreign company sell products directly on Indian e-commerce platforms?
Yes, with structural conditions. A foreign company may sell through Indian marketplace platforms as a registered seller under the B2B import route. Direct inventory-based e-commerce with FDI is not permitted. The selling entity must comply with GST registration requirements, import licensing obligations, and Consumer Protection (E-Commerce) Rules 2020 disclosure requirements. Country of origin disclosure is mandatory on every product listing.
Q2: What are the penalties for dark patterns in India under the 2023 CCPA Guidelines?
The CCPA can impose penalties on platforms and sellers found to be using dark patterns. Under the Consumer Protection Act, 2019, penalties for misleading practices can reach ₹10 lakh for a first violation and ₹50 lakh for repeat violations. The CCPA can initiate proceedings suo motu, without waiting for a consumer complaint. Individual sellers and platforms can both be held liable.
Q3: Is a marketplace liable for fake or defective products sold by third-party sellers?
Not automatically, but liability can attach under specific conditions. Under the Consumer Protection Act, 2019, a marketplace platform becomes liable if it had prior knowledge of the defective product, endorsed or guaranteed the product, or modified the product. Platforms that exercise active control over listings or fulfillment in ways that exceed neutral facilitation also risk losing IT Act safe harbour protection under the IT Rules 2021.
Q4: Do FSSAI regulations apply to food products sold on e-commerce platforms?
Yes. Any e-commerce platform listing, storing, or facilitating the sale of food products must ensure that sellers hold valid FSSAI registration or licensing. Platforms that operate dark stores or fulfillment centers stocking food products require their own FSSAI license. Sellers must display their FSSAI license number on every food product listing. Non-compliance is an offence under the Food Safety and Standards Act, 2006 and can result in fines up to ₹5 lakh and operational shutdowns.



