01
Accountability
Role map
Roles depend on who decides purpose and means, who acts on instructions, and what each party actually does. Record the conclusion and its evidence; do not infer it from the vendor label.
- Name checkout, payment-operations, finance, support and integration owners.
- Record Razorpay’s role for each flow from the current agreement and processing facts.
- List banks, platforms, webhook hosts, CRM and accounting destinations separately.
02
Collection surfaces
Collection and notice touchpoints
Walk each entry path as a real user. Save the notice, fields, choices, time and destination rather than relying on a policy page alone.
- Checkout fields, order creation, payment links and support intake.
- Payment, refund, dispute and settlement events.
- Webhooks, dashboard exports and reconciliation files.
03
Purpose discipline
Purpose and data minimisation checks
Every field and copy should have a named operating reason, accountable owner and review event.
- Send only fields required for payment and reconciliation.
- Avoid copying payment metadata into CRM notes or support tickets without need.
- Limit webhook storage and reconciliation export columns.
04
Choice evidence
Consent and preference evidence
When consent is relied on, preserve the affirmative action and withdrawal path. Where another legal route is assessed, record that analysis instead of manufacturing a consent record.
- Display the relevant business notice around checkout collection.
- Keep payment processing assessment separate from marketing permission.
- Ensure optional communication choices are not bundled with payment.
05
Least privilege
Access control and privileged roles
Test ordinary view, sensitive fields, bulk action, export, configuration and integration access separately.
- Review owner, administrator, operations, developer and support access.
- Restrict keys, webhook secrets, exports and refunds.
- Exercise role removal and secret rotation.
06
Lifecycle
Retention, deletion, backup and export behaviour
A delete button is not a lifecycle rule. Record the start event, end event, exception, system action, residual copy and accountable approver.
- Define retention for orders, settlements, disputes, webhooks and local copies.
- Record provider, finance and legal constraints before deletion.
- Dispose of exports and test connected-system changes.
07
Service chain
Processor, sub-processor and contract checks
Use the current contract and actual architecture. A product page cannot establish the complete role allocation for your organisation.
- Retrieve current terms, data terms, sub-processor and incident information.
- Inventory checkout, webhook, finance, CRM and support integrations.
- Document assistance, return, deletion and exit expectations.
08
Detection + response
Logs, monitoring and breach evidence
Coverage, event types, retention and exportability vary. Preserve an evidence timeline without claiming that one log proves the complete event.
- Monitor team changes, key rotation, webhook failures, refunds and exports.
- Preserve signed webhook validation and investigation evidence.
- Connect payment security events to the internal breach workflow.
09
Request workflow
Rights-request search, export, correction and erasure workflow
- 01
Verify the requester without asking for unnecessary payment credentials.
- 02
Search business order, provider dashboard, support, finance and webhook records.
- 03
Review legal and dispute-retention exceptions.
- 04
Correct business-controlled fields and document provider/downstream actions.
10
Bounded configuration
Configuration checklist
Dashboard privileges match payment-operation need.
- Admin path
- Verify in the current admin console
- Evidence to save
- Dated team-role review and exceptions.
Endpoints, secrets, payload fields and failure handling are owned.
- Admin path
- Verify in the current admin console
- Evidence to save
- Endpoint inventory, rotation record and test event.
Exports are access-controlled and disposed of.
- Admin path
- Verify in the current admin console
- Evidence to save
- Export recipient and deletion record.
No menu-path fiction: open the current vendor documentation and your live console together. Feature names, paths and entitlements can change.
11
Retrievable proof
Evidence to save
Checkout field and notice map
Team-role review
Key and webhook inventory
Webhook verification test
Reconciliation export register
Rights-search and retention decision
Save redacted configuration evidence in an approved internal location. This private preview does not accept uploads or store these records.
12
Do not overclaim
Known limitations and questions for the vendor
Known limitations
- Available roles and dashboard features can change by product and account.
- The provider and the business may each retain different records.
- This guide does not assess card-industry or financial-sector obligations.
Questions to resolve
- Which fields are sent at checkout?
- Where are webhook payloads stored?
- Who can export, refund or rotate keys?
- Which records must remain for disputes or finance?
13
Traceable record
Official vendor sources, DPDP sources and corrections
Vendor documentation supports configuration questions only. DPDP statements are mapped separately to official Indian sources and phased commencement records.
Official vendor documentation
Official DPDP record
- Act No. 22 of 2023Ministry of Law and Justice, Government of India · checked 2026-09-27 ↗
- G.S.R. 843(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 846(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 892(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
Reviewed · not counsel-reviewed · educational implementation guidance, not legal advice, certification or a legal conclusion.
Report or inspect a correctionRazorpay is a trademark of Razorpay Software Private Limited. It is referenced nominatively; no affiliation or endorsement is implied.