01
Accountability
Role map
Roles depend on who decides purpose and means, who acts on instructions, and what each party actually does. Record the conclusion and its evidence; do not infer it from the vendor label.
- Name store, ecommerce, support, developer and fulfilment owners.
- Separate platform, host, app/plugin, payment, delivery and marketing roles.
- Document responsibility from contracts and actual access.
02
Collection surfaces
Collection and notice touchpoints
Walk each entry path as a real user. Save the notice, fields, choices, time and destination rather than relying on a policy page alone.
- Account registration, checkout, contact forms, reviews and support.
- Orders, addresses, fulfilment, returns and fraud checks.
- Apps/plugins, pixels, webhooks, exports and data warehouse sync.
03
Purpose discipline
Purpose and data minimisation checks
Every field and copy should have a named operating reason, accountable owner and review event.
- Remove unnecessary checkout and account fields.
- Review app/plugin and pixel access to customer and order data.
- Limit abandoned-cart, draft-order and export retention.
04
Choice evidence
Consent and preference evidence
When consent is relied on, preserve the affirmative action and withdrawal path. Where another legal route is assessed, record that analysis instead of manufacturing a consent record.
- Place notice and choices at relevant account, checkout and marketing surfaces.
- Test marketing withdrawal across store, email, SMS and advertising tools.
- Do not confuse account creation or checkout with optional marketing consent.
05
Least privilege
Access control and privileged roles
Test ordinary view, sensitive fields, bulk action, export, configuration and integration access separately.
- Review staff, collaborator, host, database and app/plugin access.
- Restrict exports, refunds, customer-data scopes and production credentials.
- Exercise collaborator and staff removal.
06
Lifecycle
Retention, deletion, backup and export behaviour
A delete button is not a lifecycle rule. Record the start event, end event, exception, system action, residual copy and accountable approver.
- Define events for accounts, abandoned carts, failed orders, completed orders and support.
- Test platform/WordPress erasure, order treatment, backups and app/plugin copies.
- Document records retained for finance, fraud or dispute purposes.
07
Service chain
Processor, sub-processor and contract checks
Use the current contract and actual architecture. A product page cannot establish the complete role allocation for your organisation.
- Retrieve platform/host terms and list every app, plugin, payment and fulfilment service.
- Review scopes and webhook topics.
- Record exit, deletion, return, security and incident commitments.
08
Detection + response
Logs, monitoring and breach evidence
Coverage, event types, retention and exportability vary. Preserve an evidence timeline without claiming that one log proves the complete event.
- Monitor staff, app/plugin, export and checkout configuration changes.
- Log webhook failures and unauthorised data access.
- Preserve an evidence timeline for commerce incidents.
09
Request workflow
Rights-request search, export, correction and erasure workflow
- 01
Search account, order, support, marketing and app/plugin records.
- 02
Verify the requester without disclosing order history.
- 03
Review retention exceptions and anonymisation effects.
- 04
Record downstream app/plugin responses and backup treatment.
10
Bounded configuration
Configuration checklist
Every extension has a purpose, scope, owner and exit decision.
- Admin path
- Verify in the current admin console
- Evidence to save
- Current app/plugin inventory and access review.
Store settings are tested by record state and exception.
- Admin path
- Verify in the current admin console
- Evidence to save
- Test case, results and residual copies.
Applicable request mechanisms are configured and exercised.
- Admin path
- Verify in the current admin console
- Evidence to save
- Test request and response record.
No menu-path fiction: open the current vendor documentation and your live console together. Feature names, paths and entitlements can change.
11
Retrievable proof
Evidence to save
Platform and extension inventory
Checkout field/notice map
Staff and collaborator review
Webhook or exporter test
Order-retention matrix
Rights-request exercise
Save redacted configuration evidence in an approved internal location. This private preview does not accept uploads or store these records.
12
Do not overclaim
Known limitations and questions for the vendor
Known limitations
- Apply Shopify documentation only to Shopify and WooCommerce documentation only to WooCommerce.
- Apps, plugins, themes and custom code can create additional flows.
- Order records may be anonymised or retained depending on configuration and legal need.
Questions to resolve
- Which platform and extensions are active?
- Which apps/plugins access protected customer data?
- How are failed and completed orders treated differently?
- Where do exports and backups remain?
13
Traceable record
Official vendor sources, DPDP sources and corrections
Vendor documentation supports configuration questions only. DPDP statements are mapped separately to official Indian sources and phased commencement records.
Official vendor documentation
Official DPDP record
- Act No. 22 of 2023Ministry of Law and Justice, Government of India · checked 2026-09-27 ↗
- G.S.R. 843(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 846(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 892(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
Reviewed · not counsel-reviewed · educational implementation guidance, not legal advice, certification or a legal conclusion.
Report or inspect a correctionShopify is a trademark of Shopify Inc.; WooCommerce is a trademark of Automattic Inc. References are nominative and do not imply endorsement. No affiliation or endorsement is implied.