What about DPDP Act 2023 + RBI tokenisation compliance?
Both are mandatory and both are wired into every Standard-tier build. DPDP (Digital Personal Data Protection Act 2023), India’s GDPR-equivalent, came into effect 2023, full enforcement expected 2026-27. We implement: explicit consent capture (no pre-ticked boxes), purpose-limitation per data field, data-principal rights (access / correction / erasure / nomination), 72-hour breach notification to the Data Protection Board, and a DPO contact surface in the privacy policy. Consent + DSAR automation is configured per store-view, not site-wide. RBI Card Tokenisation (CoFT) 2022+, merchants and payment aggregators can NOT store raw card PANs anymore. Only network-issued tokens (via Visa / Mastercard / Rupay / Amex token vaults) are allowed. We wire your Razorpay / CCAvenue / PayU vault correctly so your Magento DB never sees a card number. RBI cross-border data residency (proposed) we keep an eye on, for now, payment data must be stored in India only.