Legal & Compliance for Business
Your website makes promises about your customers' data. Do you know what they are?
A contact form, a newsletter box, a payment button, an analytics tag, a WhatsApp number. Each one collects something about a person. Most small businesses never decided what to do with it, and a template privacy policy copied from elsewhere does not answer the question. This session explains what a business website should carry, how to think about consent, what rules apply to online sellers, and how the new data protection law changes the picture. It is awareness, not legal advice.

Explore this page6 sections
A policy copied from another site describes another business.
Customers, banks, platforms and, increasingly, regulators look at what a business says about their data and whether it does what it says. A privacy policy that mentions tools you do not use, or misses the ones you do, is worse than a short honest one.
This session is general information for awareness. It is not legal advice, and it does not replace a qualified lawyer, company secretary or chartered accountant, who should be consulted about a specific situation.
What the session covers
37 topics across 7 areas. Seven parts, from the basics to what is changing. 6 apply to almost any business; the rest only in a particular case.
What a Business Website Usually NeedsPlain, accurate and kept up to date.6
- Who you are: the business's legal name, address and contact details
- What you sell, the real prices and any extra charges
- Refund, cancellation, delivery and complaint terms in plain language
- A privacy policy that matches what the site actually does
- Terms of use for the site or service, where relevant
- A named person or email for complaints and data requests
Privacy Policy and Consent TodayThe rules in force now, before the new law applies in full.4
- Section 43A of the Information Technology Act, 2000 and the 2011 rules on reasonable security practices apply today to a body corporate, a term the Act defines to include firms and sole proprietorships engaged in commercial activity
- Those rules call for a published privacy policy where personal information is collected, and written consent, including by email, before collecting sensitive personal data such as financial information or passwords
- The Digital Personal Data Protection Act, 2023 removes section 43A when its amending provisions take effect, which is expected on the eighteen-month timetable of around May 2027; check the notification
- Until then, a clear policy and honest consent are sensible practice
Forms, Cookies, Analytics and WhatsApp ListsEvery tool you add collects something.6
- Listing every form, tag, plug-in and chat widget on your site and what each collects
- Collecting only what you need for the purpose you state
- Pre-ticked boxes and bundled consent: the DPDP Act asks for consent that is free, specific, informed, unconditional and unambiguous, with a clear affirmative action
- Keeping a record of when and how a person agreed, because under the Act the business must be able to prove notice and consent
- Making it as easy to withdraw as it was to agree
- Adding people to marketing lists only with their agreement
Selling Online: Consumer RulesIf you sell goods or services through a website or app.5
- The Consumer Protection (E-Commerce) Rules, 2020 apply to e-commerce entities; whether you are one depends on how you operate, so check
- Those rules include displaying the entity's details, appointing a grievance officer, and acknowledging complaints within 48 hours and resolving them within a month
- Marketplace sellers face information duties of their own
- Honest descriptions, prices and claims
- The Central Consumer Protection Authority's 2023 guidelines on dark patterns list thirteen deceptive design practices, including false urgency; check whether they apply to you
These descriptions are summaries. Read the current text of the rules and guidelines for your case.
Security Basics for a Small SiteMost small-business incidents come from weak habits, not clever attackers.6
- Strong, separate passwords and two-step login for email, hosting, domain and payment accounts
- Keeping the site software and plug-ins updated
- Regular backups, stored away from the site, and tested
- Knowing who has admin access, and removing it when people leave
- The DPDP Rules list minimum safeguards such as encryption or masking, access control, logs, backups and appropriate vendor contracts, applying from around May 2027
- Asking a professional whether any sector rule or the national cyber-incident reporting directions apply to you
What Changes Under the DPDP RulesEnough to start preparing, not to finish.6
- The Rules were notified in November 2025 and apply in phases
- Most duties on businesses, including notice, safeguards and breach intimation, are due about eighteen months after notification
- Notices must be clear, itemise the data and state the purpose
- People can ask to access, correct or erase their data, and businesses must publish how
- Special rules apply to the data of children
- A separate session covers the Act and Rules in detail
Content, Images and New ToolsIf it appliesWhere small sites most often slip.4
- Using images, fonts, music or text you do not have a licence for
- Posting customer photos or testimonials without their permission
- Pasting customer details into free online or AI tools without reading their terms
- Claims in your content that you cannot support
A ten-minute audit of your own website
- List every form and what it collects
- List every tool, plug-in and tag that sees visitor data
- Read your privacy policy and tick what is true
- Check who holds the admin login for each tool
- Check that refund and complaint details are findable
- Note what you would tell a customer who asked what you hold on them
What this session is not
- Not a privacy policy template to copy
- Not legal advice about whether any law applies to you
- Not an audit of anyone's website
- Not a cyber-security service
- Not a recommendation of any tool or vendor
How the session runs
Led by a facilitator, with a qualified lawyer or technology professional where the topic needs one. Participants run the ten-minute audit on their own website, or on a made-up example if they do not have one, and list what their policy should say. Hypothetical cases, clearly labelled, show where a policy and practice diverge. The facilitator points to the official sources for each rule, because the rules and their dates are still moving.
What your students leave with
- A list of the pages and policies a small business website should have
- A clear picture of what personal data their own site and tools collect
- An understanding of what a privacy notice should say, and what it should not promise
- Awareness of the rules that can apply to businesses selling online
- A short security routine for site logins, backups and vendors
- Knowing what changes as the DPDP Rules come into effect, and what to ask a professional
Scheduled sessions
Nothing scheduled yet
Sessions are arranged with a college once a date is agreed. Ask us and we will find the right person for it.
A student rather than a college? See what is coming up, or ask your placement team to host this.
A short, accurate privacy policy that you follow is better than a long one that you do not.
Tell us who your students are and what stage they are at. Sessions are free for participants.