The direct selling industry in India consists of about ₹21,000 crore and is regulated by the first comprehensive regulatory regime to be put in place for the direct selling industry. These three aspects of direct selling are regulated by the following three laws:
- Direct Selling Rules (DSR) 2021 - entity structure, seller agreements, and income disclosure.
- Consumer Protection (E-Commerce) Rules, 2020 - liabilities of sales online, pricing, and dark patterns.
- Digital Personal Data Protection (DPDP) Act, 2023 - data consent, storage and how to respond to a data breach.
Non-compliance with any of these three laws may lead to penalties of up to ₹250 crore and orders from customer commissions and damage to the brand. This ₹250 crore penalty ceiling is specific to the DPDP Act, 2023; the DSR 2021 and E-Commerce Rules 2020 carry their own separate penalty structures under the Consumer Protection Act, 2019, and do not attract this figure. The following offers a compliance checklist, and each section will offer a step-by-step guide to achieving compliance with the above three regulations for direct selling and D2C companies.
Direct Selling Rules (DSR) 2021 - Compliance Checklist
The Consumer Affairs Ministry has implemented the DSR 2021 under the Consumer Protection Act 2019 that is applicable to all the organizations, both single-level and multi-level (direct sales). Under this legislation, there are key points that will be required of all organizations (i.e., you will have to supply these to all customers) as well.
| Requirement | What You Must Do |
|---|---|
| Entity Registration | Direct Selling business should be registered in India as a Company or Limited Liability Partnership (LLP) as per the applicable laws in the country. Specifically, a company must be incorporated under the Companies Act, 2013 (18 of 2013); a partnership firm must be registered under the Partnership Act, 1932 (9 of 1932); and a limited liability partnership must be registered under the Limited Liability Partnership Act, 2008 (6 of 2009). The Direct Selling Entity shall abide by the rules of the Consumer Protection (Direct Selling) Rules, 2021, such as becoming a partner in the convergence process of the National Consumer Helpline (NCH) and meeting all other requirements as outlined in the Rules. Additionally, the Direct Selling Entity must comply with all applicable laws, regulations, licenses, registrations, approvals, certifications and standards that may be pertinent to the products or services which are offered, marketed, distributed or sold under the Direct Selling model. |
| Written Distributorship Agreement | Distributors need to sign a legally binding agreement or contract with the Direct Selling Entity that outlines the rights, obligations, terms and conditions for the relationship. The agreement should contain, inter alia, the conditions of enrolment, the rules of conduct, the conditions for termination or resignation, the rules for the return and refund of the product, provisions on grievance redressal, and the provisions applicable. Agreement can be made in writing or electronically, and electronic signatures shall be deemed to be valid and legally binding pursuant to applicable laws. |
| Cooling Off Period | The Consumer Protection (Direct Selling) Rules, 2021, do not state a cooling-off period of 30 days. The Rules also mandate the Direct Selling Entity to allow for a reasonable cooling-off period for consumers to return goods and get a refund as per the company's return policy. |
| No Pyramid Scheme Structure | Any incentive or commission paid to a Direct Seller must come only from actual product sales. Commissions linked to recruitment or joining fees are not permitted under DSR 2021. |
| Grievance Officer | Appoint a Grievance Officer and post the contact information on your company's website. The Grievance Officer must acknowledge a written complaint within 48 hours of receiving it and resolve the complaint within 30 days of receipt. |
Consumer Protection (E-Commerce) Rules 2020 - Compliance Checklist
These rules will apply to all businesses that sell goods and services online (e.g. through their website, market places such as Amazon and Flipkart etc.), social commerce (Instagram and WhatsApp) or through an app. Additional obligations are added to these rules by the amendments of 2021 and the CCPA Dark Patterns Guidelines of 2024.
| Requirement | What You Must Do |
|---|---|
| Seller Identity Display | Inform your visitors about your registered business name, complete address, GSTIN and Customer Care contact on your website footer, during checkout and on all your bills. |
| Country of Origin | The name of the country of origin needs to be mentioned on every product listing, particularly for imported products - which is very important. This can be included as part of the product image. |
| Total Price Transparency | The full price (including GST, shipping and other costs) must be displayed prior to checkout. No Hidden charges. |
| Return & Refund Policy | Your return policy has to be clearly displayed before purchasing - not in footer. Explain the step down/up process. There are often complaints about 'no return' policies in consumer law. |
| No Dark Patterns | CCPA 2024 bans: Fake Countdowns, False Low Stocks, Forced Bundling With Pre-Checked Add-Ons, Subscription Traps, and Confirm-Shaming Opt-Out Language. Test your complete checkout user interface. |
| Genuine Flash Sales Only | Flash sales are only valid if there is the actual stock limitation. When there is stock on hand but it is marketed as 'Sold Out' it is an unfair trade practise. |
| Grievance Officer (E-Commerce) | Use a separate line to display your Grievance Officer's name and contact for e-commerce use. Must acknowledge within 48 hours. The 50L+ user platforms should also have a Nodal Officer. |
DPDP Act 2023 - Data Privacy Compliance Checklist
The Digital Personal Data Protection Act, 2023, is India's first comprehensive law of data privacy. This is particularly important for direct sellers—your business gathers huge quantities of personal information—phone numbers, buyer records, financial information, location information, and maps of your entire relationship with your direct sellers. Violation penalties are up to ₹250 crore.
| Requirement | What You Must Do |
|---|---|
| Explicit Consent Mechanism | Capture explicit, specific consent at anytime, anywhere. Pre-ticked boxes are not allowed. 'By using our site you agree...' is not considered valid consent under the DPDP. |
| Purpose Limitation | Do not use data for other than its intended purpose. If you've gathered a phone number to deliver to - separate consent is required to send marketing information. |
| Right to Erasure | Provide an in-app and website 'Delete My Account' function. Ensure that data is deleted as soon as practicable, which includes from backups and third party processors, within 30 days. |
| Children's Data (Under 18) | Children under 18 years old should only have their data collected with verified parental consent. If you are in the business of selling products to youth, institute age-gating on your website and/or app. |
| Data Breach Response Plan | Report to the Data Protection Board of India (DPBI) and all affected users within the prescribed time in case of a breach. Develop your incident response plan before you are involved in an incident. |
| Third Party Data Agreements | All data processors (your CRM, email service provider, payment processor, logistics provider, etc.) need a Data Processing Agreement (DPA) signed. You are the data owner for their processing of data of your users. |
| Restriction on Personal Data Transfer Out of India | DPDP imposes restrictions on transferring personal data across borders. CRM systems, marketing automation software, analytics tools—audit all SaaS applications that are using international data servers. |
Conclusion
The companies constructing sustainable, effective compliance models will be the ones to be the leaders as compared to the ones who are following the short-term growth strategies.
There are various laws and regulations applicable to direct sale as well there is a significant current action which has the potential of impacting the way the market operates (these include DSR 2021, E-commerce Rules 2020 & DPDP Act 2023). Compliance with these regulations is critical in order to operate legally and successfully.