The Department of Consumer Affairs notified the Consumer Protection (E-Commerce) (Amendment) Rules, 2026 on September 9, 2026, as G.S.R. 789(E). The rules come into force on January 1, 2027. They amend the 2020 e-commerce rules and change how a platform must be built. Three changes need the most technical work. First, you need a price-history system that can justify the “prior price” shown with every discount. Second, you must run a yearly dark pattern self-audit and display a certificate on your platform. Third, your grievance workflow must acknowledge complaints within 48 hours and connect with the National Consumer Helpline.
We have worked as a mobile app development company in India for more than 12 years, building e-commerce apps, marketplaces, and ERP-connected platforms. Most consumer protection updates we have seen were mainly about policy wording. This one reads more like a product spec. The Department’s September 10, 2026 press release shows why the government acted. The National Consumer Helpline received 17,71,622 grievances in 2025, and 5,11,196 of them, about 29 percent, were about e-commerce. Below, we cover each requirement in turn, explain it in plain language, and list what must change in your app, website, backend, admin panel, and processes.
This guide explains technical implementation and is not legal advice. Confirm your obligations with your legal counsel.
Who the Rules Apply To
The 2020 rules already covered e-commerce entities running either a marketplace model or an inventory model. They also covered entities outside India that systematically offer goods or services to Indian consumers. The 2026 amendment keeps that scope. For engineering planning, what matters is that the new duties apply at different levels.
Obligations added to Rule 4 apply to every e-commerce entity. That includes a D2C brand selling from its own website or app (an inventory entity) and a multi-vendor marketplace. The Rule 4 obligations are:
- search integrity and sponsored listing labels
- the prior price rule
- the invoice font rule
- the dark pattern self-audit
- grievance timelines and National Consumer Helpline partnership
- disclosures for imported goods
- display of your own legal name, addresses, and contact details
Obligations added to Rule 5 apply only to marketplace entities. They cover expanded seller information, the plain-language explanation of ranking, limits on how consumer information is used, and the bundled fee ban. Rule 6 adds duties for sellers who list on marketplaces. Rule 7 updates the product information duties for inventory entities.
The amendment does not add any exemption based on business size. Many brands sell through their own storefront and on marketplaces at the same time. Those brands carry two sets of duties: they are an inventory entity on their own site and a seller on every marketplace where they list.
Prior Price and Discount Display
Rule 4(13) says that when an e-commerce entity or a seller announces a price reduction, it must show the prior price next to the reduced price. The notification defines “prior price” as the lowest price of the good or service in the thirty days before the price reduction was announced.
For example, suppose you want to show “was ₹2,999, now ₹1,999.” That is only valid if ₹2,999 was the lowest price in the previous 30 days. If the same product sold at ₹2,199 during a flash sale two weeks earlier, your prior price is ₹2,199, and the discount you can show is much smaller.
The notified text does not explain how the rule applies in three common situations: products listed for less than 30 days, personalized or member-only prices, and stacked coupons or bank offers. Your counsel should decide your position on each. Your system should be flexible enough to support whichever interpretation they choose.
What changes in your app and backend
Price history store. Log every price change for every SKU in an append-only table. On a marketplace, log changes per seller as well. Each record should hold the price, the effective start and end timestamps, the sales channel, and who made the change.
Prior price calculation. When a promotion is created, a backend service should calculate the minimum price across the 30-day window. It should then store that value on the promotion record so you can reproduce the exact number later if anyone asks.
Display. Show the prior price wherever the discount appears. That includes product pages, listing cards, the cart, promotional banners, and discount-led push notifications and emails. Put a clear label on it, such as “Lowest price in the last 30 days.”
Admin panel. Remove free-text “original price” fields from promotion setup so that sellers and category managers cannot enter their own strike-through prices. MRP display is governed by separate laws. Ask your counsel how MRP and the prior price should appear together on the page.
Timing. The prior price calculation needs 30 days of clean data. That means price-history logging must be live by the first days of December 2026 at the very latest. October is a better target.
One of our solutions architects explains where this data should live: “Price history and consent records belong in the core commerce database, as append-only event tables. They should not live in the CMS, the search index, or a frontend cache. Calculate the prior price on the server, stamp it onto the promotion when it is created, and have every channel read that stamped value. If the app works out the number on its own, sooner or later two screens will show different prior prices for the same product, and you will not be able to prove which one was correct.”
Search Results, Ranking Disclosure, and Sponsored Listings
This area has three parts.
The first is search integrity. Rule 4(11)(c) prohibits any e-commerce entity from misleading users by manipulating search results or search indexes relative to what the user searched for.
The second is sponsored labels. Rule 4(12) requires every e-commerce entity to mark sponsored listings clearly, with prominent disclosures.
The third applies only to marketplaces. Rule 5(3)(f) requires a publicly available, plain-language explanation of the main parameters that decide how goods or sellers are ranked. The parameters must be listed in descending order of importance, along with their relative weight. The amended definition of “ranking” in Rule 3(1)(j) now covers how sellers are ranked as well as products, whatever technology is used to rank them. You have to explain the factors behind your ranking, but you do not have to publish the algorithm itself.
What changes in your app and backend
Ranking signal inventory. List every signal that affects ranking. Typical signals include text relevance, sales velocity, ratings, delivery speed, price, seller performance, personalization, and ad bids. Record the weight of each one. Keep this document versioned alongside your ranking configuration so the public explanation always matches what runs in production.
Disclosure page. Publish the explanation at a stable URL. Link to it from search result pages and from the site footer. Add a step to your release process that requires reviewing the page whenever ranking logic changes.
Sponsored labels. Set an is-sponsored flag at the ad server. Carry it through the search API to every place a listing can appear, including search grids, category pages, carousels, “similar products” widgets, and paid home banners. Check that caching layers do not strip the label.
Older app versions. Native app builds released before the change will not render the new label. You will need to raise the minimum supported app version and prompt users to update.
Search integrity review. Review any business rule that forces products into results, or pushes them down, regardless of the query. Keep logs of sample queries and the results they returned so you have evidence if you ever need it.
Dark Patterns and the Yearly Self-Audit
Rule 4(15) makes the Guidelines for Prevention and Regulation of Dark Patterns, 2023 binding on every e-commerce entity. It also adds two new duties. Each entity must conduct a yearly self-audit to confirm its platform is free of dark patterns, and it must prominently display a certificate to that effect.
The 2023 Guidelines list 13 specified dark patterns. They include false urgency, basket sneaking, confirm shaming, forced action, subscription traps, interface interference, bait-and-switch, drip pricing, disguised advertisements, and nagging. Before this amendment, following the Guidelines was treated largely as good practice. From January 1, 2027, it is a recurring legal obligation that you must be able to prove.
Our UX lead describes how these patterns usually get into a product: “Nobody signs off on a dark pattern in a sprint review. They show up as defaults. A protection plan gets pre-ticked for an A/B test and nobody switches it back. An ‘Only 3 left’ badge reads from a marketing field instead of live stock. A cancel button ends up three screens deep because the retention team wanted to show one more offer. Audit whole flows rather than individual screens, because the problem usually sits in the step between them.”
What changes in your app and backend
Checkout. Show the full payable amount, including every fee, before the final step. Fees should not appear for the first time at payment, which is drip pricing. Don’t add anything to the cart without the user’s action; that is basket sneaking. Decline buttons should use neutral wording to avoid confirm shaming.
Subscriptions and memberships. Canceling should take as much effort as signing up. Show the renewal date and amount before any charge. Tell users clearly when a free trial will convert to a paid plan.
Pre-selected options. Donations, insurance, gift wrap, express delivery, and marketing opt-ins should all default to off.
Urgency timers and scarcity badges. Countdown timers should read the real offer end time from the backend and should not reset when the page reloads. Stock counters should come from the inventory service.
Ads and prompts. Label promoted content as advertising. Limit how often you ask users to rate the app, turn on notifications, or accept other permissions, so prompts don’t become nagging.
Audit evidence. For each audit, keep screen recordings of each key flow on each platform and each supported app version, with the date recorded.
Certificate display. The rules require the certificate to be displayed “prominently” but do not set a location or format. We recommend a footer link on every web page and a link in the Legal or About section of your apps. The certificate should be dated and signed off by an accountable officer.
Treat the yearly audit as a minimum. Add a dark pattern check to your release checklist, so that a new feature launched in March cannot quietly undo the certificate you issued in December.
Is your platform ready for January 1, 2027?
We audit e-commerce apps and backends against the 2026 rules and deliver a scoped compliance plan within 48 hours. Request a compliance audit.
Grievance Redressal and National Consumer Helpline Integration
Rule 4(5) sets three duties for your grievance officer. The officer must acknowledge every consumer complaint within 48 hours. The officer must give the complainant a copy of the recorded complaint. The complaint must be redressed within one month of receipt.
Rule 4(7) now requires every e-commerce entity to become a partner in the National Consumer Helpline (NCH) convergence process. Under the 2020 rules, this was a best-efforts commitment.
Rule 4(2) requires you to display your legal name, the principal address of your headquarters and all branches, your website details, and the email, landline, and mobile numbers for both customer care and the grievance officer. These requirements apply to every e-commerce entity.
What changes in your app and backend
Single ticketing flow. Every complaint should become a ticket, regardless of the channel it arrives through: app, web form, email, call center, chat, social media, or NCH. When the ticket is created, save a snapshot of the complaint exactly as recorded, and do not allow that snapshot to be edited. Save any later changes as new versions.
Acknowledgment. Send an acknowledgment with the ticket number and a copy of the recorded complaint by email, SMS, or in-app message, and store proof of delivery. Automate this so it goes out within minutes. Treat 48 hours as the outer limit, not the target.
Resolution tracking. Start the one-month clock on the date of receipt, which is not always the date an agent picks up the ticket. Set escalation triggers well before day 30, and give managers a dashboard of tickets that are approaching the deadline.
NCH connection. Once you are onboarded as a convergence partner, complaints routed from NCH should arrive in the same queue as your other tickets, tagged with their source, and status updates should go back as required. The Department will confirm the onboarding details. Build the NCH connection as a separate adapter, so that if the data format changes, you do not have to touch your core ticketing system.
Contact details. Store your legal name, addresses, and contact numbers in one place in the admin panel. Every footer and every app contact screen should read from that single record, so that an address change updates everywhere at once.
Seller and Product Disclosures and Invoice Changes
Marketplace seller information. Under Rule 5(3)(a), marketplaces must now show each seller’s business name and whether the business is registered. They must also show the seller’s geographic address, customer care number, website and email where available, and ratings or aggregated feedback. If a consumer asks in writing after a purchase, the marketplace must provide further details about the seller, such as the addresses of its headquarters and branches, for dispute resolution.
Marketplace product information. Rule 5(3)(c) adds best before or use before dates to the pre-purchase information marketplaces must show. For food products, this is subject to the Food Safety and Standards Act, 2006.
Seller duties. Rule 6(5) requires sellers on marketplaces to disclose the country of origin, the cost of return shipping, and any identification number issued by the Central Government, such as a GSTIN or an MSME registration number.
Inventory entities. Rule 7(1)(a) applies matching product information duties to inventory entities, including best before dates and the cost of return shipping.
Imported goods. For every entity, Rule 4(6) requires the importer’s name and details and the full country of origin for imported goods.
Invoices. Rule 4(14) requires the seller’s name to appear on the invoice in the same font size as the e-commerce entity’s name.
What changes in your app and backend
Seller onboarding. Add the new fields as mandatory. Validate GSTIN formats. Require supporting documents, and set a cycle for re-verifying seller details. A listing should not go live until all required fields are complete.
Product catalog. Add fields for country of origin, importer, best before date, and return shipping cost. Update the bulk upload templates and APIs that sellers use. Product page templates should display these fields before purchase.
Post-purchase seller details. Add a “request seller details” option on the order page, or through support, with a templated written response.
Invoice template. Many businesses generate invoices in accounting systems, ERPs, or enterprise systems rather than in the app itself. If that applies to you, you’ll need to make the font change in that system. It also helps to sync seller master data between the ERP and the marketplace so the details on the invoice and the product page always match.
Consent for Data Use and the Bundled Fee Ban
Both of these duties apply only to marketplace entities.
Use of consumer information. Rule 5(6) is narrower than a general data consent law. It stops a marketplace from using information it collects for two purposes. The first is selling goods through any seller, whether related to the marketplace or not, when those goods carry a brand or name in common with the marketplace. The second is promoting or advertising a seller as associated with the marketplace. The notified text attaches an exception where the marketplace has the consumer’s express and affirmative consent. Ask your counsel how that consent condition applies to each of the two purposes. Either way, a general acceptance of your terms and conditions will not be enough.
Bundled fees. Rule 5(7) prohibits a marketplace from collecting bundled fees from users for services unrelated to the platform. Loyalty and membership programs, and the benefits offered under them, are exempt.
What changes in your app and backend
Consent capture. Add purpose-specific consent toggles that are unticked by default and separate from acceptance of your terms.
Consent ledger. For each consent, record the user, the purpose, the version of the text shown, a timestamp, the channel, and any later withdrawal. CRM tools, ad audience builders, and marketing automation should check the ledger before they use any data.
Data flow mapping. If you run private label products or promote sellers as associated with the platform, map exactly how consumer data flows into those programs.
Fee audit. List every fee line at checkout, such as platform, convenience, packaging, handling, and protection fees. Link each one to the platform service it pays for, and tag any fee that belongs to a membership program. Store this in a fee catalog so the checkout breakdown and your compliance records come from the same source.
DPDP timeline. The Digital Personal Data Protection Rules, 2025 have their own separate timeline. They were notified on November 13, 2025. Consent manager provisions take effect twelve months later, on November 13, 2026, and most substantive obligations on data fiduciaries apply from May 13, 2027. In early 2026, MeitY also consulted on shortening some timelines for large data fiduciaries, so check the current position with your counsel. If you are building consent systems now, design them for both sets of rules so you do not have to rebuild the same ledger twice within six months.
Compliance Timeline: Working Back From January 1, 2027
As of late September, you have about three months. This is the plan we are using with clients.
October: Audit
Map each requirement to screens, services, and processes. Record your key user flows for the dark pattern review. List your ranking signals and the gaps in your seller data. Build the fee inventory.
Turn on price-history logging immediately, because you can’t create the 30-day window retroactively. Agree on interpretations with legal counsel on the open questions, such as new listings and stacked discounts.
November: Build
Build the prior price service and the promotion controls in the admin panel. Ship sponsored labels, the ranking disclosure page, the grievance workflow changes, the new seller and catalog fields, the updated invoice template, the consent ledger, and the fee catalog. Submit app updates to the app stores with enough time for review.
December: Test and Certify
Run QA on every channel and on every supported app version. Check a sample of prior price calculations against the logged price history. Simulate complaints to test your SLA timers and escalations. Complete the dark pattern self-audit, sign it, and publish the certificate. Set the minimum app version.
If you run year-end sales, deploy these changes before the sale begins. Do not deploy during the sale.
Requirement to System Map
| Requirement | Applies to | Frontend | Backend | Admin panel | Invoices | Support |
|---|---|---|---|---|---|---|
| Prior price display, Rule 4(13) | All entities and sellers | Yes | Yes | Yes | No | No |
| Search integrity and sponsored labels, Rules 4(11) and 4(12) | All entities | Yes | Yes | Yes | No | No |
| Ranking parameter disclosure, Rule 5(3)(f) | Marketplaces | Yes | Yes | Yes | No | No |
| Dark pattern self-audit and certificate, Rule 4(15) | All entities | Yes | Yes | Yes | No | Yes |
| Grievance timelines and NCH partnership, Rules 4(5) and 4(7) | All entities | Yes | Yes | Yes | No | Yes |
| Entity contact details, Rule 4(2) | All entities | Yes | No | Yes | No | Yes |
| Seller and product disclosures, Rules 5(3), 6(5), and 7(1) | Marketplaces, sellers, inventory entities | Yes | Yes | Yes | No | Yes |
| Imported goods disclosures, Rule 4(6) | All entities | Yes | Yes | Yes | No | No |
| Seller name font size on invoice, Rule 4(14) | All entities | No | Yes | No | Yes | No |
| Consent for specified data uses, Rule 5(6) | Marketplaces | Yes | Yes | Yes | No | No |
| Bundled fee ban, Rule 5(7) | Marketplaces | Yes | Yes | Yes | Yes | No |
How StudioKrew Helps
StudioKrew was founded in 2013. Since then, we have delivered more than 250 apps and software products, plus more than 700 games, including e-commerce and marketplace platforms. Our teams work from Chicago, Oakville in Canada, New Delhi, and Dubai. We help you comply with these rules in three ways.
Compliance audit. We review your app, website, backend, admin panel, and support processes against each requirement described above. You get a written gap report with each gap mapped to the systems it affects. Every inquiry receives a scoped written proposal within 48 hours.
Implementation. Our custom app development teams build the changes across native apps, web storefronts, and backend services, including price-history infrastructure, sponsored label pipelines, and ticketing workflows. Much of this work sits at the intersection of the storefront and back-office systems. We have handled that before: see an online marketplace with ERP integration we built. Our developers bill between $18 and $55 per hour. We don’t quote a fixed price for compliance work because every stack starts from a different place.
Ongoing support. The self-audit repeats every year, and consumer protection rules will keep changing. Our application maintenance and support retainers keep your platform compliant as the rules change. They typically cost 15 to 20 percent of the original build cost per year.
Three months to compliance. Start with an audit.
Our team maps every requirement to your app, backend, and admin panel, then delivers the changes with an ongoing support retainer for future rule updates.
Get a Free Compliance PlanFrequently Asked Questions
When do the e-commerce amendment rules 2026 come into force?
The Consumer Protection (E-Commerce) (Amendment) Rules, 2026 were notified on September 9, 2026, through G.S.R. 789(E) and come into force on January 1, 2027. They amend the Consumer Protection (E-Commerce) Rules, 2020.
What is the prior price rule?
When an e-commerce entity or a seller announces a price reduction, it must show the prior price next to the reduced price. The prior price is the lowest price of that product or service in the 30 days before the price reduction was announced, so platforms need stored price history to calculate it reliably.
What is a dark pattern self-audit?
Every e-commerce entity must comply with the Guidelines for Prevention and Regulation of Dark Patterns, 2023, conduct a yearly self-audit to confirm its platform is free of dark patterns, and prominently display a certificate to that effect. In practice, the audit reviews flows such as checkout, subscriptions, default selections, and urgency messaging.
Do the rules apply to small D2C brands and inventory sellers?
Yes. The Rule 4 duties, including prior price display, sponsored labels, the dark pattern self-audit, grievance timelines, and the invoice font rule, apply to every e-commerce entity, including a D2C brand selling from its own site or app. The amendment adds no size-based exemption. Ranking disclosure, the consent restrictions, and the bundled fee ban apply only to marketplace entities.
How long does it take to make an e-commerce app compliant?
It depends on your stack, the number of channels you run, and whether you already store price history. For most platforms, we plan about three months: an audit in October, the build in November, and testing and certification in December. Price-history logging should start as early as possible because the prior price calculation needs 30 days of data.


