1. 🛡️ Statutory Compliance
  2. 🛡️ DPDP Act 2023 Compliance
MudraHQ AppAdmin ConsoleGitHub
  • 🛡️ DPDP Act 2023 Compliance

🛡️ DPDP Act 2023 Compliance

How MudraHQ implements statutory data protection under the Digital Personal Data Protection Act 2023 and reconciles with CGST Act Section 36.

Loading documentation…

Powered by heyo-docs

On this page

🏛️ Core Statutory Principles Implemented1. Statutory Notice & Purpose Limitation (Sections 4 & 5)2. Reconciliation with CGST Act Section 36 (The 72-Month Rule)3. Grievance Redressal Officer (Section 13)4. Customer Ledger PII Masking

MudraHQ is engineered to comply with the Digital Personal Data Protection Act (DPDP Act 2023) and the DPDP Rules 2025, establishing enterprise-grade privacy protection for Indian consumers and merchants.


🏛️ Core Statutory Principles Implemented

1. Statutory Notice & Purpose Limitation (Sections 4 & 5)

  • Every merchant and customer onboarding flow captures explicit, recorded consent before collecting personally identifiable information (PII).
  • The statutory privacy notice is accessible at any time via:
    text
    GET /api/privacy/notice
    It enumerates the exact categories of data collected (name, phone, address, GSTIN) and limits processing strictly to tax invoicing and regulatory accounting.

2. Reconciliation with CGST Act Section 36 (The 72-Month Rule)

Under Indian tax law, Section 36 of the CGST Act 2017 mandates that every registered taxable person must preserve books of accounts and invoices for 72 months (6 years) from the due date of filing the annual return.

  • The DPDP Conflict: DPDP Section 12 allows consumers to request data erasure.
  • The MudraHQ Solution: When a customer exercises their Right to Erasure, MudraHQ triggers an Automated Anonymization & Scrubbing Engine:
    • Name is replaced with Anonymized Customer (DPDP-SEC12-xxxx).
    • Phone, email, and street address are scrubbed to NULL.
    • Invoice line items, tax splits (CGST/SGST/IGST), and total amounts are preserved to maintain tax ledger integrity.
    • An immutable audit record is saved in audit_logs.

3. Grievance Redressal Officer (Section 13)

MudraHQ designates a statutory Grievance Redressal Officer reachable at support@mudrahq.tech with a mandatory turnaround resolution SLA of under 30 days.

4. Customer Ledger PII Masking

Public unauthenticated ledger views (/view/ledger/:customerId) automatically mask customer phone numbers (+91 98480****345) and physical addresses to prevent unauthorized scraping or exposure.