Everyday millions of consumers open an app, add something to a cart and receive their door-step delivery within days. This effortless experience is enabled by businesses successfully navigating complex legal frameworks – contracts, data, taxes, compliance and liability – that is invisible to the end user but forms the backbone of the business. We help organisations build the legal infrastructure your digital business actually needs.
India’s digital commerce market is one of the fastest growing e-commerce markets in the world and is projected to cross USD350 billion by 2030. Alongside this growing digital economy, the legal landscape in India is also evolving – perhaps not at the same pace – to regulate the businesses and address the concerns arising from the modern digital commerce. Regulatory agencies are more active than they have ever been. Platforms that were once lightly governed are now subject to multiple overlapping frameworks and the cost of getting it wrong has risen sharply. The Consumer Protection (E-Commerce) Rules, 2020, the IT Act, GST implications across state borders, payment aggregator regulations, FDI restrictions on marketplace inventory models, and data privacy requirements under the Digital Personal Data Protection Act, 2023 — these aren’t abstract compliance boxes to tick. These regulations directly affect how one structures their platform, write the terms of service, handle returns, process payments, and manage vendor relationships. The brands that scale sustainably are the ones that treat legal infrastructure as a business function and not an afterthought.
Legal services for digital commerce:
We provide practical, commercially aware legal support across every stage of the e-commerce journey – from launch through scale to liquidity.
Platform architecture and regulatory structuring
The legal structuring of an e-commerce platform determines what it can and cannot do, who can invest in it and what obligations it carries. For instance, a 100% FDI is allowed under the automatic route in B2B e-commerce and marketplace models but is strictly prohibited in inventory based B2C models wherein platforms own the goods. Getting the base before building is significantly easier and economical then restructuring later. We advise on marketplace vs. inventory distinction, FDI compatible entity structures and configurations that provide businesses operational flexibility while conforming with the regulatory lines. For businesses already operating, we conduct regulatory audits that identify structure exposure and advise on corrective steps that minimise business disruption.
Key areas:
- Foreign policy interpretation and entity structuring
- FEMA compliance for foreign invested platforms
- CCO competing law analysis for dominant platforms
- Regulatory audits and restricting advisory
Terms, policies and customer facing documents
The Terms of Use is a contract. The Refund Policy is a representation to consumers and the Privacy Policy is a legally enforceable commitment. Under the Consumer Protection (E-commerce) Rules 2020, all of them are subject to specific content requirements that many businesses often fail to meet.
We draft and review customer facing documents that serve both the purposes: are clear and readable for the customers and are robust enough to protect the business in case of consumer disputes and regulatory reviews. We also audit existing documentation for businesses in transition, expansion or restructuring, to ensure that the policies evolve along in sync with the actual operations.
Key areas:
- Terms of use and seller terms drafting and review
- Refund, cancellation and returns policies
- Privacy policy and consent notices
- Mandatory disclosures under the E-Commerce Rules
- Documentation audit and gap analysis
Data privacy and digital personal data protection
With the enforcement of the Digital Personal Data Protection Act, 2023 [DPDP Act 2023] businesses in India are now facing a data protection framework with significant penalties, a Data Protection Board with enforcement powers and consumers who are increasingly aware of their rights. The DPDP Act 2023 imposes specific obligations around consent, data fiduciary duties, grievance mechanisms and cross-border data flows. These obligations don’t necessarily require longer or complex policies but rather a clear understanding of how the data actually moves through your business – from acquisition to CRM to retargeting to analytics – making each step compliant.
We assist in building data governance framework that meets these business requirements without slowing down the marketing engine.
Key areas:
- Data audit and personal data flow mapping
- Consent management framework design
- Data processing agreements with third-party vendors
- Cross-border data transfer mechanisms
- Data breach response planning and notification procedures
Payments, fintech integration and RBI compliance
The checkout experience is one of the most regulated aspect of e-commerce. Payment aggregators and payment gateways are subject to RBI’s PA/PG framework which imposes licensing requirements and consumer dispute resolution standards that flow upstream to the merchant. Similarly, conversion tools such as buy-now-pay-later options, co-branded cards, EMI structures or wallet top-ups – each carry distinct regulatory obligations.
We advise on structuring fintech integrations as per the business requirements and review agreements with payment service providers to ensure liability and compliance obligations are correctly allocated.
Key areas:
- PA/OG regulatory compliance and licensing advisory
- Tokenisation compliance under RBI guidelines
- Payment service provider agreements
Vendor, seller and logistics contracts
Every commercial relationship in a business carries legal risk which should be contractually allocated. It may include manufacturing agreements, white-label and co-packing agreements, logistics and distribution agreements for D2C brands and seller onboarding agreements, fulfilment partner contracts and warehousing arrangements for marketplaces. We draft, negotiate and review agreements – making sure liability is properly allocated, SLAs are enforceable, and your platform is protected when a third-party vendor raises a dispute.
Key areas:
- Seller onboarding and marketplace agreements
- Manufacturing, CMO and co-packing contracts
- Logistics and fulfilment centre agreements
- Warehousing and dark store lease arrangements
- Distribution and retail channel contracts
Cross-border e-commerce and export-import compliance
International transactions require addressing a special legal infrastructure including customs classifications, export documentation, transfer pricing, VAT/GST in foreign jurisdictions and country-specific consumer protection laws. We advise Indian brands going global and foreign brands entering India on the legal framework required to make cross-border commerce work.
Key areas:
- Export documentation and customs compliance
- Transfer pricing for cross border related-party transactions
- Import licensing and customs classification advisory
- Foreign brand market entry structuring for India
Brand Protection and IP enforcement
For D2C brand, a trademark is often the most valuable asset in the business. A brand built over years can easily be diluted within months by counterfeits in the market. Moreover, counterfeit listings, brand impersonations and seller IP violations have become endemic to marketplace platforms and not only carry reputational risk but also create legal exposure.
We manage end-to-end IP protection for digital commerce clients: trademark registration and portfolio management, brand registry enrolment on domestic and international platforms, monitoring for infringing listings, take-down notice strategy and execution, and litigation where enforcement is necessary.
Key areas:
- Trademark registration and portfolio management
- Brand registry on Amazon, Flipkart and other platforms
- Counterfeit listing monitoring and take down strategy
- IP policies and enforcement strategy
Advertising, marketing and consumer law compliance
In addition to being creative and dynamic, digital marketing is being increasingly scrutinised in India. Flash sale rules, influencer disclosure requirements, claim substantiation standards, and dark patterns regulations under the consumer protection framework create significant advertising law exposure for digital-first brands. ASCI’s guidelines on influencer advertising require clear disclosure of commercial relationships and the Drugs and Cosmetics Act and FSSAI regulations impose additional restrictions on claims made by health, wellness, and food brands.
We work with marketing and products teams – not just the legal team – because compliance in advertising is as much a product design and copyright question, as a legal one. We review campaigns, advice on influencer contract and promotional structures to keep marketing compliant.
Key areas:
- Dark pattern audit and product design compliance
- Influencer agreements and ASCI disclosures
- Advertising claim substantiation and pre-launch reviews
- Consumer complaint response and ASCI representation
Dispute resolution and consumer grievance management
For e-commerce businesses, a high volume of transactions creates a corresponding exposure to consumer forum proceedings that often drain on management time and resources if not handled systematically. Consumer forums, arbitration proceedings, and platform-mediated disputes require fast, well-prepared responses.
We design internal grievance redressal systems that meet the statutory requirements for response timelines and appointed officers, and that resolve complaints efficiently before they escalate to forum proceedings. We also represent clients in proceedings before Consumer Dispute Redressal Commissions, arbitration tribunals, and civil courts.
Key areas:
- Internal grievance redressal system design
- Arbitration clause drafting and proceedings
- Seller and vendor dispute resolutions
- Representation in consumer disputes
Why Corrida Legal?
Our lawyers speak the language of your business. We understand how D2C growth loops work, why a 3PL agreement matters more than what founders think and how a consumer grievance escalation path should be designed. When businesses approach us, less time is spent on context and more on getting to the advice needed. With e-commerce regulation moving across DPIIT, MeitY, RBI, CCI, FSSAI and CDSCO, a single question about a product launch may touch tax, IP, consumer law and competition law. We not only follow each of these regulatory conversations and share regular briefings with clients on developments affecting their business before the developments become compliance obligations, but our integrated team ensures that you get coordinated advice, not competing memos from separate departments.
We don’t believe in one-size-fits-all legal advice. We understand your business, your ambitions, and deliver counsel that’s tailored to both. Whether you’re launching, scaling, or navigating a specific legal challenge — we’d like to understand your situation before we say anything else.
FAQs
Do all e-commerce businesses need customised Terms of Use and Privacy Policies?
Yes. Standard templates rarely reflect how your business actually operates. Your customer-facing documents should be tailored to your business model, comply with applicable laws, and help reduce legal risk if disputes arise.
Are D2C businesses required to comply with the Digital Personal Data Protection Act?
If the business collects customer information through its website, app, marketing campaigns, or payment systems, then its likely subject to obligations under the DPDP Act. Merely updating the privacy policy does not amount to compliance under the Act.
What is the difference between an inventory model and a marketplace model and why does it matter?
The main distinction between an inventory model and a marketplace model lies in who owns the stock and how the platform operates. In inventory model, the platform owns and sells the goods directly, whereas in marketplace it acts as a matchmaking platform connecting independent sellers and buyers. The distinction affects foreign investment, platform operations, and regulatory compliance. Choosing the right structure at the outset can prevent costly restructuring and regulatory scrutiny later.
Can an online business be held liable for products supplied by third-party sellers?
In many situations, yes. Liability depends on your business model, platform design, contractual arrangements, and compliance with consumer protection laws.
When should an e-commerce business involve a lawyer?
Ideally before launching a platform, introducing a new product line, expanding internationally, raising investment, or implementing new customer-facing features—not only after receiving a legal notice.
Are influencer collaborations and online advertising legally regulated?
Yes. Marketing campaigns, influencer partnerships, discount offers, and product claims are subject to advertising and consumer protection laws.
Should standard business contracts with logistics and payment partners also be reviewed?
Most standard contracts are drafted to protect the service provider, not the business. A legal review helps ensure risk, liability, service levels, and termination rights are appropriately balanced.
How can one protect the brand from counterfeit sellers on online marketplaces?
Trademark registration is only the first step. Effective brand protection also includes marketplace enforcement strategies, take-down notices, monitoring programmes, and enforcement against repeat infringers.
What should investors look for during legal due diligence of an e-commerce company?
Common areas include corporate records, intellectual property ownership, commercial contracts, regulatory compliance, data privacy practices, employment documentation, and pending disputes.
Can a law firm act as ongoing legal counsel instead of assisting only on individual matters?
Absolutely. Many growing businesses prefer ongoing legal support that evolves with their operations, allowing legal risks to be identified early rather than addressed only after they become disputes.


