A data flow diagram (DFD) for an e-commerce website maps how customer orders, payments, inventory, and product data flow between the store, customers, admins, and payment gateways. Panel reviewers in 2026 expect a proper DFD to cover three levels (Context, Level 1, Level 2), include current-year payment integrations (GCash, PayMongo, Stripe), and align with the RA 10173 Data Privacy Act. This 2026 guide walks through the full DFD structure with clear examples for BSIT capstone defense.
Quick 2026 verdict
A defensible e-commerce DFD in 2026 has: 5-7 external entities (Customer, Admin, Payment Gateway, Courier, Supplier, PhilHealth/BIR for enterprise, Marketing Platform), 8-10 processes at Level 1 (Register, Login, Browse, Cart, Checkout, Pay, Fulfill, Track, Return, Report), and 6-8 data stores (Customers, Products, Orders, Payments, Inventory, Shipments, Reviews, Promotions). Skip any and panels notice. Add current-year payment flows and privacy notation to score above 90%.
What a DFD for e-commerce actually captures
A DFD is not the same as a flowchart or ER diagram. It shows data movement between processes, entities, and stores, not code logic or database structure. For an e-commerce project, the DFD answers: where does customer information come from, who processes each order, where do product stocks live, and how does payment confirmation flow back to the shipping team.
Panel reviewers grade the DFD on four dimensions: notation consistency (Gane-Sarson OR Yourdon-DeMarco, not mixed), decomposition correctness (Level 1 must faithfully expand what Level 0 promised), completeness (all real-world data flows shown), and current-year relevance (2026 payment methods, privacy compliance).
Level 0 (context diagram)
Level 0 shows the entire e-commerce system as a single process. Every arrow enters or leaves this one central process, connecting it to external entities.
Customer -----> [E-commerce System] <----- Admin
^ ^
| |
Payment Gateway Supplier / Vendor
| |
v v
Courier Marketing PlatformExternal entities (represented as squares) that a 2026 e-commerce DFD must include:
- Customer: browses products, places orders, pays, receives confirmation, tracks shipment
- Admin: manages products, inventory, promotions, and reviews orders
- Payment Gateway: PayMongo, GCash Merchant, Stripe, or PayPal (pick the one your project uses)
- Courier: LBC, J&T, Ninja Van, or similar shipping partner (returns tracking data)
- Supplier / Vendor: restocks inventory data flows in from external supplier feeds
- Marketing Platform: Meta, TikTok, or Google Ads if the project includes promo tracking
Level 1 (main process decomposition)
Level 1 breaks the single “E-commerce System” process into 8-10 sub-processes. Every arrow at Level 0 must still be present at Level 1, either as an input to or output from these sub-processes.
- 1.0 Register / Login: input from Customer (credentials, name, email); reads and writes to
D1: Customers - 2.0 Browse Products: input from Customer (search query, filter); reads from
D2: Products; returns product list - 3.0 Manage Cart: reads product data from
D2; stores temporary cart items inD3: Carts - 4.0 Checkout: reads cart, computes total; writes new record to
D4: Orders - 5.0 Process Payment: sends transaction to Payment Gateway; receives confirmation; writes to
D5: Payments - 6.0 Fulfill Order: decrements stock in
D6: Inventory; creates shipment record inD7: Shipments - 7.0 Ship & Track: sends shipment data to Courier; receives tracking updates back
- 8.0 Handle Returns: input from Customer (return request); updates
D4andD6 - 9.0 Manage Admin: Admin input for product CRUD, promotion setup, order review
- 10.0 Generate Reports: reads across
D2, D4, D5to produce sales, inventory, and revenue reports
Data stores (represented as parallel horizontal lines with an ID label):
D1: Customers(name, email, hashed password, address, contact number, consent flag)D2: Products(SKU, name, description, price, category, image URL, stock level)D3: Carts(session ID, product IDs, quantities, timestamps)D4: Orders(order ID, customer ID, total, status, order date)D5: Payments(payment ID, order ID, method, transaction reference, status)D6: Inventory(SKU, current stock, reorder threshold, supplier ID)D7: Shipments(shipment ID, order ID, courier, tracking number, delivery date)D8: Reviews(review ID, customer ID, product ID, rating, comment, timestamp)
Level 2 (focused sub-process zoom)
Level 2 zooms into one Level 1 process and shows its internal sub-flows. Do not try to expand every Level 1 process into Level 2 in one diagram. Pick 2-3 of the most complex processes and give each its own Level 2 diagram.
The three highest-value Level 2 decompositions for e-commerce defense:
- 5.0 Process Payment expanded into 5.1 Validate Card, 5.2 Send to Gateway, 5.3 Receive Response, 5.4 Update Payment Status, 5.5 Send Receipt to Customer
- 6.0 Fulfill Order expanded into 6.1 Check Stock, 6.2 Reserve Inventory, 6.3 Print Packing Slip, 6.4 Update Order Status to “Ready to Ship”
- 8.0 Handle Returns expanded into 8.1 Verify Return Eligibility, 8.2 Process Refund via Gateway, 8.3 Restock Item, 8.4 Update Customer Communication
2026 current-year data flows to include
Panels notice when a DFD looks like a 2018 template. Add these current-year flows to show the project is modern:
- GCash / PayMongo / Stripe integration in the Payment Gateway entity, not just generic “credit card”
- Cash on Delivery (COD) sub-flow in Fulfill Order because 75% of Filipino e-commerce is still COD in 2026
- Voucher / promo code redemption in Checkout, reading from a new
D9: Promotionsdata store - Product reviews and ratings via
D8: Reviewswith a moderation flow to Admin - AI product recommendations if the project uses collaborative filtering or a Claude/GPT API, shown as an external service reading from
D2andD4 - Data Privacy Act consent flow from Register process, storing consent flag and timestamp in
D1
Common Level 1 mistakes reviewers catch
- Missing the Return process entirely (every e-commerce site has returns; a DFD without it looks incomplete)
- Payment shown as one flat process instead of decomposed into request, response, and status update
- Inventory not connected to Fulfill Order (stock decrement missing = reviewers flag it)
- Admin entity only shows product management, not order review or promo setup
- Reviews data store missing (major e-commerce trust signal in 2026)
- No data flow from Payment Gateway back into the system (payment success confirmation missing)
- Marketing Platform not present but the paper claims social media integration
Comparison: Gane-Sarson vs Yourdon-DeMarco notation
| Element | Gane-Sarson | Yourdon-DeMarco |
|---|---|---|
| Process | Rounded rectangle | Circle |
| External Entity | Square with shadow | Square (flat) |
| Data Store | Open rectangle with ID | Two parallel lines with ID |
| Data Flow | Arrow with label | Arrow with label |
Pick one notation and use it consistently across Level 0, 1, and 2. Mixing notations is the fastest way to lose 5-10 points at defense.
Free tools to draw the diagram
Draw.io (diagrams.net) is the free default in 2026 with a full DFD notation library. Lucidchart offers cleaner exports but the free tier caps at 3 documents. PlantUML is text-based (good for version-controlled capstone repos). Avoid Rational Rose, SmartDraw, and the crippled Visual Paradigm free edition unless your school specifically requires them.
Frequently Asked Questions
How many levels does an e-commerce DFD need?
Three levels for BSIT capstone: Level 0 (context, single process), Level 1 (8-10 main sub-processes), and Level 2 (zoom into 2-3 of the most complex Level 1 processes like Payment, Fulfillment, and Returns). Going to Level 3 is overkill and rarely helps defense.
Do I need to show payment methods separately in the DFD?
Yes. Panels in 2026 expect at least 2 named payment methods in the Payment Gateway entity: one online (GCash, PayMongo, or Stripe) and Cash on Delivery. Generic “credit card” as the only option looks dated. Show COD as a separate flow because 75% of Philippine online shoppers still choose it.
What is the difference between a DFD and a flowchart?
A DFD shows data movement between processes, entities, and stores. A flowchart shows decision logic and sequence of steps. A DFD does not have “if” or “loop” symbols; a flowchart does. For BSIT capstone Chapter 3, you usually need both, and they serve different purposes.
How do I show Data Privacy Act compliance in the DFD?
Add a note or annotation on the Customers data store: “Governed under RA 10173, retention 5 years post-account-deletion.” Add a consent-verification data flow from Register to Customers. Panels in 2026 explicitly check for privacy notation on any store holding personal information.
Should I include AI product recommendations in a 2026 DFD?
Only if your project actually implements it. If your paper claims AI-powered recommendations but the DFD does not show it, reviewers flag the mismatch. Show it as an external service reading from Products and Orders, then sending suggestion data back to the Browse Products process.
Which is easier for defense: Gane-Sarson or Yourdon-DeMarco?
Yourdon-DeMarco (circles for processes) is slightly more common in Philippine BSIT textbooks. Gane-Sarson (rounded rectangles) is more common in enterprise documentation. Pick whichever your adviser prefers. What matters most is consistency across all three levels.
Related UML tutorials
- DFD for Library Management System Data Flow Diagram
- DFD for Hospital Management System Data Flow Diagram
- Data Flow Diagram for Online Shopping System
- Student Management System Class Diagram UML
