← Back to Knowledge Hub

Most privacy policies in India were never written to be read. They were copied from a US or EU template, dropped into the website footer, and forgotten. Under the DPDP Act, that document stops being a formality and becomes a legal instrument β€” the place where you prove you gave people clear notice before taking their data. Get it wrong and it's evidence against you; get it right and it's your first line of defence.

Here's exactly what a DPDP-compliant privacy notice has to contain, how it differs from the policy you probably have now, and a section-by-section structure you can build from.

Quick answer: Under the DPDP Act, your privacy notice must be a standalone, plain-language document that itemises exactly what personal data you collect, the specific purpose for each, how individuals exercise their rights, and how to reach your Grievance Officer. It must be available in English and the scheduled Indian languages, shown before or at the point of consent, and must not bury or pre-tick anything. Full compliance is required by 13 May 2027, but this is a document to fix now.

Why your current privacy policy probably fails

The typical Indian privacy policy fails the DPDP test for predictable reasons: it speaks in vague generalities ("we may collect certain information"), it lumps every purpose together, it offers no real way to exercise rights, it names no contact for grievances, and it exists only in English. The Act demands the opposite of all five. Vagueness was acceptable under the old IT Act regime. It isn't now.

What the DPDP notice rules actually require

Under Rule 3 of the DPDP Rules, the notice you give a Data Principal must:

  • be standalone and clear β€” understandable on its own, not buried inside long terms of service;
  • itemise the personal data you collect, category by category;
  • state the specific purpose of processing for each β€” not a catch-all "to improve our services";
  • explain how to exercise rights (access, correction, erasure, grievance, withdrawal of consent);
  • give the means to complain to the Data Protection Board; and
  • be available in English or any language in the Eighth Schedule of the Constitution.

The test is whether an ordinary person, reading it once, understands what you're taking and why.

Notice vs consent vs privacy policy β€” they're not the same

People blur these three, so let's separate them cleanly:

  • The notice is what you show the person before collecting data β€” the itemised, plain-language disclosure required by Rule 3.
  • Consent is the person's affirmative agreement to that processing β€” a separate act that must be free and specific.
  • The privacy policy is the broader public document on your site that houses your data practices.

In practice your privacy policy should contain a DPDP-compliant notice, and your consent flow should reference it. They work together; they aren't interchangeable.

Section-by-section: what to include

A DPDP-ready privacy policy generally needs these sections:

  1. Who we are β€” your legal name, role as Data Fiduciary, and contact.
  2. What we collect β€” an itemised list by category (identity, contact, financial, device, usage, etc.).
  3. Why we collect it β€” the specific purpose tied to each category, and the lawful basis (consent or a named legitimate use).
  4. Who we share it with β€” processors and third parties, and whether data goes outside India.
  5. How long we keep it β€” retention period per category, and your deletion practice.
  6. Your rights β€” access, correction, erasure, grievance, nomination, and consent withdrawal, with the exact steps to use each.
  7. Grievance Officer β€” name, email, and response timeline (grievances resolved within 90 days).
  8. Children's data β€” your approach to verifiable parental consent, if you process minors' data.
  9. Changes β€” how you notify updates.

The language requirement people overlook

This one trips up almost everyone. Your notice must be available in English and the scheduled Indian languages, so a user can read it in a language they understand. For a consumer-facing product that means building the notice into your localisation pipeline, not treating it as a one-off English document. It's a real engineering and translation task β€” start it early.

Dark patterns to remove immediately

The Rules ban manipulative consent design. If your current flow does any of the following, fix it now:

  • Pre-ticked consent boxes β€” consent must be an affirmative action.
  • A prominent "Accept" beside a hidden or greyed-out "Reject."
  • Consent walls that block access unless the user agrees to non-essential processing.
  • Bundled consent that forces agreement to unrelated purposes in one click.
  • Confusing or buried language designed to nudge a yes.
⚠️ Withdrawal of consent must be as easy as giving it. If saying yes is one click, saying no later must be one click too.

Worked example: rewriting one clause

Before (non-compliant): "We may collect certain personal information to provide and improve our services and for other business purposes."

After (DPDP-compliant): "We collect your name and email address to create and manage your account, and your device ID and usage data to keep the service secure and diagnose errors. We do not use this data for advertising. You can access, correct, or delete it any time from Settings, or by emailing our Grievance Officer at privacy@example.com, who will respond within 90 days."

Same idea, but now itemised, purpose-specific, rights-aware, and contactable. That's the whole shift in one paragraph.

Common mistakes

  • Hiding the notice inside the terms of service. It must be standalone.
  • Listing one vague purpose. Tie a specific purpose to each data category.
  • No Grievance Officer. A named, reachable contact is mandatory.
  • English only. Scheduled-language availability is required.
  • Copying a GDPR policy wholesale. It won't carry the India-specific notice and language rules.

Checklist

  1. Make the notice standalone and plain-language.
  2. Itemise data categories and tie a specific purpose to each.
  3. Add a full rights section with exact steps to use each right.
  4. Name a Grievance Officer with a 90-day response commitment.
  5. Provide the notice in scheduled Indian languages.
  6. Strip every dark pattern from your consent flow.
  7. State retention periods and cross-border transfers.

Frequently asked questions

Does the DPDP Act require a specific privacy policy format? It doesn't mandate a template, but it requires a standalone, itemised, plain-language notice covering data, purposes, rights, and grievance contact, available in scheduled languages.

Can I keep using my existing GDPR privacy policy? It's a useful base, but you must add the India-specific elements β€” scheduled-language availability, a Grievance Officer, DPDP rights, and Indian retention rules.

What languages must my privacy notice be in? English and/or any language listed in the Eighth Schedule of the Constitution, so users can read it in a language they understand.

Who is the Grievance Officer? A designated, reachable contact who handles Data Principal complaints and must resolve grievances within 90 days. Their details must be public.

When must my privacy policy comply? Full compliance is due by 13 May 2027, but because notice and consent are foundational, this is a fix-now task.

This article is for legal awareness and education only and is not legal advice. Confirm the current rules and your specific obligations, and consult a qualified professional before publishing a privacy policy.