Operate · Notices, Policies & Consent

Privacy notices and consent under DPDP

The Act asks for a notice, not a policy — and your privacy policy almost certainly cannot do the notice’s job.

Talk to us Why your policy is not a notice Written documents, in the languages you actually need them in.
The thing almost everyone has wrong

A privacy policy is not a notice

They are different documents doing different jobs, and only one of them is named in the law.

What the Act asks for

  • A notice, under section 5, given with or before every request for consent
  • Understandable on its own — Rule 3 says independently of anything else
  • In clear and plain language, not the register your terms are written in
  • An itemised list of the data and the purpose — not a category summary
  • Three routes named: withdraw consent, exercise rights, complain to the Board
  • Available in English or any of the twenty-two Eighth Schedule languages

What a privacy policy is

  • A general statement about the company, covering everything at once
  • Written to be linked from a footer and read by almost nobody
  • Usually broad by design — which is the opposite of itemised
  • Frequently the place a notice is buried, which defeats Rule 3’s standalone test
  • Still worth publishing — procurement, app stores and other laws expect one

Publish both. Just stop asking one of them to do the other’s work.

The practical consequence is specific. A single company-wide privacy policy, linked from the footer, cannot serve as the notice for a patient registration form, a job application and a marketing sign-up at once — because a notice is tied to this collection, for this purpose, at the moment it happens.

What we actually do

The engagement, in four steps

The writing is the last step, not the first. Starting with a draft is how you end up with a notice that describes somebody else’s business.

1

We sort your purposes by lawful basis

Every purpose placed: section 6 consent, or a named legitimate use under section 7. This is the step that shortens everything afterwards, and the one templates skip.

2

We write a notice per collection point

Standalone, itemised, in plain language, with the three routes named — one for registration, one for hiring, one for marketing, rather than one for the company.

3

We translate into the languages you serve

Chosen from who actually walks through your door, not all twenty-two. Translating into languages nobody asks for is cost with no compliance return.

4

We deal with everyone already on your books

The section 5(2) notice owed to people who consented before the Act, drafted and planned for delivery — the obligation established businesses most often have not scoped.

Alongside those, the documents nobody sees but an auditor asks for first: the retention, access and breach-response policies, and a consent record designed so section 6(10) can actually be discharged. All of it in your words, and yours to edit afterwards.

§5 · Rule 3

What has to be in it

Short list, and the failures are nearly always the same three: not standalone, not itemised, and missing one of the three routes.

Rule 3₹50 Cr

Presented so it can be understood on its own, without reading your terms, your policy or anything else.

Standalone
Rule 3₹50 Cr

An itemised description of the personal data. “Contact details” is a category; name, mobile and address are items.

Itemised
Rule 3₹50 Cr

The purpose, with an itemised description of what the person actually gets from it. Not “to improve our services”.

Purpose
Rule 3(c)₹50 Cr

How to withdraw consent, how to exercise rights, and how to complain to the Data Protection Board. All three, named.

Three routes
§5(3)₹50 Cr

English or any language in the Eighth Schedule, at the person’s option. Twenty-two of them, and you choose which you need.

Language
§6(10)₹50 Cr

You must be able to demonstrate the notice was given and the consent was given. Having collected it is not the same as being able to show it.

Provable

The last one changes how the other five are built. A notice you cannot later produce — in the version that was live on the day, in the language the person read — is a notice you cannot rely on. Which is why version history is a drafting decision, not a filing decision.

§5(2)

The notice you owe people who already said yes

This one catches almost every established business, and almost nobody has a plan for it.

01

It applies backwards

Where somebody consented before the Act commenced, you must give them a notice as soon as reasonably practicable. Not at renewal. Not next time they visit.

02

Your whole existing base

Every patient, customer, candidate and subscriber already on your records. For most businesses that is a far larger number than anyone signing up next year.

03

You may keep processing

Sending the notice does not pause your business. You continue until the person withdraws — which is exactly why the notice has to explain how they can.

04

It is a delivery problem

Tens of thousands of people, contact details of varying quality, several languages, and a record needed of who was reached and when.

05

And a drafting problem first

The notice has to describe what you have been doing with their data, which means somebody has to establish that honestly before a word is written.

The deliverables

What you actually receive

Documents, in your own words, that your team can maintain after we stop being involved.

Facing your customers

  • A notice for each collection point, not one notice for the company
  • Translations into the Eighth Schedule languages your people actually read
  • A published privacy policy, doing the job a policy is genuinely for
  • Consent wording, and the form design that makes withdrawal equally easy
  • The section 5(2) notice for your existing base, with a plan for delivering it
  • Children’s flows where they apply, including how a parent is verified

Facing your regulator

  • A purpose map: which purposes rest on consent, and which on section 7
  • Retention, access and breach-response policies your team can follow
  • A consent record designed so section 6(10) can actually be discharged
  • Version history, so you can produce the notice that was live on any given day
  • A note of what we changed and why, which is what an auditor asks first

Drafted by Indian privacy practitioners, and yours to edit — not locked inside a tool you have to keep paying for.

Most notices fail on structure, not wording.

The language is usually fine. It is standalone, itemised and the three routes that are missing — and no amount of rewriting fixes a document in the wrong place.

Questions

Straight answers

We already have a privacy policy. Is that not enough?

Almost certainly not, and it is the most common misunderstanding we meet. The Act names a notice under section 5, and Rule 3 requires it to be presented so it can be understood independently of any other information, in clear and plain language, with an itemised description of the personal data and the purpose. A company-wide policy linked from your footer is broad by design and covers everything at once — which is the opposite of itemised, and cannot be tied to the moment a particular person hands over particular data. Keep the policy; procurement teams and app stores expect one. Just do not let it stand in for the notice.

Do we really have to notify customers who signed up years ago?

Yes. Section 5(2) says that where a person gave consent before the Act commenced, you must give them a notice as soon as reasonably practicable — informing them of the personal data and the purpose it has been processed for, how to exercise their rights and withdraw, and how to complain to the Board. The relief is that you may continue processing until they withdraw, so this is not a business interruption. It is a drafting and delivery exercise across your whole existing base, and it is the obligation established businesses are most likely not to have scoped at all.

Is it safer to just ask for consent for everything?

No, and this is worth being blunt about because the instinct is so common. Consent under section 6 carries a withdrawal right under section 6(4). If you ask for consent to something you would lawfully continue under section 7 — treating a patient, running payroll — you have created a switch you cannot honour when somebody flips it. Section 6(1) also requires consent to be free and unconditional, and section 6(2) voids any part that infringes the Act, so consent you would ignore if refused was never valid consent. The first piece of work is sorting purposes by lawful basis. The writing comes after.

How many languages do we actually need?

Section 5(3) gives the person the option of English or any language in the Eighth Schedule — twenty-two of them. That is an option they hold, not twenty-two documents you must publish on day one. In practice you choose from who you actually serve: a hospital in Indore needs Hindi and English before anything else, and a national platform needs a wider set. We help you decide honestly, because translating into languages nobody asks for is a cost with no compliance return, and missing the one your patients speak is the opposite.

Can we not just download a template?

You can, and for a simple business it may get you most of the way. The parts a template cannot supply are the ones that fail: the itemised list of what you collect, the purposes you pursue, whether each rests on consent or a legitimate use, and which of your forms and screens the notice has to appear on. A template is a shape. Most of the work is what goes in it, and a generic notice that does not describe your actual processing is worse than useless because it looks compliant.

Does this include the internal policies as well?

Yes — retention, access control and breach response, written so your team can follow them rather than admire them. Worth knowing that the Act does not name these documents the way it names the notice; they exist because Rule 6 requires specific security safeguards, Rule 8 governs erasure, and Rule 7 sets what happens in a breach, and none of those can be discharged by people improvising. A policy nobody follows is evidence against you, so we keep them short enough to be followed.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

Start with the notice.

It is the one document the Act names, the first thing anyone will look at, and the cheapest thing on this site to get right.