Website Privacy Policy India: DPDP Act Requirements & Guide (2026)

Website Privacy Policy

  • Legal Documentation
  • Website Privacy Policy

Website Privacy Policy Under India's DPDP Act: What It Actually Needs to Say

Most privacy policies are written to be skimmed past, not read — a wall of legal text nobody clicks through before hitting "I agree." That's exactly the habit India's Digital Personal Data Protection Act, 2023 is designed to break. Under the DPDP framework, a privacy notice isn't just a formality sitting in your footer; it has specific, plain-language content requirements, and getting it wrong isn't a small compliance gap — it undermines the legal basis for collecting your users' data in the first place.

Here's what a privacy policy in India actually needs to contain now, and where a lot of businesses are still getting it wrong.

Why This Isn't Just a Formality Anymore

Before the DPDP Act, privacy obligations in India were scattered across the IT Act and its rules, which left a lot of businesses treating privacy policies as boilerplate. The DPDP Act changes that by making consent the primary legal basis for processing personal data, and consent is only valid if it's backed by a proper notice. In other words, a vague or generic privacy policy doesn't just look unprofessional — it can mean the consent you're relying on isn't actually valid consent at all.

The Act applies to any organisation processing digital personal data of individuals in India, and there's no exemption for small businesses or startups based on size or turnover. If your website collects a name, email, or phone number through a login form, a contact form, or a checkout page, you're a Data Fiduciary under this law, and the notice obligations apply to you.

Website Privacy Policy Under India's DPDP Act

What a DPDP-Compliant Notice Must Actually Say

Section 5 of the Act and the accompanying Rules are specific about this, more specific than most existing privacy policies currently reflect. At minimum, your notice needs:

  • An itemised description of the data being collected — not "we collect personal information," but specifically what: name, email, phone number, location, payment details, and so on
  • A specific description of the purpose for each category of data, tied to an actual business function rather than a vague catch-all
  • A working communication link through which a user can withdraw consent, exercise their rights, or reach you with a complaint
  • How to escalate to the Data Protection Board of India, if the matter isn't resolved directly with you

The notice also has to stand on its own — understandable independently of anything else you've published — and be written in plain, clear language, not buried in dense legal phrasing. It needs to be available in English or in any one of the 22 languages listed in the Eighth Schedule of the Constitution, based on what the user prefers; it doesn't mean you have to publish it in every language simultaneously, just that the option needs to exist.

Consent Has to Meet a Specific Standard

Under the Act, consent isn't valid just because a user clicked "accept." It has to be freely given, specific to the stated purpose, informed, and unconditional — meaning you can't make access to your service conditional on consent for something unrelated to actually providing that service. Bundled, blanket consent covering multiple unrelated purposes doesn't meet this bar either; each purpose needs its own clear basis.

Withdrawal matters just as much as collection. The Act requires that withdrawing consent be just as easy as giving it was — if signing up took one click, revoking consent shouldn't require an email, a phone call, and a three-day wait.

Data Principal Rights Your Policy Needs to Address

Users — referred to as "Data Principals" under the Act — have specific rights your privacy policy should clearly explain, along with how to actually exercise them:

  • The right to access what personal data you hold about them
  • The right to correction of inaccurate or outdated data
  • The right to erasure once the purpose for which the data was collected is no longer being served
  • The right to a grievance redressal mechanism, and, if unresolved, escalation to the Data Protection Board

A policy that mentions these rights in the abstract without giving users an actual method to exercise them doesn't really meet the standard. There needs to be a real point of contact, not just a statement that the rights exist.

Children's Data and Verifiable Consent

If your platform is likely to be used by children, or if you knowingly collect data from minors, the Act requires verifiable consent from a parent or guardian before processing that child's data. This verification can be done through existing information you hold, details the parent provides directly, or through recognised digital verification mechanisms. If your site has any reasonable likelihood of a younger audience, this is worth addressing explicitly in your policy rather than assuming it doesn't apply.

What Happens When Data Is No Longer Needed

Under the erasure framework in the Act, personal data has to be deleted once its purpose has been served — whether because consent was withdrawn, the stated purpose has been fulfilled, or a user simply hasn't engaged with your service within a defined retention period. Your policy should be specific about your retention timelines rather than leaving this open-ended, since vague retention language is one of the more common gaps auditors and regulators flag.

If There's Ever a Data Breach

The Act requires notifying both the Data Protection Board and affected users in the event of a personal data breach, and the notification needs to include a plain-language description of what happened, what data was exposed, what steps individuals can take to protect themselves, and how to reach you with questions. Your privacy policy should at least reference this process, even if the detailed breach response procedure lives in an internal document rather than the public-facing policy itself.

Where Existing Privacy Policies Usually Fall Short

  • Reusing a GDPR-style policy without adapting it — GDPR runs on six lawful bases for processing; the DPDP Act works primarily on consent and a narrower set of legitimate uses, so a policy built for European law often doesn't map cleanly onto Indian requirements
  • Vague data descriptions like "we may collect information about you," instead of an actual itemised list
  • No real mechanism to exercise rights — mentioning access or erasure rights without a working link or contact method to act on them
  • Burying the core notice in dense legal language, when the Rules specifically call for plain, accessible wording
  • No clear retention or deletion timeline, leaving data indefinitely without a stated reason
  • Treating the privacy policy as separate from the terms and conditions, when the two documents need to be consistent with each other, especially around data-related language

Frequently Asked Questions

If your website collects any personal data — even something as basic as an email address through a contact form — you're generally considered a Data Fiduciary under the DPDP Act, and the Act's notice and consent requirements apply, regardless of your business size.

A privacy notice, as defined under Section 5 of the DPDP Act, is a specific, plain-language disclosure tied to a particular instance of data collection. A privacy policy is typically the broader document a business publishes, which should incorporate the notice requirements along with other disclosures like retention timelines and grievance mechanisms.

You can, but many generic templates, especially ones built around GDPR, don't reflect the DPDP Act's specific requirements around itemised data descriptions, consent withdrawal mechanisms, and grievance escalation to the Data Protection Board. A generated template is a starting point, not a finished, compliant document.

It needs to be available in English or in any of the 22 languages listed in the Eighth Schedule of the Constitution, based on what the individual prefers. This doesn't require simultaneous publication in every language, only that the option exists.

Beyond regulatory risk, an inadequate notice can undermine the validity of the consent you're relying on to process user data in the first place, which has broader implications for how legally sound your data collection practices are overall.

Yes. If your platform is likely to be used by minors, the DPDP Act requires verifiable parental or guardian consent before processing a child's personal data, and this should be addressed explicitly in your policy rather than left unaddressed.

WhatsApp