Most privacy policies are written to be skimmed past, not read — a wall of legal text nobody clicks through before hitting "I agree." That's exactly the habit India's Digital Personal Data Protection Act, 2023 is designed to break. Under the DPDP framework, a privacy notice isn't just a formality sitting in your footer; it has specific, plain-language content requirements, and getting it wrong isn't a small compliance gap — it undermines the legal basis for collecting your users' data in the first place.
Here's what a privacy policy in India actually needs to contain now, and where a lot of businesses are still getting it wrong.
Before the DPDP Act, privacy obligations in India were scattered across the IT Act and its rules, which left a lot of businesses treating privacy policies as boilerplate. The DPDP Act changes that by making consent the primary legal basis for processing personal data, and consent is only valid if it's backed by a proper notice. In other words, a vague or generic privacy policy doesn't just look unprofessional — it can mean the consent you're relying on isn't actually valid consent at all.
The Act applies to any organisation processing digital personal data of individuals in India, and there's no exemption for small businesses or startups based on size or turnover. If your website collects a name, email, or phone number through a login form, a contact form, or a checkout page, you're a Data Fiduciary under this law, and the notice obligations apply to you.
Section 5 of the Act and the accompanying Rules are specific about this, more specific than most existing privacy policies currently reflect. At minimum, your notice needs:
The notice also has to stand on its own — understandable independently of anything else you've published — and be written in plain, clear language, not buried in dense legal phrasing. It needs to be available in English or in any one of the 22 languages listed in the Eighth Schedule of the Constitution, based on what the user prefers; it doesn't mean you have to publish it in every language simultaneously, just that the option needs to exist.
Under the Act, consent isn't valid just because a user clicked "accept." It has to be freely given, specific to the stated purpose, informed, and unconditional — meaning you can't make access to your service conditional on consent for something unrelated to actually providing that service. Bundled, blanket consent covering multiple unrelated purposes doesn't meet this bar either; each purpose needs its own clear basis.
Withdrawal matters just as much as collection. The Act requires that withdrawing consent be just as easy as giving it was — if signing up took one click, revoking consent shouldn't require an email, a phone call, and a three-day wait.
Users — referred to as "Data Principals" under the Act — have specific rights your privacy policy should clearly explain, along with how to actually exercise them:
A policy that mentions these rights in the abstract without giving users an actual method to exercise them doesn't really meet the standard. There needs to be a real point of contact, not just a statement that the rights exist.
If your platform is likely to be used by children, or if you knowingly collect data from minors, the Act requires verifiable consent from a parent or guardian before processing that child's data. This verification can be done through existing information you hold, details the parent provides directly, or through recognised digital verification mechanisms. If your site has any reasonable likelihood of a younger audience, this is worth addressing explicitly in your policy rather than assuming it doesn't apply.
Under the erasure framework in the Act, personal data has to be deleted once its purpose has been served — whether because consent was withdrawn, the stated purpose has been fulfilled, or a user simply hasn't engaged with your service within a defined retention period. Your policy should be specific about your retention timelines rather than leaving this open-ended, since vague retention language is one of the more common gaps auditors and regulators flag.
The Act requires notifying both the Data Protection Board and affected users in the event of a personal data breach, and the notification needs to include a plain-language description of what happened, what data was exposed, what steps individuals can take to protect themselves, and how to reach you with questions. Your privacy policy should at least reference this process, even if the detailed breach response procedure lives in an internal document rather than the public-facing policy itself.
If your website collects any personal data — even something as basic as an email address through a contact form — you're generally considered a Data Fiduciary under the DPDP Act, and the Act's notice and consent requirements apply, regardless of your business size.
A privacy notice, as defined under Section 5 of the DPDP Act, is a specific, plain-language disclosure tied to a particular instance of data collection. A privacy policy is typically the broader document a business publishes, which should incorporate the notice requirements along with other disclosures like retention timelines and grievance mechanisms.
You can, but many generic templates, especially ones built around GDPR, don't reflect the DPDP Act's specific requirements around itemised data descriptions, consent withdrawal mechanisms, and grievance escalation to the Data Protection Board. A generated template is a starting point, not a finished, compliant document.
It needs to be available in English or in any of the 22 languages listed in the Eighth Schedule of the Constitution, based on what the individual prefers. This doesn't require simultaneous publication in every language, only that the option exists.
Beyond regulatory risk, an inadequate notice can undermine the validity of the consent you're relying on to process user data in the first place, which has broader implications for how legally sound your data collection practices are overall.
Yes. If your platform is likely to be used by minors, the DPDP Act requires verifiable parental or guardian consent before processing a child's personal data, and this should be addressed explicitly in your policy rather than left unaddressed.