DPDPA Rule 3 + DPDP Rules 2025 — Privacy Policy Complete Guide
A privacy policy is not optional under India's Digital Personal Data Protection Act, 2023. It is a legal requirement — and the gap between what most Indian businesses currently publish and what the law actually requires is enormous. Nine out of ten privacy policies on Indian websites today do not meet DPDPA standards — they are too vague, too generic, fail to name third parties, do not explain consent withdrawal, and are written in language no customer can actually understand. This guide gives you the complete framework: what Rule 3 requires, what every privacy policy must contain, the difference between a privacy policy and a consent notice, how to write in plain language, when and how to update, and what a compliant structure looks like — section by section, with a usable template and a full checklist.
₹50 Cr
Penalty for failure to give adequate notice to Data Principals — Section 5 violation
₹50 Cr
Penalty per consent violation — invalid privacy policy = invalid consent basis for every user
May 2027
Full enforcement deadline — every business must have a compliant privacy policy by then
0
Revenue threshold — even a one-person business collecting customer data needs a compliant policy
📋 What This Guide Covers
- What the DPDPA requires — Section 5 and Rule 3 decoded
- Privacy policy vs. consent notice — the critical distinction
- The 8 mandatory disclosures every privacy policy must include
- Plain language — what the law requires and how to achieve it
- Section-by-section privacy policy template — with commentary
- Cookie policy — what it must say under DPDPA
- Third-party disclosures — who you must name and why
- Grievance Officer — how to disclose this in your policy
- Children's data — special disclosures required
- Cross-border transfers — what to disclose and when
- How often to update your privacy policy — and how to notify users
- The complete DPDPA privacy policy checklist
- Common mistakes Indian businesses make — and how to avoid them
1. What the DPDPA Requires — Section 5 and Rule 3 Decoded
The legal obligation to maintain a privacy policy flows from two sources: Section 5 of the DPDPA, which creates the substantive obligation to give notice before collecting personal data, and Rule 3 of the DPDP Rules 2025, which prescribes the specific content, format, and delivery requirements for that notice.
📜 Section 5 — The Core Notice Obligation (Decoded)
Section 5(1): Before or at the time of collecting personal data, the Data Fiduciary must give the Data Principal a notice that is clear, plain language, and contains the items prescribed under the Rules.
Section 5(2): Where personal data was collected before the Act's commencement and the individual has not been given a notice under Section 5(1), the Data Fiduciary must give such notice as soon as reasonably practicable before making any further request for consent.
Rule 3 (DPDP Rules 2025): Prescribes that the notice must be in plain language, accessible in the language in which the consent is sought, and must contain specific items including the personal data to be processed, the purpose, the rights available, and how to exercise them. The notice must be separate from any other document (such as terms of service).
❌ What "Notice" Does NOT Mean Under DPDPA
- A generic "we respect your privacy" statement
- A cookie banner that links to a PDF nobody reads
- A paragraph buried in page 7 of your Terms of Service
- A document copied from another company's website
- A notice given only after data collection has already happened
✅ What "Notice" MEANS Under DPDPA
- A standalone document accessible at a permanent URL
- Given before or at the time of data collection
- Written in plain, clear language the user can actually understand
- Containing all 8 mandatory items prescribed by Rule 3
- Separate from Terms of Service and any other contract
2. Privacy Policy vs. Consent Notice — The Critical Distinction
One of the most common and consequential misunderstandings in DPDPA compliance is treating the privacy policy and the consent notice as the same document. They are not — and conflating them creates legal risk under both Section 5 (notice) and Section 6 (consent).
| Dimension |
🔵 Privacy Policy (Section 5 Notice) |
🟢 Consent Notice (Section 6) |
| Legal Function |
Informs the Data Principal about all data processing activities — provides transparency across the full scope of what you do with data |
Seeks active agreement for a specific purpose — is the mechanism by which consent (a lawful basis) is obtained |
| When Delivered |
Before or at the time of any data collection — and must be accessible at all times via a permanent URL |
Immediately before the specific processing activity that requires consent — at sign-up, at checkout, at opt-in |
| Scope |
Covers ALL data processing activities — transactional, marketing, analytics, HR, everything the organisation does with personal data |
Covers ONE specific purpose — one consent notice per processing purpose (marketing emails, WhatsApp, advertising, etc.) |
| Action Required |
No action required from the user to read it — but must be accessible and must have been given before data collection begins |
Active affirmative action required — an explicit opt-in (checkbox, button click, or equivalent) |
| Relationship |
May reference or link to specific consent notices — but is a standalone document separate from them |
Must reference and be consistent with the privacy policy — consent notices should not contradict what the privacy policy states |
| Common Mistake |
Using the privacy policy as the consent mechanism — "by using this website, you consent to our privacy policy" is invalid consent under Section 6 |
Using one consent notice for multiple purposes — a single "I agree to all marketing" opt-in that covers email, SMS, WhatsApp, and advertising simultaneously is invalid under Section 6(2) |
The practical rule: Your website needs both — a Privacy Policy (the comprehensive disclosure document, accessible at all times) and separate Consent Notices (presented at specific moments when you seek active consent for specific purposes). This guide covers the Privacy Policy. If you need guidance on Consent Notices, speak to our compliance team.
3. The 8 Mandatory Disclosures Every Privacy Policy Must Include
Rule 3 of the DPDP Rules 2025 prescribes the minimum content of a DPDPA notice. Every one of these elements is mandatory — a privacy policy missing any of them is non-compliant regardless of how well-written everything else is.
1
The Personal Data Being Collected
MANDATORY
You must specifically identify the categories of personal data your organisation collects. Generic language like "we collect information you provide" is insufficient. The policy must list: name, email, phone number, address, payment details, device identifiers, browsing data, location data — every type you actually collect. If you collect different types for different services or user groups, each must be listed. If you later start collecting a new data type, the policy must be updated.
Template language: "We collect the following categories of personal data: (a) Identity data — your full name, date of birth, and photograph; (b) Contact data — email address, phone number, and postal address; (c) Payment data — bank account or payment card details (tokenised); (d) Usage data — pages visited, features accessed, and time spent on our platform; (e) Device data — IP address, browser type, device identifier, and operating system."
2
The Purpose of Processing
MANDATORY
For each category of data, the policy must state the specific purpose for which it is collected. Purpose must be specific enough to be meaningful — "improving services" is not a purpose; "analysing feature usage to identify which functions are most used and prioritise development" is. Where different data types serve different purposes, these must be mapped clearly. Where you process data under legitimate use (without consent), the specific legitimate use ground must be stated.
Template language: "We process your personal data for the following purposes: (a) Account management — to create, verify, and maintain your account (lawful basis: contract necessity); (b) Order fulfilment — to process and deliver your orders (lawful basis: contract necessity); (c) Customer support — to respond to your queries and resolve complaints (lawful basis: contract necessity); (d) Marketing communications — to send you promotional emails and offers (lawful basis: your consent — see Section 6 below)."
3
Third Parties Who Receive or Process the Data
MANDATORY
Every third party who receives or processes personal data — including Data Processors — must be disclosed. This includes: payment gateways, delivery partners, cloud infrastructure providers, email marketing platforms, analytics tools, CRM systems, advertising networks, and government agencies. The policy does not need to list every individual sub-processor's name, but must at minimum identify the categories of third parties and the specific named entities for major data flows. Where data is shared with advertising networks (Meta, Google), this must be explicitly stated.
Template language: "We share your personal data with the following categories of third parties: (a) Payment processors — Razorpay / PayU, to process your transactions; (b) Logistics partners — [Delhivery / Bluedart / name your carrier], to deliver your orders; (c) Cloud infrastructure — Amazon Web Services (Mumbai region), which hosts our platform; (d) Email platform — [Klaviyo / Mailchimp], to send you transactional and marketing communications; (e) Analytics — Google Analytics, to understand how our platform is used."
4
Retention Periods
MANDATORY
For each category of personal data (or at minimum for the major categories), the policy must state how long the data is retained. Where retention is driven by a legal obligation, the legal basis must be cited. Where there is no fixed period, the policy must explain the criteria used to determine retention (e.g. "until you delete your account, plus 90 days for backup removal"). Vague language like "we retain data as long as necessary" is not compliant.
Template language: "We retain your personal data for the following periods: (a) Account data — for the duration of your account plus 30 days after deletion, or as required by applicable law; (b) Transaction records — 7 years from the date of transaction, in compliance with GST and accounting regulations; (c) Marketing consent records — until you withdraw consent, plus 2 years for audit purposes; (d) Customer support records — 2 years from the date the query was resolved; (e) Usage and analytics data — 13 months from collection, after which it is anonymised or deleted."
5
Data Principal Rights and How to Exercise Them
MANDATORY
The policy must explain each right the user has under Sections 11–14 and provide the specific mechanism for exercising it. Rights must be explained in plain language. The mechanism must be practical and accessible — an email address, a web form, or a settings panel. Telling users to "contact us" without providing contact details is non-compliant.
Template language: "You have the following rights regarding your personal data: (a) Right to information — you can request details of the personal data we hold about you and how we use it; (b) Right to correction — you can ask us to correct any inaccurate or incomplete data; (c) Right to erasure — you can ask us to delete your personal data, subject to any legal obligations that require us to retain certain records; (d) Right to withdraw consent — you can withdraw your consent to any marketing communication at any time by [clicking unsubscribe in any email / replying STOP to any WhatsApp message / updating your account preferences at [link]]; (e) Right to nominate — you can designate another person to exercise these rights on your behalf or after your death by contacting us at [email]. To exercise any of these rights, contact our Grievance Officer at [name] — [email] — [phone]."
6
Grievance Officer Contact Details
MANDATORY
Every Data Fiduciary must appoint a Grievance Officer under Section 13, and that officer's name, designation, and contact details must be published in the privacy policy. The contact mechanism must be functional and must result in a response — a generic contact form with no individual named does not satisfy this requirement. For SDFs, the Data Protection Officer's details must additionally be disclosed.
Template language: "Grievance Officer: [Full Name], [Designation], [Company Name]. Email: [grievance@yourcompany.com]. Phone: [+91-XXXXXXXXXX]. Hours: Monday to Friday, 10:00 AM to 6:00 PM IST. We will acknowledge your grievance within 48 hours and aim to resolve it within [30] days."
7
Consent Withdrawal Mechanism
MANDATORY
The policy must explain how consent can be withdrawn — and this mechanism must be as easy as giving consent (Section 6(4)). The withdrawal mechanism must be described for each type of consent given: email marketing (unsubscribe link), WhatsApp marketing (reply STOP), advertising cookies (cookie settings panel), account analytics (account settings toggle). Where consent is withdrawn, the policy must explain the consequences — what stops, and whether the underlying service continues.
Template language: "You can withdraw your consent at any time: (a) For email marketing — click 'Unsubscribe' in any marketing email. Your email address will be removed from all marketing lists within 24 hours. (b) For WhatsApp marketing — reply 'STOP' to any message from us. You will receive one final confirmation and no further marketing messages. (c) For advertising cookies — click 'Cookie Settings' in the footer of our website and toggle off 'Marketing Cookies'. Changes take effect immediately. Withdrawing consent does not affect the lawfulness of processing before withdrawal, and will not affect your ability to use our core services."
8
How Data Principals Will Be Notified of Changes to the Policy
MANDATORY
The policy must state how the organisation will notify users when the policy is updated — particularly where those changes affect existing consent or introduce new processing activities. Merely updating the policy at the same URL without informing users is insufficient for material changes. The notification method (email, in-app notification, website banner) and the timeline for providing notice before changes take effect must both be stated.
Template language: "We review and update this Privacy Policy at least once a year, and whenever our data practices change materially. For material changes — including new data types collected, new purposes, or new third-party sharing — we will: (a) Email you at the address on your account at least 30 days before the change takes effect, and (b) Display a prominent notice on our website homepage for at least 30 days. Non-material changes (such as corrections of typographical errors or clarifications that do not affect your rights) will be published without prior notice. The 'Last Updated' date at the top of this policy will always reflect the most recent revision."
4. Plain Language — What the Law Requires and How to Achieve It
Rule 3 explicitly requires that the privacy notice be in "clear and plain language" that the Data Principal can understand. This is not a stylistic preference — it is a legal requirement. A privacy policy written in dense legalese that the average user cannot understand fails Rule 3 even if it covers all 8 mandatory items.
❌ Language That Fails the Plain Language Standard
"The Data Controller may process personal data in reliance upon the legitimate interests ground where such processing is proportionate, necessary, and does not override the fundamental rights and freedoms of the data subject, including but not limited to purposes relating to direct marketing, fraud prevention, network and information security, and internal administrative purposes..."
Problems: Passive voice. Legal terminology. No specific example. Average user cannot extract any meaningful information about what actually happens to their data.
✅ The Same Information in Plain Language
"We use your email address to send you order updates and shipping notifications — this is necessary to complete your purchase. We also use your browsing history on our website to recommend products we think you might like. We never share your personal details with advertisers."
Better: Active voice. Specific examples. Explains what actually happens. No jargon. Users understand immediately what you do and do not do.
📝 The Plain Language Test — Apply to Every Paragraph
▶The 14-year-old test: Would a 14-year-old reading this paragraph understand what you actually do with their data? If not, rewrite it.
▶Active voice: Replace "data may be processed" with "we process your data." Subject, verb, object — in that order.
▶No undefined legal terms: If you must use a legal term (like "Data Fiduciary"), define it immediately the first time it appears.
▶Sentence length: Maximum 25 words per sentence. If a sentence has more than two clauses, split it into two sentences.
▶Concrete examples: Instead of "process data for analytics," say "count how many users click the 'Buy Now' button so we can improve our checkout flow."
▶Language availability: Where your users primarily communicate in a regional language (Tamil, Telugu, Hindi, Bengali), provide the policy in that language. Rule 3 requires accessibility in the language in which consent is sought.
5. Section-by-Section Privacy Policy Template
The following is a recommended structure for a DPDPA-compliant privacy policy. Every section maps to a specific legal requirement. The order is optimised for readability — most important information first. Sections marked MANDATORY must be present. Sections marked CONDITIONAL apply only where relevant to your business.
§1
Who We Are and Who This Policy Applies To
MANDATORY
Full legal name of the entity, registered address, CIN, and a brief description of the business. Identify who the "Data Fiduciary" is (your company) and who the "Data Principal" is (your customer / user). State that this policy applies to all users of your website, app, and services.
§2
What Personal Data We Collect
MANDATORY
Full list of data categories collected, broken down by source (data you provide directly vs. data collected automatically). Include data collected through third-party integrations. Use plain-language descriptions, not technical field names.
§3
Why We Collect It — Purpose and Lawful Basis
MANDATORY
For each data category, state the purpose in plain language and identify the lawful basis (consent / legitimate use / legal obligation). A table format works well here. Where consent is the basis, link to the consent notice. Where legitimate use is relied on, identify the specific Schedule 1 ground.
§4
Who We Share Your Data With
MANDATORY
Full list of third parties — named where significant, categorised where numerous. For each, state the type of data shared, the purpose, and whether they are a Data Processor (acting on your instructions) or an independent Data Fiduciary (determining their own purposes). Include government / law enforcement disclosure obligations.
§5
How Long We Keep Your Data
MANDATORY
Retention periods by data category. Where legal obligations require minimum retention (tax records, employee records), cite the statute. State what happens at the end of the retention period — deletion or anonymisation. Explain how deletion requests are handled and any exceptions.
§6
International Data Transfers
CONDITIONAL
Required if any personal data is processed outside India — by cloud infrastructure, SaaS vendors, or overseas offices. Name the countries, name the entities, and state the safeguards in place (DPA with the vendor, standard contractual terms). Monitor the Board's restricted country notifications and update this section accordingly.
§7
Children's Data
CONDITIONAL
Required if your service is accessible to users under 18. Must state: minimum age, parental consent process, what data is collected from children, and that children's data is never used for behavioural tracking or targeted advertising. If your service is strictly for adults only, state this explicitly and describe your age verification mechanism.
§8
Your Rights and How to Exercise Them
MANDATORY
List all rights under Sections 11–14 in plain language with the specific exercise mechanism for each. Include the response timeline. Include the right to escalate to the Data Protection Board if the Grievance Officer does not resolve the issue within the prescribed period.
§9
Cookies and Tracking Technologies
CONDITIONAL
Required if your website uses cookies, pixels, or other tracking technologies. See Section 6 of this guide for full cookie policy requirements. At minimum: list cookie types (essential, analytics, marketing), explain what each does, state which require consent, and explain how to manage or disable them.
§10
Data Security — What We Do to Protect Your Data
MANDATORY
A brief, plain-language description of security measures — encryption, access controls, security testing. Do not make absolute security guarantees. Do state what you will do if a breach occurs — including notification to the Data Protection Board and to affected users. Include the breach notification timeline.
§11
Grievance Officer and How to Contact Us
MANDATORY
Full name, designation, email, phone, and working hours of the Grievance Officer. Response timeline commitment. Escalation path — how to contact the Data Protection Board if the Grievance Officer does not respond or resolve adequately. For SDFs: also disclose the DPO's details.
§12
Changes to This Policy
MANDATORY
Review frequency (at minimum annually), notification mechanism for material changes (email + website notice), period of notice before changes take effect (recommend 30 days for material changes), and link to or statement about where previous versions can be accessed.
6. Cookie Policy — What It Must Say Under DPDPA
If your website uses any tracking technology — cookies, pixels, scripts, localStorage, fingerprinting — you need a cookie policy as part of your privacy notice. Tracking technologies collect device identifiers and behavioural data, both of which are personal data under DPDPA.
| Cookie Type |
What It Does |
Consent Required? |
Examples |
| Essential / Strictly Necessary |
Required for the website or app to function — login sessions, shopping cart, form tokens, load balancing |
NO — Legitimate Use |
JSESSIONID, CSRF token, cart session, auth token |
| Analytics / Performance |
Measures how users interact with the website — pages visited, time spent, user flow, conversion funnel data |
YES — Consent Required |
Google Analytics (_ga, _gid), Hotjar, Mixpanel, Amplitude |
| Preference / Functional |
Remembers user preferences — language, currency, display settings, notification preferences |
SITUATIONAL |
lang_preference, currency_code, theme_mode |
| Marketing / Advertising |
Tracks users across sites to build advertising profiles and serve targeted ads — the highest-risk cookie category |
YES — Explicit Consent |
Meta Pixel (_fbp), Google Ads (gclid), LinkedIn Insight, TikTok Pixel |
The Meta Pixel problem — the most common cookie compliance violation in India: The Meta Pixel and Google Ads tags fire automatically on page load on the vast majority of Indian e-commerce websites — collecting visitor device IDs, IP addresses, and behavioural data and sending them to Meta and Google's US servers before the user has given any consent. Under DPDPA, this is: (1) processing personal data without consent, (2) sharing with a third party without disclosure, and (3) a cross-border transfer without notice. All marketing and advertising cookies must be blocked until explicit consent is given — and a cookie consent management platform must be implemented that genuinely blocks pixel firing until opt-in.
7. Third-Party Disclosures — Who You Must Name and Why
Rule 3 requires identification of the persons to whom personal data is transferred or disclosed. "Persons" in this context includes both Data Processors (who process on your instructions) and independent Data Fiduciaries (who receive data and determine their own purposes). Here is a practical guide to what level of disclosure is required for different vendor types:
- Payment gateway (Razorpay, PayU, Stripe)
- Cloud infrastructure (AWS, GCP, Azure)
- Major analytics platform (Google Analytics)
- Advertising platforms (Meta, Google Ads)
- Email marketing platform (Mailchimp, Klaviyo)
- CRM (Salesforce, HubSpot, Zoho)
- Primary logistics / delivery partner
- BNPL / EMI provider (LazyPay, Simpl)
🟡 Category Disclosure Acceptable
- "Background verification agencies"
- "Last-mile delivery sub-contractors"
- "Customer support platform providers"
- "Security and fraud detection vendors"
- "HR and payroll processing partners"
- "Professional advisors (legal, audit, tax)"
🟢 Always Disclose Separately
- Any government or law enforcement disclosure — and on what basis (legal obligation vs. court order)
- Group company or affiliate sharing — and for what purpose
- Business sale / merger — how data is treated in M&A
- Advertising network retargeting — named platforms, named countries
8. Grievance Officer — How to Disclose This in Your Policy
The Grievance Officer disclosure is one of the most commonly omitted mandatory elements in Indian privacy policies. It is not optional — Section 13 requires appointment and the privacy policy is the primary mechanism for publication of the officer's details.
✅ Grievance Officer Disclosure — Complete Template
Grievance Officer
Name: [Full Name of Appointed Officer]
Designation: [e.g. Head of Legal / Compliance Manager / Data Protection Officer]
Company: [Registered Name of Your Company]
Email: [dedicated email address — e.g. privacy@yourcompany.com or grievance@yourcompany.com]
Phone: [+91-XXXXXXXXXX]
Address: [Registered office address]
Working Hours: Monday to Friday, 9:30 AM to 6:00 PM IST (excluding public holidays)
We will acknowledge your complaint or query within 48 hours of receipt and aim to resolve it within 30 days. If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India at [link to Board's complaint portal when operational].
Important: The Grievance Officer must be a real, named individual — not a department, not a generic "privacy team" email, not an AI chatbot. The email must be monitored and must result in human responses within the stated timeline. The Board has the power to investigate complaints about unresponsive Grievance Officers.
9. Children's Data — Special Disclosures Required
If your product or service is accessible to users under 18, or if you process data of individuals under 18 in any capacity, your privacy policy must contain a dedicated children's data section that goes beyond the general disclosures.
📋 Children's Data Section — What Must Be Included
①The age below which parental/guardian consent is required (under 18 for DPDPA)
②How parental consent is obtained and verified before any data is collected from a child
③What data is specifically collected from children and why — with higher justification required
④An explicit statement that children's data is never used for behavioural tracking, profiling, or targeted advertising
⑤How parents can access, correct, or delete their child's data — and the specific mechanism for doing so
⑥What happens when a child turns 18 — whether and how data is transitioned to the user's own control
If your service is adults-only: State this explicitly — "Our services are not directed at children under 18. We do not knowingly collect personal data from individuals under 18. If we become aware that we have collected data from a child without verifiable parental consent, we will delete it immediately." Then describe your age verification or age assurance mechanism.
10. Cross-Border Transfers — What to Disclose and When
If any personal data leaves India — whether to a cloud server, a SaaS platform, an overseas parent company, or a foreign support team — this must be disclosed in the privacy policy. Even before the restricted country list is notified, the disclosure obligation under Section 5 applies to cross-border flows.
✅ Cross-Border Transfer Disclosure — Template
"Some of your personal data is processed or stored outside India. Specifically:
Cloud infrastructure: Our platform is hosted on Amazon Web Services (AWS) in its Mumbai (ap-south-1) region. Backup data may be stored in AWS's Singapore (ap-southeast-1) region for disaster recovery purposes. Both regions are operated by Amazon Web Services, Inc. (USA). We have a Data Processing Agreement with AWS governing the handling of your data.
Email marketing: Your email address and communication preferences are processed by Klaviyo, Inc. (USA), which operates servers in the United States. We have a Data Processing Agreement with Klaviyo governing the handling of your data.
Analytics: Website usage data is processed by Google LLC (USA) through Google Analytics. Data is processed on servers in the United States. Google's data processing terms govern this transfer.
We ensure that all international transfers are governed by appropriate contractual terms. We will update this section promptly if any cross-border transfer destination is restricted by the Data Protection Board of India."
11. How Often to Update Your Privacy Policy — and How to Notify Users
| Trigger for Update |
Type of Change |
Notification Required |
Notice Period |
| New data type collected |
MATERIAL |
Email to all existing users + prominent website banner. Must obtain fresh consent if new purpose requires it. |
30 days before |
| New purpose for existing data |
MATERIAL |
Email notification + fresh consent notice for the new purpose — cannot rely on existing consent for a new purpose. |
30 days before |
| New third-party sharing |
MATERIAL |
Email notification + new consent if the sharing requires it (e.g. adding a new advertising partner). Website update. |
30 days before |
| Change in Grievance Officer |
MODERATE |
Update the policy immediately with new officer's details. Email notification recommended but not strictly required for this change alone. |
Immediately |
| New cross-border transfer destination |
MODERATE |
Update policy and notify users if the new destination is not already covered by existing consent/disclosure. Especially important when restricted country list is notified. |
Before transfer begins |
| Annual review — no material changes |
MINOR |
Update the 'Last Updated' date. No proactive notification to users required for clarifications, corrections, or non-substantive updates. |
Immediate publication |
| Regulatory update (new Board Rules) |
MATERIAL |
Mandatory update within whatever transition period the Rules prescribe. Monitor Board notifications actively — subscribe to official gazette notifications. |
Per Board timeline |
12. The Complete DPDPA Privacy Policy Checklist
Use this checklist to audit your existing privacy policy or to verify completeness before publishing a new one. Every item marked 🔴 is mandatory under the DPDPA and Rules. Every item marked 🟡 is required if the relevant processing activity applies to your business.
- 🔴 ☐ Legal name and address of the Data Fiduciary
- 🔴 ☐ All categories of personal data collected — specifically listed
- 🔴 ☐ Purpose of processing — for each data category
- 🔴 ☐ Lawful basis — for each processing purpose
- 🔴 ☐ Third parties named — all significant Data Processors
- 🔴 ☐ Retention periods — by data category with legal basis where applicable
- 🔴 ☐ Right to information — explained with exercise mechanism
- 🔴 ☐ Right to correction — explained with exercise mechanism
- 🔴 ☐ Right to erasure — explained with exercise mechanism
- 🔴 ☐ Right to withdraw consent — with specific mechanism per consent type
- 🔴 ☐ Right to nominate — explained with exercise mechanism
- 🔴 ☐ Grievance Officer — name, designation, email, phone, response timeline
- 🔴 ☐ Consent withdrawal as easy as giving — confirmed and explained
- 🔴 ☐ Data security measures — plain language description
- 🔴 ☐ Breach notification commitment — to Board and to users
- 🔴 ☐ Policy update mechanism — notification method and timing
- 🔴 ☐ Last Updated date — visible at top of document
- 🟡 ☐ Cross-border transfers — countries, vendors, safeguards
- 🟡 ☐ Children's data — parental consent, tracking prohibition
- 🟡 ☐ Cookie policy — types, purposes, consent status, management
- 🟡 ☐ Advertising and retargeting — platforms named, consent required
- 🟡 ☐ Automated decision-making — if used, disclosed and explained
✍️ Format and Accessibility Checklist
- 🔴 ☐ Separate from Terms of Service — standalone document
- 🔴 ☐ Accessible at a permanent, stable URL
- 🔴 ☐ Linked from website footer — on every page
- 🔴 ☐ Linked from app settings / account page
- 🔴 ☐ Available before any data collection begins — at sign-up
- 🔴 ☐ Written in plain language — no undefined legal terms
- 🔴 ☐ Sections are logically ordered — most important information first
- 🔴 ☐ Headings and sub-headings for each major section
- 🟡 ☐ Available in regional language(s) of primary user base
- 🟡 ☐ Accessible on mobile without horizontal scrolling
- 🟡 ☐ PDF version available for download
- 🔴 ☐ Grievance Officer email is monitored — real responses within 48 hours
- 🔴 ☐ Rights request intake process is functional — tested and working
- 🔴 ☐ Consent withdrawal actually works — tested across all channels
- 🔴 ☐ Policy version control in place — previous versions archived
- 🔴 ☐ Annual review calendar entry — mandatory at minimum
- 🟡 ☐ Cookie consent management platform blocks pixels before opt-in
- 🟡 ☐ DPAs in place with every named third party
- 🟡 ☐ Staff trained on responding to rights requests and grievances
13. Common Mistakes Indian Businesses Make — and How to Avoid Them
| # |
Mistake |
Why It's a Problem |
How to Fix It |
| 1 |
Copying another company's privacy policy |
The policy won't reflect your actual data practices — which is itself a misrepresentation and an additional DPDPA violation |
Audit your actual data flows first. Draft a policy that reflects what you actually do — not what you wish you did. |
| 2 |
Bundling privacy policy with Terms of Service |
Rule 3 requires the notice to be separate from any other document. Combining them makes each non-compliant. |
Maintain separate URLs: yourcompany.com/privacy and yourcompany.com/terms. Link between them but keep them distinct. |
| 3 |
No Grievance Officer named |
Direct violation of Section 13. The most common omission in Indian privacy policies — present in 90%+ of current policies. |
Appoint a specific named individual today. Publish their name, email, and phone number. Test the inbox. Respond within 48 hours. |
| 4 |
"We collect data to improve our services" as a purpose |
This is a non-purpose. It explains nothing about what data is collected, how it is analysed, or what decisions are made with it. Fails the plain language and specificity requirements. |
Replace with: "We analyse which features users click most often to decide which parts of the app to improve next. We do not use individual profiles for this — only aggregate counts." |
| 5 |
No third-party disclosures |
Failing to disclose that Google Analytics, Razorpay, or a logistics partner receives user data violates Rule 3's mandatory disclosure requirement. |
List every significant third party. Use your vendor audit as the source. Update the list whenever you add a new vendor. |
| 6 |
No retention periods stated |
"We retain data as long as necessary" is not a retention period. It provides no useful information and does not meet the Rule 3 specificity requirement. |
Build a retention schedule. Define specific periods for each data category. Implement actual deletion at those periods — the policy is only compliant if the process actually runs. |
| 7 |
Using the privacy policy as a consent mechanism |
"By using this website you consent to our Privacy Policy" is not valid consent under Section 6 — it is not free, specific, informed, unconditional, or an affirmative act. |
Remove this language entirely. Implement separate, specific consent notices for each purpose requiring consent. The privacy policy informs — it does not consent. |
| 8 |
Policy never updated after initial publication |
Every new tool, vendor, or data type added since the policy was written is an undisclosed third party or undisclosed data type — accumulating silent violations over time. |
Set a calendar reminder for an annual review. Create an internal policy update trigger for any new vendor, new data type, or new purpose — before that change goes live, not after. |
📊 DPDPA Privacy Policy — At a Glance
8
Mandatory disclosures required by Rule 3 — missing any one makes the entire policy non-compliant
₹50 Cr
Penalty for notice violations — applies per user affected by an inadequate privacy notice
12
Recommended sections in a complete DPDPA-compliant privacy policy
Annual
Minimum review frequency — plus an update trigger for any material change in data practices
May 2027
Enforcement deadline — every Data Fiduciary must have a compliant privacy policy in place
Your Privacy Policy Needs to Be Right the First Time
A privacy policy that fails Rule 3 is not just a compliance document gap — it means every consent you have ever obtained is potentially invalid (because it was obtained without a compliant notice), and every data processing activity since your first customer is operating without a lawful basis. The remedy is not cheap or quick when discovered by the Board during an investigation. It is far less expensive to get it right now.
This guide gives you the framework — but a privacy policy that is genuinely compliant with DPDPA must reflect your actual data practices, your actual vendor relationships, your actual consent flows. That requires a data audit, a legal review, and bespoke drafting. Generic templates do not pass Board scrutiny, and the Board has made clear it will scrutinise privacy notices closely in its early enforcement actions.
Our Privacy Policy Drafting Service covers the complete process — data flow audit, purpose mapping, third-party identification, bespoke DPDPA-compliant drafting, plain language review, Grievance Officer appointment support, and a compliance certificate confirming that your privacy policy meets Rule 3 requirements. Delivered in 10 working days.