privacy policy
How to Review a Privacy Policy Under India's DPDP Act
A privacy policy is not a formality you paste from a template and forget. Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), the document you publish on your website or app is a legal notice with specific, checkable contents, and getting it wrong is a compliance gap, not just a bad look. (Adira, which publishes this guide, makes contract and compliance software, so we have a commercial interest in you caring about documents like this one, but it is written to be useful on its own.)
Here is what a DPDP-compliant notice must contain, how consent and withdrawal work under the Act, what rights you owe your users, and where India's rules differ from the GDPR most people default to copying.
What "privacy policy" means under Indian law
The DPDP Act never uses the phrase "privacy policy." It uses "notice," and ties it directly to the consent request. Section 5(1) says:
"Every request made to a Data Principal under section 6 for consent shall be accompanied or preceded by a notice given by the Data Fiduciary to the Data Principal, informing her: (i) the personal data and the purpose for which the same is proposed to be processed; (ii) the manner in which she may exercise her rights under sub-section (4) of section 6 and section 13; and (iii) the manner in which the Data Principal may make a complaint to the Board." Source: Section 5, Digital Personal Data Protection Act, 2023
Three things fall out of that sentence, and most privacy policies fail at least one. The notice must itemise the personal data and purpose, not describe categories in the abstract ("information you provide us"); explain how to withdraw consent and reach grievance redressal under Section 13; and explain how to complain to the Data Protection Board of India. A policy missing that third element, the Board complaint route, is incomplete even if everything else reads well.
Section 5(3) adds a language requirement: the notice must be available, at the Data Principal's option, in English "or any language specified in the Eighth Schedule to the Constitution." An English-only notice on an Indian consumer product is a gap worth closing.
Consent mechanics: what counts, and how withdrawal works
Section 6(1) sets the bar for valid consent:
"The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose." Source: Section 6, Digital Personal Data Protection Act, 2023 (Indian Kanoon)
A pre-ticked checkbox, a bundled "I agree" click that also authorises marketing calls, or consent implied from continued use, none of that clears "clear affirmative action." A blanket consent covering ten unrelated purposes is weak design even where nothing in it is individually false.
Withdrawal is where most privacy pages stay vague. It must be at least as easy as giving consent, and once withdrawn, "the Data Fiduciary shall, within a reasonable time, cease... processing the personal data," unless separately authorised by law. The Act's own illustration: withdrawing consent can stop new orders on an app, but not processing needed to fulfil an order already paid for. State, in one place, how to withdraw and what stops working.
One more mechanism worth knowing: the Consent Manager, defined in Section 2 as a person registered with the Data Protection Board who acts as "a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent." If your notice references one, check it is actually Board-registered, not an in-house settings page borrowing the name.
The rights your notice has to point to
Section 5(1)(ii) requires the notice to explain how a Data Principal exercises rights under Section 6(4) and Section 13. A compliant policy should name four rights specifically.
Access, Section 11. A Data Principal can obtain "a summary of personal data which is being processed" plus "the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared." That second part is easy to skip, and exactly what a sharp user tests first.
Correction and erasure, Section 12. A Data Principal can ask the Fiduciary to "correct the inaccurate or misleading personal data," "complete" incomplete data, "update" it, or request erasure. The Fiduciary must erase "unless retention... is necessary for the specified purpose or for compliance with any law," a narrow carve-out: "we might need it later" is not a stated legal requirement.
Grievance redressal, Section 13. Every Fiduciary must provide "readily available means of grievance redressal" and respond "within such period as may be prescribed," capped at 90 days by Rule 14. Section 13(3) makes this a mandatory first step: "the Data Principal shall exhaust the opportunity of redressing her grievance under this section before approaching the Board." A policy jumping straight to "contact the Board" describes a step the Act does not let a user skip.
Nomination, Section 14. A Data Principal can nominate another individual to exercise these rights on their death or incapacity. Few Indian policies mention this; a compliant one explains how to register a nominee.
Retention, cross-border transfer, and children's data
Section 8(7) requires erasure once "the purpose for which it was collected is no longer being served" and no other law requires retention, and requires the Fiduciary to cause its Processors to do the same. State a retention period, or the criteria for one, per category; "as long as necessary" restates the statute without adding anything checkable.
Section 16(1) gives cross-border transfer a negative-list structure: the government can "notify that the transfer of personal data by a Data Fiduciary to any country or territory outside India shall not be made." Transfer is allowed by default except to a country specifically named, and as of this writing none has been. Still state whether data is processed outside India and where (GDPR's contrast below is stricter).
Section 9(1) requires "verifiable consent of the parent or lawful guardian" before processing a child's data (under 18) or that of a person with a disability who has a lawful guardian, and bars processing "likely to cause any detrimental effect on the well-being of a child," plus behavioural tracking and targeted ads aimed at children. Rule 10 fills in "verifiable": the Fiduciary confirms the adult's identity and age using details it already holds or an approved mechanism such as DigiLocker. A product likely used by minors needs that mechanism described, not a US-style "not directed at children" disclaimer.
Security safeguards and breach notification
Section 8(5) requires a Fiduciary to "protect personal data in its possession or under its control... by taking reasonable security safeguards to prevent personal data breach." "Reasonable" is undefined, so naming an actual standard, encryption at rest and in transit, access controls, ISO 27001, does more work than repeating the word back at the reader.
Section 8(6) requires notice to the Board and affected Data Principals on a breach, "in such form and manner as may be prescribed." Rule 7 of the DPDP Rules, 2025 fixes the clock: immediate intimation to the Board, a fuller report within 72 hours, and notice to Data Principals also without delay. State how users will actually be notified, so the promise is checkable.
The Grievance Officer question, and the IT Rules 2011 legacy
Section 10 lets the government designate certain Fiduciaries as Significant Data Fiduciaries; Section 10(2) then requires an India-based Data Protection Officer reporting to its board, an independent data auditor, and a periodic impact assessment.
The DPDP Act itself never uses the term "Grievance Officer," familiar from older internet law. Rule 9 requires every Fiduciary to "prominently publish on its website or app, and mention in every response to a communication for the exercise of the rights of a Data Principal... the business contact information of the Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary the questions of the Data Principal." Every Fiduciary needs a named, current contact, even without a formal DPO; a policy still carrying an old SPDI-era "Grievance Officer" block should be checked against this.
Before the DPDP Act, privacy obligations sat mainly in Section 43A of the IT Act, 2000 and the Reasonable Security Practices and Sensitive Personal Data or Information Rules, 2011 (the "SPDI Rules"), covering only "sensitive personal data" like financial and health information. Section 44(2) omits Section 43A, notified to take effect 13 May 2027. Until then the SPDI Rules remain technically in force, but the DPDP Act and its 2025 Rules now govern in practice, and cover all personal data, not just SPDI's narrower category.
Red flags
| Normal | Red flag | Why it matters |
|---|---|---|
| Itemised list of personal data, by category and purpose | Vague "information you provide us" | Fails Section 5(1)(i) outright |
| Explains how to withdraw consent and what stops working | Consent described as given, never as withdrawable | Silent on a right Section 6 guarantees |
| Names an internal grievance channel with a response window | Jumps straight to "contact the Board" | Skips the Section 13(3) exhaustion step |
| States a retention period, or the criteria for one | "We retain data as long as necessary" | Restates Section 8(7) with nothing checkable |
| States whether and where data is processed outside India | Silent on cross-border processing | No visibility if a restricted-country notice ever issues |
| Verifiable parental consent process, for a product minors use | Generic "not directed at children" disclaimer | Does not meet Section 9's standard |
| Named security standard and a breach-notification channel | Only "we take security seriously" | Nothing checkable under Section 8(5) |
| Current DPO or contact-person details, matching Rule 9 | Old "Grievance Officer" block, unreviewed | May not satisfy the actual requirement |
| Explains how to complain to the Data Protection Board | No mention of the Board | Fails Section 5(1)(iii) directly |
Bad clause, better clause
Bad (common boilerplate): "We may collect information you provide to us and information about your use of our services. We may use this information to operate and improve our services, and may share it with third parties as necessary. By using our services, you consent to this policy."
Better: "We collect the personal data listed below, for the purposes stated against each. We process it only with your consent, given by affirmative action, or where a ground under Section 7 applies. You may withdraw consent anytime through Settings > Privacy; this will not affect processing already completed but will stop the features listed there. You may request a summary of your data, correction, or erasure through [link]; we respond within [X] business days, and if unresolved you may complain to the Data Protection Board of India at [channel]. We retain your data for [stated period], after which it is deleted. Our privacy contact is [name, email], published here and in every response to a rights request, per Rule 9 of the DPDP Rules, 2025."
What changed: an unspecified category became an itemised list; "you consent" became a two-way promise on withdrawal; "contact us" became a timed rights process with a Board escalation; open-ended retention became a stated period; and the contact block became functional, not decorative.
How it interacts with related pages
A privacy policy is the external document; it should stay consistent with the internal contract language covering the same ground: the DPDP Act for contracts for the clause checklist, data protection clauses under the DPDP Act for Fiduciary and Processor role allocation, and how to review a Data Processing Agreement for the vendor-side contract Section 8(2) requires.
You can draft or mark up a privacy notice clause by clause, free, in Weave, before you publish it.
US and global contrast
The US has no single federal law comparable to the DPDP Act. Notice comes from sector statutes (HIPAA, GLBA) and state laws like the California Consumer Privacy Act, built around a right to know, delete, and opt out of sale, not India's access-correction-erasure-nomination-grievance structure.
GDPR is the closer, stricter comparison. Article 13 requires disclosing the legal basis for processing and the retention period or its criteria, detail many DPDP-only notices skip. Its transfer regime is stricter by default too: an adequacy decision or approved safeguard is required before data leaves the EU, where Section 16 permits transfer unless a country is specifically restricted. Serving both audiences means writing to the higher bar on both, explicitly.
Checklist
- Personal data itemised by category and purpose, not described in the abstract
- Consent request meets Section 6(1): free, specific, informed, unconditional, unambiguous
- Withdrawal mechanism described, as easy as giving consent, with stated consequences
- Access, correction, erasure, and nomination rights explained (Sections 11, 12, 14)
- Internal grievance channel named, with a response window inside the 90-day Rule 14 cap
- Board complaint route explained, positioned after grievance redressal, not instead
- Retention period or criteria stated per data category
- Cross-border processing disclosed, with location stated
- Verifiable parental consent process described, if minors are likely users
- Named security standard and a stated breach-notification channel
- Current DPO or contact-person details published, matching Rule 9
- If EU users are served, GDPR Article 13 disclosures layered in
FAQ
Is a privacy policy legally required in India, or just good practice? For any Data Fiduciary requesting consent, yes. Section 5(1) requires the notice to accompany or precede every consent request, so processing personal data without one fails the Act's notice obligation, independent of whether a complaint has been filed.
Can I use one privacy policy for both Indian and EU users? One document can work if it satisfies both regimes' content and transfer rules. Many businesses run a shared core with region-specific sections instead.
What happens if I don't mention the Data Protection Board in my privacy policy? The notice is incomplete under Section 5(1)(iii), which specifically requires disclosing "the manner in which the Data Principal may make a complaint to the Board." This is a commonly missed element in policies adapted from foreign templates.
Do I need separate parental consent language if my product is not aimed at children? If genuinely unlikely to be used by anyone under 18, a general statement can suffice, but that needs to be a real assessment, not an assumption. Meaningful use by minors requires the Section 9 verifiable-consent mechanism, not a US-style disclaimer.
How is a Consent Manager different from the consent settings inside my own app? A Consent Manager under Section 2 is a separate, Board-registered platform usable across multiple Fiduciaries. In-app settings you build are not a Consent Manager unless registered as one; do not use that term for your own page.
Are the old IT Rules 2011 requirements still relevant to my privacy policy? Largely superseded in practice. The SPDI Rules stay technically in force until Section 43A of the IT Act is omitted, effective 13 May 2027, but the DPDP Act and its 2025 Rules are the operative standard now, covering all personal data, not just SPDI's narrower category.
This guide gets you to a working understanding of what a DPDP-compliant privacy notice should contain, and where India's requirements differ from GDPR's. It does not tell you whether your specific policy, for your specific data flows and user base, meets your compliance obligations, that depends on facts a lawyer needs to review, and is not legal advice. Talk to a lawyer before publishing or materially changing a policy for a product handling sensitive categories, children's data, or cross-border flows.
Frequently asked questions
- Is a privacy policy legally required in India, or just good practice?
- For any Data Fiduciary requesting consent, yes, functionally required. Section 5(1) of the DPDP Act, 2023 requires the notice to accompany or precede every consent request, so processing personal data without one fails the Act's notice obligation, independent of whether a complaint has been filed.
- Can I use one privacy policy for both Indian and EU users?
- One document can work if it satisfies both regimes' content and transfer rules, GDPR Article 13's fuller disclosure list plus the DPDP Act's Board-complaint and grievance-redressal information under Section 5. Many businesses instead run a shared core policy with region-specific sections.
- What happens if I don't mention the Data Protection Board in my privacy policy?
- The notice is incomplete under Section 5(1)(iii) of the DPDP Act, which specifically requires disclosing "the manner in which the Data Principal may make a complaint to the Board." This is a commonly missed element in policies adapted from foreign templates.
- Do I need separate parental consent language if my product is not aimed at children?
- If your product is genuinely unlikely to be used by anyone under 18, a general statement can suffice, but that needs to be a real assessment, not an assumption. Meaningful use by minors requires the Section 9 verifiable-consent mechanism, with identity and age verification under Rule 10 of the DPDP Rules, 2025, not a disclaimer borrowed from a US COPPA-style policy.
- How is a Consent Manager different from the consent settings inside my own app?
- A Consent Manager, defined in Section 2 of the DPDP Act, is a separate, Board-registered platform usable across multiple Data Fiduciaries. In-app consent settings you build yourself are not a Consent Manager unless actually registered as one; do not use that term for your own settings page.
- Are the old IT Rules 2011 requirements still relevant to my privacy policy?
- Largely superseded in practice. The Reasonable Security Practices and Sensitive Personal Data or Information Rules, 2011 (SPDI Rules) remain technically in force until Section 43A of the IT Act is omitted, an amendment notified to take effect 13 May 2027 under Section 44(2) of the DPDP Act, but the DPDP Act and its 2025 Rules are the operative standard now, and they cover all personal data, not just the SPDI Rules' narrower sensitive-data category.
Sources
- Section 5, Digital Personal Data Protection Act, 2023 (notice requirements)
- Section 6, Digital Personal Data Protection Act, 2023 (consent, withdrawal) - Indian Kanoon
- Section 9, Digital Personal Data Protection Act, 2023 (children's data, verifiable parental consent) - Indian Kanoon
- Section 11, Digital Personal Data Protection Act, 2023 (right to access information) - dpdpa.com
- Section 12, Digital Personal Data Protection Act, 2023 (right to correction and erasure) - dpdpa.com
- Section 13, Digital Personal Data Protection Act, 2023 (right to grievance redressal) - dpdpa.com
- Section 14, Digital Personal Data Protection Act, 2023 (right to nominate) - dpdpa.com
- Section 16, Digital Personal Data Protection Act, 2023 (cross-border transfer)
- Digital Personal Data Protection Rules, 2025, Rule 7 (breach intimation timelines)
- Digital Personal Data Protection Rules, 2025, Rule 9 (publishing DPO/contact-person details)
- Digital Personal Data Protection Rules, 2025, Rule 10 (verifiable parental consent for children)
- Section 44, Digital Personal Data Protection Act, 2023 (amendments to IT Act, omission of Section 43A) - dpdpa.com
- Article 13 and Article 44, GDPR (notice content and cross-border transfer)
- The DPDP Act for Contracts: What Changes in Your Agreements - Adira Journal
- Data Protection Clauses in Indian Contracts Under the DPDP Act - Adira Journal
See how Adira drafts in your voice and reads contracts from your side.
Explore the showroomWorking through a contract like this? Weave is Adira’s free tool to read, mark up, and connect any contract in your browser — no account needed.
Try Weave — free