AMLEGALS — Strategic Lawyering
Back to Documents
Notice

Privacy Notice Under DPDPA

The foundational document every Data Fiduciary must present before collecting personal data

Section 5Section 6Rule 3

The Privacy Notice is not a formality. It is the first legal instrument that establishes your relationship with the Data Principal. Under DPDPA, this notice must be presented before or at the moment you seek consent. Not after. Not buried in terms of service. Before.

What the Law Demands

Section 5 of the DPDPA 2023 mandates that every Data Fiduciary provide a notice containing specific information. Rule 3 of the DPDP Rules 2025 expands this requirement with granular detail. The notice must itemize each category of personal data you collect. It must state every purpose for which you process that data. It must explain how the Data Principal can withdraw consent. And it must provide a clear channel for grievances.

Key Points
  • Itemized description of personal data categories
  • Specific purposes for each data category
  • Consent withdrawal mechanism
  • Grievance redressal contact details
  • Data retention periods where applicable

Standalone Requirement

The privacy notice under DPDPA must be standalone. This is a departure from common practice where privacy disclosures are embedded within lengthy terms of service. The regulator expects a dedicated document. Clear. Accessible. Written in plain language that an average person can understand without legal training.

Language and Accessibility

Rule 3(2) requires the notice to be available in English and all languages specified in the Eighth Schedule to the Constitution. This means 22 languages. If your user base includes speakers of Hindi, Tamil, Bengali, or any scheduled language, you must provide the notice in that language. Translation is not optional.

Timing Is Everything

The notice must be provided before seeking consent or at the time of seeking consent. Presenting it after data collection is a violation. Relying on implied consent without notice is a violation. The sequence matters because the law treats informed consent as foundational.

Essential Clauses

Data Categories Itemization

Rule 3(1)(a)

Each type of personal data must be listed separately with its processing purpose

Purpose Specification

Section 5(1)

Vague purposes like "improving services" are insufficient. State specific, concrete purposes.

Consent Withdrawal Procedure

Section 6(4)

Must explain exactly how a Data Principal can revoke consent with equal ease as granting it

Grievance Officer Details

Rule 3(1)(d)

Name, designation, and contact information of the person handling complaints

Third-Party Sharing Disclosure

Section 8(2)

If data will be shared with Data Processors or other entities, this must be stated

Cross-Border Transfer Notice

Section 16

If data may be transferred outside India, explicit disclosure required

Implementation Steps

1

Conduct a data inventory to identify all personal data categories you collect

2

Map each data category to its specific processing purpose

3

Draft the notice in clear, plain language avoiding legal jargon

4

Engage professional translators for scheduled language versions

5

Establish the grievance redressal mechanism before publishing the notice

6

Integrate the notice presentation into your data collection workflows

7

Test user flows to ensure notice appears before consent is sought

8

Implement version control to track notice updates over time

Frequently Asked Questions

Need This Document Drafted?

Understanding the requirement is the first step. Having it implemented correctly is what protects your organization. Our team drafts DPDPA-compliant documents tailored to your specific operations.

Get in Touch

DPDPA Privacy Notice: questions and answers

What must a DPDPA privacy notice contain?

Section 5 read with Rule 3 requires a notice, understandable independently of other information, that itemises the personal data and the specified purpose, and explains how the Data Principal may withdraw consent, exercise rights and complain to the Board. A Data Principal has the right to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The design of translation operations is an implementation matter.

What makes consent valid under DPDPA?

Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action and limited to personal data necessary for the specified purpose. Withdrawal must be as easy as giving consent.

Is a Data Fiduciary responsible for its vendors under DPDPA?

Yes. Section 8(1) makes the Data Fiduciary responsible for compliance in respect of processing undertaken by it or on its behalf by a Data Processor. Section 8(2) requires a Data Fiduciary to engage a Data Processor under a valid contract. Detailed contractual clause architecture is an implementation best practice guided by Section 8(2).

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPDPA Privacy Notice?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPDPA Privacy Notice under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPDPA Privacy Notice under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPDPA Privacy Notice?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPDPA Privacy Notice rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPDPA Privacy Notice?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPDPA Privacy Notice · DPDPA Exposure Assessment