What the notice must contain
Section 5(1) requires a description of the personal data and the purpose. Rule 3 adds:
- An itemised description of the personal data being collected.
- The purpose of processing for each item of personal data.
- The manner in which the Data Principal may exercise the rights under Sections 11 to 14.
- The manner in which the Data Principal may make a complaint to the Data Protection Board.
Section 5(3) requires the notice to be available in English and every language listed in the Eighth Schedule to the Constitution of India. Section 6(4) requires the notice to inform the Data Principal that consent may be withdrawn at any time, and that withdrawal is as easy as giving consent.
How to draft the notice
The notice is a legal document, but it must be understood by the Data Principal. The drafting approach:
- 01
Build on the RoPA
The record of processing activities lists every data set, purpose and lawful ground. The notice draws directly from this register.
- 02
Itemise purposes
Each purpose gets its own line, written in plain language. Do not bundle multiple purposes into a single paragraph.
- 03
State the lawful ground
For each purpose, state whether it relies on consent (Section 6) or a legitimate use (Section 7). If consent, the Data Principal must be asked.
- 04
Describe the rights
In plain language, explain how the Data Principal can access, correct, erase their data, and raise a grievance. Provide the channel.
- 05
Describe the withdrawal mechanism
Section 6(4) requires withdrawal to be as easy as giving consent. The notice must explain how to withdraw.
- 06
Describe the Board complaint route
The notice must tell the Data Principal how to complain to the Data Protection Board if the grievance is not resolved.
- 07
Translate
Provide the notice in English and every Eighth Schedule language (Section 5(3)). Machine translation is not enough — the legal effect is the same in each language.
Common errors in DPDPA privacy notices
Many organisations have adapted their existing GDPR privacy policies for DPDPA. The common errors:
- Referring to GDPR lawful bases (legitimate interest, contract performance) that do not exist in the DPDPA. The only grounds are consent (Section 6) and the listed legitimate uses (Section 7).
- Bundling purposes into broad categories instead of itemising each one.
- Missing the withdrawal mechanism or making withdrawal harder than giving consent.
- Missing the Board complaint route.
- Not providing the notice in the Eighth Schedule languages.
- Using the notice as a liability-limitation document instead of an information document.
The privacy policy beyond the statutory notice
The Section 5 notice is the minimum. Many organisations also publish a broader privacy policy that covers security practices, retention periods, processor disclosures, transfer destinations and cookie practices. The DPDPA does not require all of this in the notice, but it is good practice and may support the mitigation evidence under Section 33(2) in a Board inquiry.
The key discipline is separating what the law requires from what is voluntary. The Section 5 notice must be clear, itemised and given at the right time. The broader policy can sit alongside it.
How AMLEGALS drafts the notice and policy
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.
The team drafts the Section 5 notice from the RoPA, reviews existing privacy policies for DPDPA gaps, drafts consent language that meets Section 6, and coordinates translations.

