AMLEGALS — Strategic Lawyering
DPDPA compliance · Notice

DPDPA privacy policy drafting: the notice every Data Fiduciary must give under Section 5

Section 5 of the DPDPA requires every Data Fiduciary to give a notice to each Data Principal before or at the time personal data is collected. Rule 3 prescribes the contents. The notice must be clear, in plain language, and itemise each purpose. This guide covers what the notice must contain and how to draft it.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 5 min read

A privacy notice document with highlighted sections and a gold seal, beside a pen and compliance checklist
Short answer

Under Section 5 of the Digital Personal Data Protection Act, 2023, every Data Fiduciary must give each Data Principal a notice before or at the time of collecting personal data, or as soon as reasonably practicable where the data was collected before the Act came into effect. The notice must describe the personal data being collected and the purpose of processing (Section 5(1)). Rule 3 prescribes the contents: an itemised description of the personal data and the purpose of its processing, the manner in which the Data Principal may exercise their rights under Sections 11 to 14, and the manner in which the Data Principal may make a complaint to the Data Protection Board. The notice must inform the Data Principal that consent may be withdrawn (Section 6(4)), and that withdrawal is as easy as giving consent.

  • Privacy policy
  • Notice
  • Section 5
  • Rule 3
  • Consent
  • Section 6
  • Withdrawal
  • DPDP Rules 2025
Legal basis
Section 5 (notice), Rule 3 (contents), Section 6 (consent)
When given
Before or at the time of collection; or as soon as practicable for pre-Act data
Must include
Itemised purposes, rights, withdrawal mechanism, Board complaint route
Language
English and every language in the Eighth Schedule to the Constitution (Section 5(3))

What the notice must contain

Section 5(1) requires a description of the personal data and the purpose. Rule 3 adds:

  • An itemised description of the personal data being collected.
  • The purpose of processing for each item of personal data.
  • The manner in which the Data Principal may exercise the rights under Sections 11 to 14.
  • The manner in which the Data Principal may make a complaint to the Data Protection Board.

Section 5(3) requires the notice to be available in English and every language listed in the Eighth Schedule to the Constitution of India. Section 6(4) requires the notice to inform the Data Principal that consent may be withdrawn at any time, and that withdrawal is as easy as giving consent.

How to draft the notice

The notice is a legal document, but it must be understood by the Data Principal. The drafting approach:

  1. 01

    Build on the RoPA

    The record of processing activities lists every data set, purpose and lawful ground. The notice draws directly from this register.

  2. 02

    Itemise purposes

    Each purpose gets its own line, written in plain language. Do not bundle multiple purposes into a single paragraph.

  3. 03

    State the lawful ground

    For each purpose, state whether it relies on consent (Section 6) or a legitimate use (Section 7). If consent, the Data Principal must be asked.

  4. 04

    Describe the rights

    In plain language, explain how the Data Principal can access, correct, erase their data, and raise a grievance. Provide the channel.

  5. 05

    Describe the withdrawal mechanism

    Section 6(4) requires withdrawal to be as easy as giving consent. The notice must explain how to withdraw.

  6. 06

    Describe the Board complaint route

    The notice must tell the Data Principal how to complain to the Data Protection Board if the grievance is not resolved.

  7. 07

    Translate

    Provide the notice in English and every Eighth Schedule language (Section 5(3)). Machine translation is not enough — the legal effect is the same in each language.

Common errors in DPDPA privacy notices

Many organisations have adapted their existing GDPR privacy policies for DPDPA. The common errors:

  • Referring to GDPR lawful bases (legitimate interest, contract performance) that do not exist in the DPDPA. The only grounds are consent (Section 6) and the listed legitimate uses (Section 7).
  • Bundling purposes into broad categories instead of itemising each one.
  • Missing the withdrawal mechanism or making withdrawal harder than giving consent.
  • Missing the Board complaint route.
  • Not providing the notice in the Eighth Schedule languages.
  • Using the notice as a liability-limitation document instead of an information document.

The privacy policy beyond the statutory notice

The Section 5 notice is the minimum. Many organisations also publish a broader privacy policy that covers security practices, retention periods, processor disclosures, transfer destinations and cookie practices. The DPDPA does not require all of this in the notice, but it is good practice and may support the mitigation evidence under Section 33(2) in a Board inquiry.

The key discipline is separating what the law requires from what is voluntary. The Section 5 notice must be clear, itemised and given at the right time. The broader policy can sit alongside it.

How AMLEGALS drafts the notice and policy

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.

The team drafts the Section 5 notice from the RoPA, reviews existing privacy policies for DPDPA gaps, drafts consent language that meets Section 6, and coordinates translations.

Questions and answers

DPDPA Privacy Policy Drafting: common questions

Is a privacy policy the same as a DPDPA notice?

Not exactly. The DPDPA notice is the specific communication required by Section 5 at the time of collection. A privacy policy is a broader document. The notice must be part of — or accompany — the policy, but the policy alone may not satisfy Section 5 if it is not given at the right time or does not itemise purposes.

In how many languages must the notice be given?

In English and every language listed in the Eighth Schedule to the Constitution of India (Section 5(3)). There are 22 such languages.

Can a GDPR privacy policy be used for DPDPA?

Not without changes. The DPDPA does not recognise GDPR lawful bases such as legitimate interest or contract performance. The purposes must be itemised, and the notice must include the Board complaint route and the withdrawal mechanism.

What happens if the notice is not given?

Processing without a valid notice means consent is not informed (Section 6(1) requires consent to be informed). The penalty ceiling for breach of any other provision of the Act is up to ₹50 crore, as determined by the Board after inquiry.

Must the notice be given again for existing data?

Section 5(2) requires the notice to be given as soon as reasonably practicable where personal data was collected before the Act came into effect.

Contact

Draft or review your DPDPA privacy notice

Share your current privacy policy and RoPA (if you have one). The AMLEGALS data privacy team will identify the gaps against Section 5 and Rule 3 and draft the notice.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

DPDPA Privacy Policy Drafting: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPDPA Privacy Policy Drafting?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPDPA Privacy Policy Drafting under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPDPA Privacy Policy Drafting under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPDPA Privacy Policy Drafting?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPDPA Privacy Policy Drafting rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPDPA Privacy Policy Drafting?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPDPA Privacy Policy Drafting · DPDPA Exposure Assessment