AMLEGALS — Strategic Lawyering
Transparency

How to Create a Privacy Notice Under DPDPA

Drafting notices that inform without overwhelming and satisfy legal requirements

Updated 15 January 2025

Executive Summary

The privacy notice is the primary mechanism for informing Data Principals about data processing activities. Section 5 and Rule 5 prescribe notice requirements, but meeting these requirements while maintaining readability presents a drafting challenge. This guide addresses how to create notices that fulfil legal obligations while actually communicating to readers.

Key Takeaways

  • 1
    Structure notices for readability with layered information architecture
  • 2
    Include all mandated content without unnecessary elaboration
  • 3
    Use clear language appropriate to your audience
  • 4
    Keep notices current by establishing update procedures
  • 5
    Make notices accessible through multiple channels

1Notice Requirements Under DPDPA

Section 5 requires that before or at the time of requesting consent, the Data Fiduciary provide notice containing specified information. Rule 5 elaborates on required content. The notice must enable informed consent decisions.

2Required Content Elements

Certain information must appear in every privacy notice to satisfy statutory requirements.

1

Personal Data Description

Identify the categories of personal data that will be collected and processed. Be specific enough to be meaningful without creating an exhaustive list that becomes incomprehensible.

2

Processing Purposes

Explain why each category of data is collected and how it will be used. Purposes should be specific, not generic statements like 'improving our services'.

3

Legal Basis

Indicate whether processing is based on consent or legitimate uses under Section 7. For consent-based processing, link to consent mechanisms.

4

Data Sharing

Disclose categories of third parties with whom data will be shared and the purposes of sharing.

5

Cross Border Transfers

If data will be transferred outside India, disclose this fact and the recipient countries or regions.

6

Retention Periods

State how long personal data will be retained for each purpose, or the criteria used to determine retention.

7

Data Principal Rights

Describe the rights available under DPDPA and how to exercise them.

8

Grievance Mechanism

Provide contact details for the grievance officer and explain the complaint process.

3Structuring for Readability

A notice that satisfies all legal requirements but cannot be understood fails its purpose. Structure enhances comprehension.

1

Layered Approach

Provide a concise summary of key points at the outset, with detailed sections below. Readers can grasp essentials quickly while detailed information remains available.

2

Clear Headings

Use descriptive headings that help readers find relevant sections. 'How We Use Your Data' communicates better than 'Section 4.2'.

3

Plain Language

Avoid legal jargon where simpler alternatives exist. Define necessary technical terms. Write for your audience, not for lawyers.

4

Visual Aids

Consider tables, icons, or infographics to present information accessibly. A data flow diagram may communicate more effectively than paragraphs of text.

Practical Tips

  • •Test notice comprehension with actual users before finalising
  • •Reading level analysis tools can identify overly complex language

4Contextual and Just In Time Notices

The comprehensive privacy notice need not be the only communication. Contextual notices at point of collection reinforce key information.

1

Collection Point Notices

When collecting specific data types, provide brief, relevant information about that collection. A form collecting phone numbers might note 'We will use this for account security and order updates'.

2

Feature Specific Notices

When users access features involving significant data processing, provide targeted information. A location sharing feature should explain location data use at activation.

3

Linking to Full Notice

Contextual notices should link to the comprehensive notice for complete information. They supplement rather than replace the main document.

5Keeping Notices Current

Privacy notices must reflect actual practices. Changes in processing require notice updates.

1

Version Control

Maintain version history with dates. Archive previous versions as they document what users were told at different times.

2

Change Detection Process

Establish procedures to identify when processing changes require notice updates. Include privacy review in product development processes.

3

Communicating Changes

When notices change materially, notify users through appropriate channels. For significant changes, fresh consent may be required.

4

Periodic Review

Schedule regular notice reviews independent of specific changes to ensure ongoing accuracy.

6Accessibility and Availability

Notices must be accessible to Data Principals across all touchpoints.

1

Website Placement

Publish the notice prominently on your website. Footer links are standard, but consider additional placement in account sections and data collection flows.

2

Mobile Accessibility

Ensure notices display properly on mobile devices. Long, desktop-formatted documents frustrate mobile readers.

3

Application Integration

Mobile apps should include in-app access to privacy notices, not just links to web versions.

4

Language Versions

Consider providing notices in languages your users understand. English-only notices may not satisfy the informed consent requirement for non-English speakers.

7Special Notice Requirements

Certain processing activities require enhanced notice.

1

Childrens Data

When processing data of children, notices should address the guardian providing consent. Explain verification procedures and parental controls.

2

Sensitive Data

Processing of sensitive personal data warrants prominent, specific notice given the heightened privacy implications.

3

Automated Decision Making

Where significant decisions are based on automated processing, explain the logic involved and how individuals can seek human review.

Frequently Asked Questions

Need Implementation Support?

Our data protection team can help translate these guidelines into organisation-specific policies, procedures, and technical implementations.

Get Expert Guidance

Create Privacy Notice: questions and answers

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What must a DPDPA privacy notice contain?

Section 5 read with Rule 3 requires a notice, understandable independently of other information, that itemises the personal data and the specified purpose, and explains how the Data Principal may withdraw consent, exercise rights and complain to the Board. A Data Principal has the right to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The design of translation operations is an implementation matter.

When must personal data be erased under DPDPA?

Section 8(7) requires erasure once the specified purpose is no longer served or consent is withdrawn, unless retention is required by law. Rule 8 and the Third Schedule prescribe time periods for specified classes of Data Fiduciaries, with prior intimation to the Data Principal before erasure.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Create Privacy Notice?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Create Privacy Notice under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Create Privacy Notice under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Create Privacy Notice?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Create Privacy Notice rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Create Privacy Notice?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Create Privacy Notice · DPDPA Exposure Assessment