Somewhere in your website footer is a privacy policy nobody has opened in three years. It was copied from a US template, it says "we may collect certain information", and under the DPDP Act it is now evidence β of what you told people, or of what you did not.
A DPDP-compliant privacy notice is a standalone, plain-language document that itemises the personal data you collect, ties a specific purpose to each category, explains how to exercise rights and how to reach your Grievance Officer, and is available in English and the scheduled Indian languages.
The bottom line
What it has to be: standalone and readable on its own, shown before or at the point of consent, with nothing buried and nothing pre-ticked.
What it has to contain: itemised data categories, a specific purpose for each, the rights and how to use them, and a named Grievance Officer.
By when: full compliance is due 13 May 2027, but notice sits underneath everything else, so it is the piece to fix first.
Why the policy you have probably fails
The typical Indian privacy policy fails for five predictable reasons. It speaks in generalities β "we may collect certain information". It lumps every purpose into one sentence. It offers no real route to exercise a right. It names nobody for grievances. And it exists only in English.
The Act asks for the opposite of all five. Vagueness was survivable under the old IT Act rules, which nobody enforced. It is not survivable now.
What Rule 3 actually requires
Under Rule 3 of the DPDP Rules, the notice you give a Data Principal must:
- be standalone and clear β understandable on its own, not buried inside long terms of service;
- itemise the personal data you collect, category by category;
- state the specific purpose of processing for each, rather than a catch-all "to improve our services";
- explain how to exercise rights: access, correction, erasure, grievance and withdrawal of consent;
- give the means to complain to the Data Protection Board; and
- be available in English or any language in the Eighth Schedule of the Constitution.
The working test is whether an ordinary person, reading it once, understands what you are taking and why.
Notice, consent and privacy policy are three things
These get blurred constantly, and separating them makes the drafting easier.
- The notice is what you show the person before collecting data β the itemised, plain-language disclosure Rule 3 describes.
- Consent is their affirmative agreement to that processing, a separate act that has to be free and specific.
- The privacy policy is the broader public document on your site where your data practices live.
Your privacy policy should contain a compliant notice, and your consent flow should point at it. They work together and they are not substitutes for each other.
What goes in, section by section
- Who we are β legal name, your role as Data Fiduciary, contact details.
- What we collect β an itemised list by category: identity, contact, financial, device, usage and so on.
- Why we collect it β the specific purpose attached to each category, and the lawful basis, whether that is consent or a named legitimate use.
- Who we share it with β processors and third parties, and whether data leaves India.
- How long we keep it β a retention period per category, and what deletion actually looks like.
- Your rights β access, correction, erasure, grievance, nomination and withdrawal, each with the steps to use it.
- Grievance Officer β name, email and response timeline, with grievances resolved within 90 days.
- Children's data β your approach to verifiable parental consent, if you process the data of minors.
- Changes β how you tell people the policy has been updated.
The language requirement nearly everyone misses
The notice must be available in English and the scheduled Indian languages, so that a user can read it in a language they actually understand.
For a consumer product that means the notice belongs in your localisation pipeline rather than sitting as a one-off English page maintained by whoever wrote it. Translation and the engineering to serve the right version take time, which is the argument for starting now rather than in the last quarter before the deadline.
Dark patterns to remove
The Rules ban manipulative consent design. Fix these wherever they appear:
- pre-ticked consent boxes, since consent has to be an affirmative action;
- a prominent "Accept" beside a hidden or greyed-out "Reject";
- consent walls blocking access unless the user agrees to non-essential processing;
- bundled consent forcing agreement to unrelated purposes in one click;
- language written to nudge a yes rather than to inform.
And withdrawal has to be as easy as agreeing. If saying yes takes one click, saying no later takes one click.
One clause, rewritten
Before: "We may collect certain personal information to provide and improve our services and for other business purposes."
After: "We collect your name and email address to create and manage your account, and your device ID and usage data to keep the service secure and diagnose errors. We do not use this data for advertising. You can access, correct, or delete it any time from Settings, or by emailing our Grievance Officer at privacy@example.com, who will respond within 90 days."
The idea has not changed. What changed is that the second version is itemised, purpose-specific, rights-aware and contactable, which is the whole shift compressed into a paragraph.
Common mistakes
- Hiding the notice inside the terms of service. It has to stand on its own.
- Listing one vague purpose for everything. Each data category needs its own.
- Naming no Grievance Officer. A reachable, named contact is mandatory.
- Publishing in English only. Scheduled-language availability is a requirement, not a nicety.
- Reusing a GDPR policy as-is. It will not carry the India-specific notice and language rules.
Frequently asked questions
Does the DPDP Act require a specific privacy policy format? No template is mandated, but the notice must be standalone, itemised and plain-language, covering data, purposes, rights and grievance contact, and available in the scheduled languages.
Can I keep using my existing GDPR privacy policy? As a base, yes. You still have to add the India-specific elements: scheduled-language availability, a Grievance Officer, DPDP rights and Indian retention rules.
What languages must my privacy notice be in? English, or any language listed in the Eighth Schedule of the Constitution, so that users can read it in a language they understand.
Who is the Grievance Officer? A designated, reachable contact who handles Data Principal complaints and must resolve grievances within 90 days. Their details have to be public.
When must my privacy policy comply? Full compliance is due by 13 May 2027. Because notice and consent sit underneath every other obligation, this is the one to do early.
Does the notice have to be a separate page from the privacy policy? Not necessarily. It has to be standalone in the sense of being readable on its own, which a clearly separated section inside the policy can satisfy β burying it in the terms of service does not.