At a glanceThis is a free, ready-to-fill notice template for anyone collecting personal data in India under the DPDP Act. It covers every item Section 5 and the DPDP Rules require: an itemised list of what you collect and why, a link to act on it, how to withdraw consent, how to exercise rights, how to raise a grievance, and how to complain to the Data Protection Board. Fill in the bracketed fields, delete rows you don’t need, and give it to people before you collect their data, not buried in a policy after.
Educational resource only. This provides a template for the notice requirement under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and its Rules; it is not formal legal advice, and you should have it reviewed for your own specific data collection before you use it.
The situation
Starting a notice from a blank page means guessing at what the law actually requires you to say. This template starts you from the full list instead: fill in your specifics, and every mandatory item is already accounted for.
What this template is (and when you need it)
A notice is the plain-language statement you show someone at or before you collect their personal data: this template is a ready-made starting point for writing yours. It’s built directly off the itemised requirements in Section 5 of the DPDP Act and Rule 3 of the DPDP Rules. Use it anywhere you capture personal data, from a signup form to a checkout page, a document-upload step, or an app’s onboarding flow. It is not the same as your full privacy policy (see What a DPDP privacy notice must contain for that distinction). A notice is shorter, purpose-specific, and shown at the moment of collection.
The template: copy and fill in
Copy everything below, replace the bracketed fields with your own details, and delete any row that doesn’t apply to you.
Notice
Last updated: [DATE]
[Your Business/Product Name] (“we”, “us”) collects the following personal data when you [the action]:
What we collect, why, and how long we keep it:
| Personal data | Purpose | How long we keep it |
|---|---|---|
| Name | [purpose] | [retention period] |
| Email address | [purpose] | [retention period] |
| [Document Name] | [purpose] | [retention period] |
This data enables [the purpose]. You can act on this notice, or review our full policy, at [link].
Language: You can get this notice in [the languages you support], or another Scheduled language on request, by [method].
How to withdraw consent: You can withdraw your consent at any time by [method]. Withdrawing is as easy as giving consent was, and it won’t affect anything already done lawfully before you withdrew.
Your rights: You can ask us to let you access, correct, or erase your personal data, or nominate someone to act on your behalf, by [method].
Grievance redressal: If you have a concern about how we’ve handled your data, contact our Grievance Officer: [Name], [email address]. We will respond within [timeframe].
Complaints: If you’re not satisfied with our response, you can complain to the Data Protection Board of India.
How to fill it in
Every bracketed field maps to something Section 5 or Rule 3 actually requires: none of them are optional filler. Show it before you collect data, not after. Adding a notice retroactively doesn’t make consent gathered earlier “informed.”
[DATE]
- What it means: When you last updated this notice, so the person reading it knows how current it is.
- Examples: “12 Aug 2026.”
[Your Business/Product Name]
- What it means: Your business or product’s name, as the person reading this will recognise it.
- Examples: “Acme Consulting Pvt Ltd”; “Acme app.”
[the action]
- What it means: The specific thing someone is doing when you collect their data.
- Examples: Creating an account, placing an order, submitting a form.
[Document Name]
- What it means: The name of any field you collect beyond Name and Email. Pick the one field this row is for. Add a separate row for each additional field instead of listing several in one row: one data type, one purpose, and one retention period per row.
- Examples: Phone Number, PAN, Aadhaar, or another ID document.
[purpose]
- What it means: The specific reason you collect that field, in plain language. Never a vague catch-all like “to improve our services.”
- Examples: “To personalise your account,” “To send order confirmations,” “To verify your identity by OTP.”
[retention period]
- What it means: How long you actually keep that specific field before deleting or anonymising it. Different fields can have different periods; don’t default to “as long as we want.”
- Examples: “For as long as your account is active, plus 90 days after closure”; “3 years from the transaction date”; “Until you withdraw consent.”
[link]
- What it means: Wherever someone can act on this notice or read your full policy.
- Examples: Your website, your app, or a dedicated privacy policy page.
[the languages you support]
- What it means: Rule 3 requires the notice to be available in English or a language from the Eighth Schedule, at the data principal’s choice. List what you actually offer, and give a real way to request another one.
- Examples: “English and Hindi”; “English, with other Scheduled languages available on request.”
[method]
- What it means: However someone can actually reach you to withdraw consent or exercise a right.
- Examples: Emailing [email protected], or using a “Manage consent” setting in your account.
[Name], [email address], [timeframe] - your Grievance Officer
- What it means: A real person or role handling grievances, not a generic support inbox, plus a real response timeframe you hold yourself to: it’s the clock a complainant can rely on before escalating to the Board.
- Examples: “Data Protection Officer,” “[email protected],” “30 days.”
What this template doesn’t cover
This is a notice, not your whole compliance programme, and it isn’t legal advice. It doesn’t cover consent-flow design (see DPDP consent, explained), your broader privacy policy, data security, or sector-specific requirements. The retention period stated here is the headline figure per field, not a substitute for a full retention and deletion policy. It also doesn’t replace a lawyer’s review of your specific data collection: treat it as a complete starting structure, not a substitute for checking it fits what you actually do.
FAQ
Is this template legally binding as-is?
No. It’s a starting structure covering the items DPDP requires a notice to contain. Fill it in accurately for what you actually collect, and have it checked against your own situation before you rely on it.
Is a notice the same as a privacy policy?
No. A notice is shorter and purpose-specific, shown at the point of collection. A privacy policy is your broader standing document. See “What a DPDP privacy notice must contain” for the full distinction.
Can I use one notice for my whole app, or do I need a separate one per form?
You need a notice covering whatever data you’re collecting at that specific point of collection. Different forms collecting different data need their own itemised list. Reuse the same template structure for each.
Do I need to give an exact retention period for every field?
No fixed format is required, but you need to be able to show data isn’t kept indefinitely. A plain, accurate description (“until you close your account”) is fine.
Do I need to translate the notice into every Indian language?
No. Only into what you actually support, with a real way for someone to request another Scheduled language.