At a glanceUnder India’s DPDP Act, the notice you give when collecting someone’s personal data must, in plain language, itemise what data you’re taking and the specific purpose for each, and tell the person how to withdraw consent, exercise their rights, raise a grievance, and complain to the Data Protection Board. It has to stand on its own — not be buried inside a longer privacy policy.
Educational resource only. This explains the notice requirement under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and its Rules; it is not formal legal advice.
What is a DPDP privacy notice?
The notice is the plain-language statement you give at or before collecting personal data — it’s what makes consent “informed.” Consent under the DPDP Act only counts if the person was told, clearly and upfront, what they’re agreeing to. The notice is how you tell them. It must be understandable on its own, without the reader having to dig through other documents to make sense of it.
What must the notice contain?
The notice has to be itemised and complete — a vague “we collect data to serve you better” fails. Under the DPDP Rules, it must set out:
- An itemised description of the personal data you’re collecting — listed, not lumped together.
- The specific purpose for each, and the goods, services, or functions that depend on that processing.
- A link to your website or app where the person can act on what follows.
- How to withdraw consent — and it must be as easy to withdraw as it was to give.
- How to exercise their rights under the Act (access, correction, erasure, nomination).
- How to raise a grievance with you.
- How to make a complaint to the Data Protection Board of India.
That list is the test: if any item is missing, the notice isn’t complete.
Use the templateDPDP notice template — a ready-to-fill notice covering every item on this list.
When and how do you have to give it?
The notice comes first — at or before the moment you collect the data, not after. It has to be clear, concise, and accessible, and presented so the person can read and understand it independently of your other terms. On request, you must also make it available in English or any of the 22 languages in the Eighth Schedule to the Constitution — so a notice that only ever exists in English isn’t enough if someone asks for another listed language.
How is a notice different from a privacy policy?
A notice is purpose-specific and sits at the point of collection; a privacy policy is the broader, standing document — and the policy can’t stand in for the notice. This is the most common mistake: relying on a general privacy policy the person might read later. The DPDP notice has to be there, then and there, tied to the specific data and purpose in front of them. The policy is still useful, but it doesn’t discharge the notice duty.
What happens if the notice is missing or buried?
No proper notice means no informed consent — and consent that isn’t informed isn’t valid. Because the burden of proving valid consent sits on you (the Data Fiduciary), a missing, vague, or buried notice doesn’t just risk a complaint; it undercuts the legal basis for everything you do with that data. The substantive notice-and-consent standard becomes fully enforceable in May 2027, which is the window businesses have to get this right.
FAQ
Does my existing privacy policy count as a DPDP notice?
Not on its own. The notice must be itemised, purpose-specific, and given at the point of collection; a general policy read later doesn’t satisfy it.
What’s the single most-missed item in a notice?
Usually the clear route to withdraw consent and to complain to the Data Protection Board — both are mandatory and often left out.
Do I have to translate my notice into other languages?
You must make it available in English or any Eighth Schedule language on request, so be ready to provide a translation if asked.