How to read a privacy notice before you click "I Agree": a plain checklist
At a glanceBefore you agree, a good privacy notice should tell you four things in plain language: what personal data is being collected, the specific purpose it’s for, how to withdraw consent later, and how to complain. If a notice is vague about the purpose, bundles unrelated uses into one “I agree,” or hides how to opt out, treat that as a reason to pause — under India’s DPDP Act, that notice may not support valid consent anyway.
Educational resource only. This explains what to look for in a privacy notice under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.
Under the DPDP Act, a company has to give you a clear notice before it takes your consent — that’s what makes consent “informed.” So the notice isn’t fine print to scroll past; it’s the thing that tells you what you’re actually agreeing to. Here’s how to read one quickly.
The 60-second checklist
Run a notice past these six checks before you tap “I Agree.”
- ☐ What data is being collected? It should name the actual items — phone number, email, Aadhaar, location — not just “your information.”
- ☐ What’s the specific purpose? Look for a clear, named reason (“to deliver your order,” “to process your loan”). “For business purposes” or “to improve our services” is too vague to be meaningful.
- ☐ Is the collection matched to the purpose? A torch app asking for your contacts, or a shopping site demanding your Aadhaar to browse, is collecting more than the stated purpose needs.
- ☐ Can you say no to the extras? The core service and optional uses (like marketing) should be separable — not one bundled tick that forces you to accept everything.
- ☐ **How do you withdraw consent later?** The notice should tell you how to take your consent back — and it must be as easy as giving it.
- ☐ How do you complain? It should point you to a grievance officer / Data Protection Officer or a contact channel, and mention your ability to escalate to the Data Protection Board of India.
If a notice passes all six, agreeing is an informed choice. If it fails several, that’s your signal to slow down.
Why these four points matter
A notice exists to let you consent with your eyes open — the checks above are just that requirement, in plain terms.
The DPDP Act requires the notice (Section 5) precisely so your consent (Section 6) is free, specific and informed. Each check maps to a real protection: naming the data and purpose is what “specific” means; separable choices are what “unconditional” means; a clear withdrawal and complaint route is what keeps your consent meaningful after the fact. A notice that skips these isn’t just badly written — it’s failing to give you what the law says you’re owed before you agree.
Red flags that mean “don’t agree yet”
Some patterns are a signal the notice — and the consent it’s asking for — falls short.
- A pre-ticked box, or “by continuing, you agree.” Consent needs a clear, active step from you; a pre-filled tick or silent “continuing” isn’t it.
- One “I agree” covering many unrelated uses. Consent is meant to be per purpose. A single bundled tick for the service and marketing and sharing with partners doesn’t meet that bar.
- A purpose so broad it means nothing. “For business and marketing purposes” tells you nothing you can actually assess.
- No way to withdraw, or a deliberately buried one. If you can’t find how to opt out, the exit isn’t “as easy as giving,” which the Act requires.
- Being forced to consent to unrelated data use to get the service at all. A service can ask for what it genuinely needs — not use access as a lever for extras.
Spotting one of these doesn’t mean the company is acting in bad faith, but it does mean you’re within your rights to pause, decline the extras, or withdraw later.
FAQ
Do I have to read the whole privacy policy every time?
No — the six checks above are the fast version. A privacy notice at the point of collection should surface the key points (data, purpose, withdrawal, complaint) without you reading a long policy.
What if the notice is vague about why my data is needed?
Treat vagueness as a red flag. A purpose has to be specific for your consent to be valid, so “for business purposes” is a reason to pause rather than agree.
Can I agree to the service but not to marketing?
You should be able to. Consent is per purpose, so a compliant notice lets you accept the core service while declining optional uses like marketing.
I already agreed without reading it — can I undo that?
Yes. You can withdraw consent at any time, and it must be as easy as giving it was.
Related Articles
Collecting personal data from your own customers?
These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.
Run the compliance self-check →