How do I write a DPDP-compliant consent notice?
The structure of a notice that actually meets the Act's standard.
Itemise, don't bundle
The core rule is granularity. Instead of one blanket 'I agree to the privacy policy', break consent into specific purposes — account creation, marketing emails, analytics — each of which the person can accept or decline independently. A purpose the person did not separately agree to is not consented.
What every notice must contain
State the personal data collected, each purpose, how to exercise rights (access, correction, erasure), how to withdraw consent, and how to complain to the Data Protection Board. Make the withdrawal route as frictionless as the opt-in — a one-click email signup needs a one-click unsubscribe.
Language and accessibility
The person must be able to access the notice in English or any language listed in the Constitution's Eighth Schedule. Keep sentences short and avoid legalese; a notice no one can understand fails the 'informed' test even if it is technically complete.
Frequently asked questions
Can I use one consent checkbox for everything?
No. Consent must be specific to each purpose. A single checkbox covering unrelated purposes is not valid consent under the Act.
Does the notice have to be in regional languages?
The individual must be able to access it in English or a language listed in the Eighth Schedule. Offering regional-language versions is the safe approach for consumer products.
What makes consent invalid?
Consent that is bundled, pre-ticked, obtained by dark patterns, conditional on unrelated services, or hard to withdraw is invalid.
Generate a compliant consent notice
Use the Consent Notice Builder to produce an itemised, plain-language notice mapped to your purposes.
Build a Consent Notice