What is a privacy notice under DPDP — what it must contain

What is a privacy notice under DPDP — what it must contain
Privacy Notice

What is a privacy notice under DPDP — what it must contain

A DPDP privacy notice is not a legal disclaimer — it is a functional disclosure document with specific mandatory content. Here is what it must say.

Quick Answer: Under the DPDP Act 2023, a Data Fiduciary must provide a Notice to the data principal before or at the time of collecting personal data. The Notice must contain: the personal data being collected and the purpose of processing; the way in which the data principal may exercise their rights (access, correction, erasure, nomination, grievance); and the way in which the data principal may make a complaint to the Data Protection Board. The Notice must be made available in English and in the languages listed in the Eighth Schedule of the Constitution at the data principal's request. It must be provided before consent is sought — you cannot obtain consent to a processing activity that is not yet described in a Notice. A privacy policy page is a common form of Notice, but must be actively brought to the data principal's attention, not buried in a footer link.

What personal data categories must the Notice cover?

The Notice must identify every category of personal data that you process: identity data (name, email, phone, address, date of birth); financial data (bank account, credit card, UPI, PAN); health data (medical history, insurance, prescriptions); usage and behavioural data (app activity, purchase history, browsing behaviour); device and technical data (IP address, device ID, cookies, location); and any sensitive data categories. Be specific — 'information necessary for our services' is not sufficient. Data principals must understand exactly what you collect before they consent.

What purposes must the Notice specify?

For each data category, the Notice must specify the purpose: why you collect it and what you do with it. Acceptable purpose statements: 'Your contact details are used to deliver orders and send order confirmation emails.' 'Your purchase history is used to recommend similar products.' 'Your browsing behaviour is used to show you personalised advertisements from our advertising partners.' Unacceptable purpose statements: 'to improve our services', 'as described in our terms', or 'for legitimate business purposes'. The more specific the purpose, the more legally defensible the Notice.

How must data principal rights be described in the Notice?

The Notice must tell data principals: how to submit an access request (email address, web portal, in-app mechanism); how to request correction of inaccurate data; how to request erasure; how to withdraw consent; how to nominate a person to exercise rights on their behalf; how to reach the grievance officer; and how to file a complaint with the Data Protection Board (once the Board's online portal is live). These must be practical, working mechanisms — not theoretical references to rights that are impossible to exercise.

What are the language requirements for the Notice?

The Notice must be available in English. On request from a data principal, the Notice must also be made available in any language listed in the Eighth Schedule of the Constitution of India (which includes 22 languages: Assamese, Bengali, Gujarati, Hindi, Kannada, Kashmiri, Konkani, Maithili, Malayalam, Manipuri, Marathi, Nepali, Odia, Punjabi, Sanskrit, Santali, Sindhi, Tamil, Telugu, Urdu, Dogri, Bodo). For consumer-facing businesses with diverse user bases, proactively translating the Notice into the major regional languages is recommended rather than waiting for individual requests.

How must the Notice be presented — in a privacy policy or separately?

The Notice can be in a privacy policy, a separate consent form, an onboarding screen, or any other format — but it must be actively brought to the data principal's attention before consent is sought. A link in a website footer that a user might never click does not satisfy the Notice requirement. Best practice: present a summary of the Notice at every data collection point (registration form, checkout, contact form) with a link to the full Notice; require the user to positively acknowledge the Notice before proceeding; and ensure the Notice is specific to the data being collected at that point.

How often must the Notice be updated?

Update the Notice whenever: you add a new data category to your processing; you add a new purpose for an existing data category; you start sharing data with new third parties; you change the retention period; or your grievance mechanism changes. When you update the Notice, inform existing data principals of the change and, where the change requires new consent, seek fresh consent. Maintain a version history of your Notice — if the Board investigates a processing activity from two years ago, you need to produce the Notice that was in effect at that time.

Frequently asked questions

Is a one-time Notice sufficient or must it be provided every time data is collected?

A Notice provided at the time of the initial relationship (account registration, employment onboarding) covers all processing activities described in it for the duration of the relationship — you do not need to re-issue the Notice every time you process data under the same basis. However, if you start processing data for a new purpose not covered in the original Notice, you must provide a supplementary Notice covering the new purpose and, where needed, seek fresh consent.

Do we need to issue a Notice for processing on the legitimate use basis?

Even when processing on the legitimate use basis (State functions, legal obligation, employment), you should issue a Notice informing the data principal of the processing. While the DPDP Act focuses Notice requirements most strongly on consent-based processing, transparency is a general principle — and regulatory guidance and court interpretation is likely to treat Notice as a baseline obligation across all lawful bases. At minimum, inform employees and customers what data is processed on a non-consent basis and why.

Can the Notice be combined with the consent form?

Yes. The Notice and the consent mechanism can be combined — the Notice describes the processing purpose, and immediately below is the consent checkbox or button. This is the most practical approach for registration flows and onboarding screens. Ensure the Notice appears before the consent mechanism, not after — you cannot ask for consent and then describe what you're asking consent for. The order matters: Notice, then consent, not the other way around.

Write your DPDP-compliant privacy notice

Niti Bharat's Privacy Notice Generator creates a customised, DPDP-compliant notice — with correct purpose descriptions, rights mechanisms, language provisions, and retention periods.

Generate Your Privacy Notice
Previous Post Next Post

Get Free DPDP Checklist