What must a website privacy policy include for DPDP compliance?

What must a website privacy policy include for DPDP compliance?
Privacy Policy

What must a website privacy policy include for DPDP compliance?

Most Indian website privacy policies do not meet the DPDP Act's Notice requirements. Here is what they must include to comply.

Quick Answer: Under the DPDP Act 2023, a website privacy policy functions as a Notice that must be provided to data principals before or at the time of collecting their personal data. A DPDP-compliant website privacy policy must include: the specific categories of personal data collected (not just 'information you provide'); the specific purpose for each data category; the third parties and Data Processors with whom data is shared; the retention period for each category; data principal rights and how to exercise them; how to file a complaint with the Data Protection Board; and the languages in which the policy is available. Most current Indian privacy policies fail on specificity — they describe data in vague terms and do not adequately describe each processing purpose.

What data categories must a website privacy policy name?

Name every data category your website or app collects: contact data (name, email, phone); account data (username, password hash, profile details); financial data (payment method, billing address, transaction history); behavioural data (pages visited, products viewed, cart contents, session duration); device data (IP address, browser type, operating system, device ID); location data (if collected — delivery address, device GPS if enabled); and third-party data (data from social login — Google, Meta — or data enrichment services). Be specific: 'we collect your name and email address' is better than 'we collect personal information'.

How must a DPDP privacy policy describe processing purposes?

For each data category, state the specific purpose: 'Your email address is used to send order confirmations, delivery updates, and account security notifications. With your consent, your email address is also used to send promotional newsletters.' Separate essential processing (covered by the service contract) from optional processing (requiring consent). Avoid generic purpose descriptions: 'to improve our services', 'for business purposes', or 'as described in our terms' do not meet DPDP's specificity requirement.

How must a privacy policy describe third-party sharing?

The policy must identify: which third parties receive personal data; what data they receive; and for what purpose. Best practice: name the specific vendor categories (payment processor, email marketing platform, analytics provider) and name the vendors themselves (Razorpay, Mailchimp, Google Analytics). Where you share data with advertising partners or data brokers, name them and specify the consent required. If you share data with government authorities on legal request, describe the circumstances.

What retention periods must a privacy policy disclose?

For each data category, specify the retention period: 'Your account data is retained for 3 years after account closure.' 'Transaction records are retained for 8 years as required by tax law.' 'Your browsing behaviour data is retained for 12 months.' General statements like 'we retain data as long as necessary' do not meet the specificity requirement. If retention periods vary by data category (as they will), specify them per category. This forces internal discipline about actual retention practices.

How must data principal rights be presented in a privacy policy?

Include a dedicated 'Your Rights' section: list each right (access, correction, erasure, withdrawal of consent, nomination, grievance); explain specifically how to exercise each (send an email to privacy@yourcompany.com with subject line 'Data Access Request' and your registered email address; use the Delete Account button in your account settings); state the response timeline (within 30 days of a valid request); and provide the Data Protection Board's complaint mechanism once the Board is operational.

What language and accessibility requirements apply to the privacy policy?

The privacy policy must be in plain language that a reasonably intelligent non-lawyer can understand. Avoid jargon; explain technical terms if used. Provide the policy in English; make it available in Eighth Schedule languages on request. Use headings and numbered sections for navigation. Ensure the policy is accessible on mobile devices — most Indian internet users access websites on smartphones. The policy should be linked prominently from every data collection point, not only from a footer link on the homepage.

Frequently asked questions

How often should we update our privacy policy?

Update whenever: you add a new data category; you start a new processing purpose; you add new third-party sharing; you change your retention periods; or you add new rights mechanisms. Inform existing users of material updates with an in-app or email notification. Keep a version archive — if the Board investigates a practice from a specific date, you need to show what policy was in effect then. Annually review the policy in full even if no specific changes trigger an update.

Does a mobile app need a separate privacy policy from a website?

An app can use the same privacy policy as the website if the data collection and processing are the same. However, if the app collects additional data types (location, camera, contacts, device sensors) that are not collected on the website, these must be specifically disclosed in the app's privacy notice — either in the same policy or a supplementary app-specific notice. App store guidelines (Google Play, Apple App Store) also require privacy labels and disclosures that complement but do not replace the DPDP Notice.

Can we copy another company's privacy policy?

Copying another company's privacy policy is: legally ineffective (the policy must describe your actual data practices, not someone else's); potentially plagiarism; and a DPDP compliance failure (an inaccurate privacy policy that does not reflect what you actually do is worse than no policy, because it may mislead data principals). Use published policies as structural templates but describe your own data practices accurately.

Update your website privacy policy for DPDP

Niti Bharat's Privacy Policy Generator creates a DPDP-compliant website privacy policy — with accurate data category descriptions, purpose statements, retention periods, and rights mechanisms tailored to your business.

Generate Your Privacy Policy
Previous Post Next Post

Get Free DPDP Checklist