How to Build a Privacy Policy That Satisfies DPDP Act
India's DPDP Act requires a clear privacy notice before collecting personal data. Build a compliant privacy policy with this structure and template guide.
- DPDP Act Section 5 requires a notice before or at the time of collecting personal data.
- The notice must describe the data being collected, the purpose of processing, and how to exercise data principal rights.
- Plain language is required — legalese-heavy policies that obscure material facts violate the spirit of the Act.
- The privacy policy and the consent notice are related but distinct — understand the difference.
- Your privacy policy must also satisfy GDPR if you have EU users — build with both requirements in mind.
In this guide
DPDP Act Notice Requirements
Section 5 of the DPDP Act requires Data Fiduciaries to give a notice to data principals before or at the time of collecting their personal data. The notice must describe: the personal data to be collected, the purpose of processing, the manner in which they may exercise their rights under the Act, and the manner in which they may make a complaint to the Data Protection Board.
The notice must be clear, in plain language, and accessible. The central government may prescribe the form and content of the notice in Rules. Until Rules are published, the Act itself defines the minimum requirements.
Privacy Policy vs Consent Notice
These are related but distinct documents. The privacy policy is a comprehensive document (typically on your website) that describes your entire data processing programme — all data types, all purposes, all retention periods, all third-party sharing. It satisfies Section 5 for existing users and provides the reference document that the consent notice points to.
The consent notice is the specific notice presented to a data principal at the point of data collection — typically a form, sign-up screen, or data collection moment. It may be shorter and more specific, pointing to the full privacy policy for complete details.
Required Sections
Identity and contact information: who is the Data Fiduciary? Include company name, registered address, and contact details for the Data Protection Officer or Grievance Officer.
Data collected and purpose: specific categories of personal data collected (name, email, phone, IP address, usage data) and the specific purpose for each category.
Legal basis for processing: consent, or legitimate use under the DPDP Act. Where consent is the basis, describe how consent is obtained and how it can be withdrawn.
Data retention: how long each category of data is retained and the criteria used to determine retention periods.
Third-party sharing: which categories of vendors or partners receive personal data, for what purpose, and what protections apply.
Data principal rights: how to exercise rights under Sections 11, 12, and 13 of the DPDP Act — with the contact details of the Grievance Officer.
Language and Readability
The DPDP Act requires the notice to be in "clear and plain language." This is a substantive requirement. A policy written in dense legalese that a reasonable person cannot understand fails this requirement.
Practical guidance: write at a reading level that an educated non-specialist can understand. Use short sentences. Use active voice. Define technical terms when you must use them. Avoid passive constructions that obscure who is responsible.
The Act requires notices to be made available in all languages specified in the Eighth Schedule of the Indian Constitution if requested by data principals. For consumer-facing products with large Indian user bases, planning for multilingual notices is important.
Aligning with GDPR
If you have EU users, your privacy policy must also satisfy GDPR Articles 13 and 14. GDPR requires more detail in several areas: the legal basis for each processing activity, data subject rights under Articles 15–22, right to lodge a complaint with a supervisory authority, and information about cross-border transfers.
Build a single privacy policy that satisfies both DPDP Act and GDPR requirements. GDPR's requirements are generally more detailed, so a GDPR-compliant policy typically also satisfies DPDP Act requirements with minor additions.
Template Structure
1. Who We Are (Data Fiduciary identity and contact). 2. What Personal Data We Collect. 3. How We Use Your Data (purpose by data category). 4. Legal Basis for Processing. 5. How Long We Keep Your Data. 6. Who We Share Your Data With. 7. International Data Transfers (if applicable). 8. Your Rights Under the DPDP Act. 9. How to Exercise Your Rights / Contact Our Grievance Officer. 10. How to Lodge a Complaint with the Data Protection Board. 11. Changes to This Privacy Policy. 12. Effective Date and Version History.
Maintenance and Updates
Your privacy policy must be updated when: your data processing activities change, new third-party processors are added, or applicable law changes (DPDP Rules when published, GDPR enforcement developments).
Set a calendar reminder for annual review. When you update the policy: increment the version number and "last updated" date, notify existing users of material changes, and re-collect consent if you are adding new processing purposes.
Frequently Asked Questions
Can a B2B SaaS company use its terms of service as a privacy notice?
Does the DPDP Act require cookie consent?
How often should we update our privacy policy for DPDP compliance?
Do we need a separate privacy policy for employees?
What is the DPDP Act penalty for a non-compliant privacy policy?
Automate your compliance today
AuditPath runs 86+ automated checks across AWS, GitHub, Okta, and 14 more integrations. SOC 2 and DPDP Act. Free plan available.
Start for free