Skip to content
Back to Blog
·9 min read·compliance

DPDP Act Privacy Policy and Consent: India Compliance Guide

DPDP Act 2023 requires valid consent and a compliant privacy notice for Indian websites. Covers notice rules, data principal rights, and compliance steps.

BR

Bachao.AI Research Team

Cybersecurity Research

Check DPDP Compliance

Compliance risk for Indian SMBs

Non-compliance with the DPDP Act 2023 carries penalties up to ₹250 crore. This post explains what's at stake and what action to take.

The Digital Personal Data Protection Act 2023 (DPDP Act) fundamentally changes how Indian websites and apps must handle user data. Every data fiduciary — any entity that determines the purpose and means of processing personal data — must provide a clear notice before collecting data, obtain free, specific, informed, unambiguous, and withdrawable consent, and honour the rights of data principals on demand. Failure to meet these requirements exposes your organisation to significant regulatory penalties from the Data Protection Board of India. This guide covers what a compliant privacy notice must contain, how valid consent works under DPDP, and the practical steps Indian businesses need to take now.

What the DPDP Act 2023 Actually Requires

The DPDP Act, notified by MeitY (Ministry of Electronics and Information Technology) in August 2023 and available at meity.gov.in, creates a rights-based framework for digital personal data. It applies to any processing of digital personal data within India, and to processing outside India if it involves offering goods or services to individuals in India.

The core obligations for data fiduciaries are:

    1. Notice — Provide a clear, plain-language notice to every data principal before or at the time of collecting personal data.
    2. Consent — Obtain valid consent that meets all five attributes: free, specific, informed, unambiguous, and withdrawable.
    3. Purpose limitation — Process data only for the purpose for which consent was given.
    4. Data minimisation — Collect only what is necessary for the stated purpose.
    5. Storage limitation — Erase personal data when the purpose is fulfilled or consent is withdrawn.
    6. Accuracy — Take reasonable steps to ensure data is accurate and complete.
    7. Security safeguards — Implement reasonable security measures to prevent data breaches.
⚠️
WARNING
The DPDP Act applies retroactively to existing data collections. If your website or app already holds personal data collected without a proper DPDP-compliant notice and consent mechanism, you are required to issue a fresh notice and obtain fresh consent.

What a Compliant Privacy Notice Must Contain

Under Section 5 of the DPDP Act, every notice to a data principal must include, in clear and plain language:

  1. The personal data being collected and the purpose for which it will be processed.
  2. The manner in which the data principal may exercise their rights (access, correction, erasure, grievance).
  3. The manner in which the data principal may withdraw consent.
  4. A link or reference to the contact details of the Data Protection Officer (or a nominated grievance officer, if no DPO is mandatory for your organisation).
The notice must be provided in English and, where the data principal requests, in any language listed in the Eighth Schedule of the Indian Constitution. This bilingual requirement is a practical obligation that many websites currently ignore.
Notice ElementDPDP Act RequirementCommon Gap Found
Purpose of processingSpecific, not generic"Improving services" without detail
Data types collectedListed explicitlyBlanket "any information you provide"
Rights of data principalAccess, correction, erasure, grievanceNo mention of erasure right
Consent withdrawal pathClear mechanism statedNo withdrawal option offered
Grievance contactName/email of officerGeneric contact form only
Language availabilityEnglish + Eighth Schedule on requestEnglish-only with no option stated
Consent Manager referenceIf applicableNot mentioned
💡
TIP
Keep your privacy notice short, scannable, and in active voice. The DPDP Act specifically requires "plain language" — legal boilerplate copied from GDPR templates does not satisfy this standard and may itself be a non-compliance finding.

Section 6 of the DPDP Act sets out the requirements for consent. Consent is only valid when it is:

    1. Free — Not conditional on accessing a service unless the data is genuinely necessary for that service. Pre-ticked boxes, dark patterns, and forced bundling invalidate consent.
    2. Specific — Given for a clearly defined purpose. Omnibus consent for "all present and future uses" is invalid.
    3. Informed — Given after the data principal has been provided the requisite notice.
    4. Unambiguous — Indicated by a clear affirmative action. Silence, inactivity, or pre-ticked checkboxes do not constitute consent.
    5. Withdrawable — Withdrawal must be as easy as giving consent, and must take effect immediately for future processing.
graph TD A[Data Principal visits website] --> B[Consent Notice Served - purpose and rights] B --> C{Data Principal Decision} C -->|Gives consent - affirmative action| D[Processing begins - purpose limited] C -->|Declines consent| E[Service restricted or continues without data processing] D --> F[Data used for stated purpose only] F --> G{Purpose fulfilled or consent withdrawn?} G -->|Purpose fulfilled| H[Data erased or anonymised] G -->|Consent withdrawn by data principal| I[Processing stops immediately] I --> J[Erasure within reasonable timeline] H --> K[End of lifecycle] J --> K style A fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style B fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style C fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style D fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style E fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style F fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style G fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style H fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style I fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style J fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style K fill:#1e3d2f,stroke:#10B981,color:#e2e8f0

A practical implication: if your sign-up form has a pre-checked "I agree to marketing emails" box, that consent is invalid under DPDP. Users must actively check it. Similarly, if your mobile app requests location access as a condition of using a feature that does not need location data, that consent is not free.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

The DPDP Act introduces the concept of a Consent Manager — a registered entity through which data principals can give, manage, review, and withdraw consent across multiple data fiduciaries through a single interface. Consent Managers will be registered with and regulated by the Data Protection Board of India.

For businesses, working through a registered Consent Manager shifts certain consent-record-keeping obligations to the Consent Manager. However, it does not absolve the data fiduciary of its core obligations. The rules around Consent Manager registration, interoperability standards, and certification are expected in the subordinate rules that MeitY is developing.

Practically, businesses should architect their consent infrastructure to be Consent Manager-compatible: store consent records with a unique identifier per data principal, make consent records queryable, and expose a consent withdrawal API endpoint that can be called by external Consent Manager platforms.

Handling Children's Personal Data

Section 9 of the DPDP Act imposes heightened obligations for processing personal data of children (under 18 years). Key requirements:

    1. Verifiable parental or guardian consent is mandatory before processing a child's personal data.
    2. Processing that is likely to cause harm to a child is prohibited regardless of consent.
    3. Tracking, behavioural monitoring, and targeted advertising directed at children are explicitly prohibited.
🚨
DANGER
If your platform is likely to be accessed by users under 18 — including educational apps, gaming platforms, student portals, and consumer e-commerce — you must implement an age-verification mechanism and a verifiable parental consent flow before any data processing begins. Relying on a self-declaration checkbox ("I am above 18") alone is unlikely to satisfy the "verifiable" standard.

Significant Data Fiduciaries (SDFs), a category to be notified by the Central Government, will face additional compliance obligations around children's data processing, including algorithmic transparency and mandatory data audits.

Data Principal Rights Your Platform Must Support

The DPDP Act grants data principals the following rights, each of which requires a corresponding operational capability on your platform:

Right to access information (Section 11) — A data principal can request a summary of their personal data being processed and the purposes for which it is being processed. Your system must be able to generate this summary and deliver it on request.

Right to correction and erasure (Section 12) — A data principal can request correction of inaccurate or misleading data, completion of incomplete data, and erasure of personal data no longer necessary for the stated purpose. Your database architecture must support targeted deletion or anonymisation per user, not just account deactivation.

Right to grievance redressal (Section 13) — Every data principal must have access to a grievance mechanism. Grievances must be addressed within the timeline specified in the rules (expected to mirror existing IT Act obligations). The Data Protection Board is the appellate authority if the fiduciary does not respond adequately.

Right to nominate (Section 14) — A data principal can nominate another individual to exercise rights on their behalf in the event of death or incapacity.

pie title Data Principal Rights Under the DPDP Act 2023 "Access and Information" : 25 "Correction and Completion" : 20 "Erasure" : 20 "Grievance Redressal" : 20 "Right to Nominate" : 15
1 billion+Estimated data principals covered by the DPDP Act (MeitY 2023)
30 daysExpected grievance resolution timeline under draft DPDP Rules (MeitY 2023)

Practical Steps to Make Your Indian Website Compliant

Step 1 — Conduct a Data Mapping Exercise

Before updating your privacy policy, map every point where personal data enters your systems: sign-up forms, payment flows, analytics scripts, third-party SDKs, CRM integrations, and API calls to partners. This data map becomes the factual basis for your notice.

Step 2 — Rewrite Your Privacy Notice

Replace legal boilerplate with a plain-language notice that lists each data type, its purpose, the retention period, and the withdrawal method. Keep it under 1,000 words for the summary; link to a full policy for detail. See the DPDP compliance guide for a structured checklist.

Add a consent management component (cookie banner for web, permissions screen for mobile) that:

    1. Captures an explicit affirmative action for each consent category
    2. Records the consent with a timestamp and the version of the notice shown
    3. Surfaces a withdrawal option in the user account settings
    4. Triggers downstream erasure or processing-stop workflows on withdrawal

Step 4 — Build Rights-Response Workflows

Create internal processes for receiving and fulfilling access, correction, and erasure requests. Assign ownership (typically the DPO or a compliance lead). Define SLA timelines. Test the erasure path end-to-end, including cascading deletes or anonymisation in backup stores and third-party processors.

Step 5 — Assess Your Security Posture

The DPDP Act mandates "reasonable security safeguards." While the Act does not prescribe specific technical controls, CERT-In's Information Security Practices and ISO 27001 are the reference benchmarks. A periodic VAPT assessment — by Bachao.AI, operated by Dhisattva AI Pvt Ltd, or with a CERT-In empanelled partner — identifies vulnerabilities in your web and API attack surface that could lead to a notifiable data breach.

Step 6 — Appoint a Grievance Officer and Publish Contact Details

Even before the DPDP rules are finalised, publish the name, email, and response-timeline commitment of a nominated grievance officer on your privacy notice page. This is also a requirement under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 for most platforms.

ℹ️
INFO
The DPDP Act's rules are still being finalised by MeitY. However, the substantive obligations in the Act itself — notice, consent, rights, security, grievance — are already in force. Waiting for all subordinate rules before starting compliance work is a risk posture, not a legal position.

DPDP vs GDPR: Key Differences for Indian Businesses

Many Indian businesses have adapted GDPR-style privacy policies. While there is philosophical overlap, the DPDP Act has distinct requirements:

DimensionGDPRDPDP Act 2023
Lawful basis options6 lawful bases (consent, contract, legitimate interest, etc.)Primarily consent and certain legitimate uses; no "legitimate interests" balancing test
Right to portabilityYesNot explicit in the Act; may be in rules
DPO requirementMandatory for certain controllersDPO equivalent for Significant Data Fiduciaries only
Children's age threshold16 (varies by Member State)18
Cross-border transfersAdequacy decisions + SCCs + BCRsTransfer to notified countries permitted; blacklisting model
Territorial scopeGlobal (EU residents)India-centric + extraterritorial for India-targeted services
A GDPR-compliant privacy policy does not automatically satisfy DPDP. The consent validity requirements, children's data rules, and rights mechanisms need India-specific implementation.
🎯Key Takeaway
The DPDP Act 2023 requires affirmative, withdrawable consent, a plain-language notice listing every data type and purpose, and operational workflows to honour access, correction, and erasure requests. Organisations that treat privacy compliance as a one-time policy update rather than an ongoing operational capability will be the first to face scrutiny from the Data Protection Board.

Frequently Asked Questions

Does the DPDP Act apply to my small business website that only collects a contact form submission?
Yes. Any entity processing digital personal data of individuals in India is a data fiduciary under the DPDP Act, regardless of size. A contact form that collects a name, email, or phone number is personal data processing. You need a notice and a consent mechanism. Startups and small businesses are not currently exempted, though the rules may create lighter obligations for certain categories.
Is a cookie banner sufficient for DPDP consent?
A cookie banner is one component, but not sufficient on its own. DPDP consent must be free, specific, informed, unambiguous, and withdrawable for each purpose. Your banner must describe each processing activity, allow granular opt-in per category, and provide an equally accessible withdrawal path. A "by continuing to browse you accept" banner does not meet the unambiguous standard.
What does consent withdrawal actually require on the technical side?
Withdrawal must stop future processing immediately. Practically, this means: updating a consent flag in your database, pausing any scheduled marketing or profiling processes tied to that user, notifying downstream data processors, and triggering a data deletion or anonymisation flow if the purpose has been fulfilled. The withdrawal mechanism must be as easy to use as the original consent mechanism.
Do I need a Data Protection Officer under the DPDP Act?
A DPO (or equivalent) is mandatory only for Significant Data Fiduciaries (SDFs), a category the Central Government will notify based on volume, sensitivity, and risk factors. However, every data fiduciary must publish the contact details of a grievance officer who can receive and resolve data principal complaints, regardless of whether a formal DPO appointment is required.
How does the DPDP Act handle data collected before the Act came into force?
The DPDP Act requires data fiduciaries to issue a fresh notice to data principals whose data was collected before the Act, and to obtain fresh valid consent for any continuing processing. You cannot grandfather old consent obtained under pre-DPDP terms that did not meet the Act's validity requirements.
Where can I find the official DPDP Act text and rules?
The Digital Personal Data Protection Act 2023 is available on the MeitY website at meity.gov.in. Draft rules and public consultation documents are also published there. The Data Protection Board's operational procedures will be notified separately once the Board is constituted.
BR

Bachao.AI Research Team

Cybersecurity Research

AI-powered security research and threat intelligence from the Bachao.AI team. Covering the latest vulnerabilities, CVEs, and cybersecurity developments affecting Indian businesses.

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

See where your business stands against the DPDP Act 2023

Free automated scan — risk score in under 2 hours. No credit card required.

Check DPDP Compliance
Find your vulnerabilitiesStart free scan →