On this page
- Four things the law asks you to put in front of people
- 1. The notice that comes with each consent request
- 2. A contact for questions about their data
- 3. How a person makes a request
- 4. The grievance response period
- A checklist for the page
- What a page cannot do on its own
- When this applies
- What this article covers
- Common questions
- In the news
- Sources
Most Indian websites carry a page called “Privacy Policy”. The DPDP Act and the DPDP Rules do not use that term. They list what you must tell people, and what you must publish, in four places. A privacy page that covers all four, plus a notice shown where you ask for consent, rests on the text of the law rather than on a generic template.
Four things the law asks you to put in front of people
- A notice with each request for consent. It comes with the request or before it.
- A contact for questions about their data. Published on your website or app.
- How to make a request. The ways a person can ask to use their rights, published on your website or app.
- A grievance response period. Published, and not longer than 90 days.
1. The notice that comes with each consent request
Whenever you ask for consent, whether on a sign-up form, at checkout or in an app permission screen, a notice must come with the request or before it. The Rules set the minimum content. The notice must give:
- an itemised description of the personal data, item by item;
- each specific purpose, and a specific description of the goods or services, or the uses, that the processing provides or enables;
- the link to your website or app, or both;
- a description of the other means, if any, by which the person can withdraw consent, use their rights under the Act, and make a complaint to the Board.
The Rules also say the notice must be understandable independently of any other information you make available. That matters for the privacy page. A link to a long policy does not replace the notice: the notice itself has to make sense on its own, in clear and plain language. The person must also be able to read it in English or in any language listed in the Eighth Schedule to the Constitution.
2. A contact for questions about their data
You must publish, prominently on your website or app, the business contact information of your Data Protection Officer, if the law requires you to have one, or of a person who can answer on your behalf the questions people raise about the processing of their personal data. The Rules add that you must mention this contact in every response to a communication in which someone exercises a right. A request for consent must also carry the contact of a Data Protection Officer, where applicable, or of another person you have authorised to respond.

3. How a person makes a request
Publish, prominently, the details of the means a person can use to make a request to exercise their rights, and any particulars you need to identify them under your terms of service, such as a username or other identifier. The Rules treat any sequence of characters you issued to identify the person as an identifier, for example a customer identification file number, an application reference number, an enrolment ID, an email address or a mobile number.
The rights the page should point to are the ones the Act gives: a summary of the personal data you process and who it was shared with, correction, completion, updating and erasure, a grievance process, and nominating another person to act in the event of death or incapacity. The Rules also let a person nominate others using the means you provide.
4. The grievance response period
Publish, prominently, the period within which you respond to grievances under your grievance redressal system. The Rules say it must be a reasonable period not exceeding ninety days, and that you must put technical and organisational measures in place so that you can respond within it. State the number of days you commit to on the page. The 90 days is the outer limit for grievances. It is not a deadline for every rights request.
The Act asks a person to use this process first: they must exhaust your grievance redressal before approaching the Board. A clear path on the page makes that possible.
A checklist for the page
| Put on the page | What it covers |
|---|---|
| Business contact | Name or role and the email or phone for questions about personal data. |
| How to make a request | The form, address or app screen to use, and any identifier you need. |
| The rights in plain words | Access, correction, completion, updating, erasure, grievance, nomination. |
| How to withdraw consent | As easy as giving consent was. Say where to click or whom to write to. |
| Grievance period | The number of days, never more than 90, and where to complain. |
| How to complain to the Board | A line saying a person may complain to the Data Protection Board of India after using your grievance process. |
| Language options | English or any language in the Eighth Schedule to the Constitution. |
What a page cannot do on its own
A privacy page is not the consent notice. The notice comes with the request for consent and lists the data item by item. Consent itself must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the purpose. A page cannot fix a request that asks for more data than the purpose needs. If you are building both, write the notice first and let the page repeat its contents. See what a consent notice must contain.
The page also cannot promise what you do not do. If you say you erase data when it is no longer needed, make sure the retention schedule behind that line exists. The retention article sets out the rules.
When this applies
The notice, contact, request and grievance duties start on 13 May 2027, eighteen months after the notifications published on 13 November 2025. You can publish the page earlier. If people have already given consent before 13 May 2027, when section 5 comes into force (counted from 13 November 2025), the Act expects a notice to them as soon as reasonably practicable. The timeline article explains the dates.
What this article covers
This article covers the DPDP Act and the DPDP Rules only. Cookie banners, sector rules and other laws that may bind your site are outside it, so ask counsel what else belongs on the page. If you run an online store, DPDPA for online stores lists the personal data a typical store holds. To check whether the Act applies to your business at all, use the processing map.
Common questions
Does the DPDP Act require a privacy policy?
The Act and Rules do not use the term privacy policy. They require a notice with each request for consent, a published business contact, published ways to make rights requests, and a published grievance response period of no more than 90 days.
What must a consent notice contain?
An itemised description of the personal data, each specific purpose, the link to your website or app, and how to withdraw consent, use rights and complain to the Board. It must be understandable on its own.
Do I have to publish a contact for data questions?
Yes. Publish prominently on your website or app the business contact of your Data Protection Officer, if the law requires you to have one, or of a person who can answer on your behalf, and mention it in every response to a rights communication.
How long can I take to respond to grievances?
You must publish a reasonable period, not exceeding ninety days, for responding to grievances, and put technical and organisational measures in place to respond within it.
In which languages must the notice be available?
In clear and plain language, with the option to read it in English or in any language listed in the Eighth Schedule to the Constitution.
Next steps
- Check whether the DPDP Act applies to your business, free, in a few clicks
- How-to 04: Set the rules, in the toolkit
- How-to 05: Ask properly, in the toolkit
- The free duties list, every duty in plain words
In the news
- Inside India's DPDP rules: Shaping future of personal data privacy in digital era
Press summary of what people must be told at collection; our checklist covers the website side.
- From Checkbox To Control: Operationalising Consent Under DPDP Act
Practitioner view on consent in practice, beyond the wording of a policy page.
Sources
Every section, rule and date above was checked against the official text on 5 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)
- Section 5(1)Notice with or before every consent request
- Section 5(2)Notice as soon as reasonably practicable where consent was given before commencement
- Section 5(3)English or any Eighth Schedule language
- Section 6(1)Valid consent: free, specific, informed, unconditional, unambiguous
- Section 6(3)Plain language, language option and a contact in the consent request
- Section 6(4)Withdrawal as easy as giving consent
- Section 8(9)Publish a contact for questions about processing
- Section 8(10)Grievance redressal mechanism
- Sections 11 to 14Rights of access, correction, completion, updating, erasure, grievance redressal and nomination
- Section 13(3)Exhaust grievance redressal before approaching the Board
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
- Rule 1(4)Rules 3, 9 and 14 in force eighteen months from publication
- Rule 3Notice: stands alone; itemised data and specific purposes; link, withdrawal, rights, complaint
- Rule 9Publish the contact; mention it in every response to a rights communication
- Rule 14Publish how to make requests and the identifier; grievance period of not more than ninety days; nomination
Notifications
Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)
- G.S.R. 843(E), clause (c)Sections 5, 6 (except 6(9)), 8 and 11 to 15 in force eighteen months from 13 November 2025
A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.


