Does the DPDP notice have to be in 22 languages? What section 5(3) actually says
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 12 min read
Does the DPDP notice have to be in 22 languages?
The short answer
No, not in the sense most vendor content suggests. Section 5(3) requires the Data Fiduciary to give the Data Principal the option to access the contents of the notice in English or any language specified in the Eighth Schedule to the Constitution. The option belongs to the individual: your obligation is to be able to serve the notice in whichever listed language a person opts for, not to present every notice in every language up front, and not to pick one language yourself. Section 6(3) attaches the same option to every consent request, and Rule 3 sets the quality bar of a standalone, clear and plain, itemised notice. Nothing in either instrument makes consent invalid because a person could not read the notice, and the Schedule's 250 crore cap is entry 1, for security safeguards under section 8(5); this site reads a language failure as falling to the residual entry 7, up to 50 crore, and only after the Board determines on inquiry that the breach is significant. Section 5, section 6(3) and Rule 3 all sit in 18 month commencement groups, computed to 13 May 2027, interpretation until officially confirmed.

A claim keeps appearing in vendor decks and compliance blogs: DPDP notices "must be presented in English or any of the 22 languages", or bluntly, "your privacy notice has to be in 22 languages". The actual provision says something narrower and more interesting, and the difference decides whether you are running a translation readiness programme or a 22 language publishing project.
What section 5 requires before the language question arises
Section 5(1) requires that every request for consent under section 6 be accompanied or preceded by a notice from the Data Fiduciary telling the Data Principal 3 things: the personal data and the purpose for which it is proposed to be processed, the manner in which she may exercise her rights under section 6(4) and section 13, and the manner in which she may complain to the Data Protection Board. Section 5(2) extends this to consent collected before the Act commences: a comparable notice must go out as soon as reasonably practicable, and processing may continue unless and until consent is withdrawn.
That is the notice. Then comes the subsection everyone paraphrases.
The language subsection, verbatim
"The Data Fiduciary shall give the Data Principal the option to access the contents of the notice referred to in sub-sections (1) and (2) in English or any language specified in the Eighth Schedule to the Constitution."
Read it slowly, because every word is doing work.
Whose option it is. The duty on the Data Fiduciary is to give the Data Principal the option. The choice of language belongs to the individual reading the notice, not to the organisation writing it. A fiduciary that publishes its notice in English alone and calls that "English or any of the 22 languages, and we picked English" has inverted the sentence.
What the option covers. The option is to access the contents of the notice. The person must be able to read what the notice says, in full, in the language they opt for. It is an access guarantee attached to the notice contents, not a formatting instruction about how the notice is first presented.
What it does not say. The text does not say the notice must be presented in every listed language simultaneously, and it does not say the fiduciary may satisfy the provision by choosing any one language from the list. Operationally, the plain reading is this: whichever of the listed languages a Data Principal opts for, you must be able to serve the notice contents in that language.
Where the number 22 comes from
The DPDP Act and the DPDP Rules never state a number. The words are "in English or any language specified in the Eighth Schedule to the Constitution", full stop. The Legislative Department print of the Constitution, consolidated as on 1 May 2024, numbers the entries of the Eighth Schedule 1 to 22 on their face and closes at Urdu. That is background about the Constitution of India, and not something found anywhere in the DPDP documents themselves. This site holds no later consolidated print, so what it can date is narrower than the count: in March 2026 a state legislative assembly was still passing a resolution seeking the inclusion of a further language, which shows that language was not in the Schedule then and says nothing about any other. The legal anchor is the reference to the Schedule, so if the Schedule ever changes, the notice obligation follows it automatically. Precision here is not pedantry: pinning your compliance documentation to "22 languages" hardcodes a constitutional fact the DPDP text deliberately left as a reference.
The consent request carries the same option
Section 6(3) requires every request for consent to be presented in clear and plain language, "giving her the option to access such request in English or any language specified in the Eighth Schedule to the Constitution", together with the contact details of a Data Protection Officer where applicable or another authorised contact. So the language capability you build is used twice: once for the section 5 notice and once for the consent request itself. Build it as one system.
Rule 3 sets the quality bar in every language
Rule 3 shapes what the notice must be wherever it appears: presented and understandable independently of any other information, written in clear and plain language, giving a fair account sufficient for specific and informed consent, including at minimum an itemised description of the personal data and the specified purposes with a specific description of the goods, services or uses enabled, plus the communication link and any other means to withdraw consent with comparable ease, exercise rights and complain to the Board.
Nothing in Rule 3 is English only. A translated notice that drops the itemised data description, compresses the purposes, or loses the withdrawal link fails Rule 3 exactly as an English notice would. Translation is not summarisation.
What this means for an app or a website
In practice, giving the option looks like ordinary product work. A language selector on the notice and consent screens, or honouring the account or device language with a visible way to switch, is the natural mechanism. Behind it, keep the notice as structured content so that when a purpose changes, every language version updates together; a stale translation is a wrong notice, and section 5 does not have a good language exception.
Which languages to prepare first is a business call. The statute gives the individual the option across the whole list, so plan your pipeline for the full list, but sequencing by the languages your users actually read is a recommendation grade decision the text leaves to you. The text ranks nothing; it only guarantees the option.
The vendor phrasing, corrected politely
"Must be presented in English or any of the 22 languages" is an understandable compression, but it makes 2 quiet substitutions: it turns give the option to access into present, and it hands the choice implied by "or any" to the fiduciary instead of the Data Principal. The stronger variant, "must be in 22 languages", overshoots in the other direction by inventing a simultaneous publication duty. Compliance planning should run on the words: give each person the option, and be ready to honour whichever language they pick.
What happens if the option is not given
Nothing in the Act attaches an automatic consequence to a language failure, and 2 propositions that travel with this question are absent from both instruments: that a notice a person cannot read makes their consent invalid by itself, and that the failure carries the headline cap of 250 crore rupees. Here is what the text does say, in the order it would actually happen.
The 250 crore figure belongs to a different duty. Section 33(1) lets the Board impose "such monetary penalty specified in the Schedule", and the Schedule is a table of 7 entries. The 250 crore entry is entry 1, and it names 1 thing: failing to take reasonable security safeguards to prevent personal data breach under section 8(5). Entry 2 names section 8(6), entry 3 section 9, entry 4 section 10, entry 5 section 15, and entry 6 a voluntary undertaking accepted under section 32. Neither section 5(3) nor section 6(3) appears anywhere in entries 1 to 6, which leaves the residual entry:
"7. Breach of any other provision of this Act or the rules made thereunder. May extend to fifty crore rupees."
Entry 7 of the Schedule to the DPDP Act 2023, quoted as a row from the India Code consolidated print; the Gazette sets the same table column by column.
Reading a language failure into entry 7 is this site's inference from the structure of the table, not a mapping the Gazette prints; what the Gazette prints is the residual wording itself. The answer survives the alternative framings, because out of the whole of section 8 the Schedule names only subsections (5) and (6), so treating the failure instead as a breach of the section 8(4) duty to implement appropriate technical and organisational measures lands in entry 7 as well, and a failure of Rule 3 reaches the same entry through its own words, breach of any other provision of this Act or the rules made thereunder. Note also what the penalty column says. Every amount in it that names a figure is expressed as "May extend to", so it is a ceiling and not a tariff.
A penalty is not automatic, and it is not the first step. The route the Act prints begins with a complaint. Section 27(1)(b) has the Board act on a complaint by a Data Principal about "a breach in observance by a Data Fiduciary of its obligations in relation to her personal data or the exercise of her rights", or on a government reference, or in compliance with the directions of a court. Section 28(3) then requires the Board to determine whether there are sufficient grounds to proceed with an inquiry, and section 28(4) lets it close the proceedings, for reasons recorded in writing, where there are not. Money arrives only at the end: section 33(1) requires the Board to determine on conclusion of an inquiry that the breach is significant, and to give the person an opportunity of being heard, before imposing anything at all. Section 33(2) then directs it to have regard to 7 matters in fixing the amount, among them the nature, gravity and duration of the breach and whether the person acted to mitigate its effects. The machinery in full is set out in how a complaint becomes an order and an appeal, and the caps in the penalties article.
No provision makes consent invalid merely because a person could not read the notice. The invalidity provision is section 6(2), and it runs a different test:
"Any part of consent referred in sub-section (1) which constitutes an infringement of the provisions of this Act or the rules made thereunder or any other law for the time being in force shall be invalid to the extent of such infringement."
Section 6(2) of the DPDP Act 2023.
2 things follow from the words. The subject is a part of consent, and the operation is severance to the extent of the infringement rather than destruction of the whole. The Act's own illustration under the subsection makes it concrete: a person buying an insurance policy consents both to the processing needed to issue the policy and to waiving her right to complain to the Board, and it is the waiver that is invalid. That is a test about what the consent covers. It is not a test about whether the reader understood the language it was written in, and nothing in the Act or the Rules makes comprehension a validity switch.
Where comprehension does bear. On this site's reading, section 6(1) is the provision to read for that. Consent "shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action", so informed is a condition of valid consent in its own right, and the section 5 notice is the mechanism the Act gives for informing. An argument that a person was never informed therefore has a home in the text. What the Act does not do is state the result, which is why the shorthand overreaches. The text pushes back harder than that in 1 place worth naming. Section 2(za) defines a specified purpose as "the purpose mentioned in the notice given by the Data Fiduciary to the Data Principal in accordance with the provisions of this Act and the rules made thereunder", and section 6(1) ties consent to that specified purpose, so a notice not given in accordance with the Act is an argument about the consent and not only about the notice. This site treats that as a reading and not as the law: the Act states no consequence, and no decision of the Board or guidance under the Act construes the point. The provision that gives the point practical force is section 6(10): where consent is the basis of processing and a question about it arises in a proceeding, the Data Fiduciary "shall be obliged to prove that a notice was given by her to the Data Principal and consent was given by such Data Principal to the Data Fiduciary in accordance with the provisions of this Act and the rules made thereunder". A notice served with no option to access its contents in a listed language is a notice whose compliance the fiduciary would have to prove. That is the real exposure here, and it is evidential rather than automatic.
None of it is live yet, and it starts when the duty does. Section 27, except clause (d) of subsection (1), and sections 28 to 34 sit in the same commencement group of G.S.R. 843(E) paragraph (c) as section 5 itself, which the section below dates. Paragraph (a) commenced sections 18 to 26 on publication, among other provisions, which is how the Board comes into existence and how it is constituted, but the power to inquire into a complaint and impose a penalty is in the later group; whether the Board is operational is a separate question this site tracks. So the duty and the power to penalise its breach commence on the same date, and there is no period in which the language option is owed with no consequence attached to it.
When this bites
Section 5 sits in the 18 month commencement group of notification G.S.R. 843(E) paragraph (c). So does section 6(3), because that paragraph covers "sub-sections (1) to (8) and (10) of section 6", and paragraph (b) puts only section 6(9) and section 27(1)(d) in the 1 year group. Rule 3 sits in the 18 month group of Rule 1(4). All 3 compute to 13 May 2027, interpretation until officially confirmed, and that computation runs from a publication date the Government has itself printed 2 ways, which is set out in the 13 or 14 November question. Multilingual notice readiness is slow, unglamorous work, which is exactly why the preparation window exists.
What to do
Draft the master notice with the privacy notice generator; it assembles the Rule 3 elements from your inputs so translations start from a complete skeleton. Then run your current notice, and the structure of each translated version, through the privacy notice checker, which maps every gap to the exact provision. The official texts live at Section 5 and Rule 3. Notice content is usually drafted by legal, and the legal and privacy counsel guide sets out what else tends to land there.
Related tool
Privacy Notice Checker
Check whether your notice covers the elements the DPDP sources require.
Open
Related tool
Privacy Notice Generator
Assemble a starting template for your privacy notice from the Rule 3 minimums, which are not in force yet.
Open
Section 5, official text →Rule 3, official text →What must a DPDP privacy notice contain? →
Privacy noticeLanguagesSection 5Eighth Schedule to the Constitution