What must a DPDP privacy notice contain? Section 5 and Rule 3
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 15 min read
What must a privacy notice contain under the DPDP Act and Rules?
The short answer
2 provisions govern it and neither is in force yet. Section 5(1) of the Act says every consent request must be accompanied or preceded by a notice informing the individual of the personal data and the purpose it will be processed for, the manner of exercising her rights under section 6(4) and section 13, and the manner of complaining to the Board. Rule 3 then sets the shape: the notice must be understandable independently of any other information the fiduciary has made available, must give in clear and plain language a fair account enabling specific and informed consent including at minimum an itemised description of the personal data and the specified purpose or purposes with a specific description of the goods, services or uses, and must give the particular communication link and a description of other means, if any, through which the person can withdraw consent with ease comparable to the ease with which she gave it, exercise her rights and complain to the Board. Section 5 sits in the 18 month commencement group of notification G.S.R. 843(E) and Rule 3 in the 18 month group of Rule 1(4).

2 provisions decide what a DPDP notice says, and they are not the same list. Section 5 of the Digital Personal Data Protection Act, 2023 says when a notice is owed and names 3 things it must inform. Rule 3 of the Digital Personal Data Protection Rules, 2025 sets the shape of the document and adds 2 minimum contents. Neither is in force. That is the most useful planning fact on this page, and the one almost every notice template on sale leaves out.
Section 5 and Rule 3, and when each starts
| Provision | What it does | Commencement group |
|---|---|---|
| Section 5(1) | A notice must accompany or precede every consent request, informing of the data and purpose, the manner of exercising rights under section 6(4) and section 13, and the manner of complaining to the Board | 18 months |
| Section 5(2) | A notice is also owed to people who gave consent before section 5 starts, as soon as reasonably practicable, and processing may continue until they withdraw | 18 months |
| Section 5(3) | The person may opt to access the notice in English or any Eighth Schedule language | 18 months |
| Rule 3(a) | The notice must be understandable on its own | 18 months |
| Rule 3(b) | Clear and plain language, a fair account for specific and informed consent, and 2 named minimums | 18 months |
| Rule 3(c) | A communication link and a description of other means, for 3 named actions | 18 months |
The 2 instruments arrive together, which is not true everywhere in this framework. Commencement notification G.S.R. 843(E) puts "sections 3 to 5" in its 18 month group, and Rule 1(4) puts "Rules 3, 5 to 16, 22 and 23" in the 18 month group of the Rules. Computed from the publication date printed on the Gazette masthead, both fall on 13 May 2027. That calendar date is this site's interpretation until officially confirmed, because each instrument states a period rather than a date and neither says how the period is counted. The 1 day discrepancy in those file records is set out separately.
So nothing on this page is a duty you owe today. What it is, is the specification you are building against. Section 17 sits over all of it: section 17(1) disapplies Chapter II, where section 5 lives, in the cases it lists, and section 17(3) lets the Central Government notify Data Fiduciaries, including startups, to whom section 5 shall not apply. No such notification has issued. The exemptions are set out separately.
The Act's list and the Rules' list do not match
"Every request made to a Data Principal under section 6 for consent shall be accompanied or preceded by a notice given by the Data Fiduciary to the Data Principal, informing her, — (i) the personal data and the purpose for which the same is proposed to be processed; (ii) the manner in which she may exercise her rights under sub-section (4) of section 6 and section 13; and (iii) the manner in which the Data Principal may make a complaint to the Board, in such manner and as may be prescribed."
Read item (ii) slowly. The Act's own notice list reaches the right to withdraw consent in section 6(4) and the right of grievance redressal in section 13. It does not name section 11, the right to access information about personal data, or section 12, the right to correction and erasure, or section 14, the right to nominate.
Rule 3(c)(ii) is wider. It requires the means through which the person may "exercise her rights under the Act", without limitation. On this site's reading the practical answer is the wider one, because the Rule is the prescription section 5(1) itself points to with the words "in such manner and as may be prescribed", and a notice satisfying the Rule necessarily satisfies the narrower list. It is worth knowing that the gap is in the text rather than in the summaries, because a notice built only from the Act's 3 items would be short of Rule 3.
It has to stand on its own
"be presented and be understandable independently of any other information that has been, is or may be made available by such Data Fiduciary"
This is the requirement most existing policies fail, and it fails them on structure rather than on wording. A notice that makes sense only next to your terms of service, your cookie banner, a help centre article and a linked list of vendors is not understandable independently of other information the fiduciary has made available. The phrase reaches forward too, covering information that "may be made available", so a cross reference to a page you have not written yet does not save it.
Neither the Act nor the Rules ever use the words "privacy policy" or "privacy notice". Both phrases appear 0 times in the Gazette print of the Act, 0 times in the India Code consolidated print, and 0 times in the English section of the Rules. The instrument the law knows is a notice, attached to a consent request. Keeping your general privacy policy is fine. What Rule 3(a) does not accept is a document that only makes sense next to the rest of what you publish, and that is what most general policies are.
Itemised attaches to the data, and only to the data
"give, in clear and plain language, a fair account of the details necessary to enable the Data Principal to give specific and informed consent for the processing of her personal data, which shall include, at the minimum, — (i) an itemised description of such personal data; and (ii) the specified purpose or purposes of, and specific description of the goods or services to be provided or uses to be enabled by, such processing"
2 minimums, and they carry different standards. Item (i) demands an itemised description of the personal data. Item (ii) demands the specified purpose or purposes and a specific description of the goods, services or uses.
That difference appeared between the draft and the notified text. In the draft Rules published for consultation on 3 January 2025 as G.S.R. 02(E), the same clause read "the specified purpose of, and an itemised description of the goods or services to be provided or uses to be enabled by, such processing". Between the draft and notification, "itemised" was dropped from the goods and services limb and replaced with "specific", and the single "specified purpose" became "the specified purpose or purposes". Reading those 2 edits together, this site takes the change to mean a product catalogue is not required while a vague one is still not enough, and that a single notice may carry more than 1 purpose. That reading is an inference from a drafting change, not a statement either text makes.
What survives untouched is the word "itemised" over the personal data. Broad categories written to cover everything are the opposite of an itemised description, and this is the clause that forces a data inventory before a notice can honestly be written. The words "at the minimum" also mean Rule 3(b) is a floor: adding more is permitted, and nothing in the Rule caps the notice.
The 2 illustrations printed with section 5
The Act does not leave this abstract. Section 5 carries 2 Illustrations, and an Illustration printed with a provision is part of the printed provision.
The first sits under section 5(1). An individual opens a bank account through a bank's app or website and, to complete know your customer requirements under law, opts for a live video based identification process. The bank must accompany or precede the request for that personal data with a notice describing the personal data and the purpose of its processing. The point the Illustration makes is timing: the notice does not follow the collection, and a compliance obligation under another law does not remove the notice duty for the consent based processing that carries it out.
The second sits under section 5(2), and is the one worth reading twice if you have an existing user base. An individual gave consent to an ecommerce operator before commencement. Upon commencement, the operator must, as soon as practicable, give her information describing the personal data and the purpose of its processing, "through email, in-app notification or other effective method". The Illustration therefore shows the retrospective notice being pushed to the person rather than published and left to be found, though "other effective method" is left open.
The notice you will owe to people who already said yes
Section 5(2) is the provision that decides whether your existing consents survive, and the answer is that they do:
"the Data Fiduciary may continue to process the personal data until and unless the Data Principal withdraws her consent."
There is no re consent event. You owe a notice as soon as it is reasonably practicable, containing the same 3 items as section 5(1) with the purpose stated in the past tense, and processing continues unless and until the person withdraws.
The harder question is which consents count as given "before the date of commencement of this Act", when parts of the Act commenced on 13 November 2025 and section 5 has not commenced at all. Section 1(2) is the provision that bears on it:
"It shall come into force on such date as the Central Government may, by notification in the Official Gazette, appoint and different dates may be appointed for different provisions of this Act and any reference in any such provision to the commencement of this Act shall be construed as a reference to the coming into force of that provision."
Section 5 was appointed a commencement date of its own by paragraph (c) of G.S.R. 843(E), separate from the date paragraph (a) gave the provisions that started on 13 November 2025. On this site's reading that makes section 5 one of the provisions section 1(2) is describing, so the reference inside section 5(2) to the commencement of the Act falls to be read as a reference to the coming into force of section 5 itself. Section 6 is in the same 18 month group, so no consent taken before that date can be consent on a request "made to a Data Principal under section 6", which is what section 5(1) attaches to; on the competing reading, that the words point only at the date the Act first came into force at all, consents taken in between would fall outside both sub sections. Nothing printed forecloses either reading and no Board or court has applied one. On that reading, which is this site's inference from 2 provisions and the notification read together rather than anything printed in one place, every consent you hold on the day section 5 starts is a section 5(2) consent, including consents you take next year. The retrospective notice is not a legacy clean up for data collected before November 2025. It is a duty over your whole consented base as it stands on that morning, and it has no fixed deadline, only the standard of what is reasonably practicable.
3 working paths, not 3 promises
"give, the particular communication link for accessing the website or app, or both, of such Data Fiduciary, and a description of other means, if any, using which such Data Principal may —"
The 3 items that follow on the next Gazette page are withdrawal of consent, exercise of rights under the Act, and complaint to the Board. 2 things in this clause are easy to miss.
The first is that Rule 3(c) asks for "the particular communication link", singular and particular. A link to a homepage, or to a policy page that mentions rights in prose, is not the particular link for doing the thing. The second is comparable ease, carried into the notice by Rule 3(c)(i) and stated as a right by section 6(4):
"withdraw her consent, with the ease of doing so being comparable to that with which such consent was given"
That is a product constraint rather than a drafting one. On this site's reading, consent taken with 1 tap in an app is hard to square with a withdrawal route that runs only through a written request to a postal address, though the Act names no such example and no Board or court has yet applied the test. The full set of consent duties under section 6 is set out separately, and the Consent Manager route in section 6(7) is one of the "other means" a notice can describe.
What the notice does not have to carry
| Claim in circulation | What the text actually supports |
|---|---|
| The notice must state a retention period, and say when data will be deleted | The phrase "retention period" appears 0 times in the Act and 0 times in the English section of the Rules. Rule 3(b) sets 2 minimums and neither is a retention period. Retention is governed instead by section 8(7), section 8(8) and Rule 8 with the Third Schedule, which fix when data must go rather than what a notice announces. "At the minimum" means you may state one; nothing in section 5 or Rule 3 requires it |
| You must appoint a Grievance Officer and publish that officer in the notice | "Grievance Officer" appears 0 times in the Act and 0 times in the English section of the Rules. Section 13 gives a right of grievance redressal against the fiduciary; it appoints nobody. Rule 9 requires publishing on the website or app the business contact information of a Data Protection Officer "if applicable, or a person who is able to answer" questions about processing. The Act's appointment duties are section 10(2)(a), a Data Protection Officer, and section 10(2)(b), an independent data auditor, and both reach a notified Significant Data Fiduciary only |
| The 90 day grievance timeline belongs in the notice | That period comes from Rule 14(3), which is a duty to publish on the website or app, not a Rule 3 element. On this site's reading, as printed Rule 14(3) has lost its object: it requires a fiduciary to "prominently publish ... within a reasonable period not exceeding ninety days under its grievance redressal system". The corresponding draft sub rule, draft rule 13(3), required publishing "the period under its grievance redressal system", which is what the final text appears to have been capping. Gazette page 30 was not touched by the corrigenda, so it stands as printed |
| The notice must name the legal basis for processing | The Act carries no such element. Section 4 allows 2 grounds, consent or a section 7 legitimate use, and neither section 5(1) nor Rule 3 asks you to name which one applies. In practice the section 5 notice exists only where consent is the ground, because section 5(1) attaches it to a request made under section 6, so the basis is implicit in the artefact rather than declared in it. Nothing resembling deemed consent or legitimate interest is available |
| The notice must list every recipient and third party you share with | The word "recipient" appears 0 times in the Act and 0 times in the English section of the Rules, and no clause of Rule 3 asks the notice to carry a sharing list. That is a point about the notice, not about disclosure generally: section 11(1)(b) gives an individual the right to obtain, on request, from a fiduciary she has previously given consent to, the identities of all other Data Fiduciaries and Data Processors her personal data has been shared with, along with a description of the data shared, so you have to hold the record even though the notice need not print it. Engaging a Data Processor for activity related to offering goods or services is governed by section 8(2), which permits it only under a valid contract |
| Existing users all have to consent again when the law starts | Section 5(2)(b) says the opposite. Give the notice as soon as it is reasonably practicable and processing continues "until and unless the Data Principal withdraws her consent" |
| Rule 3 requires an itemised list of the goods and services you offer | The draft asked for an itemised description of the goods or services to be provided. The notified Rule 3(b)(ii) requires a "specific description of the goods or services to be provided or uses to be enabled". "Itemised" survives only over the personal data in item (i) |
| The notice must be published up front in 22 languages | Section 5(3) gives the individual the option to access the contents in English or any Eighth Schedule language. The duty is to be able to serve the language a person opts for, not to publish every version by default. Section 5(3) is covered in full separately |
| 1 privacy policy on the website covers the notice duty | Rule 3(a) requires the notice to be understandable independently of any other information the fiduciary has made available. A policy that leans on your terms, a cookie banner or a vendor page fails that on its face |
Why the burden of proof decides the format
Section 6(10) is the sentence that should shape how you store a notice, not just how you write one:
"Where a consent given by the Data Principal is the basis of processing of personal data and a question arises in this regard in a proceeding, the Data Fiduciary shall be obliged to prove that a notice was given by her to the Data Principal and consent was given by such Data Principal to the Data Fiduciary in accordance with the provisions of this Act and the rules made thereunder."
The obligation is to prove that a notice was given, not merely that one exists. A notice served from a page you edit in place cannot be shown in the form it took on the day a particular person consented. On this site's reading, the practical consequence is that notice versions need to be retained and each consent needs to point at the version it was given under. That is a recommendation drawn from where the Act puts the burden, and the Act prescribes no format, no medium and no retention period for the evidence.
What to do before this commences
- Inventory first. The itemised description in Rule 3(b)(i) cannot be written from a policy, only from a real field level record of what you collect. That includes whatever your cookies and trackers hold, which is where the itemised description usually breaks down, and where most guidance imports a vocabulary the Act never uses.
- Separate the artefacts. The Rule 3 notice, the section 6(3) consent request, the Rule 9 published contact and the Rule 14(1) rights request means are 4 different things in 3 different provisions, and only the first is the notice.
- Build the particular links, not the promises: a working withdrawal path with comparable ease, a rights request path and a route to complain to the Board.
- Plan the section 5(2) push. Unless a section 17 exemption reaches you, whatever your consented base looks like on the day section 5 starts you owe every one of those people a notice, and the Illustration printed with section 5(2) describes it being given by email, in app notification or other effective method.
- Check a draft notice against Rule 3 element by element, or start one from the provisions, rather than against a template written for another jurisdiction. The official text lives at section 5 and Rule 3.
Related tool
Privacy Notice Checker
Check whether your notice covers the elements the DPDP sources require.
Open
Related tool
Privacy Notice Generator
Assemble a starting template for your privacy notice from the Rule 3 minimums, which are not in force yet.
Open
Section 5, official text →Rule 3, official text →DPDP consent requirements under section 6 →Does the notice have to be in 22 languages? →