Compliance

DPDP Consent Notice: Checklist and Format for Websites & Apps

Section 5 makes a standalone consent notice mandatory before collecting any personal data. What it must contain, where to place it, and common mistakes.

Check your DPDP readiness — free More on the blog

DPDP Consent Notice: Checklist and Format for Websites & Apps

The single most common compliance defect found on Indian websites and mobile apps is the missing consent notice. Most product teams assume that linking to a generic privacy policy in the footer of a signup modal satisfies the law. Under the Digital Personal Data Protection Act, 2023, it does not. Section 5 creates an affirmative, independent obligation: before or at the time personal data is requested, the Data Fiduciary must give the Data Principal an itemised notice. If the notice is absent, ambiguous, or incomplete, the consent that follows is legally void under Section 6.

The five statutory elements every notice must contain

  • The specific personal data collected — itemising name, email, mobile number, location data, or payment identifiers rather than using catch-all phrases.
  • The specified purpose — exactly what the collected data will be used for, restricted strictly to what is necessary for that transaction.
  • The withdrawal procedure — clear instructions explaining how the user may revoke consent at any time, which under Section 6 must be as simple as giving it.
  • The grievance redressal contact — name, title, and business contact information of the designated grievance officer under Section 16.
  • Right of complaint to the Board — explicit mention that the individual has the right to file a complaint with the Data Protection Board of India if dissatisfied with the response.

Four implementation mistakes that destroy compliance

If consent was given with one click, revoking it cannot require sending a registered post letter or navigating through six obscure account menus.

  • The buried notice — hiding the notice clauses deep inside general Terms & Conditions.
  • The bundled checkbox — asking a user to accept promotional marketing, third-party data sharing, and core service terms in a single "I Agree" click.
  • The pre-ticked box — pre-populating opt-in checkboxes. Valid consent requires an active, deliberate affirmative indication.
  • English-only interfaces for regional audiences — Section 5(3) grants users the right to access the notice in their choice of 22 scheduled Indian languages.

How to audit your collection touchpoints

Audit every touchpoint where data enters: lead forms, guest checkout, newsletter popups, job application forms, and support chat widgets. Each touchpoint requires tailored notice language explaining the purpose specific to that interaction. You can generate a fully compliant notice and comprehensive disclosure framework with our DPDP privacy policy template, or evaluate your digital touchpoints against statutory benchmarks with the free DPDP readiness check. Read our full legal analysis of Section 5 of the DPDP Act for detailed case notes.

Common questions

What is a Section 5 consent notice under the DPDP Act?

A statutory disclosure document presented to an individual prior to collecting their personal data. It must explicitly state what personal data is being gathered, the exact purpose of collection, how consent can be withdrawn, the grievance redressal channel, and how to complain to the Data Protection Board.

Can a privacy policy replace a Section 5 consent notice?

No. A general privacy policy describes overall organizational data practices. Section 5 mandates an itemised, context-specific notice presented before or at the moment of collection. A hyperlinked footer reading "By signing up you agree to our Privacy Policy" does not satisfy Section 5.

What languages must a DPDP consent notice support?

Under Section 5(3), a Data Principal must be given the option to view the consent notice in English or any of the 22 official languages listed in the Eighth Schedule to the Constitution of India.

What happens if a business collects data without a valid notice?

Processing data collected without a compliant Section 5 notice is unlawful under Section 6. The Data Protection Board can penalise the failure under Section 33, with exposure reaching up to ₹50 crore for general compliance failure and up to ₹250 crore if inadequate notice leads to a wider breach.

Related reading

  • Understanding the Writing Requirement for Arbitration Agreements — Section 7 of the Arbitration and Conciliation Act mandates that arbitration agreements be in writing, and a mere venue clause does not satisfy the requirement, costing businesses delays and extra litigation if ignored
  • Cost of Ignoring Internal Committee Rules Under POSH Act — Failing to set up an Internal Committee or file the required annual report can attract a fine of up to fifty thousand rupees and, on repeat, double the penalty plus possible licence cancellation, threatening a small business’s ability to operate.
  • Understanding Section 73 Compensation for Breach of Contract — Section 73 limits recoverable damages to losses that naturally flow from a breach or were foreseen by the parties, excluding remote or indirect losses and reducing awards where the injured party failed to mitigate.

Written by Swaraj Layek

Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this