Compliance
Section 5 makes a standalone consent notice mandatory before collecting any personal data. What it must contain, where to place it, and common mistakes.
Check your DPDP readiness — free More on the blogThe single most common compliance defect found on Indian websites and mobile apps is the missing consent notice. Most product teams assume that linking to a generic privacy policy in the footer of a signup modal satisfies the law. Under the Digital Personal Data Protection Act, 2023, it does not. Section 5 creates an affirmative, independent obligation: before or at the time personal data is requested, the Data Fiduciary must give the Data Principal an itemised notice. If the notice is absent, ambiguous, or incomplete, the consent that follows is legally void under Section 6.
If consent was given with one click, revoking it cannot require sending a registered post letter or navigating through six obscure account menus.
Audit every touchpoint where data enters: lead forms, guest checkout, newsletter popups, job application forms, and support chat widgets. Each touchpoint requires tailored notice language explaining the purpose specific to that interaction. You can generate a fully compliant notice and comprehensive disclosure framework with our DPDP privacy policy template, or evaluate your digital touchpoints against statutory benchmarks with the free DPDP readiness check. Read our full legal analysis of Section 5 of the DPDP Act for detailed case notes.
A statutory disclosure document presented to an individual prior to collecting their personal data. It must explicitly state what personal data is being gathered, the exact purpose of collection, how consent can be withdrawn, the grievance redressal channel, and how to complain to the Data Protection Board.
No. A general privacy policy describes overall organizational data practices. Section 5 mandates an itemised, context-specific notice presented before or at the moment of collection. A hyperlinked footer reading "By signing up you agree to our Privacy Policy" does not satisfy Section 5.
Under Section 5(3), a Data Principal must be given the option to view the consent notice in English or any of the 22 official languages listed in the Eighth Schedule to the Constitution of India.
Processing data collected without a compliant Section 5 notice is unlawful under Section 6. The Data Protection Board can penalise the failure under Section 33, with exposure reaching up to ₹50 crore for general compliance failure and up to ₹250 crore if inadequate notice leads to a wider breach.
Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this