Compliance

Why a Separate DPDP Consent Notice Is Mandatory for Indian Businesses

Failing to give a clear, stand‑alone consent notice before collecting personal data makes the processing unlawful and can trigger hefty penalties under the DPDP Act, costing businesses both financially and reputationally.

Check your DPDP readiness — free More on the blog

Why a Separate DPDP Consent Notice Is Mandatory for Indian Businesses

The Digital Personal Data Protection Act of 2023 obliges every data fiduciary to present a distinct consent notice to each data principal before or at the moment consent is sought. This notice must be written in plain language, either in English or any language listed in the Eighth Schedule, and cannot be hidden inside a longer privacy policy. Its purpose is to ensure that individuals understand exactly what personal data is being collected and why.

Core Elements Required in the Notice

Section 5 spells out five mandatory components for the notice. First, it must identify the specific categories of personal data that will be collected. Second, it must state the precise purpose for processing that data. Third, it must explain the mechanism by which the individual can withdraw consent at any time. Fourth, it must describe how a grievance can be raised with the fiduciary. Finally, it must outline the procedure for lodging a complaint with the Data Protection Board.

When the Notice Must Be Delivered

The notice is required at every point where personal data is gathered – whether through online sign‑up forms, point‑of‑sale registrations, CCTV capture, HR onboarding, or simple contact forms. If data was collected before the Act came into force and consent is now needed, the fiduciary must issue the notice as soon as reasonably practicable, providing the same information and the right to withdraw. Delaying this step does not excuse non‑compliance.

Common Pitfalls That Lead to Penalties

These mistakes often arise from a desire to simplify documentation, but the law treats them as serious breaches. Because the notice must be clear and separate, any cross‑reference to a broader policy does not satisfy the statutory requirement. Similarly, a combined notice‑consent form can confuse the data principal about their right to withdraw, undermining the transparency the Act seeks to guarantee. If a business collects data without a compliant notice, the processing is deemed unlawful. The Data Protection Board can launch an investigation and impose penalties as outlined in the schedule, with the most severe breaches attracting fines up to several hundred crore rupees. Beyond monetary loss, non‑compliance can damage brand trust and invite regulatory scrutiny, affecting future business operations.

  • Embedding the notice inside a lengthy privacy policy instead of a stand‑alone document
  • Merging the notice and consent request on a single form without separating the two steps
  • Using only English when the user base includes speakers of other Eighth Schedule languages
  • Leaving out the explicit withdrawal pathway or grievance mechanism

Common questions

What exactly must a DPDP consent notice contain?

A DPDP consent notice must list the personal data being collected, state the specific purpose of processing, explain how consent can be withdrawn, describe the grievance‑raising process, and outline how to complain to the Data Protection Board. It must be in plain language and presented in English or any Eighth Schedule language, separate from any longer privacy policy.

Can I satisfy the notice requirement by linking to my privacy policy?

No. The Act requires a stand‑alone notice given at the point of data collection. Simply linking to a privacy policy does not meet the requirement, because the notice must directly present the five mandatory elements and cannot be buried within a larger document.

What are the financial risks of ignoring the consent notice rule?

Collecting data without a compliant notice is unlawful processing. The Data Protection Board can levy penalties up to several hundred crore rupees, depending on the severity of the breach. In addition to fines, businesses may face reputational damage and increased regulatory oversight.

How should I handle data collected before the DPDP Act came into force?

For data gathered prior to the Act, you must issue a Section 5 notice as soon as reasonably practicable. The notice must contain the same five elements and give the data principal the right to withdraw consent. Failure to do so treats any subsequent processing as non‑compliant.

Related reading

  • Understanding the Writing Requirement for Arbitration Agreements — Section 7 of the Arbitration and Conciliation Act mandates that arbitration agreements be in writing, and a mere venue clause does not satisfy the requirement, costing businesses delays and extra litigation if ignored
  • Cost of Ignoring Internal Committee Rules Under POSH Act — Failing to set up an Internal Committee or file the required annual report can attract a fine of up to fifty thousand rupees and, on repeat, double the penalty plus possible licence cancellation, threatening a small business’s ability to operate.
  • Understanding Section 73 Compensation for Breach of Contract — Section 73 limits recoverable damages to losses that naturally flow from a breach or were foreseen by the parties, excluding remote or indirect losses and reducing awards where the injured party failed to mitigate.

Written by Swaraj Layek

Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this