Compliance
Failing to give a clear, stand‑alone consent notice before collecting personal data makes the processing unlawful and can trigger hefty penalties under the DPDP Act, costing businesses both financially and reputationally.
Check your DPDP readiness — free More on the blogThe Digital Personal Data Protection Act of 2023 obliges every data fiduciary to present a distinct consent notice to each data principal before or at the moment consent is sought. This notice must be written in plain language, either in English or any language listed in the Eighth Schedule, and cannot be hidden inside a longer privacy policy. Its purpose is to ensure that individuals understand exactly what personal data is being collected and why.
Section 5 spells out five mandatory components for the notice. First, it must identify the specific categories of personal data that will be collected. Second, it must state the precise purpose for processing that data. Third, it must explain the mechanism by which the individual can withdraw consent at any time. Fourth, it must describe how a grievance can be raised with the fiduciary. Finally, it must outline the procedure for lodging a complaint with the Data Protection Board.
The notice is required at every point where personal data is gathered – whether through online sign‑up forms, point‑of‑sale registrations, CCTV capture, HR onboarding, or simple contact forms. If data was collected before the Act came into force and consent is now needed, the fiduciary must issue the notice as soon as reasonably practicable, providing the same information and the right to withdraw. Delaying this step does not excuse non‑compliance.
These mistakes often arise from a desire to simplify documentation, but the law treats them as serious breaches. Because the notice must be clear and separate, any cross‑reference to a broader policy does not satisfy the statutory requirement. Similarly, a combined notice‑consent form can confuse the data principal about their right to withdraw, undermining the transparency the Act seeks to guarantee. If a business collects data without a compliant notice, the processing is deemed unlawful. The Data Protection Board can launch an investigation and impose penalties as outlined in the schedule, with the most severe breaches attracting fines up to several hundred crore rupees. Beyond monetary loss, non‑compliance can damage brand trust and invite regulatory scrutiny, affecting future business operations.
A DPDP consent notice must list the personal data being collected, state the specific purpose of processing, explain how consent can be withdrawn, describe the grievance‑raising process, and outline how to complain to the Data Protection Board. It must be in plain language and presented in English or any Eighth Schedule language, separate from any longer privacy policy.
No. The Act requires a stand‑alone notice given at the point of data collection. Simply linking to a privacy policy does not meet the requirement, because the notice must directly present the five mandatory elements and cannot be buried within a larger document.
Collecting data without a compliant notice is unlawful processing. The Data Protection Board can levy penalties up to several hundred crore rupees, depending on the severity of the breach. In addition to fines, businesses may face reputational damage and increased regulatory oversight.
For data gathered prior to the Act, you must issue a Section 5 notice as soon as reasonably practicable. The notice must contain the same five elements and give the data principal the right to withdraw consent. Failure to do so treats any subsequent processing as non‑compliant.
Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this