Data protection · Provision
Before collecting personal data a Data Fiduciary must give a clear notice of what it collects, why, and how consent can be withdrawn. No notice means no lawful collection.
Quick Statutory Answer
Under Section 5 of the DPDP Act 2023, every Data Fiduciary must give an itemised, plain-language consent notice before or at the time of seeking personal data consent. The notice must specify the personal data to be collected, the exact purpose of processing, how consent may be withdrawn, how grievances can be raised, and how a complaint can be made to the Data Protection Board. A generic privacy policy does not substitute for a Section 5 notice.
| Mandatory Notice Item | Statutory Requirement (s.5) | Non-Compliant Practice | Compliant Implementation |
|---|---|---|---|
| Personal Data Categories | Itemise exact data fields collected | Vague phrase: "such other information" | Explicit list: Name, email, mobile, PAN, IP |
| Specified Purpose | State precise processing objective | Broad catch-all: "to improve our services" | Distinct purpose: "to process payment and issue invoice" |
| Withdrawal Path | Describe clear withdrawal mechanism | Requiring a written registered post letter | In-app or 1-click toggle matching consent ease |
| Grievance Redressal | Publish name & contact of DPO/Grievance Officer | Generic unmonitored mailbox (info@) | Named officer email with statutory turnaround |
| Language Accessibility | English or any Eighth Schedule language | English-only form for regional app users | Language selector offering user preferred regional tongue |
Processing is unlawful. Collection without a proper notice is a breach of the Act and may engage the penalty schedule under section 33.
A notice required under section 5 of the Digital Personal Data Protection Act, 2023, given before or at the time of collecting personal data. It must state what personal data is collected, the specific purpose, how to withdraw consent, how to raise a grievance, and how to complain to the Data Protection Board. It must be in plain language in English or any Eighth Schedule language.
Under section 5, the consent notice must: (1) identify the personal data being collected; (2) state the purpose of processing; (3) describe how consent may be withdrawn; (4) describe how a grievance may be raised; and (5) describe how a complaint may be made to the Board. It must be in clear and plain language, not buried in a longer document.
Not on its own. A privacy policy is a disclosure document; a consent notice under section 5 is a specific, itemised communication given before or at the point of collection. Linking to a policy without the required elements in the notice does not satisfy section 5.
Collection without a section 5-compliant notice is processing without valid consent. The Data Protection Board can investigate and impose penalties under the Schedule, with ceilings up to ₹250 crore for the most serious failures.
Similar in purpose, different in structure. The DPDP Act does not replicate GDPR's six lawful bases — consent and certain legitimate uses are the primary bases in India. The notice format, language requirements and grievance path are India-specific. A GDPR-format notice does not satisfy section 5.
Before every collection of personal data: signup forms, order flows, CCTV systems, HR files, contact forms — any point where a name, phone number, email, address, photograph or any identifier is taken from a natural person in India.
A plain-English summary of what this provision requires, not a reproduction of it and not legal advice. Read alongside the bare Act, and take advice on anything turning on your own facts.