Data privacy (DPDP Act, 2023) · Template

DPDP-compliant privacy policy template

Most Indian privacy policies are GDPR text with the country name changed. The DPDP Act, 2023 uses its own vocabulary — data fiduciary, data principal, consent manager — and imposes its own duties, and a policy that never mentions them is evidence that nobody read the Act it claims to comply with.

Generate this document See all 21 templates

When you need this

  • If your website, app or POS collects any personal data of individuals in India
  • Before a payment gateway, marketplace or enterprise customer completes vendor onboarding
  • When you begin any marketing that relies on consent you have to be able to demonstrate
  • Where you share data with third parties — delivery partners, analytics, payment processors
  • As the first document to fix after a DPDP readiness assessment, because everything else references it

What this document must contain

  • The categories of personal data collected — Specific categories, not 'information about you'. A data principal cannot exercise a right over a category they were never told about.
  • The purpose of each processing activity — The Act is built around processing for a stated, lawful purpose. Purpose is what a consent notice attaches to, so a policy that lists data without purposes cannot support the consent it relies on.
  • How rights are exercised — Access, correction, erasure and grievance redressal each need a route the reader can actually use — an address and a realistic response window, not a general contact form.
  • A named grievance contact — The Act contemplates a readily available means of grievance redressal. An unmonitored inbox is a compliance gap that surfaces at the worst moment.
  • Third parties and processors — Say who receives the data and why. Each named processor should also sit behind a contract under s. 8(5).
  • Retention and deletion — How long data is kept and what triggers deletion. Indefinite retention is a position, and it should be a deliberate one.
  • How changes are notified — A policy that can change silently offers the reader nothing to rely on.

The law that governs it

  • DPDP Act, 2023 — the Schedule — Penalties are substantial, reaching up to ₹250 crore for certain breaches, and they stack per violation. This is the provision that makes data protection a board-level matter rather than a website chore.
  • DPDP Act, 2023 — s. 8(5) — A data fiduciary may engage a processor to process personal data only under a valid contract. Every vendor named in your policy should have one.
  • DPDP Act, 2023 — s. 8(6) — In the event of a personal data breach, the fiduciary must give intimation to the Board and to each affected data principal in the prescribed form and manner.
  • DPDP Act, 2023 — ss. 11–13 — Data principals have rights to access information about processing, and to correction, completion, updating and erasure. Your policy has to describe how each is exercised.

Common mistakes

  • Publishing GDPR text with 'India' substituted, which uses the wrong terminology and misses the Act's own duties
  • Listing data categories without stating the purpose each is processed for
  • Naming a grievance contact that nobody monitors
  • Claiming a lawful basis the Act does not use, borrowed from another jurisdiction
  • Never revisiting the policy after adding a new processor, so the disclosure and the reality diverge

Frequently asked questions

Does the DPDP Act apply to my small business?

The Act applies to the processing of digital personal data within India, including data collected offline and later digitised, and to processing outside India in connection with offering goods or services to data principals in India. In practice that reaches almost any business with a website, an app, a CRM or a customer database — size is not the test.

Is a GDPR privacy policy enough for India?

No. The DPDP Act uses its own concepts and duties — data fiduciary and data principal rather than controller and subject, its own consent notice requirements, its own breach intimation duty under s. 8(6), and its own rights under ss. 11 to 13. A GDPR policy will be missing those and will describe bases the Indian Act does not use.

What are the penalties under the DPDP Act?

The Schedule to the Act sets out financial penalties for different classes of breach, reaching up to ₹250 crore, and they apply per violation. The amount in any given case is determined by the Data Protection Board having regard to the factors the Act specifies.

Do I need a privacy policy if I only use WhatsApp for orders?

If you collect names, phone numbers, addresses or payment details of individuals in India, you are processing personal data, and the channel does not change that. The obligations attach to the processing rather than to having a website.

Related documents