Triad ICS
Menu

Insights/Regulatory Newsroom

DPDP Rules 2025: The 8 Mandatory Elements of Your Privacy Notice

Published

Reading time2 minutes

FromTriad ICS Research

The DPDP Rules 2025 set a clear bar for privacy notices. Here is what yours must contain.

The Digital Personal Data Protection Rules 2025 were notified on 13 November 2025. Among the first things every Data Fiduciary should revisit is the privacy notice, because under the DPDP Act consent is only valid if it follows a proper notice. A vague, copy-pasted “privacy policy” buried in a footer will not meet the standard.

Reading Section 5 of the Act together with the notice requirements in the Rules, we recommend treating the following eight elements as mandatory.

1. It stands on its own

The notice must be understandable independently of any other document. Referring the reader to your terms of service or a separate policy for the essentials does not work.

2. An itemised description of the personal data

List the categories of personal data you collect: name, phone number, address, payment details, device identifiers. Itemised means specific, not “information you provide to us”.

3. The specified purpose for each item

Each category of data should be tied to the purpose it serves. “To deliver your order” and “to send marketing offers” are different purposes and should be presented separately.

4. The goods, services or uses enabled by the processing

Tell the Data Principal what they receive in return: the service, feature or benefit that the processing makes possible.

The notice must give a clear way to withdraw consent, and the Rules expect withdrawal to be comparable in ease to giving it. If consent took one tap, withdrawal should not need an email to a generic inbox.

6. How to exercise Data Principal rights

Explain how people can access, correct, update or erase their data, raise a grievance, and nominate someone to act for them.

7. How to complain to the Data Protection Board of India

The notice must tell people how they can approach the Board if they are not satisfied with your response.

8. Plain language and a contact who can answer

Use clear, plain language, and offer the notice in English or any language listed in the Eighth Schedule of the Constitution where your audience needs it. Publish the business contact details of your Data Protection Officer, or of the person who can answer questions about processing.

A practical checklist

  • Map every point where you collect personal data: website forms, apps, WhatsApp, offline forms.
  • Write one notice per collection context, not one notice for everything.
  • Version your notices so you can prove which text a person saw when they consented.
  • Test withdrawal yourself: time how long it takes.

The full set of obligations applies from 13 May 2027, but notices touch every product surface and take longer to change than most teams expect. Starting now is the practical choice.

This article is general information, not legal advice. Compliance services do not guarantee certification; certification bodies issue certificates.

Turn Insight into Action