How to draft a privacy policy that actually complies with India’s DPDP Act 2023

How to Draft a Privacy Policy That Actually Complies with India’s DPDP Act 2023

If you’re drafting a DPDP Act 2023 privacy policy for your startup or website right now, there’s a good chance you’ve already downloaded two or three “free privacy policy templates” from the internet and felt a nagging sense that something’s missing. That instinct is usually correct. I review privacy policies alongside contracts for founders and businesses regularly, and most generic templates circulating online were built for GDPR or CCPA, then lightly reworded with an Indian flag emoji and a mention of “applicable Indian laws” — which isn’t the same thing as actual DPDP Act compliance. This guide walks through what a genuinely compliant privacy policy under India’s Digital Personal Data Protection Act 2023 actually needs to include, based on what I actually look for when reviewing one.

This is general guidance, not a substitute for a policy reviewed against your specific business — you should still have your final draft reviewed by a lawyer, especially if you handle sensitive categories of data or operate at scale. But this DPDP Act 2023 checklist will get you significantly closer to a document that reflects what the law actually requires, not just what looks good copied from a US or EU template.

A Quick Primer: What the DPDP Act Actually Regulates

The Digital Personal Data Protection Act, 2023 is India’s first comprehensive law dedicated specifically to digital personal data. It was enacted in August 2023, with rules and phased enforcement rolling out over roughly 12 to 18 months after notification. Unlike GDPR, which covers personal data in any format, the DPDP Act specifically applies to digital personal data — information collected in digital form, or physical data that’s later digitized.

The Act introduces three core roles you need to understand before you can draft anything meaningful:

  • Data Fiduciary — the entity that decides why and how personal data is processed (this is you, if you’re running a website or app collecting user data)
  • Data Processor — an entity processing data on behalf of a Data Fiduciary
  • Data Principal — the individual whose personal data is being collected (your users, customers, or site visitors)

If your website or app has any Indian users, collects any digital personal data, or offers goods and services to individuals in India, the DPDP Act likely applies to you, regardless of where your company is legally headquartered — the law has extraterritorial reach similar to GDPR. This is exactly the kind of compliance question I help founders and businesses work through directly — you can read more about my background in contract and compliance law on my about page.

What a Compliant Privacy Policy Must Actually Include

1. A Clear, Standalone Consent Notice

This is where most generic templates fail immediately. Under the DPDP Act, consent must be free, specific, informed, unconditional, and unambiguous, backed by a clear affirmative action from the user — not a pre-ticked checkbox or implied consent buried in terms of use. Your privacy policy needs a distinct section (not vague filler language) explaining exactly what data you collect and the specific purpose for each category of collection. This is the same discipline that goes into drafting any legally sound clause — if you’re working through this alongside your broader contracts, my checklist on drafting contracts that actually protect you covers the same principle of precise, specific language over vague boilerplate.

2. Purpose Limitation, Stated in Plain Language

You need to specify why you’re collecting each type of data, and that purpose has to be genuinely specific — not a catch-all phrase like “to improve our services.” If you collect email addresses for account creation and separately for marketing communications, those need to be stated as distinct purposes, since a user can consent to one without consenting to the other.

3. Data Principal Rights Section

Your policy must clearly lay out user rights under the Act, including the right to access their data, the right to correction and erasure, and the right to nominate someone to exercise these rights on their behalf in the event of death or incapacity. This nomination right is a genuinely unique feature of the DPDP Act that most GDPR or CCPA-based templates simply don’t include, because neither of those frameworks has an equivalent provision.

4. A Functional Grievance Redressal Mechanism

The Act requires that data principals be able to raise grievances directly with you before escalating to India’s Data Protection Board. Your privacy policy needs a named contact point or grievance officer, a clear process for how complaints are handled, and a reasonable response timeline. A generic “contact us” email buried in your footer generally won’t satisfy this requirement on its own — the same way a missing dispute resolution clause weakens a commercial contract, a vague grievance process weakens your privacy policy’s enforceability.

5. Children’s Data Provisions

The DPDP Act sets 18 as the threshold for what counts as a child’s data, requiring verifiable parental or guardian consent before processing. This is notably stricter than GDPR, which typically defaults to age 16 (with member states able to lower it to 13). If your website or app could plausibly be used by anyone under 18, your policy needs explicit language addressing parental consent mechanisms — a detail almost every GDPR-based template gets wrong when adapted for India, since it simply doesn’t need to exist there.

6. Data Retention and Erasure Timelines

Your policy should specify how long you retain different categories of personal data, and under what conditions data gets deleted. Certain categories of entities — particularly e-commerce, social media, and gaming platforms — face specific erasure and intimation obligations once a user account becomes inactive, along with defined windows for advance notice before deletion. Even if these particular timelines don’t apply to your business category, stating a clear retention policy is expected as baseline good practice.

7. Cross-Border Data Transfer Disclosure

If you use cloud infrastructure, analytics tools, or vendors based outside India, your policy needs to disclose this. The DPDP Act’s approach to cross-border transfer differs from GDPR’s adequacy-decision framework — India’s government can restrict transfers to specific countries via notification rather than requiring a formal adequacy assessment for every transfer. Your policy should acknowledge that data may be processed outside India and reference the applicable safeguards you’ve put in place.

8. Breach Notification Commitment

The DPDP Act requires notifying both the Data Protection Board and affected data principals in the event of a personal data breach, without the narrower “risk-based” threshold GDPR uses for some notifications. Your policy should commit to this notification process, even in general terms, since silence here is one of the clearest signals of an under-baked, copy-pasted template.

9. Significant Data Fiduciary Disclosures (If Applicable)

If your business processes data at a scale or sensitivity that could classify you as a Significant Data Fiduciary, additional obligations apply, including appointing a Data Protection Officer, conducting periodic Data Protection Impact Assessments, and engaging an independent auditor. Most early-stage startups won’t fall into this category immediately, but it’s worth stating in your policy how you’ll handle this threshold if your business scales. I’ve seen this exact scaling challenge up close moving from traditional legal practice into building digital products myself — you can read that story in From Courtroom to Code: Why a Contract Lawyer Started Building Digital Products.

Where Most Free Templates Get It Wrong

Having reviewed a fair number of these, here’s the pattern I see repeatedly:

They’re GDPR policies with find-and-replace edits. Swapping “GDPR” for “DPDP Act” and “data controller” for “Data Fiduciary” doesn’t create compliance — it creates a document that references the wrong legal concepts, since the two laws don’t map onto each other cleanly.

They skip the nomination right entirely. Since this provision doesn’t exist in GDPR or CCPA, templates built for those frameworks simply have no equivalent section, and most drafters don’t know to add it.

They use vague, catch-all purpose statements. “To provide and improve our services” might pass muster informally, but it doesn’t reflect the DPDP Act’s expectation of specific, purpose-limited consent.

They ignore the children’s data age threshold difference. Templates built for GDPR-based markets default to language around 13-16 year-olds, missing India’s stricter 18-year threshold entirely.

They don’t address the grievance officer requirement properly. A generic support email address isn’t the same as a defined grievance redressal process with a named point of contact and response commitments.

DPDP Act vs GDPR vs CCPA: Key Differences at a Glance

AspectDPDP Act (India)GDPR (EU)CCPA (California)
ScopeDigital personal data onlyAll personal data, digital and physicalPersonal information of California residents
Key terminologyData Fiduciary, Data PrincipalData Controller, Data SubjectBusiness, Consumer
Legal basis for processingPrimarily consent, plus limited “legitimate uses”Multiple lawful bases (consent, contract, legitimate interest, etc.)Opt-out based, not consent-first
Children’s data age thresholdUnder 18Under 16 (member states can lower to 13)Under 16 (opt-in required for sale)
Unique featureConsent Managers, nomination rightsData portability, automated decision-making protectionsRight to opt out of data “sale”
Data processor obligationsObligations rest primarily with Data FiduciaryDirect obligations on processors tooDirect obligations on service providers
PenaltiesUp to ₹250 crore per violationUp to €20 million or 4% of global turnoverCivil penalties per violation, lower ceilings

A Practical Checklist Before You Publish Your DPDP Act Privacy Policy

Before you consider your privacy policy finished, run through this quickly:

  • Does it name you correctly as a Data Fiduciary and define your users as Data Principals?
  • Does every data collection purpose get stated specifically, not bundled into vague language?
  • Is there a standalone, clear consent mechanism — not a pre-checked box?
  • Does it include the right to nominate someone for grievance redressal in case of death or incapacity?
  • Is there a named grievance officer or clearly defined complaint process?
  • Does it address children’s data with the correct 18-year threshold if relevant to your platform?
  • Does it disclose cross-border data transfers if you use non-Indian vendors or cloud infrastructure?
  • Does it commit to breach notification procedures?
  • Has it been reviewed by someone with actual legal expertise in Indian data protection law, not just adapted from a template?

If you’re building or scaling a startup, getting this right early avoids a much more expensive retrofit later — both in legal risk and in the engineering work needed to actually operationalize consent flows, data deletion requests, and grievance handling once your user base grows. The same logic applies to your commercial agreements — if you haven’t reviewed those recently, my contract-drafting checklist covers the clauses founders most commonly skip and later regret.

Final Thoughts

A genuinely DPDP-compliant privacy policy isn’t just a legal formality — it’s a real signal to your users, and increasingly to investors doing due diligence, that you understand and respect how their data is handled. Copy-pasting a GDPR template with a few word swaps might look complete at a glance, but it misses provisions that are uniquely Indian, like the nomination right and the specific grievance redressal structure, and it can leave you exposed to penalties that scale meaningfully with your company’s growth. Treat this as foundational infrastructure, not paperwork — get a qualified lawyer to review your final draft, and revisit it as your data practices evolve alongside your business. If you’d like a second set of eyes on your policy or your broader contracts, feel free to reach out and learn more about my practice.


Frequently Asked Questions

Does the DPDP Act apply to startups outside India? Yes, if the startup processes digital personal data of individuals in India or offers goods and services to individuals in India, the Act’s extraterritorial provisions can apply regardless of where the company is legally headquartered.

Is a GDPR-compliant privacy policy automatically DPDP compliant? No. While there’s conceptual overlap, the DPDP Act includes unique requirements — like the nomination right, a specific grievance redressal structure, and a stricter children’s data age threshold — that most GDPR-based templates don’t address at all.

What happens if my startup’s privacy policy isn’t DPDP compliant? Non-compliance can expose your business to penalties under the Act, which can scale up to ₹250 crore per violation depending on the nature and severity of the breach, in addition to reputational and investor due-diligence risk.

Do I need a Data Protection Officer for a small startup? Only if your business qualifies as a Significant Data Fiduciary based on factors like the volume and sensitivity of data you process. Most early-stage startups won’t meet this threshold immediately, but it’s worth monitoring as your user base and data footprint grow.


Parvez Ali is a Contract Lawyer based in Saharanpur, Uttar Pradesh, working with individuals and businesses on contract drafting, review, and data compliance. Learn more at ParvezAli.me.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top