8 minutes

DPDP Act Itemised Notices: Unbundling Consent for D2C Enterprises

Understand how the DPDP Act and Rules 2025 force large e-commerce enterprises to replace legacy privacy policies with itemised, multi-language consent notices ahead of the 13 May 2027 deadline.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Overview of Itemised Consent Notices

The Digital Personal Data Protection Act, 2023 requires enterprises to restructure how they collect customer data. Compliance teams have exactly 255 days remaining until the 13 May 2027 hard deadline to transition from legacy privacy policies to granular consent workflows. This shift directly targets the widespread practice of bundling marketing opt-ins with checkout terms. Data Fiduciaries need to implement specific, itemised notices before collecting personal data.

What Section 5 Requires for Notices

Under Section 4 of the Act, a Data Fiduciary may process personal data only for a lawful purpose based on the Data Principal giving consent or under certain legitimate uses defined in Section 7. Consent remains the primary basis for processing, except where Section 7 legitimate uses apply. Section 5 states that a notice must accompany or precede every consent request. The law requires this notice to inform the Data Principal of the exact personal data collected and the specific purpose for processing. It also directs the Data Fiduciary to explain how the individual may exercise their rights under Section 6 and Section 13. These rights include consent withdrawal and data access. The notice details the exact manner in which the Data Principal may make a complaint to the Data Protection Board.

Jurisdictional Scope under Section 3

Section 3 limits this consent and notice framework to digital personal data processed within the territory of India. It covers data collected in digital form and non-digital data digitized subsequently. The law also applies to processing outside India if the processing connects to any activity related to offering goods or services to Data Principals within India. The Act provides specific exemptions. Section 3 excludes personal data processed by an individual for any personal or domestic purpose. It also excludes personal data made publicly available by the Data Principal or by any other person under a legal obligation to publish it. Retail platforms collecting checkout data do not qualify for these exemptions.

DPDP Rules 2025 on Itemised Mechanics

The Act sets the statutory baseline. The DPDP Rules 2025 operationalise the exact mechanics for notice delivery. A general privacy policy no longer qualifies as adequate notice for specific consent collection. The Rules dictate that notices are itemised. Data Fiduciaries can no longer bury them in a long legal document. Under Rule 3, an itemised notice explicitly separates the data requested, the specific goods or services provided, and the specific consent asked for. An e-commerce platform cannot bundle shipping address collection with promotional email lists. Rule 3 creates an extensive localization duty. Companies need to make the itemised notice available in all 22 languages specified in the Eighth Schedule to the Constitution. The user decides which language to read.

Comparing Privacy Policies to Itemised Notices

Legal teams often confuse the new itemised notice with a standard website privacy policy. A privacy policy is a single, static page that outlines general data practices across an entire organization. It covers everything from employee data to vendor management. An itemised notice operates differently. It is a dynamic, context-specific disclosure presented exactly at the point of data collection. The itemised notice isolates only the data fields requested in that specific web form. It binds those fields to the immediate transaction. A customer buying a shirt sees an itemised notice for their shipping address and payment details. This display is completely separate from the general privacy policy hyperlink in the website footer.

The Operational Burden for Large Enterprises

Implementing itemised notices creates a recurring operational burden for legal and product teams. Every checkout flow, lead capture form, and mobile app registration needs a mapped control owner. Teams maintain an evidence pack for each consent artifact generated. A competent team can manage a few landing pages on simple spreadsheets. This manual approach breaks down quickly when handling millions of transactions across diverse product lines and 22 regional languages. Generating an audit trail for regulatory reporting requires tracking exactly when a buyer withdraws marketing consent but retains transaction processing consent. Cross-team accountability between legal, marketing, and engineering becomes a daily operational requirement. The Data Fiduciary holds the burden of proof to show that notice was given and consent was freely obtained.

Breach Notification and Timelines

The Rules 2025 introduce rigid timelines for security incidents. A Data Fiduciary provides breach intimation to affected Data Principals without delay. At the same time, the compliance team reports the incident to the Data Protection Board within 72 hours of becoming aware of the breach. Incident response plans require pre-approved workflows to hit consumer and regulatory deadlines. Tracking the specific language preference of each affected user is a strict requirement during a breach. The notification to the Data Principal needs to match the language they selected for the original itemised notice.

Correcting Common Legal Misconceptions

Enterprise teams misinterpret the scope of the Act frequently. One error is assuming consent is the sole legal basis for processing data. Section 7 legitimate uses exist for scenarios like medical emergencies or state functions. Retail platforms rarely qualify for these exceptions. Another misconception involves data classifications. The Act does not create a separate heightened category for health or financial data that requires a different consent form. The law applies a uniform standard to all digital personal data. Applicability covers Data Principals in India regardless of citizenship or nationality. A foreign tourist making a purchase while physically located in India falls under the protection of the Act.

Implementation Checklist for Compliance Leaders

1. Audit existing checkout flows for bundled consents. In-house manual review works for small sites. Large enterprise architectures require automated scanning tools.

2. Draft itemised notice templates. Separate shipping data requirements from marketing data requests. Establish distinct consent toggles for each purpose.

3. Translate the itemised notices into all 22 scheduled languages. Use translation management software to maintain legal accuracy and update velocity across platforms.

4. Implement a centralized consent registry for audit evidence. Connect frontend toggles to backend databases to allow rapid data retrieval during regulatory audits.

5. Map 72-hour breach notification workflows. Coordinate protocols between security, legal, and engineering teams to ensure rapid data compilation.

6. Update vendor agreements. Ensure third-party payment processors only process data for the purposes explicitly stated in your itemised notice.

Penalties and Enforcement Risk

The Data Protection Board of India enforces these obligations with substantial financial penalties. Failure to fulfill duties under the Act, including improper notice and consent mechanisms, carries a penalty ceiling of up to 250 crore rupees per instance. Failure to notify the Board and affected Data Principals of a personal data breach also carries a maximum penalty of 250 crore rupees. The Board calculates these penalties based on the nature, gravity, and duration of the non-compliance. A systemic failure to provide itemised notices across a major retail platform aggregates into massive financial risk.

Addressing D2C Compliance with Tooling

Specialized software helps bypass the friction of adapting heavy banking governance platforms to retail environments. ComplyDP provides a Consent Unbundler that naturally separates shipping data from marketing data at the checkout layer. The platform auto-translates itemised notices into regional languages to satisfy Rule 3 requirements while maintaining an immutable audit trail for the Board. Legal teams keep control over their evidence packs without forcing product managers into complex coding workflows. Run a free gap assessment at freescan.complydp.com to map your current checkout exposure.

Sources

Frequently asked questions

How do itemised notices under DPDP Rules differ from our current privacy policy?

A privacy policy is a single general document outlining overall data practices. The DPDP Rules 2025 mandate an itemised notice presented before or during data collection. This notice explicitly links the exact data requested to the specific goods or services and the specific consent asked for.

Can we continue bundling marketing consent with checkout terms?

The DPDP Act prohibits bundled consent structures. A Data Fiduciary separates requests. An e-commerce platform cannot make shipping address collection conditional on subscribing to promotional emails.

Are we required to translate privacy notices into local languages?

Rule 3 of the DPDP Rules 2025 requires a Data Fiduciary to make the itemised notice available in all 22 languages specified in the Eighth Schedule to the Constitution. This lets the Data Principal read the notice in a language they comprehend.

What is the timeline for reporting a data breach under the new Rules?

The compliance team intimates affected Data Principals without delay. A detailed incident report goes to the Data Protection Board within 72 hours of the enterprise becoming aware of the breach.

When is the hard deadline to comply with the DPDP Act?

Enterprises have 255 days remaining to implement these changes across all digital touchpoints. The hard compliance deadline is set for 13 May 2027.