4 mins

DPDP Notice Refresh Checklist for Enterprises

A step-by-step runbook for Heads of Compliance to update privacy notices and consent artefacts when processing purposes or vendor relationships change.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

When to use this checklist

Enterprises face a strict change-management burden under the Digital Personal Data Protection Act, 2023. You have exactly 255 days until the hard compliance deadline of 13 May 2027. Use this runbook when your organisation alters a processing purpose, onboards a new processor, or updates Data Protection Officer contact details. Section 5 of the Act requires that any request for consent be accompanied by an itemised notice. When underlying facts change, the notice requires a refresh. This checklist ensures your control owners capture the update and generate an evidence pack for the Data Protection Board of India.

Prerequisites

Before executing a notice refresh, your team requires an accurate Record of Processing Activities. The RoPA must separate processes relying on consent from those relying on Section 7 legitimate uses. You also need a finalised list of data processors involved in the new processing activity. A clear map of which Data Principals are affected dictates the distribution list for the updated notice.

Step-by-step checklist

1. Identify the scope change. Owner: Product or Business Unit. Action: Document the exact data fields, new processors, or new purposes introduced. Evidence to retain: Approved change-request ticket. Frequency: Per event.

2. Draft the updated itemised notice. Owner: Legal or DPO. Action: Write the revised notice detailing the new purpose and rights under Section 6. Evidence to retain: Version-controlled notice document translated into English and applicable Eighth Schedule languages. Frequency: Per event.

3. Distribute the notice to affected Data Principals. Owner: IT. Action: Push the new notice via email, SMS, or in-app prompt. Evidence to retain: Delivery receipt logs. Frequency: Per event.

4. Collect fresh consent. Owner: IT. Action: Obtain explicit affirmative action from the Data Principal if the processing purpose expands. Evidence to retain: Immutable consent artefact with timestamp. Frequency: Per event.

5. Update external registries. Owner: Compliance. Action: Sync the new notice parameters with registered Consent Managers. Evidence to retain: API confirmation logs. Frequency: Per event.

DPBI breach intimation

A notice refresh often follows a data breach or vendor compromise. If a processor change stems from a security incident, the DPDP Rules 2025 mandate rapid action. You must submit an intimation to affected Data Principals without delay and provide a detailed report to the DPBI within 72 hours. Updating the privacy notice to reflect the new, secure processor is a subsequent step after meeting these strict breach reporting timelines.

Effort and budget reality

Updating a notice manually requires cross-functional coordination. A single purpose change often consumes 40 hours of combined effort across legal drafting, IT deployment, and compliance verification. Manual tracking risks generating a fragmented audit trail. General GRC tools often fail to capture specific consent artefacts tied to a discrete notice version. Purpose-built DPDP tooling absorbs this operational drag. Automated platforms maintain version control, map the updated notice to the specific consent log, and push changes to applications instantly.

Documentation pack

An auditor will ask for a specific set of records to verify compliance with Section 5. Compile the previous notice version, the updated notice, and the internal approval matrix. Your RoPA fields require immediate updates to reflect the new processing parameters. Keep a mapped record of the vernacular languages offered to the Data Principal during the refresh.

Red flags

Certain indicators signal that your notice refresh process is not regulator-ready. A major warning sign is silently updating a privacy policy on your website without pushing an itemised notice to existing Data Principals. Another issue is failing to re-verify verifiable parental consent when a child user is involved. Relying on a pre-ticked box for the new processing purpose directly violates the affirmative action requirement.

Run a gap analysis to see if your current notice management process holds up to DPBI scrutiny. Baseline which steps are covered and which require automated tracking. Visit freescan.complydp.com to evaluate your audit readiness today.

Sources

Frequently asked questions

When does an enterprise need to issue a fresh notice under the DPDP Act?

A fresh notice is required whenever a data fiduciary changes the purpose of processing, onboards a new processor, or updates the DPO contact details. Section 5 mandates that the Data Principal receives updated itemised information before fresh consent is sought.

Can we rely on our existing GRC software to track DPDP notice updates?

Standard GRC tools track high-level policies but often lack the capability to link a specific version of a notice to an individual consent artefact. DPDP compliance requires granular proof that a specific user saw the updated notice and provided affirmative consent.

What happens if a vendor changes how they process data?

The primary data fiduciary remains responsible for the processor actions. You must update your RoPA, issue a revised notice to the Data Principals, and capture fresh consent if the new vendor processing expands the original purpose.

How much effort does a manual notice refresh take?

Managing a single purpose change manually across legal, IT, and product teams typically takes 40 hours of combined effort. Automating the workflow reduces this time by maintaining version control and syncing notices directly to consent logs.

Are we required to offer the updated notice in multiple languages?

Yes. The DPDP Act requires the notice to be available in English and any language specified in the Eighth Schedule to the Constitution. The updated notice must maintain this accessibility.