5 min read
Is a privacy policy enough, or do we need itemised notices under the Rules 2025?
A generic privacy policy fails the requirements of the DPDP Act, 2023. Learn how itemised notices work, what Section 5 and Rule 3 dictate for multi-language support, and how this impacts compliance readiness.
Last updated:
A standard privacy policy fails the notice requirements of the Digital Personal Data Protection Act, 2023. Section 5 states a specific notice shall accompany or precede every request for consent. A static link at the bottom of a website violates this mandate, exposing businesses during compliance audits. The Act separates a general policy from a point-of-collection notice. While a privacy policy outlines broad practices across an organization, an itemised notice explains exactly what data the business requests for a specific feature. It names the exact purpose. The Data Fiduciary presents this notice directly to the Data Principal before collection. Updating user registration flows, checkout pages, and lead generation forms requires direct engineering changes.
Section 5(1) outlines three mandatory elements for the itemised notice. The Data Fiduciary names the exact personal data proposed for processing and its specific purpose. Listing every possible data point a company collects violates this rule. The text identifies only the data required for that immediate interaction. The notice instructs the Data Principal on how to exercise their rights. This covers consent withdrawal under Section 6 and grievance redressal under Section 13. A final clause directs the company to explain the mechanism for making a complaint to the Data Protection Board. Rule 3 applies language requirements to this text. Platforms offer the option to access the notice in English and any of the 22 languages specified in the Eighth Schedule to the Constitution. Adding a multi-language toggle at every collection point requires structural updates to the frontend architecture.
Section 4 restricts personal data processing to lawful purposes. The Act defines this as any purpose not expressly forbidden by law. Processing relies on either consent or legitimate uses. When an organization uses consent as the basis, the accompanying notice requires granular detail. Bundling all data collection into one broad acceptance checkbox violates the specificity rules. Data Principals need a distinct choice for each processing activity. Processing data under Section 7 legitimate uses removes the Section 5 notice obligation for that specific dataset. An itemised notice triggers only upon a request for consent. Mixing consent-based data and legitimate-use data inside a vague policy obscures the legal basis.
Section 3 defines the territorial scope of these notice requirements. The law covers the processing of digital personal data within India when collected in digital form. It also includes data collected in non-digital form and digitised subsequently. Foreign entities face these exact obligations under specific conditions. The Act applies to processing outside India if the activity involves offering goods or services to Data Principals within the country. A Section 5 notice is a legal prerequisite for valid consent in cross-border scenarios. The text excludes personal data processed by an individual for a personal or domestic purpose. It drops coverage for personal data made publicly available by the Data Principal or any person under a legal obligation.
Section 5 provides an illustration regarding a bank account application. An individual opts for a live, video-based customer identification process via a mobile app to complete legal Know-Your-Customer requirements. The bank issues a notice detailing the exact data required for this video verification. A general privacy policy on the main website fails the consent test here. Instead, the bank surfaces the notice in the app at the exact moment the video KYC initiates. The text specifies camera access and biometric data for the KYC process. This prompt includes the mandatory rights and Board complaint mechanisms. The system supports the Eighth Schedule language toggles during this interaction.
Enterprise procurement teams embed DPDP requirements into their security questionnaires. Prospective clients request consent record workflows during compliance audits. Supplying a generic privacy policy reveals a structural gap in readiness. Evidence of itemised, multi-language notices and logged consent satisfies these vendor assessments. Dynamic notice generation handles this workflow, replacing manual code updates across 22 languages. This approach helps compliance teams meet the legal standard. Software solutions store the exact version of the notice displayed to the user at the exact timestamp of their consent.
Data collected before the Act requires retrospective action. The Data Fiduciary provides an itemised notice detailing the original data and purpose as soon as reasonably practicable. The Data Principal retains the right to withdraw consent upon receiving this document. Following a withdrawal, the organization stops processing the personal data within a reasonable time. This mandate forces a dedicated workflow to prompt existing users with the new Section 5 format. Previous acceptance of a broad privacy policy fails to cover future processing. The legacy notice includes the exact same three elements and language options mandated for new users. Original consent remains valid until the individual explicitly withdraws it. The burden rests on the Data Fiduciary to prove the legacy notice transmission.
Managing this transition requires an audit of current data flows. 1. Map all data collection points in the application to locate reliance on general privacy policy links. 2. Draft itemised notices for each point that name data types, purposes, withdrawal rights, and board complaint mechanics. 3. Implement the Rule 3 requirement for English and the 22 Eighth Schedule languages. 4. Replace broad consent checkboxes with specific acceptance buttons tied to the exact notice. 5. Deploy a consent management tool that logs these interactions for investor due diligence rounds. Identifying where current user flows fail the itemised notice requirements is a strict legal requirement. Run a diagnostic test at freescan.complydp.com to locate gaps in the consent architecture before the next enterprise security review.
Sources
Frequently asked questions
How is an itemised notice different from our website privacy policy?
A privacy policy describes broad data practices across a business. An itemised notice explains exactly what data the business requests for a specific feature and the exact purpose.
Do we need itemised notices for legitimate uses?
The notice rules of Section 5 do not apply to data processed under Section 7 legitimate uses. An itemised notice triggers specifically upon a request for consent.
How do we handle existing users who accepted our old privacy policy?
Data collected before the Act requires retrospective action. The Data Fiduciary provides an itemised notice detailing the original data and purpose in the prescribed languages as soon as reasonably practicable.
Will missing itemised notices block enterprise sales?
Yes. Enterprise procurement teams embed DPDP requirements into their security questionnaires. Providing evidence of itemised, multi-language notices and logged consent satisfies vendor compliance assessments.
ComplyDP