DPDP Compliance: How to Write a Privacy Policy and Consent Flow That Works
- A DPDP-compliant privacy policy must clearly state what data you collect, why, for how long, and who can access it.
- Consent must be freely given, specific, and easy to withdraw; buried consent in terms and conditions won't hold up.
- A well-designed website built with compliance in mind from the start avoids costly rewrites and legal friction later.
Why Your Privacy Policy Matters Now
India's Digital Personal Data Protection (DPDP) Act came into force in 2023. If you collect any personal data from users—names, emails, phone numbers, location, payment details, anything—you need a compliant privacy policy and a proper consent mechanism. Ignoring this exposes you to penalties and, worse, erodes user trust.
The good news: a solid privacy policy isn't legal theatre. It's a clear conversation with your users about what you're doing with their data.
The Core Sections Your Privacy Policy Must Have
What data you collect
List every piece of personal data you gather: name, email, phone, address, IP address, cookies, browsing behaviour, payment info. Be specific. "We collect information" is too vague.
Why you collect it (your lawful basis)
You need a legal reason to process data. Under DPDP, this usually means consent, contract fulfillment, legal obligation, or legitimate business interest. State this clearly for each type of data. Example: "We collect your email to send you order confirmations" (contract). "We collect your location to deliver your product" (contract). "We collect your browsing behaviour to show you relevant ads" (consent).
How long you keep it
Don't say "forever." Specify retention periods. Example: "We keep order data for 7 years for tax compliance, then delete it." "We keep marketing opt-in data until you unsubscribe."
Who has access
Name third parties who touch your data: payment gateways, email platforms, analytics tools, delivery partners. Be transparent. If you're sending data overseas, mention that too and explain safeguards.
User rights
Under DPDP, users can ask to see their data, correct it, delete it, or withdraw consent. State clearly how they can exercise these rights (email, contact form, dashboard).
Security measures
Briefly describe how you protect data: encryption, access controls, staff training. Reassure without overpromising.
Consent Flow: The Practical Approach
Consent must be real
Burying consent in a 50-page terms document doesn't work. Present it upfront, in plain language, before or during sign-up.
Make it specific and granular
Don't ask for blanket consent. Break it down:
- "I agree to receive order confirmations via email" (essential)
- "I agree to marketing emails about new products" (optional)
- "I agree to share my data with delivery partners for tracking" (essential for e-commerce)
- "I agree to analytics tracking to help us improve the site" (optional)
Make withdrawal easy
An unsubscribe link in every email is table stakes. Add a preference centre on your website where users can toggle consent on or off anytime. No friction, no questions.
Document it
Keep records of when each user gave consent, what they consented to, and how they did it. If a regulator asks, you need proof.
Plain Language Over Legal Speak
Write your policy for a 14-year-old, not a lawyer. "We collect your phone number so we can call you about your order" beats "We process telephonic identifier data pursuant to contract execution." Users who understand what's happening are users who trust you.
A Quick Checklist
- Privacy policy published on your website
- Covers all data you collect
- Explains the "why" for each data type
- States retention periods
- Lists third-party access
- Explains user rights and how to exercise them
- Consent form is separate, upfront, and granular
- Consent can be withdrawn easily
- Consent records are logged and retained
Build It Right From the Start
A website designed with compliance baked in from day one—proper consent pop-ups, data flows logged, retention policies enforced—saves you from panicked retrofits and legal headaches later.
Note: This is general information, not legal advice. Consult a data protection professional or lawyer to tailor your policy to your specific business and jurisdictional needs.
Need a website that is compliant and secure from day one?
We build data-driven websites, web apps and platforms with compliance and security handled properly. Tell us about your project.
Get a free quoteThis article is general information, not legal advice. For your specific situation, please consult a qualified professional.
