SP & SC — Legal and Taxation Service
Share

Website Terms, Privacy Policy and the DPDP Act

By SP & SC EditorialUpdated 28 September 20267 min read

Is your website compliant with the DPDP Act, 2023? Learn how to draft mandatory Privacy Policies and Terms of Use to avoid massive penalties and build user trust.

Website Terms, Privacy Policy and the DPDP Act

Short answer: Every Indian website collecting personal data must have a privacy policy compliant with the Digital Personal Data Protection (DPDP) Act, 2023. This policy must clearly state what data you collect, why, and for how long. The Act mandates explicit user consent and imposes significant penalties for non-compliance, making it crucial for all businesses to update their legal documents.

What is the difference between a Privacy Policy and Terms & Conditions?

A Privacy Policy explains how you handle user data, while Terms & Conditions (T&C) are the rules for using your website or service. The policy is a legal requirement under the DPDP Act to ensure data protection. The T&C, on the other hand, form a binding contract between you and your users, outlining rights, responsibilities, and limitations of liability. Both are essential for any online business.

Why is a Privacy Policy mandatory for my Indian website?

A privacy policy is mandatory under Section 5 of the Digital Personal Data Protection (DPDP) Act, 2023, if you process any digital personal data of individuals within India. This duty to provide a clear, concise, and accessible notice is a cornerstone of the law. Failure to provide this notice before or at the time of collecting data is a direct violation and can attract significant penalties from the Data Protection Board of India.

What are the key requirements under the DPDP Act, 2023?

The DPDP Act requires you to fundamentally change how you approach user data. Key obligations for you as a 'Data Fiduciary' include giving clear notice (Section 5), obtaining free, specific, informed, and unambiguous consent with a clear affirmative action (Section 6), collecting only data that is necessary for the specified purpose ('data minimisation'), ensuring data accuracy, and deleting personal data once its purpose is served (Section 8).

What information must I include in my Privacy Policy?

Your policy must be a transparent and honest declaration of your data practices. It must detail the types of personal data collected, the specific purpose for each type of collection, how users can exercise their rights (like correction or erasure), and the contact details for your designated contact person or Data Protection Officer for grievance redressal. The notice must be available in English and, upon request, in the 22 languages specified in the Eighth Schedule of the Constitution.

FeaturePre-DPDP Policy (Often Vague)DPDP-Compliant Policy (Specific & Clear)
ConsentImplied or bundled consent ("By using this site, you agree...")Explicit, specific, and freely given consent for each purpose. Easy withdrawal.
NoticeGeneral statement about data collection.Detailed notice about what data is collected and for what specific purpose.
Data DeletionVague retention periods like "as long as necessary".Data deleted as soon as the specified purpose is met, with defined periods.
User RightsLimited or no mention of user rights.Clear process for users to access, correct, or erase their data.
Children's DataOften no specific provisions.Requires verifiable parental consent for users under 18; no tracking or targeted ads.
LanguageComplex legal jargon.Presented in clear and plain language. Available in multiple Indian languages.

What are the penalties for non-compliance with the DPDP Act?

The Data Protection Board of India can impose substantial financial penalties for non-compliance, as specified in the Schedule to the Act. These are not trivial fines. For instance, a breach in observing obligations to protect data can result in a penalty of up to ₹250 crore. Failure to provide adequate notice to a user (a Data Principal) can lead to a penalty of up to ₹200 crore. These figures underscore the critical importance of compliance.

Do I need a separate Cookie Policy?

While the DPDP Act focuses on 'personal data' and doesn't explicitly name 'cookies', the act of collecting user information via cookies falls under its purview. Best practice is to include a detailed section on cookies within your Privacy Policy or maintain a separate, clear Cookie Policy. You must obtain explicit consent before deploying any non-essential cookies (like those for analytics, advertising, or tracking) on a user's device. A simple "This site uses cookies" banner is no longer sufficient; users must be given a genuine choice to accept or reject.

Worked example

Scenario: 'Bengaluru Sips', a new Private Limited Company, launches a website to sell artisanal coffee, delivering across India. They need to collect customer names, addresses, phone numbers, and email IDs for orders and marketing.

DPDP Compliance Steps:

  1. Consent Mechanism: During the checkout process, 'Bengaluru Sips' cannot use a pre-ticked box for consent. They must implement two separate, unticked checkboxes:
    • [ ] I consent to my data (name, address, phone) being processed for the purpose of fulfilling and delivering my order. [Link to Privacy Policy]
    • [ ] I consent to receive marketing updates about new products and offers via email. I understand I can withdraw this consent anytime.
  2. Privacy Policy (Notice): Their policy, accessible from the website footer and at the point of consent, must clearly state:
    • Data Collected: Name, shipping/billing address, phone number, email address, IP address.
    • Purpose 1 (Order Fulfilment): To process payment, pack the order, and arrange delivery via a third-party courier. The legal basis is the user's explicit consent.
    • Purpose 2 (Marketing): To send promotional emails. The legal basis is separate, explicit consent.
    • Data Retention: Order data is retained for 7 years as required for financial and tax audits. Marketing consent data is retained until the user withdraws consent.
    • User Rights: A section explaining how a user can log into their account to view, edit their details, or send an email to a specific address to request data correction or erasure.
    • Grievance Officer: The name and email address of the person designated to handle data-related queries (e.g., privacy@bengalurusips.com).

Result: By implementing these specific and transparent measures, 'Bengaluru Sips' is compliant with the DPDP Act, builds trust with its customers, and significantly reduces its risk of facing penalties.

Common mistakes

  1. Copy-Pasting Policies: Using a template or another website's policy without tailoring it to your specific data collection, processing, and storage practices.
  2. Using Pre-Ticked Boxes: Consent must be a clear, affirmative action by the user. Pre-checked boxes are not valid consent under the DPDP Act.
  3. Bundling Consent: Asking for a single consent for multiple purposes (e.g., creating an account, marketing, and sharing data with third parties). Each purpose requires separate consent.
  4. Vague Purpose Statements: Using broad terms like "for improving our services" is insufficient. You must specify exactly how the data will be used for that improvement.
  5. Making Consent Withdrawal Difficult: Users must have a right to withdraw their consent that is as easy to exercise as giving it.
  6. Not Updating the Policy: Failing to update your privacy policy when you introduce new services, start collecting new types of data, or change how you process data.

How SP & SC helps

Navigating the complexities of the DPDP Act, 2023, requires expert legal guidance. At SP & SC, we draft and review website legal documents, including Terms & Conditions, Privacy Policies, and Cookie Policies, ensuring they are fully compliant and tailored to your business operations. We help you understand your obligations as a Data Fiduciary and implement practical, robust solutions to protect your business from legal risks. You can find out more about our Business Contract Drafting services.

Frequently asked questions

Can I just copy a Privacy Policy from another website?

No. This is a common but dangerous mistake. Your policy must accurately reflect your specific data practices. Copying a policy will almost certainly contain inaccuracies about your data handling, leading to non-compliance with the DPDP Act and exposing you to penalties.

Does the DPDP Act apply to my small blog?

Yes, if you process any digital personal data. This includes collecting email addresses for a newsletter, using analytics tools that track user IP addresses, or having a comments section where users enter their name and email. The size of your operation does not grant an exemption.

What is a "Data Fiduciary"?

A Data Fiduciary is any person or entity (like your company, partnership, or even you as a sole proprietor) that, alone or with others, determines the purpose and means of processing personal data. If you decide why and how to collect and use user data, you are a Data Fiduciary and are responsible for compliance.

What is a "Data Processor"?

A Data Processor is an entity that processes personal data on behalf of a Data Fiduciary. For example, your cloud hosting provider (like AWS or Google Cloud) or a third-party delivery company are Data Processors. You, as the Data Fiduciary, are responsible for their compliance when they handle your users' data.

How often should I update my Privacy Policy?

You must update it whenever your data processing activities change. It is also a best practice to review it at least once a year to ensure it remains current with your business operations and any amendments or judicial interpretations of the law.

Get a fixed-fee quote

Ensuring your website is legally compliant is not a DIY task. Share your website details and existing documents with us for a review. We provide a written fixed-fee quote for drafting or updating your policies. Contact SP & SC or WhatsApp us at +91 90356 74566. We handle all documentation and compliance matters end-to-end, letting you focus on your business.

Written by

SP & SC Editorial

Editorial team at SP & SC Legal and Taxation Services — practising advocates, chartered accountants, and company secretaries publishing hands-on guidance from live client files.

Reviewed by

Poojith Krishna

Founding Partner, SP & SC Legal & Taxation

Last reviewed 28 September 2026

Related reads

WhatsAppCall usGet quote