Organizations often believe that once the privacy policy has been implemented on their website, they have complied with the data-protection obligations under the statute. With the principal compliance obligations under the Digital Personal Data Protection Act, 2023 (“DPDP Act”/ “Act”) scheduled to come into force on May 13, 2027, this is only a starting point. The requirements under the DPDP Act go beyond a mere compliance checklist, ensuring each compliance requirement is operationalized to adequately protect the personal information of individuals.
Under the DPDP Act read with the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”/ “Rules”), the requirements of demonstrating a Privacy Notice, obtaining valid consent and processing the data so obtained for a lawful purpose form the cornerstone of compliance requirements under the DPDP Act.
Under the DPDP Act, a “Data Fiduciary” means any person who, alone or in conjunction with other persons, determines the purpose and means of processing personal data. A “Data Principal” means the individual to whom the personal data relates and, where such individual is a child or a person with disability who has a lawful guardian, includes her parent or lawful guardian, as applicable. “Personal Data” means any data about an individual who is identifiable by or in relation to such data.
Data Fiduciaries usually implement these compliance obligations through the UI/UX of their digital products and services. A privacy banner, a pop-up or a link to a policy page may display information, but may not, by itself, demonstrate that the notice was actually brought to the attention of the Data Principal at the point of data collection. Implementation through UI/UX therefore requires more than a footer link or a one-time checkbox.
Accordingly, the regulatory analysis must look beyond the user interface and examine how the business actually implements notice and consent. A Data Fiduciary that merely displays a privacy policy may face a different compliance position from one that integrates context-specific notices, captures granular consent for distinct processing purposes, maintains auditable consent logs, and enables frictionless withdrawal. Its legal exposure will therefore depend not only on how it describes its data practices, but also on the degree of operational control it exercises over the data collection, purpose limitation and consent lifecycle.
Operationalizing Notice and Consent under the DPDP Act
1. Privacy Notice
The first requirement under the DPDP Act is a Privacy Notice as per Section 5 of the DPDP Act read with Rule 3 of the DPDP Rules, 2025.[1] It mandates that every request for obtaining consent by the Data Fiduciary shall be preceded or accompanied by a notice given to the Data Principal (“Privacy Notice”).
The Privacy Notice so provided shall consist of the following:
i. Itemised list of Personal Data collected;
ii. The purpose for which the Personal Data is collected and will be processed;
iii. The specific description of the goods or services to be provided or uses to be enabled by, such processing; and
iv. The particular communication link for accessing the website and app, through which the Data Principal may:
- withdraw her consent;
- exercise her rights under the DPDP Act; and
- make a complaint to the Data Protection Board for breach of their rights
The Privacy Notice shall be presented and be understandable independently of any other information made available by the Data Fiduciary and shall provide, in clear and plain language, a fair account of the information necessary to enable the Data Principal to give specific and informed consent. The language of the Privacy Notice shall be in English or any other languages specified under the Eighth Schedule.[2] Where a Data Principal had consented to the processing of her personal data before the commencement of the relevant provisions of the DPDP Act, the Data Fiduciary must, as soon as reasonably practicable, provide the notice prescribed under section 5(2). The Act does not require blanket re-consent and permits the processing to continue until the Data Principal withdraws her consent.
In practice, the fiduciaries implement this through several channels operating together, such as website privacy banner before collecting data, in-app notices, human resource onboarding forms for employee data and vendor or partner intake forms, essentially where the Personal Data is shared for commercial or business purposes. In recent times, many intermediaries have sought updated consent from their users for continuation of services, through Privacy Notices intimated via email.
2. Privacy Policy
Before the DPDP Act, privacy policies were a principal means through which organisations communicated their data practices. However, a privacy policy is primarily a transparency document and does not, by itself, amount to “privacy by design”. Although the DPDP Act does not expressly use that term, section 8(4) requires Data Fiduciaries to implement appropriate technical and organisational measures for effective observance of the Act and the Rules.
The DPDP Act does not separately mandate a document titled a “privacy policy”. Where consent is sought, however, the statutory notice must satisfy section 5 and rule 3. A broader privacy policy may supplement, but cannot substitute for, that notice. This position is without prejudice to privacy-policy requirements under other applicable laws or sectoral regulations. Yet, the privacy policy still serves an important function for managing end-to-end obligations between the Data Fiduciary and the Data Principals, considering the limited information provided under the Privacy Notice.
A privacy policy drafted in extensive language or structure undermines the transparency requirements under the DPDP Act. This concern has also arisen in the proceedings concerning WhatsApp’s 2021[3] privacy policy, where the Supreme Court, while hearing pending appeals, made oral observations regarding the ability of ordinary users to understand a “take-it-or-leave-it” privacy policy and exercise meaningful choice. These observations should not be treated as a final adjudication of the issues before the Court.
In practice, the statutory Privacy Notice may be supported by a broader privacy policy written in clear, plain and accessible language. Together, these documents can form part of the organisation’s transparency and compliance framework, provided that the statutory notice remains independently understandable and satisfies section 5 and rule 3.
Consent Mechanism Under the DPDP Framework
Where consent is relied upon as the ground for processing, the Data Fiduciary must obtain valid consent under section 6 after providing the required Privacy Notice. The consent so obtained shall be free, specific, informed, unconditional, unambiguous, with clear affirmative actions, and shall signify the agreement of the Data Principals to process their data for the specified purpose. Consent must relate to a specified purpose and be limited to the personal data necessary for that purpose. Consent requests should not bundle unrelated purposes, use pre-ticked boxes or treat silence or inactivity as consent. The Data Fiduciary shall ensure that every request for consent shall be presented to the Data Principal in unambiguous language, with providing them the option to access such request in English or any other any language specified in the Eighth Schedule to the Constitution of India and the contact details of an individual for communication to exercise their rights under the DPDP Act.
Before the enactment of the DPDP Act, the consent once provided by the Data Principal was processed for multiple purposes beyond the specified purpose without the ease of withdrawing consent. However, under the DPDP Act, the Data Fiduciary is required to ensure that the Data Principals can withdraw consent with the same ease as providing consent. The Data Fiduciary shall ensure that once the consent is withdrawn, it shall, within a reasonable time, cease and cause its data processors to cease the processing of the Personal Data of such Data Principal, unless processing without consent is required or authorised under the DPDP Act, the Rules or any other law for the time being in force in India but the withdrawal of consent shall not affect the legality of processing of the Personal Data based on the consent before its withdrawal.
A Data Principal may also give, manage, review or withdraw her consent through a Consent Manager registered with the Data Protection Board of India. Under rule 4 and the First Schedule, an applicant for registration must, among other conditions, be a company incorporated in India. The Consent Manager registration framework is scheduled to come into force on November 13, 2026. The Consent Manager enables the Data Principals to regulate their consent by providing, managing, reviewing and withdrawing consent across multiple platforms of different Data Fiduciaries from a single interface, while the underlying responsibility for lawful processing of such Personal Data still vests in the Data Fiduciaries. The Consent Manager does not determine the purpose or means of processing and cannot read or exploit the personal data that passes through its systems, and its role is to standardise the mechanics of consent, thus providing a uniform, user‑centric platform for exercising data rights.[4] This is not a mandatory requirement for the Data Fiduciaries under the DPDP framework, however is crucial for the Data Fiduciaries engaged in the fintech, healthtech, and e-commerce business, , where a standardised, auditable mechanism for managing consent materially reduces both user friction and compliance risk.
In practice, the consent mechanism under the DPDP framework must operate as a lifecycle rather than a one-time checkbox. The consent under the DPDP framework may, for operational purposes, be structured into a series of stages, comprising of collection, validation, update, renewal and withdrawal of the consent as mentioned below:
i. Collection Stage: At this stage, the consent must be obtained in a purpose‑specific and granular manner. The interface should separate mandatory purposes from optional ones, avoid bundled consent, require a clear affirmative action for each non‑essential purpose, and record every consent event as a consent artifact capturing the Data Principal’s identity, the specific purpose, timestamp, consent status and language preference.
ii. Validation Stage: At this stage, the consent should be checked before any processing begins. The Data Fiduciary should confirm, in real time, that consent exists for the relevant user and purpose, that it remains active and has not been withdrawn or expired, and that the requested processing does not exceed the scope of the purpose originally consented to, with each validation action logged for audit and error handling where consent is absent or invalid.
iii. Update and Renewal Stage: At this stage, the consent records and user choices should be revisited where the purpose or scope of processing changes when the scope or duration of processing changes. The Data Fiduciary shall implement measures to notify Data Principals of new or modified purposes or retention policies, explain how these changes affect their data, and allow them to update or renew consent through a flow that is as simple as the initial grant, while recording the updated or renewed purposes, timestamps and status in the consent records.
iv. Withdrawal Stage: At this stage, the consent must be revocable in a straightforward, purpose‑specific manner. A user‑facing dashboard or interface should allow Data Principals to withdraw consent for one or more specific purposes without affecting others, trigger immediate cessation of related processing by the Data Fiduciary and its processors, and log the withdrawal event together with its metadata and notifications in an immutable audit trail to demonstrate compliance and accountability under the DPDP framework.[5]
In digital environments, the same consent principles may apply where cookies or similar technologies process personal data and consent is relied upon as the applicable ground. In such cases, a cookie banner and preferences interface may assist in obtaining purpose-specific consent and enabling its withdrawal. The DPDP Act and the Rules do not, however, prescribe cookie categories such as “essential”, “performance”, “analytics” or “marketing”, or mandate a particular cookie-banner design.[6]
Section 6(10) places the burden on the Data Fiduciary to prove that the required notice was given and valid consent obtained. Data Fiduciaries should therefore maintain records sufficient to establish the consent status, applicable purpose, relevant notice and subsequent withdrawal or modification. The DPDP Act and the Rules do not require every consent event to be recorded in an immutable log containing a source IP address and cryptographic hash. Separately, rule 8(3) prescribes a minimum one-year retention period for specified personal data, traffic data and processing logs for the purposes identified in the Seventh Schedule.
Lawful Purpose and Processing of Personal Data
Under section 4, personal data may be processed only in accordance with the DPDP Act and for a lawful purpose, either on the basis of consent or for one of the “certain legitimate uses” specified in section 7. A lawful purpose means a purpose that is not expressly forbidden by law. Where consent is relied upon, the notice must identify the personal data and the purpose for which it is proposed to be processed, and the consent must relate to that specified purpose.
Section 7 permits processing for specified categories of legitimate use, including: the specified purpose for which the Data Principal voluntarily provided her personal data without indicating non-consent; qualifying provision of subsidies, benefits, services, certificates, licences or permits by the State; specified State functions; disclosures to the State required by law; compliance with judgments, decrees or orders; medical emergencies; epidemics and public-health threats; disasters or breakdowns of public order; and specified employment-related purposes. These are limited statutory categories and not a general permission to process personal data beyond the communicated purpose.
Section 17 is an exemptions provision and should not be described as a general alternative ground for processing. Under section 17(1), specified provisions of the Act do not apply where processing is necessary for: enforcing a legal right or claim; the performance of judicial, quasi-judicial, regulatory or supervisory functions; prevention, detection, investigation or prosecution of offences or contraventions; processing in India of personal data of persons outside India pursuant to a contract with a person outside India; specified corporate restructuring transactions; or ascertaining the financial information, assets and liabilities of a person who has defaulted on a loan or advance. Under section 17(2), the Act does not apply to processing by notified State instrumentalities in specified interests, or to qualifying research, archiving or statistical processing undertaken in accordance with rule 16 and the Second Schedule.
Reliance on sections 7 or 17 must remain within the express scope and conditions of the applicable provision. Section 6(1) separately requires consent-based processing to be limited to personal data necessary for the specified purpose. The Second Schedule also prescribes necessity and purpose-limitation standards for processing under section 7(b) and section 17(2)(b). The DPDP Act does not, however, state a general proportionality test applicable uniformly to every form of processing under sections 7 and 17.
In operational terms, the Data Fiduciary should maintain an internal record mapping each processing activity to its lawful basis under the DPDP Act, whether consent under Section 6, legitimate use under Section 7, or an exemption or overriding ground under Section 17. For each activity, the record should identify the relevant statutory provision, the specific purpose communicated in the notice, and any reliance on statutory functions, legal obligations or research grounds, so that the organisation can demonstrate, if required, that the processing fell within a recognised lawful purpose and was not carried out on an informal or assumed basis.
Internal Operating Model for Data Fiduciary
A Data Fiduciary cannot discharge notice, consent and lawful processing as a single function. These depend on coordinated design choices across various teams such as product, finance, legal and operations. The product and engineering team carries the primary responsibility for the user journey, and they shall ensure that the consent-obtaining interface shall not consist of pre-ticked boxes, hidden defaults, or bundled permissions and the withdrawal mechanism shall be as easy as providing the consent. They need to further ensure that the processing logs are searchable with time-stamp and linked to the specific activity they authorize to ensure that any claim of valid consent or legitimate use can be demonstrated when required.
While the legal and compliance team, must map each processing activity to check its compliance with the DPDP Act, review notice and consent language for clarity and alignment with the DPDP framework and maintain records wherever, the processing has been done without the consent of the Data Principal. The mapping should be done frequently as the products, vendors, scheme and data flow change and the organization should reflect the actual processing taking place.
Third-party processors should be engaged under a valid contract and subjected to appropriate contractual and technical controls concerning processing instructions, security, cessation and erasure. Under section 8, the Data Fiduciary remains responsible for processing undertaken on its behalf by a Data Processor; the notice and consent obligations are not independently imposed on the Data Processor merely by virtue of its status as a processor.
DPDP compliance is not a legal checklist undertaken by one department. It is a cross‑functional way of working that runs through the organisation’s day‑to‑day operations. The financial stakes show why this discipline matters because non‑compliance can attract heavy penalties under the DPDP Act, along with reputational and operational risk. A well‑designed internal operating model is therefore both protection and value as it helps a Data Fiduciary reduce user friction, maintain trust and show accountability from collection through processing, retention and deletion.
Disclaimer: Nothing contained in this document shall be considered or be construed as a legal advice provided by Synergia Legal or any of its members.
Contact Us: For any further information, please send an email at admin@synergialegal.com
[1] The Digital Personal Data Protection Act, 2023, s. 5(1); Digital Personal Data Protection Rules, 2025, r. 3
[2] The Digital Personal Data Protection Act, 2023, s. 5(3); Digital Personal Data Protection Rules, 2025, r. 3(a)
[3] Meta Platforms Inc. & Anr. v. Competition Commission of India & Ors., appeals pending before the Supreme Court; see also WhatsApp LLC v. Competition Commission of India & Ors., Competition Appeal (AT) No. 1 of 2025, judgment dated 4 November 2025
[4] The Digital Personal Data Protection Act, 2023, s. 6(7) – (9); Meity’s Business Document for Consent Management Under the DPDP Act, 2023, 2025, cl. 4.1
[5] Meity’s Business Document for Consent Management Under the DPDP Act, 2023, 2025, cl. 4.1
[6] Meity’s Business Document for Consent Management Under the DPDP Act, 2023, 2025, cl. 4.2
