Back to articles
DPDP Act

DPDP Consent & Notice: A Practical Checklist

How to draft a DPDP-compliant notice and consent flow — with the seven elements every notice must contain.

March 18, 2025 8 min read Vrushali Borade

Notice Requirements Under Section 5

Section 5 of the DPDP Act requires every Data Fiduciary to serve a notice on the Data Principal at or before the point of collecting personal data. The notice must be independent of any other document, written in clear and plain language, and available in English plus any of the 22 languages listed in the Eighth Schedule to the Constitution — at the Data Principal's option.

This 'itemised notice' obligation displaces the older practice of burying data collection disclosures inside a 40-page terms document. A checkbox that says 'I agree to the Terms and Privacy Policy' will not, on its own, discharge the notice obligation for new data collection.

Seven Elements Every Notice Must Contain

A compliant notice must clearly state: (1) the personal data proposed to be processed, itemised by category; (2) the specific purpose for each category; (3) the manner in which the Data Principal may exercise their rights of access, correction, erasure and grievance; (4) the manner of withdrawing consent, which must be as easy as giving it; (5) the manner of making a complaint to the Data Protection Board of India; (6) contact details of the Data Protection Officer or authorised person; and (7) where consent was previously obtained before the Act, a fresh notice at the earliest opportunity.

Consent itself must be free, specific, informed, unconditional and unambiguous — bundled consents, pre-ticked boxes, or making service delivery contingent on consent for unrelated processing are all non-starters. If a user cannot use the core service without consenting to marketing analytics, that consent is not 'free' and will not stand up to regulatory challenge.

Practical Implementation Tips

Separate marketing consent from service consent, and separate each optional processing purpose from every other. A signup form should show three or four distinct toggles — service delivery (implied by account creation), transactional communications, marketing communications, product analytics — each with its own micro-notice.

Log the exact notice version each user consented to, along with a timestamp, IP address and consent artefact. Regulators and consumer courts will ask for this trail, and the burden of proof under Section 6(1) sits squarely with the Data Fiduciary.

Publish notices in at least English and Hindi at launch, and add regional languages based on your user base. A Marathi-speaking user in Pune has an explicit statutory right to receive the notice in Marathi on request.

Rebuild your cookie banner. A single 'Accept All / Reject All / Manage' pattern with granular categories — strictly necessary, functional, analytics, marketing — is now the minimum defensible baseline, and 'reject' must be as prominent and one-click as 'accept'.

The Ten-Point Notice & Consent Checklist

Use this list before you ship any change to a signup, cookie banner or marketing form:

1. Notice is separate from Terms and Privacy Policy. 2. Data categories are itemised. 3. Purposes are specific and matched to categories. 4. Rights and grievance mechanism are explained inline. 5. Withdrawal is one click. 6. Language toggle covers English plus your top three regional languages. 7. Consent is granular and unbundled. 8. No pre-ticked boxes. 9. Consent artefact (version, timestamp, IP, user ID) is logged and retrievable. 10. A DPO or grievance officer's email is displayed with a 30-day response SLA.

ConsentNoticeChecklist

Have questions on this topic?

Book a confidential consultation with Vrushali Borade.

Book Consultation