Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook →
Resource / Templates

Privacy Policy Templates

A DPDP-compliant privacy notice is more than boilerplate. Use this clause checklist as the foundation of your notice — every element below is expected of a Data Fiduciary under the DPDP Act 2023.

What every notice must contain

Work through these eight sections when drafting or reviewing your privacy notice. A clause you cannot yet answer is a compliance gap worth closing before enforcement.

1
Identity of the Data Fiduciary

Who is collecting the data, along with the contact details of your Data Protection Officer or grievance contact.

2
Categories of Personal Data

A plain-language list of the personal data you collect — and whether any of it is sensitive or belongs to children.

3
Purpose of Processing

The specific, lawful purpose each category is used for, so consent can be genuinely informed.

4
Data Principal Rights

How individuals can access, correct, erase their data, nominate, and raise a grievance.

5
Consent & Withdrawal

How consent is captured per purpose and how it can be withdrawn as easily as it was given.

6
Retention & Sharing

How long data is kept, which processors it is shared with, and any cross-border transfers.

7
Complaint to the Board

The Data Principal's right to complain to the Data Protection Board of India.

8
Grievance Redressal

The mechanism, timelines and named contact for resolving grievances.

This checklist is general guidance, not legal advice. Have your final notice reviewed by qualified counsel before publishing.

Generate a notice in minutes

DPDP Guard's AI Privacy Policy Generator drafts a notice from your actual processing activities — every clause above, tailored to your business.