BuildWrightFor Builders
ServicesPricingResourcesPartners

BuildWright Consultants

Your virtual compliance team for early-stage businesses across India: incorporation, licenses, documentation, and dispute resolution.

Services

  • Incorporation
  • Licenses & registrations
  • Documentation
  • Dispute resolution
  • Monthly plans

Company

  • Blog
  • Resources
  • Tools
  • Partners
  • For Advisers
  • For Freelancers
  • Privacy Policy
  • Terms of Use

Get in touch

  • Free consultation
  • WhatsApp
  • Client login

BuildWright Consultants is a virtual compliance team. We do not provide advocacy or litigation representation.

Your data is encrypted in transit and at rest on Google Cloud infrastructure. We never sell it. See our privacy policy.

© 2026 BuildWright Consultants. All rights reserved.

HomeDocumentationDPDP Privacy Notice Drafting

Documentation

DPDP Privacy Notice Drafting

A privacy policy on your website is not the itemised notice the Rules require. We draft the standalone notice that actually meets s.5(1) and Rule 3, along with the consent-screen copy and withdrawal route it depends on, as one focused engagement rather than the full documentation pack.

A privacy policy in your footer is not the notice the DPDP Rules require. We draft the standalone notice that actually meets Rule 3, along with the consent-screen copy and withdrawal route it depends on, as one focused engagement.

Rule 3(a) requires the notice to be understandable independently of any other information on your site. A privacy policy linked from your terms of use, sitting alongside everything else on the page, fails that test by definition, no matter how thorough it is. Almost every Indian company believes its existing policy already covers this. Most haven't checked.

This is the smallest DPDP engagement we offer: one document, drafted from what you actually collect and where, plus the two pieces of copy it depends on to work in practice.

Scope

What's included

  • The notice stands on its own, states what you collect against the specific purpose, and carries the three required links: to withdraw consent, to exercise rights, and to complain to the Board. That's Rule 3(a), 3(b)(i)-(ii), and 3(c)(i)-(iii) in one document.

  • The consent-screen copy is drafted against the section 6(1) standard: free, specific, informed, unconditional, with a clear affirmative action. It's not lifted from a GDPR cookie banner built around a legal basis, legitimate interest, that DPDP doesn't have.

  • The withdrawal route is specified to be as easy as giving consent was, per section 6(4). If signing up takes one tap and withdrawing takes an email to support, we close that gap before delivery.

Specifics

The details

The one fact that makes this worth doing on its own

Rule 3(a): the notice "shall be presented and be understandable independently of any other information" the fiduciary has made available. A policy buried in your terms of use, or one that assumes the reader has already read your homepage, doesn't meet that bar. This is the single most common gap we find, and it's usually fixable without touching anything else on the site.

What Rule 3 actually asks for

ClauseRequirement
Rule 3(a)Understandable on its own, independent of any other information
Rule 3(b)(i)-(ii)An itemised description of the personal data, against the specific purpose
Rule 3(c)(i)-(iii)The link to withdraw consent, exercise rights, and complain to the Board

There's no sub-rule "(1)" in Rule 3 and no clause "(d)", which matters more than it sounds like it should. A notice drafted against the wrong clause structure tends to be missing something, usually the itemisation, because whoever wrote it was working from a source that had the structure wrong too.

Process

How it works

Step 1 of 4

Tell us what you collect

And where: signup form, app permission screen, in-store, an offline form.

Tell us what you collect

And where: signup form, app permission screen, in-store, an offline form.

Common mistakes founders make

  • Treating a footer-linked privacy policy as the standalone notice Rule 3(a) requires.
  • Copying consent-screen language from a GDPR cookie banner that leans on legitimate interest, a legal basis DPDP doesn't have.
  • Making withdrawal harder than signup, which fails section 6(4)'s requirement that withdrawal be as easy as giving consent.
  • Assuming a B2B product with no consumer-facing sales doesn't need a notice at all.

Clarifications

Frequently asked questions

Check it against Rule 3(a) first: does it stand on its own, or does it assume the reader has read something else on your site? If it's folded into your terms of use or a general legal page, it likely doesn't meet the standalone requirement, and that's the gap this service closes.

No. This is the notice and its supporting consent copy only. The documentation pack adds the data inventory, retention schedule, vendor agreements, breach plan, and rights SOP. Founders usually start here and upgrade into the pack when they need the rest.

Not without rewriting it. GDPR cookie banners are usually built around legitimate interest as a legal basis, and DPDP has no such basis. The consent standard here is section 6(1), which is different enough that a direct import gets the foundation wrong.

Yes. The DPDP Act's notice requirements apply to personal data collected from anyone, including an individual user at a business customer, regardless of whether the product itself is consumer-facing.

Related

Learn more

Prefer to skip the paperwork?

BuildWright can take this off your plate — done properly, the first time.

Ready to get started?

Tell us about your partners and business and we'll take it from there.

Get a Quote

Skip the hassle — have us do it for you. We do it best.

  • The journey
  • What's included
  • The details
  • How it works
  • FAQ
  • Learn more
  • Pricing

Key terms

Notice
The Rule 3 document telling a Data Principal what personal data is collected, why, and how to withdraw consent, exercise rights, and complain. Legally distinct from a general privacy policy.
Affirmative action
The section 6(1) requirement that consent be given through a clear, active step. A pre-ticked box or silence doesn't count.
Legitimate interest
A GDPR legal basis for processing data without consent. It has no DPDP equivalent, which is why a GDPR-derived policy imported wholesale usually breaks at the foundation.