Guide
A DPDP-compliant privacy policy: the checklist
August 4, 2026
Most Indian privacy policies are American templates with the company name changed. Under the Digital Personal Data Protection Act, that is now a compliance gap with penalties attached, not just bad form.
What the DPDP Act expects your policy to cover
- What you collect and why. Each category of personal data tied to a stated purpose. Blanket “we collect information to improve services” language does not meet the purpose-limitation standard.
- Consent mechanics. How consent is taken, and critically, how it is withdrawn. Withdrawal must be as easy as the giving of it.
- Data principal rights. Access, correction, erasure and grievance redressal, with an actual mechanism, not a dead email address.
- The grievance officer. A named contact and response timeline. This is one of the most-checked and most-missed items.
- Cross-border transfers. Where data goes, under what safeguards, in language a user can follow.
- Breach notification. What you commit to telling users and the Data Protection Board, and how fast.
- Children’s data. If anyone under 18 can use your product, the verifiable-consent question needs an answer in the policy, not around it.
Terms of service belong in the same pass
Your terms and your privacy policy reference each other constantly: limitation of liability, account termination, data on deletion. Drafting them together is why we sell them as one pack rather than two documents.