Skip to content

Guide

A DPDP-compliant privacy policy: the checklist

August 4, 2026

Most Indian privacy policies are American templates with the company name changed. Under the Digital Personal Data Protection Act, that is now a compliance gap with penalties attached, not just bad form.

What the DPDP Act expects your policy to cover

  • What you collect and why. Each category of personal data tied to a stated purpose. Blanket “we collect information to improve services” language does not meet the purpose-limitation standard.
  • Consent mechanics. How consent is taken, and critically, how it is withdrawn. Withdrawal must be as easy as the giving of it.
  • Data principal rights. Access, correction, erasure and grievance redressal, with an actual mechanism, not a dead email address.
  • The grievance officer. A named contact and response timeline. This is one of the most-checked and most-missed items.
  • Cross-border transfers. Where data goes, under what safeguards, in language a user can follow.
  • Breach notification. What you commit to telling users and the Data Protection Board, and how fast.
  • Children’s data. If anyone under 18 can use your product, the verifiable-consent question needs an answer in the policy, not around it.

Terms of service belong in the same pass

Your terms and your privacy policy reference each other constantly: limitation of liability, account termination, data on deletion. Drafting them together is why we sell them as one pack rather than two documents.

Need this document drafted properly?

Browse the catalog