The DPDP Privacy Notice: What Rule 3 Actually Requires from Indian SMEs
Your old privacy policy probably will not pass. Rule 3 of the DPDP Rules 2025 demands an itemised, single-purpose notice with easy consent withdrawal. This is how Indian SMEs can build one.
The DPDP Privacy Notice: What Rule 3 Actually Requires from Indian SMEs
Most Indian businesses already have a privacy policy somewhere on their website. Here is the uncomfortable part: almost none of them meet the standard the DPDP Act sets for a privacy notice. A DPDP privacy notice is not the same document as your old privacy policy, and Rule 3 of the Digital Personal Data Protection Rules, 2025 spells out why in a way that leaves little room for the vague, catch-all language most sites use today.
If you run a startup or a mid-sized company that collects any personal data (and if you have a signup form, a checkout, or an HR system, you do), this is worth reading before your legal team drafts anything.
Why the notice matters now
The DPDP Rules, 2025 were notified on 13 November 2025. The substantive obligations, including the requirement to give a proper notice before or at the time of collecting consent, take full effect around 13 May 2027, eighteen months after notification. That sounds far away. It isn't. Rewriting every consent screen, form, and app flow to meet Rule 3 is slow work, and it usually touches product, design, and legal at the same time. The businesses that start in 2026 will finish comfortably. The ones that wait until early 2027 will scramble.
The notice is also the first thing a Data Principal sees, and the first thing the Data Protection Board of India will look at if someone complains. Get it wrong and you have handed a regulator an easy finding.
What Rule 3 says, in plain terms
Rule 3 requires that your notice stand on its own. It must be understandable independently of any other document. You cannot bury it inside your terms and conditions or make someone cross-reference three other pages to work out what you are doing with their data. It has to be in clear, plain language that lets a person give specific and informed consent.
Three requirements do most of the work here.
First, an itemised description of the personal data you collect. Not "we may collect information about you." You have to list the actual categories: name, email, phone number, location, payment details, whatever applies. Each one, spelled out.
Second, the specified purpose for each item. This is where a lot of existing policies fall apart. Under Rule 3 you cannot lump everything under "to improve our services" or "for analytics and marketing." Each purpose has to be single, clear, and tied to a specific data element and the goods, services, or functions that rely on it. If you collect a phone number to send delivery updates, say that. If you also want it for promotional SMS, that is a separate purpose and, in practice, a separate consent.
Third, a working link and clear routes to act on rights. The notice must give a specific communication link to your website or app, and explain how a person can withdraw consent, exercise their rights under the Act, and file a complaint with the Data Protection Board. The Rules also make the point that withdrawing consent has to be as easy as giving it. If a single tap turned it on, a single tap should turn it off. No hunting through settings, no "email us and we'll consider it."
Where SME notices usually go wrong
A few patterns show up again and again when we review existing policies.
The blended purpose is the most common. A company writes "we use your data to provide, personalise, and improve our services and for marketing." That single sentence bundles four different purposes and makes informed consent impossible. Rule 3 wants each of those broken out.
The buried notice is next. The privacy information sits at the bottom of a long terms-of-use page that nobody reads and that mixes refund policy, shipping terms, and data practices together. Rule 3 wants the notice to be readable on its own.
The dead-end withdrawal is the third. Plenty of sites tell users they can withdraw consent but give no actual mechanism, or route them to a support inbox that takes a week. That gap becomes a real liability once the Board is hearing complaints.
A practical way to build yours
Start with a data map. You cannot describe what you collect and why until you know it, so list every point where personal data enters your business: forms, cookies, integrations, your CRM, your payroll system, third-party tools. This is the same groundwork a privacy impact assessment relies on, so the effort is not wasted.
Then, for each data category, write a single-purpose line. Keep them short and concrete. If a purpose needs the word "and" to describe it, it is probably two purposes.
Next, build the withdrawal and rights mechanics into the product, not just the text. A preferences page where consent can be toggled off, a defined route for rights requests, and a stated path to the Data Protection Board. Writing "you can withdraw anytime" is easy; wiring it up is the actual work.
Finally, keep the notice separate from your terms of service. Two documents, clearly linked, each doing one job.
Larger organisations, or those handling children's data or high volumes of sensitive information, may be classed as Significant Data Fiduciaries and carry extra duties, including appointing an India-based Data Protection Officer. If that might be you, our Data Protection Officer services and broader DPDP Act compliance support can help you scope it.
The cost of getting it wrong
The penalties under the DPDP Act are not symbolic. They run up to ₹250 crore per instance depending on the failure. A defective notice that leads to unlawful processing is exactly the kind of thing that draws attention, especially once complaints can be filed directly with the Board. Globally the direction of travel is clear: European regulators recorded over €7.1 billion in cumulative GDPR fines by early 2026, and notice-and-consent defects sit near the centre of many of those cases. India's regime is younger, but the design is similar enough that the lesson carries.
A clean, itemised notice is one of the cheaper pieces of DPDP readiness, and one of the most visible. It is a good place to start, and a good signal to customers that you take their data seriously.
This article is general guidance for Indian businesses and not legal advice; your specific obligations depend on your data practices and how you are classified under the Act. If you want a structured way to begin, our DPDP compliance checklist walks through the essentials, and you can contact us for a review tailored to your business.
Get help implementing this
Turn this reading into a compliance plan.
Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.
Book a free 30-minute consultation