Skip to content
Bhartiya IP Solutions

Privacy Policy Requirements in India: Preparing for the DPDPA

Published 20 January 2026

If you operate a website or a mobile app in India that collects personal data from users, having a Privacy Policy is not just a good practice—it’s a legal requirement. The landscape of data privacy in India is evolving rapidly with the impending enforcement of the Digital Personal Data Protection Act (DPDPA), 2023.

The Current Framework: Information Technology Act, 2000

Currently, data privacy in India is governed primarily by the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules).

Under the SPDI Rules, any body corporate that collects, receives, possesses, stores, deals, or handles personal information must provide a privacy policy.

Key Requirements under SPDI Rules:

  • Clear and accessible: The policy must be published on the website and be easily accessible.
  • Types of data collected: Clearly state what personal and sensitive personal data (e.g., passwords, financial info, health data) is being collected.
  • Purpose of collection: Explain why the data is being collected and how it will be used.
  • Disclosure: State whether the data will be shared with third parties.
  • Security practices: Outline the reasonable security practices and procedures maintained by the company to protect the data.

The Future Framework: Digital Personal Data Protection Act (DPDPA), 2023

The DPDPA introduces a much stricter regime for processing digital personal data. Once fully enforced, it will require businesses (Data Fiduciaries) to overhaul their privacy practices.

Key Impacts on Privacy Policies under DPDPA:

  • Notice and Consent: Before or at the time of requesting consent, you must provide a clear and concise notice detailing the personal data to be collected and the purpose for processing it. The consent must be free, specific, informed, unconditional, and unambiguous with a clear affirmative action.
  • Language Accessibility: Crucially, the user must have the option to view the notice in English or any language specified in the Eighth Schedule to the Constitution of India (e.g., Hindi, Bengali, Tamil, etc.).
  • Data Principal Rights: The policy must clearly explain the rights of the user (Data Principal), including the right to access, correct, erase their data, and the right to nominate someone in the event of death or incapacity.
  • Grievance Redressal: The contact details of a Data Protection Officer (DPO) or an authorized person who will respond to user grievances must be prominently displayed.

Does My App Store Listing Need a Privacy Policy?

Yes. Both the Google Play Store and Apple App Store mandate that developers provide a link to a valid, actively maintained Privacy Policy in the app’s store listing. Failure to do so can result in your app being rejected or removed from the store.

Drafting a robust Privacy Policy that complies with current IT Rules and anticipates the DPDPA is essential for building user trust and avoiding severe legal penalties.

About the Author: Naman Pathak

Naman Pathak is the Director of Bhartiya IP Solutions, specializing in IPR registration across India. With over 5+ years of experience helping startups and creators secure their Trademarks, Copyrights, and Patents, he ensures plain-language guidance through complex government filing processes.

Have Questions About Your Situation?

Start an enquiry and we'll give you specific guidance, not just general information.

Start Enquiry