Glossary · Notice
What Is a Notice Under DPDPA?
If you ask a customer, patient or parent to agree to your use of their data, DPDPA expects them to see a short standalone notice first — not a privacy policy. Section 5 and Rule 3 set what that notice must say. Build it before 13 May 2027, when the substantive rules bite.
Last reviewed: 13 August 2026
Definition
A notice is the plain-language statement you must give someone before — or at the same time as — you ask for their consent to use their personal data. Section 5 of the DPDP Act, 2023 requires it to tell the person exactly what data you are collecting, the specific purpose, how they can withdraw consent, how they can exercise their rights, and how to complain to the Data Protection Board. Rule 3 of the DPDP Rules, 2025 adds that the notice must stand on its own, in clear language, separate from your terms and privacy policy, in English or any Eighth Schedule language, with an itemised description of the personal data and the specified purposes. Consent collected before the Act also needs a fresh notice under Section 5(2), as soon as reasonably practicable.
How this matters in practice
Most SMBs bury notice inside a privacy policy — that fails Rule 3. Privigo generates standalone, itemised notices per collection point (admission form, loan application, HR onboarding), serves them in English plus Eighth Schedule languages, and binds the exact notice version shown to each consent record. When the Board asks what a person saw in 2026, you produce it, not reconstruct it.
Frequently asked questions
Is my privacy policy the same thing as a notice?
No. Rule 3 of the DPDP Rules, 2025 says the notice must be presented and understandable independently of any other information — so a clause buried inside a long privacy policy or T&C page does not satisfy Section 5. The notice is a short, standalone screen or panel shown at the point of collection, listing the specific data items and the specific purpose. Your privacy policy can still exist; it just isn't a substitute.
Do I need a notice every single time I collect personal data?
Only where you are relying on consent under Section 6. Processing that falls under a legitimate use in Section 7 — for example, data processed for employment purposes under Section 7(i), or data a person voluntarily hands over for a purpose they have not objected to under Section 7(a) — does not carry a Section 5 notice obligation, because Section 5 is tied to requesting consent. In practice most SMBs are on consent for customer data and on Section 7(i) for staff data, so you need to map which basis applies where before writing notices.
What happens if I don't give a proper notice, and when does this start applying?
Failure to give notice is not covered by a named penalty slab, so it falls under the residuary entry in the Schedule to the DPDP Act, 2023 — a financial penalty of up to ₹50 crore, decided by the Board based on the nature, gravity and duration of the breach. Rule 3 sits in the tranche of Rules that becomes enforceable on 13 May 2027, which is the date to build backwards from — not a date to start work on.
See what your current notice actually says
Book a 30-minute call. We look at one collection point — a form, an app screen, an HR onboarding pack — and map it against Section 5 and Rule 3. You leave with a written gap list, whether or not you work with us.
Book a demo
Free Gap Analysis
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.