DPDP Rules 2025 - Privacy Notice and Consent Requirements under Rule 3.

Introduction

What Is Rule 3 All About?

DPDP Rules 2025 - Privacy Notice and Consent Requirements under Rule 3.

Essentials of Privacy Notice

1. Identity & Contact Information

2. What Personal Data You Collect

3. Why You’re Collecting the Data

4. Legal Basis for Processing

5. How Data Is Used

6. Who Data Is Shared With

7. Data Retention Periods

8. User Rights

9. How Users Can Withdraw Consent

How to Make Privacy Notices Clear, Simple, and User-Focused

1. Clear and Simple Language

2. Easily Accessible

3. Presented at the Right Time

4. Layered Format

5. Consistent Across All Platforms

6. Visually Clean

Consent Requirements Under Rule 3

1. Freely Given

2. Specific

3. Informed

4. Unambiguous

5. Reversible

Examples of Good DPDP Compliance

Example 1: A Transparent Signup Form

Transparent signup form showing separate, unchecked consent for marketing and clear links to the privacy notice.

Example 2: Cookie Banners Done Right

Compliant cookie banner with 'Accept All,' 'Reject All,' and 'Customise' options for categorized consent.

Example 3: Layered Privacy Notice

Layered privacy notice structure with a short summary and navigable sections for easy readability.

Example 4: Withdrawal Made Easy

User account settings showing simple toggles for 'Privacy Preferences' to easily withdraw consent.

Common Mistakes to Avoid

Bad privacy notice with pre-checked boxes and confusing language

Why This Matters for Your Organisation

Conclusion

Key takeaways

Liked the post? Share on :

Scroll to Top