Infosek
INFOSEK

Why Your Privacy Policy Is Not a Valid DPDP Notice

Rule 3 sets three requirements for the notice a Data Fiduciary gives. A typical privacy policy fails the first one before you reach the content.

Why Your Privacy Policy Is Not a Valid DPDP Notice

The short answer

Rule 3 requires the notice given by a Data Fiduciary to a Data Principal to do three things:

Itemised means itemised

Rule 3(b)(i) asks for an itemised description of the personal data. “We collect information about you to improve our services” is not itemisation. Naming the fields is.

Rule 3(b)(ii) then wants the specified purpose and a specific description of the goods or services provided or uses enabled. Purpose and product are linked deliberately: it is not enough to say you process data for “business purposes”.

The third limb is a product requirement

Rule 3(c) requires the notice to tell the Data Principal how to withdraw consent, with ease comparable to how consent was given. If consent was one tap at sign-up, withdrawal cannot be an email to support followed by a wait.

That is an engineering commitment, not a drafting one. The notice has to point at something that exists.

Most privacy policies are written to be defensible in a dispute. Rule 3 asks for something different: a document a person can actually understand on its own, in the moment they are deciding.

Infosek Team

What to do

Common questions

What must a DPDP notice contain?

Under Rule 3 the notice must be understandable independently of any other information the Data Fiduciary makes available; must give in clear and plain language an itemised description of the personal data and the specified purpose, including a specific description of the goods or services to be provided; and must give the communication link and other means by which the Data Principal can withdraw consent, exercise her rights and complain to the Board.

Is a privacy policy enough for DPDP compliance?

Usually not. Rule 3(a) requires the notice to stand alone. A privacy policy that incorporates terms by reference, or that covers several products in general terms, does not give the itemised description Rule 3(b) requires.

Need your notices rewritten for Rule 3?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment