Digital & E-Commerce Legal Support7 min readUpdated 18 June 2026

Privacy Policy Under DPDP Rules 2025: Complete Guide

Draft a DPDP Rules 2025-compliant privacy policy for your Indian website. Expert help in Surat, Gujarat.

Tirth Inamdar, founder of Inamdar Legal

Tirth Inamdar

Founder · Inamdar Legal

Founder-reviewed legal guidanceSurat · India · Global clients

Quick answer

For privacy policy for indian websites under dpdp act in Surat, the safest approach is to combine the correct legal rule with a clean factual record, proper documents and a draft that matches the real transaction. This updated article uses the Excel source content and adds Surat/Gujarat SEO context so the reader can understand the law, collect the right papers and decide when to get drafting or review help.

UPDATE - NOVEMBER 2025: The Digital Personal Data Protection Rules, 2025 (DPDP Rules) were notified by MeitY on 14 November 2025 and are now in force on a phased timeline: immediate effect from November 2025 for foundational provisions; Consent Manager Framework from November 2026; full compliance obligations (notices, security safeguards, breach notification, children's data protections, cross-border transfer rules) from May 2027. The Data Protection Board of India has been established. The references in this article to rules being finalised should be read as updated accordingly - the Rules are now notified and businesses should be building their DPDP compliance programme actively. A privacy policy is the document on your website that tells your users what personal data you collect, why you collect it, how you use it, how you protect it, and what rights they have over their data. Under India's Digital Personal Data Protection Act 2023 (DPDP Act), having a privacy policy is not optional - it is a legal requirement for any website or app that collects personal data from users in India.

Quick Surat-Focused Answer

  • 01Primary topic: Privacy Policy for Indian Websites under DPDP Act
  • 02Location focus: Surat, Gujarat and India
  • 03Updated for current legal references and practical client preparation
  • 04Designed for service-intent SEO, not generic legal theory

The Dpdp Act 2023: What It Requires Of Data Fiduciaries

The DPDP Act governs the processing of digital personal data in India. A "data fiduciary" - any business or individual that determines the purpose and means of processing personal data - has specific obligations before and during the processing of personal data: CONSENT: Under Section 6 of the DPDP Act, a data fiduciary must obtain the free, specific, informed, unconditional, and unambiguous consent of the data principal before processing their personal data. Consent must be signified by a clear affirmative action - a pre-ticked box is not valid consent. NOTICE: Under Section 5 of the DPDP Act, a data fiduciary must give the data principal a notice in clear and plain language before or at the time of collecting personal data. The notice must state: the personal data being sought, the purpose of processing, and the data principal's right to withdraw consent. PRIVACY POLICY AS NOTICE: The privacy policy on your website serves as the DPDP Act notice requirement. It must be written in plain language, be easily accessible (typically linked in the website footer), and must cover all mandatory disclosures.

Section 1: Identity Of The Data Fiduciary

Full legal name, registered address, contact email, and (for Significant Data Fiduciaries) the name and contact details of the Data Protection Officer. Users must know who is responsible for their data.

List Every Category Of Personal Data Collected:

Data provided directly by users: name, email address, phone number, date of birth, address, payment information, identity documents Data collected automatically: IP address, device type, browser type, cookies, browsing behaviour on the website, location data (if collected) Data collected from third parties: social media login data, data from third-party analytics providers For each category, explain how it is collected - registration forms, cookies, transaction data, third-party integrations.

Section 3: Purpose Of Processing

State the specific, legitimate purpose for which each category of data is processed. Vague statements ("to improve our services") are inadequate. The DPDP Act requires the purpose to be specified precisely. Examples: Email address: to deliver order confirmations, shipping notifications, and (with separate consent) marketing communications Phone number: to verify account registration via OTP and to contact the user about their orders Payment information: to process the transaction; payment data is processed by our payment gateway [name] and is not stored on our servers Browsing behaviour: to personalise product recommendations on the website [if applicable]

Disclose Every Third Party With Whom Personal Data Is Shared:

Data processors (vendors processing data on your behalf): cloud hosting provider, payment gateway, email service provider, customer support software, analytics platform Third parties (recipients, not processors): logistics partners who receive the user's delivery address, credit bureaus for credit checks, government authorities as required by law For each category of third party, state: who they are (by name or category), what data is shared with them, and for what purpose.

Section 6: Cross-Border Data Transfers

If personal data is transferred outside India - to cloud servers in the US or Singapore, to a parent company, or to international vendors - this must be disclosed. State: the countries to which data may be transferred, the safeguards in place (contractual, encryption, etc.), and compliance with any Central Government restrictions on cross-border transfers under Section 16 of the DPDP Act.

Section 7: Data Retention

How long is each category of personal data retained? The DPDP Act requires data fiduciaries to retain personal data only for as long as necessary for the specified purpose. Common retention periods: Account data: retained while the account is active; deleted within [X] months of account deletion Transaction data: retained for [5-7 years] for tax and accounting compliance Marketing data: retained until consent is withdrawn, and deleted within [X] days of withdrawal Cookies: session cookies expire at end of session; persistent cookies expire at [X] months

Surat And Gujarat Practice Notes

People searching for privacy policy DPDP Rules 2025 India usually need more than a definition. They need to know what documents to collect, which facts matter, how the Surat or Gujarat process affects timing, and what should be changed before a draft is signed or a notice is sent. For Surat digital businesses, websites and online platforms, the legal risk is often hidden inside product flows: sign-up forms, checkout screens, refund policies, data collection, user uploads, vendor onboarding and support promises. The DPDP Act, IT Rules, consumer expectations and contract law should be translated into clear website terms, privacy notices, marketplace rules and SaaS clauses that a user can actually understand. A strong article should help a local founder see what needs to be displayed online, what should sit in the contract and what evidence should be saved. This is why every client file should be built around a clear chronology, a document index and a practical risk note. That approach makes the article useful for search readers and also mirrors how a lawyer would prepare the matter for drafting, negotiation, settlement or court.

  • Keep party names, addresses, dates, amounts and document numbers consistent across the draft.
  • Collect supporting proof before final drafting instead of after a dispute starts.
  • Check whether stamp duty, registration, statutory notice or board approval changes the timeline.
  • Use Surat-specific facts such as property location, business branch, vendor address, bank branch or project details where relevant.

Client Checklist Before You Ask For Drafting

Before asking for help with Privacy Policy for Indian Websites under DPDP Act, prepare a short brief. State who the parties are, what has happened so far, what document already exists, what result you want and what deadline is approaching. For SEO readers in Surat, this checklist is useful because it turns a broad search query into an immediate next step. For the lawyer, it reduces back-and-forth and helps produce a draft or review note that is specific rather than generic.

  • Existing draft, agreement, notice, invoice, title paper, policy or email chain.
  • Government IDs, business registration details, GST details or property identifiers where relevant.
  • Chronology of events with dates, payments, defaults, reminders and responses.
  • Your preferred outcome: draft, review, redline, settlement notice, compliance correction or negotiation support.

When to obtain a review

A review is especially useful when…

  • You are about to sign, send, rely on or respond to this document.
  • The draft was copied from an old template or another state.
  • There is money, property, business control, statutory deadline or reputation risk involved.
  • You need Surat/Gujarat-specific drafting, review or negotiation support.

Legal information notice

This article is general legal information for India and Gujarat. It is not a substitute for advice on your specific facts, documents, limitation period, stamp duty position or court strategy.

Questions, answered clearly

Common questions

Do I need a lawyer for privacy policy for indian websites under dpdp act in Surat?+

You should consider legal help when money, property, business rights, statutory timelines, compliance exposure or future enforcement is involved. A lawyer can tailor the document or notice to the facts instead of relying on a generic template.

Is a template enough for this document?+

A template may help with structure, but it often misses party-specific facts, Gujarat stamp or registration issues, statutory timelines, evidence requirements and negotiation points. Use it only after checking whether it fits the transaction.

What should I share before asking Inamdar Legal to review or draft it?+

Share the existing draft, transaction summary, dates, payment details, party information, supporting documents and the exact concern you want addressed. For urgent notices, also share the limitation or statutory deadline.

A practical next step

Need Help With Privacy Policy for Indian Websites under DPDP Act In Surat?

Share the draft, documents and timeline. Inamdar Legal can help review, redline or prepare privacy policy for indian websites under dpdp act with Surat and Gujarat-specific legal checks.