Back to DPDP Rules
Privacy Notice Requirements (R.3)
Rule 3 requirements for privacy notices - independence, itemisation, withdrawal links, and transitional provisions for existing data.
7 min read
Core Requirements
Rule 3 prescribes that the notice given by a Data Fiduciary to a Data Principal must be:
1. Independent and self-sufficient: The notice must not be embedded within terms of service, privacy policies, or other documents. It must stand on its own as a separate, identifiable communication.
2. Itemised by purpose: The notice must list each purpose of processing with a clear description of the personal data sought for that purpose. Bundling multiple purposes into a single paragraph is insufficient.
3. Include a communication link: The notice must contain a communication link to access the website or application for exercising Data Principal rights, including but not limited to withdrawal of consent.
This operationalises Section 5 of the DPDPA, which requires Data Fiduciaries to give notice before or at the time of requesting consent.
Transitional Provisions for Existing Data
For personal data collected before the Act's commencement, Data Fiduciaries must provide the notice 'as soon as reasonably practicable.' This creates a retrospective obligation - organisations must send compliant notices to all existing data subjects, not just new ones.
The notice must cover all current processing purposes for the existing data, provide the withdrawal mechanism, and itemise each purpose clearly. Organisations with large existing databases should plan a phased rollout of retrospective notices.
Practical Implementation Guidance
To comply with Rule 3, organisations should:
- Draft standalone notice documents separate from terms of service
- Create purpose-specific sections within the notice, each listing the data categories collected
- Implement a one-click or simple consent withdrawal mechanism linked from the notice
- Maintain version control of notices with timestamps
- Use clear, plain language accessible to the target audience
- Provide notices in relevant languages for the user base
- For mobile apps, consider layered notices with a summary and detailed view
- Maintain records of notice delivery and consent receipt
Comparison with GDPR Requirements
Rule 3 is broadly comparable to GDPR Articles 13-14 (information to be provided), but with notable differences:
- The DPDPA requires the notice to be independent (not embedded in privacy policies), while GDPR allows information to be provided through a privacy policy
- The DPDPA mandates a specific withdrawal mechanism link in the notice itself
- The DPDPA notice is purpose-centric (itemised by purpose), while GDPR requires broader information including legal basis, retention periods, and rights
- The DPDPA does not explicitly require information about automated decision-making or data transfers in the notice
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
