DPDP Notice Requirements: What Section 5 and Rule 3 Demand
What a DPDP notice must contain under Section 5 and Rule 3: itemised data, specific purposes, rights links, and the retrospective notice owed to existing users.
On This Page
A consent request without a compliant notice collects nothing. Under the DPDP Act 2023, the notice is the legal foundation of consent: Section 5 dictates when it must be given, and Rule 3 of the DPDP Rules 2025 dictates what it must contain. A notice that fails either test invalidates the consent built on it.
This page covers the statutory mechanics. For how to write the notice itself, structure, language, and a working template, see the privacy notice writing guide. The two documents work together: this one tells you what the law demands, that one tells you how to draft against it.
Section 5: Three Notice Obligations
Section 5 creates three distinct duties, keyed to when processing began.
Section 5(1): The Prospective Notice
Every request for consent must be preceded or accompanied by a notice informing the Data Principal of the personal data and the purpose of processing, the manner in which rights may be exercised, and the manner of making a complaint to the Data Protection Board.
The sequencing matters. Notice first, consent second. A consent checkbox that links to a disclosure the user has not seen fails the structure of the section.
Section 5(2): The Retrospective Notice
Organisations that were processing personal data before the Act commenced owe a notice to every existing Data Principal, delivered as soon as reasonably practicable. Processing may continue until the individual withdraws consent, but the retrospective notice must meet the same content standard as a fresh one.
This is the obligation most compliance programmes underestimate. An NBFC holding fifty thousand pre-Act borrower records owes fifty thousand notices, each itemised, each carrying the withdrawal route, each logged with delivery evidence. Email, SMS, and in-app delivery are all workable. What does not work is silence: data held without a served notice has no compliant consent behind it once enforcement begins.
Section 5(3): The Language Option
The Data Principal has the option to access the notice in English or any of the 22 languages in the Eighth Schedule to the Constitution. The obligation is to offer the option, not to pre-translate every notice into every language. In practice that means English and the primary language of each market as defaults, with the remaining scheduled languages available on request. The privacy notice guide covers the language strategy in detail.
Rule 3: The Content Standard
Rule 3 turns Section 5 into a checklist. It becomes enforceable on 13 May 2027, with the tranche of Rules that took an eighteen-month runway from the 13 November 2025 notification. Three requirements carry the rule.
Standalone presentation. The notice must be understandable independently of any other information the Data Fiduciary presents. A notice folded into terms of service, a loan agreement, or an onboarding flow fails on structure alone. The reader must be able to understand it without opening a second document.
Itemised content in plain language. The notice must give a fair account enabling specific and informed consent, including at minimum an itemised description of the personal data and the specified purposes with a specific description of the goods, services, or uses each purpose enables. “We collect your information to improve our services” fails both halves of that test. “PAN and Aadhaar number, collected to verify your identity during loan onboarding” passes.
The rights link. The notice must carry the communication link to the website or app, and a description of other means, through which the Data Principal can withdraw consent with ease comparable to giving it, exercise rights under the Act, and make a complaint to the Board.
The comparable-ease standard comes from Section 6(4) and it binds the notice’s own mechanics: if consent was one tap, the withdrawal route the notice discloses must be comparable. A withdrawal process routed through support tickets fails a standard the notice is required to print.
What a Defective Notice Costs
The Act does not price notice defects as a separate line item. It does not need to. A defective notice invalidates the consent collected against it, and processing without valid consent falls in the residual tier of the penalty Schedule, up to Rs 50 crore. The exposure scales with the template: one non-compliant notice format, served to a million users, taints a million consent records.
The enforcement dates frame the urgency without exaggerating it. Section 5 is already law. Rule 3’s content standard becomes enforceable on 13 May 2027. The compliance timeline has the full sequence. Retrospective notice campaigns and withdrawal infrastructure are multi-month builds, which is why the preparation window is now.
Where ConsentOS Fits
ConsentOS generates English-language privacy notices from your data inventory, so the itemised data categories and purposes in the notice match what you actually process. Consent captured against each notice is recorded with the purpose it was given for, signed as an Electronic Consent Artifact, and retrievable when the Board or an auditor asks which notice version a consent record was collected under. The Rights Management Portal gives Data Principals the withdrawal and rights route that Rule 3 requires the notice to disclose.
Run the Gap Assessment to score your notice and consent position against the Act’s requirements.
Know where you stand on DPDP compliance
Run the free Compliance Vault Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.
Enforcement milestones, rule notifications, and deadline analysis.
One email when it matters, no more.
Resources
Continue Reading
Related DPDP Act 2023 guidance from the ConsentOS knowledge base.
DPDP Privacy Notice: 22 Languages & Mandatory Disclosures (India)
A DPDP Act 2023 privacy notice in all 22 Eighth Schedule languages: required disclosures, purpose, rights, grievance contact. Compliant template included.
11 min read
Consent ManagementDPDP Consent Management: Technical Systems for Indian Businesses
The DPDP Act 2023 makes consent the legal foundation for data processing. This is what valid consent requires, how withdrawal works, and what your systems must support.
7 min read
Regulatory UpdatesDPDP Act 2023 Compliance Deadlines & Enforcement Dates (India)
Every DPDP Act date: Rules notified Nov 2025, Consent Manager registration Nov 2026, penalty enforcement May 2027. Plan your compliance timeline.
5 min read
Data Principal RightsDPDP Act 2023: All 8 Data Principal Rights with Templates (India)
Access, correction, erasure, grievance, and nominee rights under the DPDP Act 2023: the response deadlines a Data Fiduciary must meet, with ready-to-use request templates.
7 min read