When you ask for consent, give a clear notice that stands on its own: what data, for what purpose, how to withdraw consent, how to use the rights and how to complain to the Data Protection Board. For data collected before the Act, a notice is due as soon as reasonably practicable.
What it means in your sector
Banking, financial services and insurance: Account opening, loan applications, insurance proposals, app sign-ups and branch forms each need a notice, separate from the long terms and conditions.
IT, ITeS, BPO and GCC: Candidate portals, employee onboarding and your own website forms need notices. For client data, the client normally gives the notice.
Central government: ministries and departments: Where you rely on Section 7(b) and the data was not collected by consent, a notice is not required by Section 5, but Rule 5 still asks you to give a contact for questions and rights.
Healthcare and hospitals: Registration desks, appointment apps, lab forms and health-camp sign-ups need clear notices. Old patient databases need a notice too.
Official text: Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 (MeitY). The DPDP Rules were notified on 13 November 2025. Consent Manager rules start on 13 November 2026. Most duties, including notice, security, breach reporting, retention, children's data and rights, start on 13 May 2027. A proposal discussed in early 2026 to bring this date forward had not been notified when this page was last reviewed.
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.