DPDP Rules 2025: what a valid consent notice must say
· 5 min read
Reviewed by Adv. Mahir Gupta, Advocate, Delhi High Court ·

Most Indian apps, websites and businesses that collect digital personal data will soon have to rewrite their consent screens. The Digital Personal Data Protection Rules, 2025 were published on 13 November 2025, and Rule 3 describes the notice that must reach a person before the organisation (called a Data Fiduciary in the Act) asks for consent. This explainer sets out what that notice must say, in plain terms. It is general information, not legal advice.
The timeline first. The Rules came into force in phases. The institutional rules, including the setting up of the Data Protection Board, took effect at once. The registration of Consent Managers is scheduled for 13 November 2026, and the core duties, including notice and consent, are scheduled for 13 May 2027, eighteen months after the Rules were published. The law-firm analyses we read give 13 May 2027. Dates can be amended, so please check the current gazette text before fixing a date in a contract.
What does the notice have to be like? Two qualities come before content. It must be written in clear and plain language, and it must be capable of standing on its own, presented independently of other information. The Act also expects the person to have the option of reading it in English or any language listed in the Eighth Schedule to the Constitution. In practice that means a person should understand it without clicking through to a long privacy policy, and a link trail is not a substitute for the notice itself.
What must it contain? The analyses we read describe three core items. First, an itemised description of the personal data being collected, named by category and not hidden behind phrases such as 'your information'. Second, the specific purpose of the processing, together with an itemised description of the goods, services or uses that the data enables. Third, a communication link or other means by which the person can withdraw consent, exercise rights under the Act and complain to the Data Protection Board.
Itemisation is where most existing notices will fail. A notice that says 'we collect data to improve your experience' is neither specific nor itemised. A notice that says 'we collect your mobile number to send you a one-time password for login' is. If one product needs different data for different purposes, the notice should say so for each purpose, so that the person knows what each piece of data is for.
Withdrawal is the second test. The Act expects the ease of withdrawal to be comparable to the ease of giving consent, and the Rules require the notice to carry the means of withdrawal. If a person agrees with one tap, they should not have to write an email or find a hidden menu to take it back. The analyses also note that withdrawal should stop the processing that the consent covered, so the withdrawal link in the notice has to lead to something that works.
Consent Managers are the third element. A Consent Manager is a registered intermediary (a company incorporated in India) through which a person can give, manage, review and withdraw consent across several organisations from one place. The Rules lay down conditions for registration, and the registration provisions are due to come into force on 13 November 2026. An organisation does not have to appoint one, but its notice and its systems should be ready to accept a withdrawal or instruction that arrives through a Consent Manager.
Consent is also not the only lawful basis. The Act allows processing without consent for certain defined 'legitimate uses', such as performing certain functions of the State, responding to a medical emergency, and purposes related to employment. The list is enumerated, and one of the analyses we read describes it as narrower than the 'legitimate interests' idea in European law. A business should not treat it as an open door for marketing; if your purpose is not on the list, ask for consent.
A sample notice can be written as plain sentences. Here is one structure for a hypothetical Indian shopping app. Sentence one names the organisation and says what it is asking: 'Example Store asks your permission to use some of your personal data.' Sentence two itemises the data: 'We will use your name, mobile number, delivery address and order history.' Sentence three gives each purpose: 'We use your mobile number to send an OTP for login, and your address to deliver your order.'
Sentence four deals with anything optional, separately: 'If you also want offers on WhatsApp, tick this separate box; you can still order without ticking it.' Sentence five explains withdrawal: 'You can withdraw your permission at any time from Settings, then Privacy, then Withdraw consent, or by using the link below; it takes one step.' Sentence six explains rights and contact: 'To ask for your data, correct it or erase it, write to the contact given here.' Sentence seven names the remedy: 'If you are not satisfied, you may complain to the Data Protection Board of India.'
A few warning signs that a notice will not pass. The consent box is pre-ticked. One tick covers unrelated purposes. The text lives only behind a link. The withdrawal route takes more steps than the consent did. Data fields are listed as 'and other information'. Any of these makes it harder to say the consent was specific and informed.
What should an organisation do now? In the first month, map every place where personal data enters: sign-up forms, checkout, WhatsApp opt-ins, cookie banners, and forms on partner sites. Write one notice per purpose, in plain language, and test whether a first-time user can find the withdrawal step in under a minute. Keep a record of what each person was shown and when they agreed, since that record is your evidence later.
How Codesnag helps. Consent screens are also security surfaces. We review where an application collects and stores personal data, check that the withdrawal path actually stops processing and that stored records are protected, and can discuss technical preparedness for a personal data incident. This is a security review, not legal advice or a compliance opinion. If you want a second pair of eyes on a consent flow before May 2027, our team can walk through it with yours.
Sources
First published on codesnag.ai

