When individuals share their personal information with a company, it’s crucial for them to understand precisely what data is being collected, the reasons behind its collection, how it will be utilized, and what options or rights they possess.
This is where the role of a Privacy Notice becomes essential.
A Privacy Notice is more than just a document on a company’s website; it’s a crucial tool for transparency. It’s how an organization explains its personal data processing activities to individuals.
Privacy requirements differ depending on the jurisdiction, the type of organisation, and the processing activities involved. While privacy requirements vary based on jurisdiction, organization type, and specific processing activities, transparency remains a common thread across major privacy laws. This includes India’s Digital Personal Data Protection Act, 2023 (DPDP Act), the European Union’s General Data Protection Regulation (GDPR), and California’s Consumer Privacy Act (CCPA).
So, what exactly should a Privacy Notice contain, when should it be provided, and how should organisations approach it?
What is a Privacy Notice?
A Privacy Notice is information provided to individuals explaining how an organisation collects and processes their personal data.
Depending on the applicable law, it may explain matters such as:
- What categories of personal data are collected
- Why the information is collected
- How the information is used
- The legal basis or other applicable ground for processing
- Who the information may be shared with
- How long the information is retained
- Whether information is transferred to other countries
- What rights individuals have
- How individuals can exercise those rights
- How they can raise a complaint or grievance
The exact information required depends on the law that applies to the organisation and the particular processing activity.
Under regulations like the GDPR, Articles 13 and 14 mandate that controllers provide specific information to individuals. This includes their identity and contact details of the controller, the reasons and legal basis for data processing, who the data will be shared with, how long it will be kept, and the rights individuals have regarding their data. Information about international data transfers should also be included if applicable.
Is a Privacy Notice legally required?
There is no single global Privacy Notice requirement that applies identically to every organisation.
Instead, organizations must identify which data protection and privacy laws are relevant to their data processing activities and then comply with the information disclosure requirements outlined in those laws.
For example:
- The GDPR contains detailed transparency requirements under Articles 12, 13 and 14.
- The India DPDP Act, 2023 includes a specific provision regarding notice in Section 5.
- The California CCPA requires businesses to provide a Notice at Collection and a privacy policy in circumstances covered by the law.
Therefore, simply having a document named “Privacy notice” does not automatically mean that an organisation has satisfied every applicable transparency requirement.
The content, timing and method of providing the information are equally important.
What does the DPDP Act say about Notice?
The Digital Personal Data Protection Act, 2023, in Section 5 and Rule 3 of DPDP Rules 2025, mandates that any request for consent from a Data Principal by a Data Fiduciary, as per Section 6, must be accompanied or preceded by a notice.
The notice must inform the Data Principal about:
- The personal data proposed to be processed and the purpose for processing it.
- How the Data Principal can exercise the relevant rights under the Act.
- How the Data Principal can make a complaint to the Data Protection Board.
Illustration.
X, an individual, gave her consent to the processing of her personal data for an online shopping app or website operated by Y, an e-commerce service provider, before the commencement of this Act. Upon commencement of the Act, Y shall, as soon as practicable, give through email, in-app notification or other effective method information to X, describing the personal data and the purpose of its processing. The Data Fiduciary shall give the Data Principal the option to access the contents of the notice referred to in sub-sections (1) and (2) in English or any language specified in the Eighth Schedule to the Constitution.
The DPDP Act was enacted on 11 August 2023. The Government subsequently notified the DPDP Rules, 2025 on 14 November 2025.
What does Rule 3 of the DPDP Rules, 2025 say?
Rule 3 provides additional requirements for notices given by a Data Fiduciary.
The notice must:
- Be presented and understandable independently of other information provided by the Data Fiduciary.
- Use clear and plain language.
- Provide the details necessary for specific and informed consent.
- Include an itemised description of the personal data being processed.
- Specify the purpose or purposes of processing.
- Provide a specific description of the goods, services or uses enabled by the processing.
- Provide the relevant means for withdrawing consent, exercising rights and making a complaint to the Board.
This approach prioritizes making a notice understandable and useful to the individual, rather than just having one.
Is the DPDP Notice requirement already applicable?
This is a crucial distinction for organizations operating in India. The DPDP Act and Rules were officially announced in 2025, but their provisions are being implemented in stages. Therefore, organizations should not assume that all aspects of the Act and Rules became effective immediately after their notification.
For businesses preparing their compliance programme, this means the notice requirements should be considered as part of implementation planning while also checking the applicable commencement dates and the provisions already in force.
The Ministry of Electronics and Information Technology has published the Rules and the official enforcement timeline on its website.
What does the GDPR require?
The GDPR places significant importance on transparency.
Article 13 applies where personal data is collected directly from the data subject, while Article 14 applies where personal data has not been collected directly from the data subject.
Depending on the circumstances, the information provided to individuals can include:
- The identity and contact details of the controller
- Contact details of the Data Protection Officer, where applicable
- The purposes of processing
- The legal basis for processing
- Information about legitimate interests where applicable
- Recipients or categories of recipients
- Information about international transfers
- The retention period or criteria used to determine it
- Data subject rights
- The right to withdraw consent where processing is based on consent
- The right to lodge a complaint with a supervisory authority
- Information about the source of the personal data where it was not obtained directly
- Information concerning automated decision-making or profiling where applicable
Furthermore, the GDPR mandates that information be presented in a concise, transparent, intelligible, and easily accessible manner, using clear and straightforward language.
What does the CCPA require?
California provides another useful example of how transparency requirements can operate at the point where information is collected.
The CCPA, mandates businesses to provide a Notice at Collection.
The California Privacy Protection Agency explains that the Notice at Collection should generally be provided at or before the point at which personal information is collected.
Among other things, the notice must address:
- Categories of personal information collected
- Purposes for which the information is collected or used
- Whether the information is sold or shared
- The intended retention period for each category
- The relevant opt-out mechanism where applicable
- A link to the business’s privacy policy
The notice needs to be understandable, avoid overly legal or technical jargon, be readable on smaller screens and be reasonably accessible to individuals with disabilities.
This highlights a crucial principle: a Privacy Notice doesn’t always need to be a single, lengthy document. Depending on the applicable law and the context, organisations may need to present information precisely at the point where data is actually collected.
When should a Privacy Notice be provided?
Timing is crucial.
Providing privacy information only after personal data has already been collected may not fulfil the applicable transparency requirement.
For instance, under the GDPR, information required by Article 13 is generally provided when personal data is collected. Article 14 contains different timing requirements for information obtained from another source.
Similarly, California’s Notice at Collection is intended to be provided at or before collection.
In practice, organisations should therefore consider privacy information at the point where the individual interacts with the organisation.
This could include:
- Website registration
- Contact forms
- Mobile applications
- Online purchases
- Employee onboarding
- Recruitment portals
- Customer support
- Marketing subscriptions
- CCTV or physical locations
- Surveys
- Events and registrations
The appropriate form of notice may vary depending on the specific processing activity.
What should a good Privacy Notice contain?
There is no single universal template that can be copied by every organisation.
However, a well-designed Privacy Notice should generally answer the questions an individual would reasonably have about the processing of their personal data.
1. Who is collecting the data?
Identify the relevant organisation and provide appropriate contact information.
Where applicable, the notice should also identify or name the Data Protection Officer or other privacy contact.
2. What personal data is being collected?
The organisation should clearly identify the categories of information involved.
For example:
- Name and contact details
- Account information
- Employment information
- Device or technical information
- Transaction information
- Location information
- Other categories relevant to the specific processing
The notice should accurately reflect the organisation’s actual processing activities rather than listing every possible type of information.
3. Why is the data being collected?
The purpose should be specific enough for an individual to understand why their information is required.
For example, saying “for business purposes” provides little meaningful information.
A more useful explanation would identify the actual purpose, such as processing an order, providing customer support, managing an account or meeting a specific legal obligation.
4. Who will receive or access the information?
Where applicable, the notice should explain the categories of recipients or other parties with whom personal data may be shared.
This may include service providers, technology providers, professional advisers, regulators or other recipients depending on the processing activity and applicable law.
5. How long will the information be retained?
Where required, organisations should explain the retention period or the criteria used to determine it.
This is particularly important because privacy information should not suggest that personal data is retained indefinitely when the organisation actually follows defined retention practices.
6. What rights do individuals have?
The notice should explain the rights available under the applicable law and how individuals can exercise those rights.
The exact rights differ between laws and circumstances.
7. How can an individual raise a complaint?
A Privacy Notice should provide a practical way for individuals to contact the organisation regarding privacy concerns.
Where applicable, it should also explain the right to complain to the relevant regulatory authority.
Privacy Notice vs Privacy Policy: Are they the same?
While both terms are often used interchangeably, but they can serve different purposes.
A Privacy Notice generally focuses on informing individuals about how their personal data is processed.
A Privacy Policy may be a broader document describing an organisation’s overall privacy practices, individual rights, established procedures and overall commitments.
In some organisations, one document may perform both functions.
However, a single website Privacy Policy may not always be sufficient for every collection point. For example, a recruitment process, mobile application, customer registration form and physical premises may involve different categories of personal data and different processing purposes.
This is why organisations should assess whether additional or layered notices are appropriate, depending on the category of data that they collect with the purpose of processing that specific data, which can be identified through maintaining a proper Data Inventory Sheet, ROPA under DPDPA and GDPR requirement.
How should businesses create a Privacy Notice?
Creating a Privacy Notice should begin with understanding the organisation’s actual data processing activities.
A practical approach is:
Step 1: Map the personal data
Identify what personal data the organisation collects and where it comes from.
Step 2: Identify the processing purposes
Document why each category of personal data is being processed.
Step 3: Identify the applicable legal requirements
Determine which privacy laws apply based on factors such as the organisation’s location, customers, employees, services and processing activities.
Step 4: Identify data recipients
Determine which internal teams, processors, service providers or other parties receive or access personal data.
Step 5: Review retention practices
Confirm how long different categories of personal data are actually retained and whether retention schedules exist.
Step 6: Map individual rights
Identify the rights available under each applicable law and establish how individuals can exercise them.
Step 7: Draft in clear language
The notice should explain actual processing activities in language that ordinary users can understand.
Step 8: Place the notice appropriately
Do not simply publish a Privacy Notice somewhere on the website and assume the transparency requirement has been addressed.
Consider where individuals interact with the organisation and whether a notice should appear at or before the relevant collection point.
What are some common Privacy Notice mistakes?
Some common problems include:
- Using a generic Privacy Notice that does not reflect actual processing activities.
- Describing purposes too broadly.
- Failing to explain relevant data recipients.
- Providing outdated information after business processes change.
- Using complicated legal language.
- Providing the notice only after information has already been collected.
- Failing to explain available rights or how they can be exercised.
- Having a Privacy Notice that does not match internal data practices.
A particularly important issue is consistency.
If a Privacy Notice says that personal data is used for one purpose while internal systems or business processes use it for another purpose, the organisation should review the mismatch rather than relying on the wording of the notice alone.
Frequently Asked Questions (FAQs)
Is a Privacy Notice mandatory for every company?
Not necessarily in the same form. The requirement depends on the applicable privacy laws and the organisation’s processing activities. Major privacy regimes such as the GDPR, DPDP framework and CCPA contain specific transparency or notice requirements.
Is a Privacy Policy enough?
Not always. A general Privacy Policy may need to be supplemented by notices provided at specific collection points or for particular processing activities.
Can a Privacy Notice be one page?
Yes, where the organisation’s processing activities and applicable requirements can be communicated accurately and sufficiently. However, the appropriate length depends on the processing activities and applicable law. Conciseness should not come at the expense of required information.
Does a Privacy Notice need to mention every piece of data?
The answer depends on the applicable law. However, organisations should provide sufficiently specific information about the categories of personal data being processed to meet the relevant transparency requirements.
Should a Privacy Notice be updated?
Yes, Organisations should review their Privacy Notices when there are material changes to their processing activities, systems, purposes, recipients, retention practices or applicable legal requirements.
Is a Privacy Notice the same as consent?
No, A Privacy Notice provides information about processing. Consent, where required and relied upon as the applicable legal basis, is a separate concept.
The fact that an individual has been shown a Privacy Notice does not by itself mean that the individual has consented to every processing activity described in it.
Conclusion
A Privacy Notice should not be seen as a document made only for compliance purposes.
It is an important part of how an organisation communicates its approach to personal data.
For businesses preparing for privacy regulations such as India’s DPDP framework, the GDPR, the CCPA or other applicable laws, the right starting point is not simply to download a standard Privacy Notice template.
The better approach is to understand the organisation’s actual data flows, identify the purposes for which personal data is processed, determine the applicable legal requirements, and then communicate that information clearly to individuals.
A Privacy Notice is effective when it accurately reflects what the organisation actually does with personal data — and when individuals can understand that information and act on it.
As privacy regulations continue to develop, organisations should treat their Privacy Notice as a document that needs to remain aligned with their real-world processing activities, rather than as a one-time compliance exercise.
