A consent notice is not your privacy policy. It is a standalone statement at the point of collection, and under the DPDP Rules it has specified contents. Most notices in use across Indian websites fail the same three ways.
Failure one: bundling
One notice covering marketing, analytics and partner sharing means the person cannot agree to one and refuse another. Consent must be capable of being given per purpose.
Failure two: describing data as a category
Saying you collect contact information is not an itemised description. The Rules expect the list: name, email address, mobile number. Categories hide scope, which is exactly why they are not enough.
Failure three: no withdrawal route in the notice
The notice must state how to withdraw and how to complain, not only how to agree. A notice containing just the ask is incomplete.
A structure that works
- What we collect, itemised rather than categorised
- What each item is used for, one purpose per line
- A separate control per purpose, unticked by default
- How to withdraw, with the actual mechanism stated
- How to complain to us, and that the Data Protection Board exists
- A version identifier you store with the consent record
That last point is the one teams skip. If you cannot say which version of the notice someone agreed to, you cannot prove what they agreed to.
Length is not the enemy
Teams resist itemising because it lengthens the notice and they fear conversion drops. Test it rather than assume. A specific short list often reads as more trustworthy than a vague sentence, because it looks like someone thought about it.
General information, not legal advice. Rules current as of July 2026.