Data Privacy & User Rights

How to Write a Privacy Policy That Covers User Rights

Structure a privacy notice for DPDP Rule 3 and GDPR Articles 12 to 14 that explains access, correction, erasure, grievance, nomination, and consent withdrawal.

Working summary: A privacy policy that only lists cookies and contact emails is not enough for Indian and EU users. You need a notice that explains what you collect, why, and how people exercise access, correction, erasure, grievance, nomination, and consent withdrawal under DPDP Rule 3 and GDPR Articles 12 to 14.

  • DPDP Rule 3: Standalone, plain-language notice with itemised data, purposes, and working links to withdraw, exercise rights, and complain to the Board.
  • GDPR: Keep Article 13/14 fields (identity, bases, recipients, retention, rights) even when the India notice is shorter.
  • Rights block: Map Sections 11 to 14 and Articles 15 to 17 to one intake form people can actually use.
  • Withdrawal: As easy to start as giving consent (Section 6(4); Article 7(3)).
  • Write now: Notice and rights provisions are scheduled for 13 May 2027; keep version history for go-live.

A privacy policy that only lists cookies and contact emails is not enough for sites that serve Indian and EU users. You need a notice that explains what you collect, why, and how people exercise access, correction, erasure, grievance, nomination, and consent withdrawal.

This guide shows how to structure that page against the Digital Personal Data Protection Act, 2023 (DPDP Act), the Digital Personal Data Protection Rules, 2025, and GDPR Articles 12 to 14 and 15 to 22. For the India rights detail, see DPDP Act User Rights: A Practical Guide for Indian Websites. GDPR versus DPDP consent mapping is covered in GDPR vs DPDP: User Rights and Consent Compared. A full India build list appears in Data Privacy Compliance Checklist for Indian Businesses.

As of 2 October 2026, DPDP notice and rights provisions in Sections 5 and 11 to 14 are scheduled to become operative on 13 May 2027 under MeitY G.S.R. 843(E) (13 November 2025). Write the policy now; keep version history for the go-live switch.

What “privacy policy” must do under each law

DPDP Act and Rules 2025

Section 5 requires a notice before or with every consent request under Section 6. The notice must tell the Data Principal:

  • the personal data and the purpose of processing;
  • how to exercise rights under Section 6(4) (consent withdrawal) and Section 13 (grievance);
  • how to complain to the Data Protection Board.

Rule 3 of the DPDP Rules, 2025 tightens the format:

  • the notice must stand on its own (understandable without other site copy);
  • clear and plain language;
  • itemised description of personal data;
  • specified purpose or purposes, plus a specific description of goods, services, or uses enabled;
  • a communication link to your website or app, and other means, to withdraw consent (with ease comparable to giving it), exercise rights under the Act, and complain to the Board.

Additionally, Rule 14 also requires you to publish how people make rights requests and which identifiers you need, and to publish a grievance response period not exceeding ninety days.

Your long-form privacy policy can host that notice content, but the consent UI and Rule 3 notice still need to work as a standalone fair account. Do not bury Rule 3 itemisation only inside a 40-page PDF.

GDPR Articles 12 to 14

Article 12 requires information under Articles 13 and 14 (and rights communications) in a concise, transparent, intelligible, easily accessible form, using clear and plain language.

Article 13 (data collected from the person) and Article 14 (data not obtained from the person) list the transparency fields: controller identity and contact, purposes and legal bases, recipients, transfers, retention, rights (including withdraw consent where consent is the basis), and related items. Those Articles also require telling people they may withdraw consent at any time without affecting earlier lawful processing (see Article 13(2)(c) and the parallel Article 14 text).

Where you serve EU users, keep the Article 13/14 fields even if your India notice is shorter. Dual audiences often need layered notices: short Rule 3 / Art 12 summary up front, full policy below.

Use H2 sections that match how people scan. Keep a table of contents at the top on long pages.

  1. Who we are (controller / Data Fiduciary identity and contact)
  2. What personal data we collect (itemised)
  3. Purposes and legal grounds (consent, contract, legitimate interests, Section 7 uses, and so on)
  4. Cookies and similar technologies (link to cookie notice)
  5. Who we share data with (processors, other fiduciaries, legal disclosures)
  6. International transfers
  7. Retention
  8. Your rights (access, correction, erasure, and jurisdiction-specific rights)
  9. How to withdraw consent
  10. How to raise a grievance or complaint
  11. Children
  12. Security (high level; do not publish exploit detail)
  13. Changes to this notice
  14. Contact and Data Protection Officer / privacy contact

Section-by-section writing notes

1. Identity and contact

Name the legal entity that decides purposes and means. Add a privacy email or form that humans monitor. Under DPDP Section 8(9), publish business contact information of a Data Protection Officer (if you are a Significant Data Fiduciary) or another person who can answer processing questions. GDPR Article 13(1)(a) and (b) require controller identity and, where applicable, representative and DPO contacts.

2. Itemised personal data

List categories in plain language: account data, order data, support tickets, device and log data, marketing preferences, payment tokens (not full PAN if you do not store it). Rule 3 wants itemisation for consent-backed processing. GDPR expects categories under Articles 13 and 14. Avoid “and any other data we may collect” as a catch-all.

3. Purposes and grounds

Pair each purpose with a ground:

  • India: consent (Section 6) or a cited Section 7 certain legitimate use;
  • EU: an Article 6 basis (and Article 9 where special category data applies).

State what goods, services, or uses the processing enables (Rule 3). If you change purpose later, GDPR Article 13(3) requires prior information for further processing; under DPDP, new consent or a fitting Section 7 use is the safe path after legal review.

4. Sharing and processors

Name classes of recipients: hosting, payments, email delivery, analytics, support tools. Section 11 access responses may need identities of fiduciaries and processors with whom data was shared. Keep an internal schedule that matches the public summary. Processor contracts belong under Section 8(2) and GDPR Article 28; the policy should say you use processors under contract.

5. Rights that the policy must explain

Dedicate a visible “Your rights” block. At minimum cover:

Right DPDP Act GDPR
Access Section 11 Article 15
Correction / update Section 12(2) Article 16
Erasure Section 12(3); also Section 8(7) Article 17
Withdraw consent Section 6(4) Article 7(3)
Grievance Section 13; Rule 14(3) Complaint to supervisory authority (Art 77); facilitate rights (Art 12)
Nomination Section 14; Rule 14(4) Not a GDPR Chapter III twin; keep India-specific
Restriction / portability / object No direct Chapter III twins Articles 18, 20, 21 where applicable

Link each right to the same intake form or email, and list identifiers you require (Rule 14(1)). Point to your DSAR runbook or tooling guide such as How to Handle DSARs with OneTrust for internal process; keep the public page simple.

Rule 3(c) and Section 5 require the notice to explain how to withdraw consent. GDPR Article 13(2)(c) requires the same when consent is a basis. Put a short paragraph and a button or account setting path in the policy and in the consent banner preference centre. Details for product behaviour belong in Consent Withdrawal Under DPDP and GDPR: What Websites Must Support.

7. Grievance and Board / authority complaints

Publish the grievance channel and the response period (at most ninety days under Rule 14(3)). State that India Data Principals should exhaust the Section 13 process before approaching the Board. For EU users, name the lead supervisory authority if you have one, or explain how to complain to a local authority (Article 77).

8. Children

If you knowingly process children’s data, describe verifiable parental consent under DPDP Section 9 and GDPR rules for children (including Article 8 where information society services are offered directly to a child). If you do not target children, say so and describe age gates where used.

9. Retention and erasure

Give periods or criteria (for example, account life plus invoice retention required by tax law). Align with Section 8(7) and Section 12(3) exceptions, and GDPR storage limitation.

Drafting checklist before you publish

  1. Can a user understand the notice without opening other pages (Rule 3(a))?
  2. Are personal data itemised and purposes paired with goods or services enabled (Rule 3(b))?
  3. Do withdraw, rights, and Board complaint links work (Rule 3(c))?
  4. Does the EU section cover Article 13/14 fields for data you collect from the person?
  5. Is consent withdrawal as easy to start as giving consent (Section 6(4); Article 7(3))?
  6. Does the rights section match what your intake form actually supports?
  7. Is the grievance SLA published and staffed (Rule 14(3))?
  8. Are version date and change log present?
  9. Did legal review the Section 7 and Article 6 grounds?
  10. Are cookie and marketing preferences linked, not contradicted?

Common failures

  • Copying a US-only CCPA template and calling it DPDP-ready.
  • Listing rights with no working form.
  • Hiding withdrawal behind a phone-only process when consent was one click.
  • Using “legitimate interests” wording for India Section 7 without a statutory fit.
  • Stale processor lists that no longer match reality.

Sources

  • Digital Personal Data Protection Act, 2023, Sections 5, 6, 8, 9, 11 to 14: MeitY PDF.
  • Digital Personal Data Protection Rules, 2025, Rules 3 and 14; MeitY Rules page.
  • MeitY commencement notification G.S.R. 843(E), 13 November 2025.
  • Regulation (EU) 2016/679, Articles 7, 12 to 14, 15 to 22, 77: EUR-Lex.

Disclaimer

This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, privacy policies, or other privacy and data-protection controls. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.

Last updated on 27 September 2026

Share this article

Leave a Reply

Your email address will not be published. Required fields are marked *