All templates
PoliciesSection 5
Privacy Policy Template
A comprehensive, DPDP-aligned website/app privacy policy covering notice, rights, retention, and grievance redressal.
Template
PRIVACY POLICY
[Organization Name]
Effective Date: [Effective Date] | Last Updated: [Last Updated Date]
1. INTRODUCTION
[Organization Name] ("we", "us", "our") is committed to protecting the personal data of individuals ("you", "Data Principal") who interact with our website/app/service [Name]. This Privacy Policy is issued in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025, and explains what data we collect, why, how we protect it, and the rights available to you.
2. SCOPE
This Policy applies to digital personal data processed by us in connection with offering our goods/services to individuals in India, in accordance with Section 3 of the DPDP Act.
3. DATA WE COLLECT
a. Data you provide directly: [name, contact details, account credentials, payment information, etc.]
b. Data collected automatically: [device identifiers, IP address, cookies, usage logs]
c. Data received from third parties: [background-check agencies, business partners], where applicable.
4. LAWFUL BASIS FOR PROCESSING
We process your personal data on the basis of:
a. Your consent (Section 6), which is free, specific, informed, unconditional, and unambiguous, obtained via itemised notice (Section 5); or
b. A "legitimate use" recognised under Section 7, such as data you voluntarily provide for a specified purpose, compliance with a legal obligation, or a medical emergency.
5. PURPOSES OF PROCESSING
[List purposes, e.g.: account creation and authentication; service delivery and support; billing; fraud and security monitoring; legal and regulatory compliance; product improvement and analytics; marketing communications (only with separate consent).]
6. CONSENT MANAGEMENT
Where processing is based on consent, you may grant, deny, or withdraw consent at any time through [Account Settings/Consent Manager], and withdrawal is as simple as giving consent. Withdrawal does not affect the lawfulness of prior processing.
7. DATA SHARING AND DISCLOSURE
We may share your data with processors and partners under written contracts requiring them to process data only per our instructions and maintain equivalent security safeguards, consistent with Section 8(2). We do not sell your personal data.
8. CROSS-BORDER TRANSFERS
We may transfer personal data outside India for processing, subject to Section 16 of the DPDP Act and any restrictions notified by the Central Government on transfers to specific countries or territories.
9. DATA RETENTION AND ERASURE
We retain personal data only as long as necessary for the stated purpose, or as required by law. Once the purpose is served and no legal retention obligation applies (including where you withdraw consent), we erase or anonymise your data in accordance with our Data Retention Policy.
10. SECURITY SAFEGUARDS
We implement reasonable security safeguards including encryption, access controls, activity logging (retained per DPDP Rules, 2025), and periodic security reviews to prevent personal data breaches, and we maintain an incident response process to intimate the Data Protection Board of India and affected Data Principals in the event of a breach, as required under Section 8(6).
11. CHILDREN'S DATA
Where we knowingly process data of children below 18 years, we obtain verifiable parental consent and do not undertake behavioural monitoring or targeted advertising directed at children, in accordance with Section 9.
12. YOUR RIGHTS
You have the right to: (a) obtain a summary of personal data processed and processing activities (Section 11); (b) seek correction, completion, updating, and erasure of your personal data (Section 12); (c) grievance redressal (Section 13); and (d) nominate another individual to exercise these rights on your behalf in the event of death or incapacity (Section 14).
13. YOUR DUTIES
Under Section 15, you are expected to provide accurate information, not impersonate another person, and not suppress material information when exercising your rights.
14. GRIEVANCE REDRESSAL
If you have a grievance regarding processing of your data, contact our Grievance Officer / Data Protection Officer at [Email Address]. We aim to respond within [X days]. If unresolved, you may approach the Data Protection Board of India.
15. CHANGES TO THIS POLICY
We may update this Policy periodically; material changes will be notified via [email/in-app notice] and the "Last Updated" date above.
Data Protection Officer / Grievance Officer: [Name]
Address: [Postal Address] | Email: [Email Address] | Phone: [Phone Number]This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.