Consentrio

DPDP consent notice checklist (Rule 3)

3 min read · Updated 30 September 2026

Every request for consent under India's DPDP Act, 2023 must come with a notice (Section 5). Rule 3 of the DPDP Rules, 2025 sets out what that notice must contain. Use this checklist to review each notice you show.

1. It stands on its own

  • The notice is presented separately and can be understood independently of any other information, not buried in terms and conditions or a long privacy policy.
  • It is written in clear and plain language.

2. It says what data and why

  • An itemised description of the personal data you will process, such as "full name, mobile number, date of birth", not "your information".
  • The specified purpose of processing.
  • An itemised description of the goods, services or uses that the processing enables.
  • Only the data necessary for that purpose (Section 6(1)).

3. It tells people how to act on their rights

  • A link on your website or app, and a description of any other means, through which the person can:
    • withdraw consent, as easily as they gave it;
    • exercise their rights: access, correction, completion, updating and erasure, grievance redressal and nomination;
    • make a complaint to the Data Protection Board of India.

4. It is in the right language

  • Available in English or any of the 22 languages in the Eighth Schedule of the Constitution (Section 6(3)), matching the languages your users actually read.
  • Translations are reviewed, not only machine-translated, and each translation is tied to the same notice version.

5. It is separate from the consent action

  • Consent is given through a clear affirmative action: an unticked box, an "I agree" button.
  • Separate purposes can be accepted separately, for example service delivery vs marketing.
  • Refusing optional purposes does not block the core service.

6. It is versioned and provable

The burden of proving that notice was given sits with the Data Fiduciary (Section 6(10)).

  • Every notice has a version, and published versions are never edited in place.
  • Each consent record stores which version the person saw, the language, the time and the channel.
  • When purposes change, a new version is published and affected users are asked again.
  • Records are tamper-evident, so an auditor can trust them.

7. Existing users are covered

  • Users whose data you processed before the Act took effect receive a notice as soon as reasonably practicable (Section 5(2)).

8. It works everywhere you collect data

  • Web signup, mobile apps, call-centre scripts, offline forms and partner channels all show the same notice version.
  • Cookie and tracking consent on your website follows the same rules.

How Consentrio helps

In Consentrio, a notice is built from your purpose library and data categories, so the itemised description is always accurate. Each notice is versioned, has translations tied to its version, and alerts you when a purpose changes after publishing. Every consent is stored against the exact notice version and language shown, in a hash-chained audit trail, and users can withdraw from the same preference centre where they manage their consents.

Related: DPDP Act consent requirements · DPDP Rules 2025 timeline

This guide is general information, not legal advice. Check the Act and the Rules, or ask your counsel, for decisions about your organisation.