DPDP Wiki Talk to us

/The Rules · 2025

Rule 3: Notice given by Data Fiduciary to Data Principal

DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) · rule 1(4)
Provision
Rule 3 of The Digital Personal Data Protection Rules, 2025
Status
Comes into force on 13 May 2027 (phase 3)
Made under
s. 5 Notice
Source
Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF

Rule 3. Notice given by Data Fiduciary to Data Principal

Verbatim from the Gazette of India

The notice given by the Data Fiduciary to the Data Principal shall—

(a)

be presented and be understandable independently of any other information that has been, is or may be made available by such Data Fiduciary;

(b)

give, in clear and plain language, a fair account of the details necessary to enable the Data Principal to give specific and informed consent for the processing of her personal data, which shall include, at the minimum, —

(i)

an itemised description of such personal data; and

(ii)

the specified purpose or purposes of, and specific description of the goods or services to be provided or uses to be enabled by, such processing; and

(c)

give, the particular communication link for accessing the website or app, or both, of such Data Fiduciary, and a description of other means, if any, using which such Data Principal may—

(i)

withdraw her consent, with the ease of doing so being comparable to that with which such consent was given;

(ii)

exercise her rights under the Act; and

(iii)

make a complaint to the Board.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryData PrincipalBoard

Rule 3 sets out how a Data Fiduciary (an entity determining the purpose and means of processing personal data) must present a notice to a Data Principal (the individual whose data is being processed) when asking for consent. The notice must stand on its own. It must be understandable without requiring the individual to read any other information that the Data Fiduciary has made available or might make available in the future.

The notice must use clear and plain language to give a fair account of what is needed for the individual to give specific and informed consent. At a minimum, this means the notice must include an itemized description of the personal data being collected. It must also state the specific purposes for processing the data and describe the exact goods, services, or uses that the processing will enable.

Finally, the notice must tell the individual how to manage their consent and rights. It must include a specific communication link to the Data Fiduciary's website or app, along with a description of any other available methods. Through these channels, the individual must be able to withdraw their consent just as easily as they gave it, exercise their rights under the Act, and make a complaint to the Board (the Data Protection Board of India).

Key points

  • The notice must be understandable on its own, without relying on other information provided by the Data Fiduciary (a).
  • It must use clear and plain language to help the Data Principal give specific and informed consent (b).
  • The notice must include an itemized description of the personal data to be processed (b)(i).
  • It must state the specific purposes of processing and describe the goods, services, or uses enabled by it (b)(ii).
  • The notice must provide a link to a website or app, and describe other means, for the Data Principal to withdraw consent, exercise rights, or complain to the Board (c).
  • The process to withdraw consent must be as easy as the process used to give it (c)(i).

Common misreadings

  • A Data Fiduciary cannot bury the notice details inside a larger privacy policy or terms of service, because the rule requires the notice to be understandable independently of any other information.
  • The notice cannot just state a general purpose; it must provide an itemized description of the data and a specific description of the goods or services provided.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.