The Privacy Policy You Never Read Is Now a Legal Notice - Here's What to Actually Look For

Nobody reads privacy policies. Studies have estimated that reading every privacy policy of every service you use in a year would take over 200 hours. So people do not read them. They scroll to the bottom, tick the box, and get on with their lives.

India’s Digital Personal Data Protection Act, 2023 has not solved the problem of privacy policies being too long and too confusing to read. But it has changed what those documents must contain, what organisations are legally required to tell you, and what you can do when they fail to tell you the truth. The privacy policy is now a legal notice under Indian law. And knowing what to look for in it could protect your data in ways you never thought a scrolled-past document could.

What the DPDPA Requires in a Privacy Notice

Section 5 of the DPDPA specifies what every Data Fiduciary must tell you before or at the time of collecting your personal data. This is not optional. It is a legal requirement. And the notice must be in clear and plain language that you can actually understand.

The notice must tell you what personal data is being collected. It must tell you the specific purpose for which it is being collected. It must explain how you can exercise your rights under the Act, including how to access your data, correct it, withdraw consent, and file a complaint. And it must tell you how to contact the organisation’s designated data protection contact.

If a privacy policy you are reading does not contain all of these elements, the organisation is not compliant with the DPDPA. That is worth knowing.

What to Look for in Any Privacy Policy

Most people who do read privacy policies do not know what they are looking for. Here is a practical guide to the things that matter most under the DPDPA and what the answers should look like.

The first thing to look for is specificity of purpose. The policy should tell you specifically why your data is being collected, not in vague terms like “to provide and improve our services” but in concrete terms that describe actual processing activities. If the stated purposes are so broad that almost anything could fall within them, that is a red flag.

The second thing to look for is a clear list of data categories. The policy should tell you exactly what types of personal data are collected. Name, email, phone number, location, payment details, device identifiers. If the policy uses catch-all language like “information you provide to us” without specifying what that means, it is hiding the extent of collection.

The third thing to look for is third-party sharing. Who does the organisation share your data with? The policy should name or at least categorise the third parties involved, and it should explain what data is shared and for what purpose. A policy that says “we may share your data with our partners and affiliates” without further detail is not compliant with the DPDPA’s informed consent standard.

The fourth thing to look for is retention periods. How long does the organisation keep your data? The policy should specify retention periods for different categories of data, or at least the criteria used to determine how long data is kept. “We keep your data as long as necessary” is not a specific retention period.

The fifth thing to look for is your rights. The policy must explain how to access your data, how to correct inaccurate information, how to withdraw consent, and how to file a complaint. If there is no clear section on your rights as a data principal under the DPDPA, the policy is non-compliant.

The Red Flags That Should Concern You

Beyond what must be present, there are patterns in privacy policies that should raise concern about how an organisation is actually handling your data.

Extremely broad consent language is a major red flag. If a policy asks you to consent to data processing for purposes including “research, analytics, product development, marketing, business development, and any other purposes we determine from time to time,” you are being asked to give a blank cheque. The DPDPA requires specific consent for specific purposes. A catch-all consent request of this kind does not meet that standard.

Automatic consent through continued use is another red flag. Language like “by continuing to use our service after this notice, you consent to the processing described herein” does not obtain valid consent under the DPDPA. Consent requires an affirmative action, not passive continuation.

No withdrawal mechanism is a significant red flag. If the policy does not tell you how to withdraw consent for data processing, the organisation is not meeting its obligations under the Act. You have the right to withdraw consent, and the mechanism must be accessible.

Data sharing with unnamed third parties is concerning. If the policy refers to sharing with “advertising partners,” “business partners,” or “third parties” without naming them or providing a way to find out who they are, you do not have enough information to make an informed decision about whether to use the service.

What You Can Do When a Privacy Policy Fails the DPDPA Test

The DPDPA gives you, as a data principal, specific remedies when an organisation fails to meet its obligations. You have the right to file a complaint with the Data Protection Board of India if you believe your personal data rights have been violated.

Before filing a formal complaint, you have the right to raise a grievance directly with the organisation. The DPDPA requires that organisations have a grievance mechanism and respond to complaints within a reasonable timeframe. If the organisation fails to respond adequately, you can escalate to the Board.

You also have the right to request access to your personal data, to correct inaccurate data, and to request deletion of data that is being held without a legitimate purpose. These rights can be exercised at any time, independently of whether you have a specific complaint about how your data has been handled.

What Good Privacy Notice Practice Looks Like

For organisations reading this blog, the practical question is what a genuinely compliant privacy notice looks like. It is shorter than most current privacy policies. It is structured so that the most important information appears first, in plain language, at the point of data collection. It uses a layered approach, with a brief summary at the top that covers what users need to know to make a decision, linking to a more detailed document for users who want the full picture.

It names specific purposes, names or categorises third-party recipients, specifies retention periods, explains rights clearly, and provides a working contact mechanism for rights requests and complaints. It is reviewed and updated whenever data practices change. And it is written by someone who prioritises user understanding over legal protection.

How ComplyPlanet Helps

ComplyPlanet helps Indian organisations audit their existing privacy notices against the DPDPA’s requirements and rewrite them to meet the standard the law demands and that users deserve.

We review your current notice against every DPDPA requirement, identify specific gaps in content, specificity, and language, and produce a rewritten notice that is both legally compliant and genuinely readable. We also help you design the layered notice structure that works at your specific data collection touchpoints, and build the review process that keeps your notice accurate as your practices evolve.

Conclusion

The privacy policy you scroll past is now a legal document that determines what an organisation can lawfully do with your data. Knowing what it must contain, recognising when it falls short, and understanding what you can do about it puts you in control of your data in a way that was not possible before the DPDPA. Read the notice. Know your rights. Use them.

ComplyPlanet helps organisations build privacy notices that are genuinely compliant and genuinely readable. Contact us today.

ComplyPlanet – Your Compliance Backbone