Privacy Policy & Terms and Conditions Drafting
Every website or app that collects names, phone numbers or payments needs a privacy policy and terms of use that match how it actually works. Our privacy policy drafting covers both under Indian law: the IT Act and SPDI Rules today, and the Digital Personal Data Protection Act, 2023, whose main duties start on 13 May 2027.
What it is
A privacy policy tells visitors what personal data you collect, why, who you share it with and how they can ask questions or complain. Terms and conditions, or terms of use, set the rules for using your site or app: who may use it, how orders and payments work, refunds, liability and how disputes are settled.
Two sets of rules apply in India right now. Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 requires a body corporate to publish a privacy policy on its website. The Digital Personal Data Protection Rules, 2025, notified on 13 November 2025, bring stricter notice and consent duties under the DPDP Act from 13 May 2027, when Section 43A of the IT Act is also omitted.
Who it applies to
You sell online
Anyone selling goods or services online. The Consumer Protection (E-Commerce) Rules, 2020 add display and grievance duties on top of privacy law, alongside GST registration for selling online.
You run an app or SaaS product
Mobile apps, software platforms and portals that create user accounts, store customer data or process it for business clients.
Your website has an enquiry form
Think of a Faridabad coaching institute whose admission form collects students’ names, phone numbers and parents’ details. That is personal data, some of it about children.
Why it matters
Meets the law today and in 2027
SPDI Rule 4 requires a published privacy policy today. From 13 May 2027, the DPDP Rules require a clear notice before consent is taken.
Keeps large penalties away
Under the DPDP Act, failing to take reasonable security safeguards can attract a penalty of up to ₹250 crore, and failing to report a breach up to ₹200 crore. Rule 8(2) of the SPDI Rules names ISO 27001 certification as one standard for reasonable security practices.
Earns customer trust
A clear policy answers the first question a careful buyer asks: what happens to my phone number and card details?
Documents required
About your business
- Legal name, registered address and contact details
- Website or app URL
- Name and contact of the grievance officer
About the data
- Forms, sign-up fields and what each field collects
- Payment gateway, analytics, CRM and hosting providers
- Whether children use the service
- Where data is stored and for how long
About your terms
- Pricing, delivery, cancellation and refund practice
- Subscription or auto-renewal terms
- City you want disputes to be heard in
What the documents cover
| Document | Key contents | Main legal hook |
|---|---|---|
| Privacy policy | Data collected, purpose, sharing, security, retention, rights, grievance officer | SPDI Rules 4 and 5; DPDP Act and Rules |
| Consent notice | Itemised data, specific purpose, how to withdraw consent, how to complain to the Board | DPDP Rules, Rule 3 |
| Terms of use | Eligibility, accounts, payments, IP, liability, termination, governing law | Indian Contract Act, 1872; IT Act, 2000 |
| Refund and shipping policy | Return, refund, cancellation and delivery terms | Consumer Protection (E-Commerce) Rules, 2020 |
How it works
Map every form and tool
Privacy policy drafting starts with your real data flow. We go through your site or app with you: every form, cookie, third-party tool and payment flow, and where the data ends up.
Get plain-English drafts
We draft the privacy policy, terms of use and refund policy in plain English, matched to what your business actually does.
Check them against your operations
You check the drafts against your operations, and we revise. Your developer then adds consent checkboxes where the law needs them.
Publish and keep them current
You publish the pages and link them in the footer and at sign-up. We update them when your features or the law change.
Timelines
In force now
SPDI Rule 4 privacy policy and a grievance officer under Rule 5(9), who must address grievances within one month.
13 November 2026
Registration of consent managers with the Data Protection Board begins under the DPDP Rules.
13 May 2027
Data fiduciary duties start: notice under Rule 3, consent, security safeguards, breach reporting and grievance replies within 90 days.
What happens if your policies are missing or wrong
Exposure under the IT Act
Until 13 May 2027, Section 43A lets a person claim compensation from a body corporate that is negligent with sensitive personal data and causes wrongful loss.
DPDP penalties from 2027
The Data Protection Board can impose penalties up to ₹250 crore for security failures, with other breaches carrying their own limits under the Schedule to the Act.
Weak ground in a dispute
Here is the catch: copied terms that do not match your refund practice or chosen city leave you with little to rely on when a customer complains.
Frequently asked questions
Is a privacy policy mandatory for a website in India?
Yes, if your business collects personal information. Rule 4 of the SPDI Rules, 2011 requires a body corporate to publish a privacy policy on its website, stating the type and purpose of information collected and the security practices followed. From 13 May 2027, the DPDP Rules also require a clear notice before consent. A short, accurate policy published now covers both. We check the dates against the Gazette notifications before we finalise the draft.
When does the DPDP Act actually apply to my business?
The main duties start on 13 May 2027. The DPDP Rules, 2025 were notified on 13 November 2025 and phased in. The Data Protection Board provisions started at once, consent manager registration starts on 13 November 2026, and notice, consent, security and grievance duties apply from 13 May 2027. Use the time to fix your forms and policies.
Can I copy a privacy policy from another website?
No, and you should not. Good privacy policy drafting starts from your own data, because a copied policy describes someone else’s data, tools and refund practice, and may infringe their copyright too. If your policy says one thing and your app does another, the policy becomes evidence against you. Under the DPDP Rules, a notice must list the specific personal data and purposes of your own processing. We draft from your actual forms and tools.
What must a DPDP consent notice contain?
Rule 3 of the DPDP Rules, 2025 requires the notice to stand on its own and be clear. It must give an itemised description of the personal data, the specified purpose and the goods or services it enables. It must also explain how to withdraw consent, as easily as it was given, how to exercise rights and how to complain to the Data Protection Board. We draft it in that order.
Do I need a grievance officer?
Yes, in most cases. Rule 5(9) of the SPDI Rules requires a grievance officer whose details are on the website, with grievances addressed within one month. E-commerce entities must also display the officer’s name, contact details and designation, and acknowledge complaints within 48 hours under Rule 4 of the E-Commerce Rules, 2020. Name one person and publish their email address.
Are click-to-accept terms and conditions legally valid?
Yes. Section 10A of the IT Act, 2000 says a contract is not unenforceable only because it was formed electronically. The usual tests of Section 10 of the Indian Contract Act still apply: free consent, lawful consideration and lawful object. Show the terms clearly and record the user’s acceptance with a checkbox, not just a footer link. That record is what you rely on if a dispute arises.
What extra rules apply to an online store?
The Consumer Protection (E-Commerce) Rules, 2020 apply. Rule 4 requires you to show your legal name, address, website and customer care details, appoint a grievance officer, acknowledge complaints within 48 hours and resolve them within one month. Spell out return, refund and cancellation terms plainly. We draft the terms and refund policy together so they never contradict each other.
Does my app need special terms if children use it?
Yes. Under the DPDP Act and Rules, you need verifiable consent of a parent before processing a child’s personal data. The Rules allow verification through reliable identity details or a Digital Locker service provider. Schools, coaching apps and gaming platforms must plan for this before 13 May 2027. We draft the notice and list the product changes your team will need.
How often should we update our policies?
Whenever your data use changes, and at least once a year. Say a Delhi clothing brand adds a WhatsApp marketing tool mid-year. Customer numbers now reach a new processor, so the policy must say so. The DPDP phase starting 13 May 2027 is a fixed date to plan around. We keep a version history and update the pages for you, so the live text always matches your product.
What it costs
Our fee plus the government fee that applies to your case, quoted before you commit. Tell us the situation and we will price it exactly.
There is no government fee for publishing a privacy policy or terms of use.
Ready to begin?
Send us your website or app link, and we will draft a privacy policy and terms that match how your business really runs.