GMax Mart
Home Services Pricing Portfolio FAQ Reviews Blog Support Careers Change Language

Website Content

Does your website need a privacy policy? India's DPDP Act explained

· 6 min read

Does your website need a privacy policy? India's DPDP Act explained

Owners of small business sites often assume data protection rules are aimed at banks and large apps. In practice, a simple enquiry form that captures a name, phone number and email is already collecting personal data, which is exactly what the law is concerned with. This article explains, in plain language, why a privacy policy for Indian websites matters, what the Digital Personal Data Protection Act, 2023 broadly expects, and where the line sits between general guidance and professional legal advice.

Nothing here is legal advice. It is a starting point so you can ask a qualified lawyer better questions and arrive with your homework done.

What counts as personal data on a small website

Personal data means information that can identify a living person. On an ordinary business site, that usually includes more than owners realise:

  • Names, phone numbers and email addresses from contact and enquiry forms
  • Delivery addresses and order history if you sell online
  • Newsletter subscriber lists
  • Job applications and attached CVs
  • Chat transcripts from WhatsApp or a website chat widget
  • Identifiers collected by analytics and advertising scripts
  • Information stored in server logs and backups

If your site touches any of these, it is processing personal data. The question is not whether the law applies in some abstract sense, but how carefully you handle what you already collect.

The DPDP Act in plain language

The Digital Personal Data Protection Act, 2023 is India's dedicated law for digital personal data. It replaces the patchwork approach that businesses previously relied on, where a published privacy policy was largely driven by the older information technology rules and by the expectations of payment gateways and app stores.

Two terms appear throughout. The organisation that decides why and how personal data is processed is the data fiduciary, which is your business. The individual whose data it is becomes the data principal, which is your customer, subscriber or applicant. The word fiduciary is deliberate: it frames the relationship as one of trust rather than ownership.

The Act broadly applies to digital personal data processed in India, and also to processing outside India that relates to offering goods or services to people in India. Implementation has been phased through subordinate rules, with different obligations expected to take effect over time, so confirm the current position with a lawyer before assuming a deadline has or has not passed.

The core ideas you should design your website around

Notice

People should be told, in clear language, what you are collecting, why you want it, and how they can exercise their rights or complain. A privacy policy is the usual way to deliver that notice, supported by a short line next to each form.

Consent and purpose

Consent should be free, specific, informed and unambiguous, given for a stated purpose. In website terms, that means no pre-ticked boxes, no bundling a marketing sign-up into a service enquiry, and no quietly using a support email for promotional campaigns later.

Data minimisation

Collect only what you need for the stated purpose. A quote form rarely needs a date of birth, and a newsletter never needs a postal address.

Accuracy and retention

Keep records reasonably accurate, and do not hold personal data indefinitely once the purpose is over. Many small businesses store years of form submissions in an old inbox without ever deciding how long they should be kept.

Security

Take reasonable safeguards to protect the data you hold. For most sites that means HTTPS, strong and unique admin passwords, limited user accounts, updated software and encrypted or access-controlled backups.

Rights of the individual

Broadly, people can ask what data you hold about them, ask for corrections, ask for erasure where the purpose has ended, and raise a grievance. Your policy should give a working contact route for such requests, and someone in the business should actually watch that inbox.

Children, consent and specific situations

The law treats children's data more strictly, and processing data of a child generally requires verifiable parental consent, with limits on tracking and targeted advertising towards children. If your site serves schools, coaching classes, paediatric clinics or children's products, treat this as a point to raise with your lawyer rather than something to interpret yourself.

Similar caution applies if you process health information, financial details, biometric data or large volumes of customer records, or if you transfer data to vendors outside India. These situations change the analysis and deserve proper advice.

Practical steps to take on your own site

  1. List every form, script and integration on your site, and note exactly what each one collects.
  2. Note where that data ends up: an email inbox, a CRM, a spreadsheet, a courier partner, an analytics account.
  3. Delete anything you do not need, including old form plugins and unused tracking scripts.
  4. Write or update your privacy policy so it matches this real list, not a template's guesses.
  5. Add a short consent line beside each form, linking to the policy, with any marketing opt-in as a separate unticked box.
  6. Decide a retention period for each type of record and apply it.
  7. Name a person responsible for privacy queries and publish a way to reach them.
  8. Tighten security basics: HTTPS everywhere, updated software, restricted admin access, tested backups.
  9. Have a lawyer review the final policy against how your business actually operates.

Steps one and two are the most valuable and the most often skipped. A policy written without them tends to describe a business that does not exist.

Where to start this week

Begin with the data map. Open your website, list every place a visitor can type something, and follow each one to its destination. That single exercise usually reveals a forgotten plugin, an abandoned mailing list or a tracking script nobody remembers adding. Once the map is honest, drafting an accurate policy becomes straightforward, and a lawyer's time is spent reviewing rather than interviewing you.

If the technical side needs attention, such as replacing insecure forms or moving to HTTPS on a properly configured server, our team handles that as part of website development and maintenance, and you can ask specific questions through our experts.

Frequently asked questions

Does a website with no forms still need a privacy policy?

Often yes, because analytics, embedded videos, chat widgets and server logs can still collect data. A purely static page with no scripts is the rare exception, and even then a short statement reassures visitors.

Can I copy a privacy policy from another website?

It is a poor idea. A copied policy describes another company's data practices, may be copyright protected, and can be inaccurate for you. Use a template only as a structure, fill it with your own facts, and have it reviewed.

Is a privacy policy the same as a cookie banner?

No. The policy explains your overall data handling; a cookie or consent notice deals with what tracking runs in the visitor's browser. Sites that use analytics or advertising scripts usually need both.

Who should I ask for definitive answers about the DPDP Act?

A qualified lawyer or data protection professional familiar with Indian technology law. Requirements, timelines and subordinate rules evolve, so a current professional opinion is worth more than any article, including this one.

Thinking about a website?

See what a package covers and what it costs, or ask us about your own project.

Read next

Thinking…