The 8 Common Mistakes in Indian D2C Privacy Policies (and the DPDP Sections They Break)

24 Jul 2026 9 min read Admin
The 8 Common Mistakes in Indian D2C Privacy Policies (and the DPDP Sections They Break)

Try this quick experiment tonight. Pick ten Indian D2C brands you've bought from- skincare, protein powder, kids' clothes, anything you use. Go to their

Try this quick experiment tonight.

Pick ten Indian D2C brands you've bought from- skincare, protein powder, kids' clothes, anything you use. Go to their websites, scroll down to the privacy policy, and really read it.

This is my job, and I see the same eight mistakes over and over. These aren't minor wording problems; they're real conflicts with the DPDP Act, 2023, and the DPDP Rules, 2025.

Most of these policies were written years ago, probably copied from a template late at night before launch. Since then, no one has updated them. That was fine under the old rules, since they were rarely enforced.

But those days are gone. I'll explain why, and then go through the eight mistakes one at a time.

Why 2026 is when this gets real

The DPDP Act passed in August 2023. For two years, founders mostly ignored it—and that made sense. Without Rules, the Act couldn't really be enforced.

That changed on 14 November 2025, when MeitY announced the Digital Personal Data Protection Rules, 2025. The Rules set a phased schedule. Some parts started right away, including the Data Protection Board of India, which is now active. Consent Manager registration starts in November 2026, and full compliance is needed by 13 May 2027.

The penalties are listed in the Act's Schedule, and they're not minor:

Failure

Maximum penalty

Not maintaining reasonable security safeguards, Section 8(5)

₹250 crore

Not notifying a data breach, Section 8(6)

₹200 crore

Violating children's data obligations, Section 9

₹200 crore

Other violations of the Act

₹50 crore

If you run a D2C brand, this is your last easy window to fix things. Do it now, and it's a small project. Wait until a complaint hits the Board, and it becomes an emergency with a penalty.

Let's look at the eight mistakes.

Mistake 1: the policy still lives in the SPDI era

Open a typical D2C policy, and you will find this line, or something like it: "We comply with the Information Technology Act, 2000 and the SPDI Rules, 2011"

That was the right reference ten years ago, but it's no longer the main law. Once the DPDP rules fully apply, the SPDI Rules are basically replaced for personal data processing.

If your policy doesn't mention the DPDP Act, it shows no one has checked data compliance since 2023. If the Board asks to see your compliance, a policy stuck in 2019 will be used against you.

The fix: rebuild your policy based on the DPDP Act and 2025 Rules. Don't just add a sentence to an old SPDI template.

Mistake 2: the CCPA copy-paste special

You can spot these right away: an Indian brand, selling only in India, pricing in rupees, but the policy says "California residents may exercise their rights under the CCPA." Some even offer "your GDPR right" to users in Gurgaon. I’ve even seen policies that send disputes to foreign law, just because the template came from a US website builder and no one updated it. Here’s the truth: using a GDPR or CCPA template doesn't make you DPDP compliant. The laws may look similar, but the consent rules, notice requirements, grievance process, and penalties are all different. Copy-paste complianceisn'tt real compliance; it's just for show.

The fix: remove foreign law references unless you actually serve those markets. Even then, make sure the India section comes first.

Mistake 3: "By using this website, you agree"

This is the most common consent line on Indian websites, but under DPDP, it means nothing.

Section 6(1) of the Act says consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action. Browsing a website is not a clear affirmative action. Silence is not consent. A pre-ticked box is not consent.

Rule 3 of the 2025 Rules says the notice must be clear, easy to understand, and list what data is collected and why. So a vague line like "we collect your information to improve our service" doesn’t work either.

The fix: create a real consent step. Show a clear notice, let users tick or untick a box, or click a button, and keep a record of their action.

Mistake 4: no grievance officer, no contact, no door to knock on

Section 8(10) of the Act requires every Data Fiduciary to have a grievance redressal mechanism. Section 13 gives users the right to use it. The Rules require you to publish the business contact of the person who can answer data questions, and Rule 13 expects you to state the timeframe within which grievances will be handled.

Now open those ten policies again and look for a named contact for data complaints. In many, you will find nothing. Not an email, not a form. In others, you will find a generic support address that, if you actually test it, sometimes bounces.

Imagine how that looks to a regulator. The law gives your customers a right, but your website gives them no way to use it.

The fix: add a working, monitored email for data complaints in your policy, and say how quickly you’ll respond. This is honestly the easiest fix here.

Mistake 5: "We retain your data as long as necessary"

This is just keeping data forever, but saying it nicely.

The Act runs on purpose limitation. Section 8(7) requires erasure once the purpose is served and retention is no longer necessary, unless a law requires keeping it. The 2025 Rules go further for larger platforms: under Rule 8, specified classes of e-commerce, online gaming and social media businesses must erase data after three years of user inactivity, with a 48-hour advance notice to the user before deletion"

"As long as necessary for business purposes," without a clear purpose or timeline, isn’t a real retention policy. It’s just vague legal wording.

The fix: add a real retention table. List the data, the purpose, how long you keep it, and when you delete it. Even a basic table puts you ahead of most others.

Mistake 6: data shared with "trusted partners and affiliates"

This phrase should make customers uneasy and founders even more concerned.

Your customer data flows to the shipping partner, the payment gateway, the marketing tools, the analytics scripts, the WhatsApp API provider. Under the Act, you are the Data Fiduciary; they are Data Processors under Section 2, and Section 8(2) makes clear that the processing happens under a valid contract. The responsibility stays with you.

If your policy hides everything "behind "trusted third parties," it probably means you haven’t mapped your data flows. And if you can’t map your data flows, you can’t answer the first question in any breach investigation: who had access?

The fix: list the types of recipients and why you share data with them. For example, courier partners for delivery, payment processors for transactions, analytics providers for usage stats. Be specific enough that readers actually learn something.

Mistake 7: selling to children, pretending they do not exist

If your brand sells toys, schoolkids' clothes, kids’ clothes, or anything for minors, pay extra attention here.

Section 9 of the Act requires verifiable consent of a parent or lawful guardian before processing the personal data of anyone under 18. It also bans tracking, behavioural monitoring, and targeted advertising directed at children. Rule 10 of the 2025 Rules describes how that verification is expected to work, using reliable identity and age details or a virtual token.

Now look at the policies of kids’ brands. Most don’t mention children at all: no age check at signup, no parental consent process, nothing. But the penalty for Section 9 violations can reach ₹200 crore, some of the toughest in the Act.

The fix: if minors could be your users or customers, you need a real age and parental-consent process, not just a policy paragraph. This is a product change, and it’s the most urgent fix here.

Mistake 8: one click to give consent, an obstacle course to take it back

Giving consent takes one tap. But to withdraw it, users have to email support, wait, follow up, and hope for a response.

Section 6(4) of the Act is direct: the ease of withdrawing consent must be comparable to the ease with which it was given. One click in, one click out. On withdrawal, Section 6(6) expects processing to stop and data to go, within a reasonable time, unless another law requires retention.

Most policies fail here by simply not mentioning withdrawal, as if consent is a one-way street.

The fix: add a clear unsubscribe and consent-withdrawal option, and explain in your policy exactly how it works.

The 10-minute self-check

You don’t need a lawyer to spot the obvious gaps. Open your own policy and answer honestly:

1. Does it mention the DPDP Act, 2023 anywhere?

2. Does it talk about American or EU law more than Indian law?

3. Does consent depend on "by using this site you agree"?

4. Is there a named, working contact for data complaints, with a response timeline?

5. Does it say what data you keep, for what purpose, for how long?

6. Does it name the categories of parties you share with, and why?

7. If children can be your customers, is there a verifiable parental consent process?

8. Can a user withdraw consent as easily as they gave it?

Three or more wrong answers means your policy belongs to a previous era of Indian law. You have time to fix it. Just not unlimited time. The clock stops on 13 May 2027, and there is even a live proposal from MeitY's January 2026 consultation to compress the timeline further, though it has not been notified yet.

One last thing

A privacy policy is just the visible 10 percent of DPDP compliance. Updating the document without fixing your data practices is like repainting a car with a broken engine. Still, the policy is where everyone can see if your company has thought about any of this.

Right now, most have not. Which also means the brands that get this right in 2026 will hold something genuinely rare: proof, visible to customers, investors, and eventually the Board, that they take their users' data seriously.

Run the ten-policy experiment. Then run it on your own website. That second one is the read that matters.


This article is for general educational purposes only and does not constitute legal advice. Reading it does not create an advocate-client relationship. References: Digital Personal Data Protection Act, 2023; Digital Personal Data Protection Rules, 2025 (notified 14 November 2025); position stated as of July 2026.

← Back to all articles

Have a legal question?

These articles are for awareness. For advice specific to your situation, start a conversation.

Request a Consultation