Last updated on August 5th, 2026 at 08:05 am
TL;DR: A privacy policy is a legal document that tells users what personal data you collect, why you collect it, how you use and store it, who you share it with, and what rights they have over it. In India it is mandatory under the Digital Personal Data Protection Act, 2023. Globally, GDPR, CCPA, and dozens of similar laws require one for any website or app that collects personal data. A missing or stale privacy policy is not just a compliance gap: it is a regulatory risk, a reputational problem, and increasingly a dealbreaker for enterprise customers and app stores. This guide explains what a privacy policy is, what it must contain under Indian and global law in 2026, and how it fits with your other website legal documents.
Quick overview: Most businesses treat a privacy policy as something to copy and paste and forget. That approach has always been risky and in 2026 it is actively dangerous. India’s DPDP Act 2023 came fully into operation and imposed real duties on data fiduciaries, the entities that decide how personal data is processed. GDPR enforcement keeps hitting record fines. AI tools that process user data are under new scrutiny. App stores reject apps without compliant policies. This guide gives you a clear, current picture of what a privacy policy is, what it must say, and what happens if you get it wrong.
What is a privacy policy?
A privacy policy is a legal document in which an organisation tells the people whose data it collects exactly what it does with that data. It is a transparency obligation: the organisation discloses what it collects, why, how long it keeps it, who it shares it with, and what rights the individual has over their own information.
The term comes from the idea of a stated policy on privacy, a public commitment to how personal information will be handled. In practice a privacy policy is both a compliance document (it satisfies legal requirements) and a trust signal (it tells users whether your organisation can be trusted with their data).
A privacy policy is not the same as a disclaimer, which limits liability for content, or terms and conditions, which govern use of your service. Each does a different legal job, and most websites and apps need all three. For a complete view of which documents your website legally cannot do without, see our guide on legal documents your website cannot ignore.
Is a privacy policy legally required in India?
Yes. Under the Digital Personal Data Protection Act, 2023 (DPDP Act), every data fiduciary, meaning any person or organisation that determines the purpose and means of processing personal data, must provide a clear and accessible notice to data principals (the individuals whose data is collected) about what data is collected and for what purpose. That notice, in practice, is your privacy policy.
The DPDP Act is India’s first comprehensive data-protection statute. It imposes duties on data fiduciaries that include obtaining valid consent before processing personal data (except in certain legitimate-use cases), giving data principals the right to access, correct, and erase their data, reporting data breaches to the Data Protection Board within 72 hours, and appointing a Data Protection Officer where required. A privacy policy that was written before the DPDP Act came into force is almost certainly non-compliant with these duties and needs updating.
Beyond the DPDP Act, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 under the IT Act 2000 still apply in certain respects. These rules require a published privacy policy for any body corporate that collects sensitive personal data.
For the full picture of what the DPDP Act requires and how consent must be managed, see our in-depth guides on the DPDP Act and its implications and consent management under the DPDP Act.
Is a privacy policy required globally?
Yes, across most of the world, if you collect personal data from users in that jurisdiction.
GDPR (EU/EEA): The General Data Protection Regulation requires a privacy notice (the GDPR term for a privacy policy) for any organisation processing personal data of people in the EU, regardless of where the organisation is based. The information must be provided at the time of collection, in clear and plain language, and must cover the legal basis for processing, retention periods, data-subject rights, and whether data is transferred outside the EU. Fines under GDPR can reach 4% of global annual turnover or 20 million euros, whichever is higher.
CCPA (California, USA): The California Consumer Privacy Act requires businesses that collect personal information of California residents to disclose their data practices, give consumers the right to know, delete, and opt out of sale, and not discriminate against consumers who exercise their rights. The CPRA (its 2023 update) added new rights around sensitive personal information.
Other jurisdictions: Brazil’s LGPD, Canada’s PIPEDA (and its upcoming replacement), Australia’s Privacy Act, Singapore’s PDPA, and the UAE’s PDPL all impose privacy-notice requirements. If your platform or website has international users, those international legal obligations include having a privacy policy that meets each relevant standard.
What must a privacy policy contain?
The exact contents vary by jurisdiction and by what your organisation actually does with data, but these are the elements that a comprehensive 2026 privacy policy must address.
Who you are. The identity and contact details of the organisation collecting the data, and, under GDPR and the DPDP Act where required, the contact details of the Data Protection Officer.
What data you collect. A clear description of the personal data collected, broken down by category: contact information, device data, usage data, location data, financial information, and any sensitive categories (health, biometric, caste, religion, political opinion), which attract higher protection under most laws.
Why you collect it and the legal basis. The purpose of collection and, under GDPR, the legal basis: consent, contract, legal obligation, legitimate interests, or vital interests. Under the DPDP Act, the purpose must be stated in the consent notice and must be specific.
How long you keep it. Retention periods, or the criteria used to determine them, because keeping data indefinitely is not permitted under any modern data-protection law.
Who you share it with. Third parties who receive the data, including cloud providers, analytics services, payment processors, marketing platforms, and any AI tools that process user data on your behalf. Under the DPDP Act these are called data processors, and you are responsible for their compliance.
User rights. What rights individuals have over their data and how to exercise them. Under the DPDP Act these include the right to access information about processing, the right to correction and erasure, and the right to withdraw consent. Under GDPR they extend further to include portability and the right to object.
Cookies and tracking. Whether you use cookies, tracking pixels, or similar technologies, what they do, and how users can manage them. For Indian websites the cookie compliance picture intersects with the DPDP Act consent requirements.
International data transfers. If personal data is transferred outside India or the EU, the safeguards in place for that transfer.
How to contact you and make complaints. A contact point for privacy queries and complaints, and information about the relevant supervisory authority.
What changed in 2026: the key updates every privacy policy needs
Several developments in 2025-2026 mean that a privacy policy written even two years ago is likely out of date.
DPDP Act enforcement. India’s Data Protection Board became operational and began processing complaints. The 72-hour breach-notification duty is now active. Data fiduciaries who have not updated their privacy policies to reflect DPDP Act requirements are exposed.
AI data processing disclosures. If your product or website uses AI tools that process user data, including large language models, AI assistants, or automated decision-making systems, your privacy policy must disclose this. Regulators in the EU (under the AI Act and GDPR), India (under the DPDP Act’s purpose-specification requirement), and the US (under FTC guidance) are all asking whether users know their data is being fed into AI systems. A privacy policy that does not mention AI processing is increasingly inadequate. See our guide on AI vendor contracts for the contractual side of this.
Automated decision-making. Where an AI or algorithm makes decisions about users that have significant effects, employment screening, credit scoring, content moderation, the GDPR requires disclosure and, in some cases, the right to human review. Similar principles are emerging in India’s DPDP framework.
App store requirements. Both the Apple App Store and Google Play now require apps to provide accurate privacy nutrition labels and policies. A mismatch between your actual data practices and your privacy policy is an enforcement risk from the store as well as from regulators.
Children’s data. The DPDP Act has strict provisions on processing data of children under 18, requiring verifiable parental consent. If any part of your service might be used by minors, your privacy policy must address this, and your consent mechanisms must be designed for it.
Privacy policy vs data processing agreement: what is the difference?
A privacy policy is directed at end users: it tells them how their data is handled. A data processing agreement (DPA) is a contract between two businesses: the data controller (you) and a data processor (a vendor or service provider) who processes data on your behalf. Under GDPR, a DPA is legally required whenever you use a third-party processor. Under the DPDP Act, similar contractual obligations apply to data processors.
If your business uses cloud services, CRMs, email marketing platforms, or any AI tool that touches user data, you likely need both a privacy policy and DPAs with each processor. Our data processing agreement template covers the standard requirements.
How a privacy policy fits with your other website legal documents
A privacy policy is one part of a set of documents that together govern how your website or product operates legally. The others are:
Terms and conditions govern the contract between you and your users: what they can do on your site, intellectual property, payment terms, and what happens on breach.
A disclaimer limits your liability for the accuracy of your content and the outcomes of using your service.
A cookie notice or banner handles consent for non-essential cookies and tracking technologies, which is a separate requirement from the privacy policy itself.
An acceptable use policy sets out what users can and cannot do on your platform, which is increasingly important for platforms, SaaS products, and AI tools.
For SaaS businesses the documentation set is wider still, and our guide on legal documents every SaaS startup needs maps it out. For startups broadly, the legal compliance checklist for startups in India covers privacy policy requirements alongside company, tax, and employment compliance.
What happens if you do not have a privacy policy?
The consequences are real and getting more serious.
Under the DPDP Act, failure to comply with notice and consent requirements can attract penalties up to Rs 250 crore for significant breaches of obligations. The Data Protection Board can investigate complaints and impose financial penalties.
Under GDPR, fines of up to 4% of global annual turnover have been issued to businesses of all sizes. Small businesses have been fined tens of thousands of euros for basic non-compliance.
Beyond fines, enterprise customers routinely ask for your privacy policy and data-processing practices as part of vendor due diligence. A missing or outdated policy can cost you a contract. App stores, payment processors, and advertising platforms increasingly require compliant privacy policies as a condition of access.
Frequently asked questions
What is a privacy policy?
A privacy policy is a legal document that tells users what personal data a website, app, or business collects from them, why it is collected, how it is used and stored, who it is shared with, and what rights users have over their data. It is required by law in India under the DPDP Act 2023, in the EU under GDPR, in California under CCPA, and under similar laws in most major jurisdictions worldwide.
Is a privacy policy mandatory in India?
Yes. The Digital Personal Data Protection Act, 2023 requires every data fiduciary to provide a clear notice about data collection and purpose, which in practice means a privacy policy. The IT (SPDI) Rules 2011 under the IT Act 2000 also require a published privacy policy for organisations collecting sensitive personal data. A privacy policy is not optional for any Indian website or app that collects personal data.
What must a privacy policy include?
A privacy policy must cover: who you are and how to contact you, what personal data you collect, why you collect it and the legal basis, how long you keep it, who you share it with (including third-party processors and AI tools), what rights users have over their data, how cookies and tracking work, how international data transfers are handled, and how to make a complaint. The exact requirements vary by jurisdiction, but these are the core elements common to the DPDP Act, GDPR, and CCPA.
What is the difference between a privacy policy and terms and conditions?
A privacy policy tells users how their personal data is collected and handled. Terms and conditions are the contract between you and your users, governing how the service can be used, intellectual property, payments, and what happens on breach. A privacy policy and terms and conditions do different legal jobs and both are needed: one does not substitute for the other.
Does a privacy policy need to mention AI tools?
Yes, in 2026 it should. If your product or website uses AI tools that process user data, including AI assistants, large language models, or automated decision-making systems, your privacy policy must disclose this, identify what data is involved, and explain the purpose. GDPR, the DPDP Act’s purpose-specification requirement, and FTC guidance all point in this direction. Failing to disclose AI data processing is an increasing enforcement risk.
How often should a privacy policy be updated?
Whenever your data practices materially change, whenever the law changes in a way that affects your obligations, and at least once a year as a review. The DPDP Act 2023 made many pre-2024 Indian privacy policies non-compliant. A policy last updated before the DPDP Act came into force almost certainly needs revising.
What is the penalty for not having a privacy policy in India?
Under the DPDP Act 2023, penalties for failure to comply with notice and consent obligations can reach up to Rs 250 crore for significant breaches, imposed by the Data Protection Board of India after investigation. Under GDPR, fines reach 4% of global annual turnover. Beyond regulatory fines, a missing policy can result in rejection by app stores, loss of enterprise contracts, and reputational damage.
Authored and reviewed by Prakhar Rai, Advocate, founder of My Legal Pal. Prakhar is enrolled with the Bar Council of India and has over ten years of experience advising businesses and founders on data protection, contracts, and commercial compliance. He is an alumnus of the National Law School of India University, Bangalore, where he completed his Master of Business Laws, and of La Martiniere. Connect on LinkedIn.
This article is general information, not legal advice. Privacy law varies by jurisdiction and by the specific nature of your business and data practices, and the position changes frequently. For advice on your own privacy policy, speak to a qualified lawyer. For India’s primary legislation, see the Digital Personal Data Protection Act 2023 at indiacode.nic.in.
If you need a privacy policy drafted or updated for DPDP Act compliance, GDPR, or both, our team can help. See our privacy policy drafting service or speak to our contract lawyers in India.





