DPDPA Rule 3: Notice Obligations for Data Fiduciaries

DPDPA Rule 3: Notice Obligations for Data Fiduciaries

Vague privacy policies are dead. See how the DPDP rule 3 requirement forces data fiduciaries to provide clear, standalone notices for informed consent.

Himanshu Jotwani

Written by

Himanshu Jotwani

Date

Read time

6 min

What Rule 3 Requires

For years, privacy notices have been a legal fiction,a 5,000-word document, a pre-checked box, and a vague promise to “improve services.” The DPDP Act Rule 3 ends that era.

The core dpdp rule 3 requirement sets the baseline for how Data Fiduciaries must inform Data Principals before processing personal data. It is about enabling specific and informed consent, not box-ticking. The rule mandates three core elements:

  • Independent and understandable notice:
  • The notice must stand on its own.
  • It cannot be buried in terms and conditions or require cross-referencing other documents.
  • It must be presented clearly and be understandable without external context.
  • Clear and plain content that enables informed consent:
  • The notice must give a fair account of what the Data Principal needs to know to consent.
  • It must include at least:
  • An itemized description of the personal data to be processed.
  • The specified purpose or purposes of processing, along with a specific description of the goods or services to be provided or uses to be enabled through that processing.
  • Direct links and channels for control and redress:
  • The notice must provide a particular communication link to the Data Fiduciary’s website or app.
  • It must describe other means, if any, through which the Data Principal can:
  • Withdraw consent, with the ease comparable to how consent was given.
  • Exercise rights under the Act.
  • Make a complaint to the Board.

Plain English Interpretation

A notice is not a scavenger hunt. It is a standalone explainer. It cannot be hidden in legalese or dispersed across multiple documents. It should read like a direct explanation of what you plan to do with someone’s data and what they can do about it.

Illustration of a clear, standalone notice explaining data collection and user rights under DPDP Rule 3.

The content must be precise. List exactly what personal data you will collect or process. Do not say “we may collect information.” Say “we collect your name, phone number, and location history.” Then tie each processing activity to a specific purpose and a specific service or use. Vague catch-all statements do not meet the standard for “specific and informed consent.”

The notice must give a direct link to where people can manage consent and exercise rights. The link should take them straight to the relevant control surface on your website or app. If you offer other channels, such as email or a helpline, describe them.

Withdrawal of consent must be as easy as giving it. If you collected consent with one tap, withdrawal should not require a support ticket or a long form.

Finally, the notice must tell people how to complain to the Board. This is part of accountability. You must not force users to search multiple pages for a route to escalate issues.

Scope and Boundaries

  • Who is obligated: Data Fiduciaries that seek to process personal data based on consent must issue the notice to Data Principals.
  • What the notice must cover: The personal data at issue, the purposes of processing, the goods or services tied to those purposes, and direct mechanisms for consent withdrawal, rights requests, and complaints.
  • Independence requirement: The notice must be complete enough to be understandable without relying on other documents. You can still link to a privacy policy, but the notice itself must contain the required details.
  • No hidden friction: The “comparable ease” standard for consent withdrawal rules out multi-step or obscure procedures that are tougher than the original consent flow.

Rule 3 does not itself define every right or process under the Act. It focuses on the dpdp manner of collection of data,what the notice must contain and how it must be presented so that consent is specific and informed.

Practical Implementation Checklist

  • Draft a standalone notice:
  • Use short sentences and plain language.
  • Avoid technical jargon unless you explain it immediately.
  • Keep it separate from lengthy terms, while still allowing links to deeper documentation.
  • Itemize personal data:
  • List categories clearly. Example: name, date of birth, email address, transaction history, approximate location.
  • If certain fields are optional, say so.
  • Tie data to purpose and service:
  • For every data category, state the specific purpose and the service or use it enables.
  • Avoid blanket phrases like “improve services” without concrete context.
  • Build consent UX with parity:
  • If consent is one click, make withdrawal one click.
  • If consent is through a toggle, provide the same toggle for withdrawal.
  • Avoid gating withdrawal behind login if consent was collected pre-login, unless security is necessary to verify identity.
A checklist illustrating the practical implementation of DPDP Rule 3 requirements for data fiduciaries.
  • Provide a particular link:
  • Use a single, direct URL or deep link that lands on consent and rights management, not a homepage.
  • Keep this link stable and test it regularly.
  • Offer other channels where relevant:
  • If you support email, helpdesk, in-app chat, or call centers for rights, include them and describe how to use them.
  • Avoid promising channels you cannot support within statutory timelines.
  • Enable rights execution:
  • Ensure the link routes to functions for access, correction, erasure, and other applicable rights under the Act.
  • Provide clear instructions for identity verification.
  • Explain how to complain to the Board:
  • Include a concise statement that the Data Principal can make a complaint to the Board and describe how they can initiate that process through your provided channels.
  • Recordkeeping:
  • Version your notice text.
  • Log when and how the notice was presented to each Data Principal.
  • Keep proof of consent and proof of withdrawal parity.
  • Testing and controls:
  • Conduct user testing for clarity and ease of withdrawal.
  • Set up periodic reviews to confirm the link works and the content is current.

Patterns to Avoid

  • Burying notice text inside long policies without a dedicated, clear section.
  • Non-specific data descriptions such as “we collect data to provide services.”
  • Broad or shifting purposes like “for any future business use.”
  • Withdrawal flows that require contacting support when consent was given with a toggle or a single click.
  • Dead or generic links that lead to a homepage or a knowledge base instead of the actual control page.

Patterns to Adopt

  • Layered communication: a short, clear summary followed by a concise list of data items and purposes.
  • One control surface: a dedicated consent and rights page reachable via a stable link.
  • Purpose mapping: a matrix that links each data item to a specific purpose and a specific good or service.
  • Operational readiness: defined SLAs, trained staff, and automated workflows for consent changes and rights requests.

Example Notice Structure

  • What data we process: list each category.
  • Why we process it: list each specific purpose and the related good or service.
  • How you can manage this: provide the particular link to the consent and rights page.
  • Other ways to contact us: describe available channels for withdrawal and rights.
  • How to escalate: how to make a complaint to the Board.

Keep the example crisp, readable, and free of ambiguity. Every sentence should help the Data Principal decide whether to consent.

Execution Notes for Operators

Translate legal text into user-facing content that a layperson can understand in under a minute. Align your back-end systems so that notice text, consent states, and withdrawal mechanisms are consistent across web, app, and support. Monitor analytics on the consent and withdrawal paths to detect friction that could violate the “comparable ease” requirement.

A policy that does not reflect reality is just a well-written lie. Real compliance lives in your processes. It is not enough to write a good notice if your systems cannot honor it.

Ready to simplify compliance?

At Regodit, we know that mapping notice obligations to practical controls is where the real work happens. We help teams turn requirements like Rule 3 into structured workflows, controls, and audit-ready evidence that stand up under scrutiny. If you want to pressure-test your current notice and consent flows, schedule a call and we will walk through your setup together.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →