
DPDPA Section 5: What Must Be Given, When, and How
Navigate India’s new privacy laws with confidence. Master DPDP Act compliance and understand your core responsibilities as a data fiduciary in this guide.
Written by
Himanshu Jotwani
Date
Read time
6 min

For the last decade, privacy notices were designed not to be read. They were legal shields, buried at the bottom of a signup page. DPDPA Section 5 ends that era.
Before you process a single byte of personal data, you must give the individual a clear notice. It must be understandable, timely, and actionable. And if you are sitting on a mountain of consent collected before the Act came into force, you still owe those users a fresh notice as soon as reasonably practicable.
This is not a paperwork formality. It is the operational foundation for lawful consent, transparent processing, and enforceable rights.
Scope and timing
Section 5 applies to any Data Fiduciary processing personal data. The rule on timing is absolute: the notice must be given at or before the start of processing. And processing begins the millisecond data is collected, not when it hits your database.

The Act permits just-in-time notices. You can display a short, contextual prompt at the exact moment you request a specific data point, provided you also give a way to view the full notice and obtain verifiable consent.
What you cannot do is ask for forgiveness. Retroactive notice is non-compliant. Starting collection and pushing a banner or email later is a violation. The phrase “By continuing to use this site, you agree” is no longer a legal defense,it is a confession. If any collection occurs before the person sees the notice and gives consent where required, you have a problem.
What the notice must contain
Your notice must be written in clear and plain language. Legalese is now a liability. It must explicitly inform the individual of:
- What personal data will be processed and the specific purpose for each item.
- How to exercise rights of access (Section 11) and correction (Section 12).
- How to make a complaint to the Data Protection Board of India.
- How to exercise rights including consent withdrawal/data erasure (Section 13) and nominating successor (Section 14).
- Any additional disclosure requirements prescribed by the government through Rules.
Make it specific. “Business purposes” is not a purpose; it is a well-written lie. Spell out exactly what you collect and why. For example: “Name and email to create your account,” “Address to deliver orders,” “IP address to secure your account.”
Do not hide secondary purposes. If you plan to use an email address for marketing, say so. If your purposes change materially, your old notice is void. You must provide a fresh notice before you start the new use and obtain fresh consent where required.
Pre-Act consents: transitional duty
If you collected consent before the Act commenced, you do not get a free pass. Section 5 requires you to send a notice to those individuals as soon as reasonably practicable.
This transitional notice must describe the personal data you have processed, the purposes, how to exercise rights, and how to complain to the Board.
You may continue processing on the basis of that prior consent until the individual withdraws it. The notice obligation does not pause your processing, but you must meet it without delay.
Language options
You must give the person an option to access the notice in English or any language listed in the Eighth Schedule to the Constitution. This is not a translation exercise; it is a product requirement. You must build language selection into your notice delivery and respect user preferences across all channels.
Just-in-time notices in practice
Meeting DPDP notice requirements without ruining your user experience requires a layered approach. A compliant just-in-time notice contains four elements:
- Core information: What data you are about to collect and why.
- Immediate choice: A clear allow or deny mechanism that captures verifiable consent.
- The escape hatch: A link or mechanism to view the full Section 5 notice.
- Timing: Shown before or at the exact moment of collection.

Take a location prompt on a mobile app. It should state that you need location to “show nearby services” and “calculate delivery time,” offer an Allow or Deny button, and link directly to the full privacy notice.
Layered delivery works. Keep the just-in-time layer short. Offer a concise summary for those who want more. Make the full notice one click away.
Practical implementation steps
DPDPA consent management is an engineering problem disguised as a legal one. Here is how you actually build it:
- Map collection points. Identify every place you collect or generate personal data, including SDKs, cookies, forms, and support channels. You cannot protect what you cannot see.
- Write the notice in plain language. Short sentences. Active voice. No jargon. If a non-lawyer cannot explain it back to you, simplify it.
- Tie data items to purposes. For each field or signal, state the purpose. Avoid catch-all phrasing.
- Build consent flows. Block collection that requires consent until the user takes an affirmative action. Record timestamps and context.
- Offer language options. Provide English and relevant Eighth Schedule languages. Keep translations consistent across platforms.
- Enable rights requests. Publish clear channels for access, correction, withdrawal, erasure, and nomination. Define authentication and response timelines. State consequences of erasure where relevant.
- Provide Board complaint information. Explain that the person can complain to the Data Protection Board and show them exactly where to start.
- Keep notices current. When purposes, data categories, or rights handling change materially, issue an updated notice before the change takes effect and refresh consent if needed.
- Design for accessibility. Ensure notices work on mobile and desktop, and are usable with assistive technologies.
Common mistakes to avoid
The gap between passing a legal review and actually being compliant is exactly where the next fine lives. Avoid these failures:
- Sending notice after collection begins.
- Burying the notice inside terms and conditions.
- Using vague purposes like “improving services.”
- Omitting how to exercise access or correction rights.
- Showing a brief prompt without a link to the full notice.
- Letting notices go stale after product changes.
- Failing to log when and how notices were shown.
- Relying on “continued use” for consent.
- Copying foreign templates that do not match Section 5 requirements.
Evidence that stands up in an audit
Compliance asks whether you have a notice. An audit tests whether you can prove you showed it. Maintain records that prove compliance:
- Versions of the notice with dates and language variants.
- Timestamps and context showing when each person saw the notice and how they consented or declined.
- Configurations of just-in-time prompts for each data collection point.
- Logs of material changes and the rollout plan for updates.
- Records of rights requests, responses, and resolution timelines.
- The individual’s language preferences and delivery method used.
What changes in practice
- Timing discipline. No data collection starts before notice and, where required, consent.
- Precision over generalities. You must list specific data items and purposes and keep them aligned.
- Human-centric writing. Plain language is a legal requirement. Legalese is a liability.
- Operational readiness. Rights request channels and Board complaint details must be real, not placeholders.
- Continuous governance. Product changes trigger notice review and, if necessary, fresh consent.
Compliance teams win this by owning the data map, partnering with product for just-in-time design, and maintaining auditable records. Engineering enables gating and logging. Legal ensures the notice content reflects current processing and rights.
Getting this right is execution-heavy, not theory. If your teams are juggling multiple notices, language support, product sprints, and audit trails, a structured approach helps. Regodit gives you a way to standardize notice content, control rollout, and retain evidence of timing and consent across systems.
Ready to simplify compliance?
Explore how Regodit can centralize your notices, streamline consent flows, and preserve audit-ready records. If you want to pressure-test your Section 5 implementation, schedule a call and we will walk through the operational details with your team.
Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.
Keep reading
All blogs →DPDPA Rule 23: Government Requests for Information from Data Fiduciaries and Intermediaries
Handling a notice under DPDP Act Rule 23 requires strict confidentiality. Discover how to respond to government data requests and ensure full compliance.
DPDPA Rule 22: Appeals to the Appellate Tribunal
Lost at the Data Protection Board? DPDPA Rule 22 governs the digital-first appeals process. Read our complete guide to filing an appeal with the Tribunal.
DPDPA Rule 21: The Machinery Behind the Data Protection Board of India
Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.
