Privacy & Cookie Policy Drafting

A privacy policy tells people what personal data a website or app collects, why, who it is shared with, how long it is kept and how they can exercise their rights. In India a business that collects personal data online needs one, and under the DPDP Act the notice it gives must meet specific content rules.

Today the requirement comes mainly from the Information Technology Act, 2000 and the rules made under it. From 13 May 2027 the notice duties of the Digital Personal Data Protection Act, 2023 and its Rules apply. A cookie policy explains the cookies and similar trackers a site uses, and, where they collect personal data, how people can accept or refuse them.

When you need it

  • When launching a website or app

    Any site or app that collects names, email addresses, phone numbers, location or usage data needs a policy in place before it goes live.

  • Before listing an app

    The Google Play Store and the Apple App Store both require a working link to a privacy policy that matches the data the app collects.

  • When collecting leads or running ads

    Enquiry forms, newsletter sign-ups and advertising pixels all collect personal data, and each needs to be covered by the notice.

  • When the policy was copied from a template

    A policy copied from another site rarely matches what the business actually does, and many templates still describe the law as it stood before the DPDP Act.

  • When users are in Europe

    A business with users in the European Union may also need to meet the GDPR and the EU rules on cookie consent.

How the process works

Five stages, from what the site actually does to a published policy. Timings are typical, not promised.

  1. 1

    Review what the site or app does

    Usually a few days

    List the personal data collected through each form, account, app permission, payment flow, analytics tool, advertising pixel and third-party plugin, and where each goes. A policy is only as accurate as this list.

    Documents

    • Access to the website or a test build of the app
    • A list of analytics, advertising, payment and support tools in use
    • The current policy, if there is one
  2. 2

    Identify the law that applies

    Alongside the review

    Confirm which rules apply: the IT Act and its rules, the DPDP Act and Rules, the intermediary rules for platforms that host user content, the e-commerce rules for online sellers, sector rules such as those for lending or health, and the GDPR if there are users in the European Union.

  3. 3

    Draft the privacy policy

    One to two weeks

    Write the policy in plain language: what is collected and why, the legal ground for each use, sharing and transfers, retention, security, individuals’ rights, how to withdraw consent, the grievance contact and how to complain to the Data Protection Board.

  4. 4

    Draft the cookie policy and banner wording

    Alongside the privacy policy

    Group the cookies by purpose, separate those the site needs to work from those used for analytics or advertising, and write the banner and settings wording so that optional cookies can be refused.

  5. 5

    Align the forms and publish

    On publication, then at least once a year

    Check that consent wording on forms, sign-up screens and app permission prompts matches the policy, publish both policies where users can find them, and set a date to review them when the site or the law changes.

Common questions

For almost any business website that collects personal data, yes. The rules under the Information Technology Act, 2000 require a published privacy policy, and the DPDP Act requires a notice before or when consent is asked for. Platforms that host user content must also publish one under the intermediary rules.

To discuss a privacy or cookie policy, write to info@ireniclegal.com or call +91 96547 47331. Written by Adv. Kanika Marwaha Bindal; last updated 29 September 2026.