Privacy & Cookie Policy Drafting
A privacy policy tells people what personal data a website or app collects, why, who it is shared with, how long it is kept and how they can exercise their rights. In India a business that collects personal data online needs one, and under the DPDP Act the notice it gives must meet specific content rules.
Today the requirement comes mainly from the Information Technology Act, 2000 and the rules made under it. From 13 May 2027 the notice duties of the Digital Personal Data Protection Act, 2023 and its Rules apply. A cookie policy explains the cookies and similar trackers a site uses, and, where they collect personal data, how people can accept or refuse them.
When you need it
When launching a website or app
Any site or app that collects names, email addresses, phone numbers, location or usage data needs a policy in place before it goes live.
Before listing an app
The Google Play Store and the Apple App Store both require a working link to a privacy policy that matches the data the app collects.
When collecting leads or running ads
Enquiry forms, newsletter sign-ups and advertising pixels all collect personal data, and each needs to be covered by the notice.
When the policy was copied from a template
A policy copied from another site rarely matches what the business actually does, and many templates still describe the law as it stood before the DPDP Act.
When users are in Europe
A business with users in the European Union may also need to meet the GDPR and the EU rules on cookie consent.
How the process works
Five stages, from what the site actually does to a published policy. Timings are typical, not promised.
- 1
Review what the site or app does
Usually a few daysList the personal data collected through each form, account, app permission, payment flow, analytics tool, advertising pixel and third-party plugin, and where each goes. A policy is only as accurate as this list.
Documents
- Access to the website or a test build of the app
- A list of analytics, advertising, payment and support tools in use
- The current policy, if there is one
- 2
Identify the law that applies
Alongside the reviewConfirm which rules apply: the IT Act and its rules, the DPDP Act and Rules, the intermediary rules for platforms that host user content, the e-commerce rules for online sellers, sector rules such as those for lending or health, and the GDPR if there are users in the European Union.
- 3
Draft the privacy policy
One to two weeksWrite the policy in plain language: what is collected and why, the legal ground for each use, sharing and transfers, retention, security, individuals’ rights, how to withdraw consent, the grievance contact and how to complain to the Data Protection Board.
- 4
Draft the cookie policy and banner wording
Alongside the privacy policyGroup the cookies by purpose, separate those the site needs to work from those used for analytics or advertising, and write the banner and settings wording so that optional cookies can be refused.
- 5
Align the forms and publish
On publication, then at least once a yearCheck that consent wording on forms, sign-up screens and app permission prompts matches the policy, publish both policies where users can find them, and set a date to review them when the site or the law changes.
Common questions
For almost any business website that collects personal data, yes. The rules under the Information Technology Act, 2000 require a published privacy policy, and the DPDP Act requires a notice before or when consent is asked for. Platforms that host user content must also publish one under the intermediary rules.
India has no law specifically about cookies. But cookies and trackers that identify a person collect personal data, and under the DPDP Act that needs notice and a lawful ground, which will usually be consent. Cookies that a site strictly needs to work are treated differently from analytics and advertising cookies.
It is a risk. A copied policy describes someone else’s data practices, may be protected by copyright, and often cites rules that have since changed. If the policy says something the business does not do, or leaves out something it does, it becomes evidence against it.
It needs a policy that covers the app specifically: app permissions such as location, contacts and camera, device identifiers and any third-party software kits. The app stores check that the policy link works and matches what the app declares.
Under the DPDP Rules, the notice must be understandable on its own and give an itemised description of the personal data and the specific purpose of processing, how to withdraw consent, how to exercise rights under the Act, and how to complain to the Data Protection Board.
Not necessarily. Cookies can be explained in a section of the privacy policy. A separate cookie policy is clearer when a site uses many trackers, and it should match what the cookie banner actually does.
Whenever the website, app or data practices change, when new tools are added, and when the law changes. For most businesses that means a review at least once a year, and a full update before the DPDP duties apply on 13 May 2027.
Related
To discuss a privacy or cookie policy, write to info@ireniclegal.com or call +91 96547 47331. Written by Adv. Kanika Marwaha Bindal; last updated 29 September 2026.

