Skip to content

DPDP duties for websites apply in full from 13 May 2027. Check your site free

DPDPWeb
Book a free call Free website check

DPDP privacy policy and cookie policy for your website

We draft both pages from what your website really collects, with a cookie table that matches the live cookies. We draft, your legal contact approves.

  • Included in every Implementation plan
  • We draft, your legal contact approves
Book a free call See the full implementation

Written by . Last reviewed .

What should a DPDP privacy policy and cookie policy say?

A DPDP privacy policy and cookie policy should describe what the website really does: the data it collects, why, who receives it, how long it is kept, and how a person can withdraw consent, use their rights and complain. The cookie policy lists every cookie the site sets.

The DPDP Act, 2023 does not require these pages by name. It requires a notice where you ask for data (Act Section 5, DPDP Rules, 2025, Rule 3) and a published contact point (Act Section 8(9), Rule 9).

Drafted from what your website really collects

Many policy pages are copied from a template and describe a website that does not exist. We start from the other end: we scan the live site, list every cookie, tag and form, and write the pages from that.

We draft, your legal contact approves.

The data

What each form, cookie and tag collects.

The purpose

Why the website collects it.

Who receives it

The tools and companies the data is sent to.

How long it is kept

The periods your team has set.

Plus a cookie table that matches the cookies really found on the live site.

What each page should contain

A privacy policy, a Terms page and a cookie policy are not required by name. The law requires a notice at the point where you ask for data, and a published contact point for questions. In practice each page has its own job.

What each page should contain
PageWhat goes on itWhere it is mentioned
Notice at the form and the bannerThe legal core. What you collect, why, and links to withdraw consent, use rights and complain to the Board. It must stand on its own.Act Section 5. Rule 3.
Privacy policy pageThe full detail. All the data you collect and why, who receives it, how long you keep it, how to see, correct, erase and withdraw, how to complain, the contact for questions, and the languages offered.Act Sections 5, 8(9) and 11 to 14. Rules 3, 9 and 14.
Cookie policy pageA table of each cookie: name, provider, purpose, lifespan and category. How to change or withdraw choices. A link to it from the banner.Not required by name. It supports Act Sections 5, 6(1) and 6(4) and Rule 3.
Terms pageA small update. Keep it about the service, with no data consent inside it. Add a line pointing to the privacy policy.Act Section 6(1). Rule 3.

The notice itself sits on the cookie banner and below each form, which is our form consent work. The full table, with sources, is in the website guide to the DPDP Act.

The two tables at the heart of the pages

Both are illustrations. Your own tables are built from your scan and your team's answers.

Illustration

Cookie table

Example cookie table
CookieProviderPurposeLifespanCategory
[consent cookie][Consent platform]Remembers the visitor's banner choice[as found]Strictly necessary
_gaGoogle AnalyticsTells one visitor from another in reports[as found]Analytics
_gcl_auGoogle AdsMeasures ad conversions[as found]Marketing
_fbpMetaMeasures and targets ads[as found]Marketing

One row for every cookie found on the live site. Lifespans are copied from the scan, not from a template.

Illustration

Privacy policy data table

Example privacy policy data table
DataWhy we collect itWho receives itHow long we keep it
Name, phone number, email addressTo reply to your enquiry and to set up your accountOur CRM and email tools (name each one)12 months after your last contact, unless you become a customer
Pages viewed and device details, with your consentTo understand how the website is usedOur analytics tool (name it)[Period set by your team]

One row for each kind of data. The wording is replaced with your own facts.

How we work with your legal contact

We supply the facts and the drafts. Your legal contact decides the legal basis and approves the wording. It can be your in-house counsel, your law firm or your privacy consultant.

Timing

Drafts are written during the website setup, which takes about two weeks on a typical site. Policy sign-off depends on your legal team and usually adds two to four weeks.

  1. We scan the live website

    Every cookie, tag, pixel, embed and form, and what each one collects.

  2. Your team fills the gaps

    Some facts are not visible on a website, such as how long data is kept and who receives it after the form. We send a short list of questions.

  3. We draft both pages

    A draft privacy policy, a draft cookie policy and a cookie table, in plain language.

  4. Your legal contact reviews and approves

    They decide the legal basis, change what needs changing, and sign off the final wording.

  5. The pages go live and are linked

    The banner links to the cookie policy and every form links to the privacy policy. We check the cookie table against the live site once more.

What we do not do

  • Give a legal opinion on your policies or your business
  • Decide the legal basis for collecting data. That is your legal contact's call.
  • Approve the final wording. Sign-off stays with you.
  • Write about data we cannot see, such as internal systems, contracts and security. Your DPO, legal team or privacy consultant covers those.
  • Access your CRM

What you receive

  • A draft privacy policy
  • A draft cookie policy
  • A cookie table that matches the live cookies

The drafts are part of every Implementation plan, from ₹39,999. To see first how your current pages compare with what the site really does, start with the Website Audit.

View pricing

Scope. DPDPWeb works on websites only: cookie banners, form consent, and privacy and cookie policy pages. We are not a DPO service and not a law firm. Nothing on this site is legal advice.

Policy page questions

Tags and cookies are covered on the Consent Mode v2 and tag gating page.

Are your drafts legal advice?

No. We draft the pages from what your website really collects, and your legal contact approves the final wording. Nothing we provide is legal advice.

Does the DPDP Act require a privacy policy and a cookie policy?

Not by name. The Act requires a notice at the point where you ask for data (Section 5, Rule 3) and a published contact point for questions (Section 8(9), Rule 9). In practice both pages should be updated, because the full detail lives in the privacy policy and the cookie table lives in the cookie policy.

Can we use our own lawyer?

Yes, and we prefer it. We supply the facts and the drafts. Your legal contact decides the legal basis for each form and approves the policy wording.

How long does it take?

The drafts are written during the website setup, about two weeks on a typical site. Policy sign-off depends on your legal team and usually adds two to four weeks.

Why does the cookie table need to match the live cookies?

Because the table is the part of the page a visitor, or anyone checking the site, can compare with what really happens in the browser. We build it from the scan, and our audit checks that the two match.

What happens when we add a new tool or tag?

The cookie table goes out of date. The Care plan includes a monthly rescan, a review of new cookies and tags, and a cookie table update.

Do you also update our Terms page?

We flag the small changes it needs: keep it about the service, keep data consent out of it, and add a line pointing to the privacy policy. Your legal contact approves the wording.

Policy pages that match your website

Share your URL. We reply with scope, plan and timeline in writing. We draft, your legal contact approves.

Book a free call