DPDP privacy policy and cookie policy for your website
We draft both pages from what your website really collects, with a cookie table that matches the live cookies. We draft, your legal contact approves.
- Included in every Implementation plan
- We draft, your legal contact approves
Written by Shuruthi Sellamuthu. Last reviewed .
What should a DPDP privacy policy and cookie policy say?
A DPDP privacy policy and cookie policy should describe what the website really does: the data it collects, why, who receives it, how long it is kept, and how a person can withdraw consent, use their rights and complain. The cookie policy lists every cookie the site sets.
The DPDP Act, 2023 does not require these pages by name. It requires a notice where you ask for data (Act Section 5, DPDP Rules, 2025, Rule 3) and a published contact point (Act Section 8(9), Rule 9).
Drafted from what your website really collects
Many policy pages are copied from a template and describe a website that does not exist. We start from the other end: we scan the live site, list every cookie, tag and form, and write the pages from that.
We draft, your legal contact approves.
The data
What each form, cookie and tag collects.
The purpose
Why the website collects it.
Who receives it
The tools and companies the data is sent to.
How long it is kept
The periods your team has set.
Plus a cookie table that matches the cookies really found on the live site.
What each page should contain
A privacy policy, a Terms page and a cookie policy are not required by name. The law requires a notice at the point where you ask for data, and a published contact point for questions. In practice each page has its own job.
| Page | What goes on it | Where it is mentioned |
|---|---|---|
| Notice at the form and the banner | The legal core. What you collect, why, and links to withdraw consent, use rights and complain to the Board. It must stand on its own. | Act Section 5. Rule 3. |
| Privacy policy page | The full detail. All the data you collect and why, who receives it, how long you keep it, how to see, correct, erase and withdraw, how to complain, the contact for questions, and the languages offered. | Act Sections 5, 8(9) and 11 to 14. Rules 3, 9 and 14. |
| Cookie policy page | A table of each cookie: name, provider, purpose, lifespan and category. How to change or withdraw choices. A link to it from the banner. | Not required by name. It supports Act Sections 5, 6(1) and 6(4) and Rule 3. |
| Terms page | A small update. Keep it about the service, with no data consent inside it. Add a line pointing to the privacy policy. | Act Section 6(1). Rule 3. |
The notice itself sits on the cookie banner and below each form, which is our form consent work. The full table, with sources, is in the website guide to the DPDP Act.
The two tables at the heart of the pages
Both are illustrations. Your own tables are built from your scan and your team's answers.
How we work with your legal contact
We supply the facts and the drafts. Your legal contact decides the legal basis and approves the wording. It can be your in-house counsel, your law firm or your privacy consultant.
Timing
Drafts are written during the website setup, which takes about two weeks on a typical site. Policy sign-off depends on your legal team and usually adds two to four weeks.
-
We scan the live website
Every cookie, tag, pixel, embed and form, and what each one collects.
-
Your team fills the gaps
Some facts are not visible on a website, such as how long data is kept and who receives it after the form. We send a short list of questions.
-
We draft both pages
A draft privacy policy, a draft cookie policy and a cookie table, in plain language.
-
Your legal contact reviews and approves
They decide the legal basis, change what needs changing, and sign off the final wording.
-
The pages go live and are linked
The banner links to the cookie policy and every form links to the privacy policy. We check the cookie table against the live site once more.
What we do not do
- Give a legal opinion on your policies or your business
- Decide the legal basis for collecting data. That is your legal contact's call.
- Approve the final wording. Sign-off stays with you.
- Write about data we cannot see, such as internal systems, contracts and security. Your DPO, legal team or privacy consultant covers those.
- Access your CRM
What you receive
- A draft privacy policy
- A draft cookie policy
- A cookie table that matches the live cookies
The drafts are part of every Implementation plan, from ₹39,999. To see first how your current pages compare with what the site really does, start with the Website Audit.
View pricingScope. DPDPWeb works on websites only: cookie banners, form consent, and privacy and cookie policy pages. We are not a DPO service and not a law firm. Nothing on this site is legal advice.
Policy page questions
Tags and cookies are covered on the Consent Mode v2 and tag gating page.
Are your drafts legal advice?
No. We draft the pages from what your website really collects, and your legal contact approves the final wording. Nothing we provide is legal advice.
Does the DPDP Act require a privacy policy and a cookie policy?
Not by name. The Act requires a notice at the point where you ask for data (Section 5, Rule 3) and a published contact point for questions (Section 8(9), Rule 9). In practice both pages should be updated, because the full detail lives in the privacy policy and the cookie table lives in the cookie policy.
Can we use our own lawyer?
Yes, and we prefer it. We supply the facts and the drafts. Your legal contact decides the legal basis for each form and approves the policy wording.
How long does it take?
The drafts are written during the website setup, about two weeks on a typical site. Policy sign-off depends on your legal team and usually adds two to four weeks.
Why does the cookie table need to match the live cookies?
Because the table is the part of the page a visitor, or anyone checking the site, can compare with what really happens in the browser. We build it from the scan, and our audit checks that the two match.
What happens when we add a new tool or tag?
The cookie table goes out of date. The Care plan includes a monthly rescan, a review of new cookies and tags, and a cookie table update.
Do you also update our Terms page?
We flag the small changes it needs: keep it about the service, keep data consent out of it, and add a line pointing to the privacy policy. Your legal contact approves the wording.
Policy pages that match your website
Share your URL. We reply with scope, plan and timeline in writing. We draft, your legal contact approves.
Book a free call