Need Urgent Drafting within 24 Hours? Call/WhatsApp +91-9403890320

Try "Rent Agreement", "Cheque Bounce Notice", "NDA", "Will"

02 August 2026 19 min read Corporate, Business & Commercial Contracts

Privacy Policy India IT Act & Terms of Service: The Complete 2026 Compliance Guide

Complete guide to Privacy Policy India IT Act and Terms of Service for websites and apps. Legal compliance under IT Act 2000, DPDP Act 2023, Indian Contract Act. Step-by-step drafting, essential clauses, consequences of non-compliance, and expert drafting services.

Privacy Policy India IT Act & Terms of Service: The Complete 2026 Compliance Guide

Last Updated: August 2026 | Category: Corporate, Business & Commercial Contracts

What are Website Terms of Service & Privacy Policy?

Terms of Service (ToS) — also called Terms of Use, Terms and Conditions, or User Agreement — is the legally binding contract between a website/app owner and its users. It defines the rules, rights, and obligations governing the use of the website, app, or digital service. Under Indian law, a properly drafted ToS creates a binding contract under the Indian Contract Act, 1872, enforceable against every user who accesses or uses the platform.

A Privacy Policy is a legal notice that discloses how a website collects, uses, stores, processes, shares, and protects users' personal data. In India, privacy policies are mandated under the Information Technology Act, 2000 (Section 43A read with the SPDI Rules, 2011) and the recently enacted Digital Personal Data Protection (DPDP) Act, 2023. A robust privacy policy India IT Act compliant document is not just a legal requirement — it is a trust-building tool that assures users their data is safe.

Together, the ToS and Privacy Policy form the legal backbone of any digital presence in India. Whether you run an e-commerce store, a SaaS platform, a content website, a mobile app, or a simple blog, these two documents are non-negotiable for legal compliance and user protection.

Did You Know? The DPDP Act, 2023 applies to ALL entities that collect personal data in India — including sole proprietors, startups, NGOs, and small businesses. There is no "small business exemption." Every website and app that processes personal data of Indian residents must comply, regardless of the number of users.

Information Technology Act, 2000

The Information Technology Act, 2000 (IT Act) is the primary legislation governing electronic transactions and cyber activities in India. Key provisions relevant to website and app legal compliance include:

  • Section 43A: Mandates that body corporates handling "sensitive personal data" implement and maintain reasonable security practices and procedures. Non-compliance resulting in wrongful loss or gain attracts liability for damages.
  • Section 67, 67A, 67B: Penalties for publishing or transmitting obscene or sexually explicit material online — websites hosting user-generated content must have proper moderation policies and disclaimers.
  • Section 69A: Government's power to block public access to content — relevant for intermediary liability and content takedown compliance.
  • Section 79: Safe harbour provisions for intermediaries (platforms hosting third-party content). Under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, intermediaries must have a ToS, privacy policy, grievance mechanism, and comply with due diligence requirements to qualify for safe harbour protection.

SPDI Rules, 2011 (Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules)

These rules, framed under Section 43A of the IT Act, establish the framework for handling sensitive personal data. Requirements include: (a) obtaining written consent before collecting data, (b) providing a privacy policy, (c) permitting users to review and correct their data, and (d) implementing ISO 27001-compliant security practices for sensitive data.

Digital Personal Data Protection (DPDP) Act, 2023

The DPDP Act replaces the SPDI Rules as India's comprehensive data protection law. It is India's equivalent of the EU's GDPR. The Act applies to all personal data collected from Indian residents (not just sensitive data). Key requirements are discussed in the next section.

Indian Contract Act, 1872

ToS is a contract between the website owner and the user. Section 10 (valid contract requirements) and Section 27 (restraint of trade — relevant for non-compete clauses in ToS) are the most relevant sections.

Consumer Protection Act, 2019

E-commerce websites must comply with the Consumer Protection (E-Commerce) Rules, 2020, which require specific disclosures in the ToS including: seller details, return/refund/cancellation policies, delivery charges, grievance officer details, and country of origin information.

Copyright Act, 1957

ToS typically includes copyright and DMCA-style takedown provisions to protect the platform from copyright infringement liability and to establish the website's IP ownership.

The Digital Personal Data Protection Act, 2023: What You Must Know

The DPDP Act, 2023 is a landmark legislation that fundamentally changes how Indian websites and apps handle personal data. Here are the key requirements that affect your privacy policy and data handling practices:

Consent: The Foundation of Data Processing

Under the DPDP Act, consent must be: (a) free — no coercion or bundled consent, (b) specific — purpose-specific, not blanket, (c) informed — user must know what data is collected and why, (d) unconditional — consent cannot be a precondition for service unnecessarily, and (e) unambiguous — clear affirmative action required (pre-ticked boxes are NOT valid).

Your privacy policy must include a clear consent mechanism. Every purpose of data collection must be separately consented to. Users must have the right to withdraw consent at any time, and withdrawal must be as easy as giving consent.

Data Fiduciary Obligations

As a website owner (data fiduciary), you must: (a) implement appropriate technical and organisational measures to protect data, (b) notify users and the Data Protection Board of data breaches, (c) appoint a Data Protection Officer (if you are a "significant data fiduciary"), (d) ensure data accuracy and completeness, (e) erase personal data when the purpose is served, and (f) establish a grievance redressal mechanism.

Data Principal Rights

Users (data principals) have the following rights under the DPDP Act: (a) right to access their personal data, (b) right to correction and erasure, (c) right to grievance redressal, (d) right to nominate a representative to exercise rights after their death or incapacity, and (e) right to withdraw consent.

Cross-Border Data Transfer

The DPDP Act allows transfer of personal data outside India, subject to certain restrictions for "significant data fiduciaries" and data classified as "critical." This is more liberal than GDPR's approach. However, your privacy policy should disclose if data is transferred outside India and to which jurisdictions.

Exemptions

The DPDP Act exempts: (a) personal data processed for personal/domestic purposes, (b) data processed for employment purposes (limited exemption), (c) data processed by courts and judicial bodies, and (d) data processed for research, archiving, or statistical purposes (with conditions).

Data Protection Impact Assessment (DPIA)

"Significant data fiduciaries" (notified by the central government based on volume, sensitivity, risk to national security, etc.) must conduct DPIAs before processing certain categories of data. Most small and medium websites will not be classified as significant data fiduciaries initially, but this may change.

Requirement IT Act / SPDI Rules DPDP Act, 2023
Scope Sensitive personal data only All personal data
Consent Written consent Free, specific, informed, unconditional, unambiguous consent
Breach notification Not explicitly required Mandatory notification to users and DPA
Data Protection Officer Not required Required for significant data fiduciaries
Cross-border transfer Restricted — contractual necessity or adequacy required Permitted, with limited restrictions
Penalties ₹5 crore max + damages Up to ₹250 crore
Compliance Alert: The DPDP Act, 2023 was passed in August 2023, and the rules for implementation are being notified through 2024–2026. As of August 2026, the Act is in various stages of implementation. Websites and apps should transition to DPDP-compliant privacy policies and practices proactively. Our team monitors every notification and updates your documents to stay compliant.

Terms of Service: Essential Clauses

A professionally drafted Terms of Service for an Indian website/app should include the following clauses:

1. Acceptance of Terms

Clearly states that accessing or using the website constitutes acceptance of the ToS. Should include a "browsewrap" or "clickwrap" acceptance mechanism. Clickwrap (user must click "I Agree") is more enforceable in Indian courts than browsewrap (mere use constitutes acceptance).

2. User Accounts and Registration

Requirements for account creation, age restrictions (critical under DPDP Act — children under 18 require verifiable parental consent), accuracy of information, account security obligations, and grounds for suspension/termination of accounts.

3. Use of the Service

Permitted uses of the website, prohibited activities (e.g., hacking, scraping, harassment, uploading malicious content), and the website's right to moderate content and terminate accounts for violations.

4. User-Generated Content

For platforms with user-generated content: content ownership (licence back to the platform), content moderation rights, warranties regarding content lawfulness, and compliance with IT Act Section 79 intermediary guidelines.

5. Intellectual Property Rights

Clarifies that the website's content, design, logo, and software are owned by the website owner and protected under Indian copyright and trademark law. Prohibits reproduction, distribution, or derivative works without permission.

6. Payment and Refund Terms

For e-commerce and SaaS: accepted payment methods, pricing, billing cycle, automatic renewal terms, refund/cancellation policy, tax liability, and chargeback handling.

7. Third-Party Links and Services

Disclaimer regarding third-party websites, services, or advertisements. The website is not responsible for third-party content, privacy practices, or damages arising from third-party interactions.

8. Limitation of Liability

Limits the website's liability to the maximum extent permitted under Indian law. Under the Indian Contract Act, liability cannot be limited for fraud, death, or personal injury caused by negligence. This clause must be carefully drafted to avoid being struck down as unconscionable.

9. Indemnification

User agrees to indemnify the website owner against claims arising from the user's violation of the ToS or applicable law.

10. Termination

Grounds for termination by either party, notice period (if any), effects of termination (deletion of data, cessation of access), and survival of certain clauses (indemnification, IP, governing law).

11. Governing Law and Dispute Resolution

ToS must specify governing law (Indian law) and jurisdiction (specific city and state). Include an arbitration clause for dispute resolution — arbitration under the Arbitration and Conciliation Act, 1996 is faster and more cost-effective than litigation for most website disputes.

12. Amendments

Website's right to modify the ToS. Notice provisions for amendments (email notification or prominent website notice). Users' continued use after amendment constitutes acceptance.

Privacy Policy: Essential Clauses

A DPDP Act and IT Act compliant privacy policy India must include:

1. Types of Information Collected

Categories of personal data collected: (a) personal information (name, email, phone, address, Aadhaar, PAN), (b) financial information (bank details, credit/debit card data), (c) technical data (IP address, browser type, device information, cookies), (d) usage data (pages visited, time spent, actions taken), (e) user-generated content, and (f) location data (if applicable).

2. Purpose of Collection

Each purpose for which personal data is collected must be specified: account creation, service delivery, payment processing, customer support, analytics, marketing, legal compliance, etc. Under the DPDP Act, consent must be purpose-specific.

3. Consent Mechanism

How consent is obtained (opt-in checkboxes, explicit consent for sensitive data). Right to withdraw consent and the process for withdrawal. Consequences of withdrawal (the website may not be able to provide certain services).

4. Data Sharing and Disclosure

Categories of third parties with whom data is shared: service providers (payment gateways, cloud hosting, analytics), government authorities (when legally required), business partners (with consent), and affiliates. For cross-border transfer, specify the jurisdictions and adequacy measures.

5. Data Retention

How long different categories of personal data are retained. Under the DPDP Act, data must be erased when the purpose is served, unless retention is required by law. Specify retention periods for different data categories.

6. Data Security

Security measures implemented (encryption, firewalls, access controls, ISO certification if applicable). While you don't need to reveal all security details, you must state that reasonable security practices are in place as required under Section 43A of the IT Act.

7. Grievance Redressal

Under the IT (Intermediary Guidelines) Rules, 2021 and DPDP Act, websites must appoint a Grievance Officer and provide their contact details. The Grievance Officer must be a resident of India. The privacy policy must include the officer's name, email, address, and response timeline (typically 24 hours for acknowledgement, 15 days for resolution).

8. Cookies Policy

Types of cookies used (essential, functional, analytical, advertising), purpose of each cookie category, cookie duration, and user's ability to manage cookies. Under the DPDP Act, consent is required for non-essential cookies.

9. Data Principal Rights

Detailed explanation of user rights (access, correction, erasure, withdrawal of consent, grievance, nomination) and the process for exercising each right.

10. Children's Data

Under the DPDP Act, data of children (under 18) requires verifiable parental consent. The privacy policy must address whether the website collects data from children, the parental consent mechanism, and special protections.

11. Amendments to Privacy Policy

Website's right to update the privacy policy. Notice and consent requirements for material changes.

12. Contact Information

Website owner's name, registered address, email, phone — the entity ultimately responsible for data protection.

ToS vs Privacy Policy: How They Work Together

Your ToS and Privacy Policy are interdependent documents that serve different but complementary purposes:

Aspect Terms of Service (ToS) Privacy Policy
Purpose Governs the relationship between website and user — what users can/cannot do Discloses how user data is collected, used, stored, and protected
Legal basis Indian Contract Act, 1872 (contract) IT Act 2000, DPDP Act 2023 (statutory compliance)
Enforcement Binds user through acceptance — breach = breach of contract Binds website operator — violation = regulatory penalty + user claims
Key provisions IP, prohibited uses, liability limitation, termination, jurisdiction Data categories, consent, security, sharing, retention, user rights
Cross-reference ToS should reference the Privacy Policy ("Your use is subject to our Privacy Policy") Privacy Policy should reference the ToS for terms of service regarding data

Together they protect you from: user lawsuits (contractual), regulatory penalties (statutory), IP theft (contractual), data breach liability (statutory), consumer complaints (both), and intermediary liability (the IT Act intermediary safe harbour requires both documents).

Step-by-Step Drafting Process

Step 1: Website/App Audit (1–2 Days)

Our legal team conducts a comprehensive audit of your digital platform — what data you collect, how you collect it, why you collect it, who you share it with, where you store it, and what third-party services you use (analytics, payment gateways, CRM, advertising networks).

Step 2: Compliance Assessment (1 Day)

We assess which legal frameworks apply to your specific platform: IT Act, DPDP Act, SPDI Rules, Consumer Protection (E-Commerce) Rules, Intermediary Guidelines, sector-specific regulations (health, finance, education), and international laws if you serve users from the EU (GDPR) or California (CCPA).

Step 3: Drafting (2–3 Days)

Our corporate lawyers prepare: (a) a comprehensive Terms of Service tailored to your platform type (e-commerce, SaaS, content platform, marketplace, social media), (b) a DPDP Act and IT Act compliant Privacy Policy, (c) a Cookies Policy, and (d) any sector-specific addendums required.

Step 4: Implementation Review (1 Day)

We review how the documents will be presented on your website — clickwrap acceptance mechanisms, cookie consent banner, privacy policy placement, grievance officer details display. We provide implementation guidance for your development team.

Step 5: Finalisation and Delivery (1 Day)

Documents delivered in HTML (ready for website integration) and Word formats. We also provide a compliance checklist for your development and operations teams.

Turnaround time: 5–7 working days for the complete documentation package. Express delivery within 48 hours available.

Consequences of NOT Having ToS & Privacy Policy

  1. Massive DPDP Act Penalties: Up to ₹250 crore for significant data fiduciaries, or up to ₹50 crore for other violations. Even a single user complaint can trigger an investigation.
  2. IT Act Penalties: Under Section 43A, failure to maintain reasonable security practices resulting in wrongful loss can lead to damages equal to the loss suffered. Class-action suits by affected users are possible.
  3. Loss of Intermediary Safe Harbour: Under Section 79 of the IT Act, intermediaries must have a ToS and privacy policy, a grievance mechanism, and comply with due diligence requirements to qualify for safe harbour protection. Without these, you are liable for all user-generated content on your platform.
  4. Consumer Complaints: Under the Consumer Protection (E-Commerce) Rules, e-commerce platforms must have specific disclosures. Non-compliance can result in complaints before consumer courts and the Central Consumer Protection Authority.
  5. User Distrust: 78% of Indian internet users say they would stop using a website that doesn't clearly explain how their data is used. A professional privacy policy builds trust and increases conversion.
  6. Investor Due Diligence Rejection: Investors now demand data protection compliance as a condition for investment. Websites and apps without proper ToS and privacy policies are considered high-risk and unattractive for investment.
  7. No Legal Recourse: Without a ToS, you have no contractual basis to take action against users who abuse your platform — whether it's scraping content, posting illegal material, or violating your IP rights.
Case in Point: In K.S. Puttaswamy v. Union of India (2017), the Supreme Court declared the right to privacy a fundamental right under Article 21 of the Constitution. This landmark judgment, combined with the DPDP Act, means that Indian citizens have constitutional and statutory rights to data protection. Websites that violate these rights face both regulatory action and fundamental rights claims.

Penalties Under DPDP Act & IT Act

Violation Applicable Law Maximum Penalty
Failure to implement reasonable security practices IT Act Section 43A Damages for wrongful loss + ₹5 crore
Breach of personal data by data fiduciary DPDP Act Section 32 ₹250 crore
Failure to obtain valid consent DPDP Act Section 32 ₹50 crore
Failure to notify data breach DPDP Act Section 32 ₹25 crore
Failure to comply with data principal rights DPDP Act Section 32 ₹10 crore
Non-compliance with intermediary guidelines IT Act Section 79 + Rules Loss of safe harbour + court orders
Breach of confidentiality IT Act Section 72 ₹1 lakh + imprisonment up to 3 years

Why Choose Affordable Legal Drafting?

  1. DPDP Act Specialists: Our legal team has deep expertise in the DPDP Act, 2023 and its implementation rules. We are among the first legal drafting platforms in India to offer DPDP-compliant privacy policies.
  2. Full IT Act Compliance: Every privacy policy we draft complies with Section 43A, SPDI Rules, Intermediary Guidelines, and the IT Act as a whole.
  3. Website and App Specific: We draft separate documentation for websites, mobile apps, e-commerce platforms, SaaS products, content platforms, and social media — each with industry-specific clauses.
  4. GDPR & CCPA Addendums: If you serve users from the EU or California, we add GDPR and CCPA-specific addendums to ensure international compliance.
  5. Implementation Support: We don't just give you documents — we guide you on how to implement them on your website including cookie consent banners, acceptance flows, and grievance display.
  6. Affordable Pricing: Complete ToS + Privacy Policy + Cookies Policy package starts at just ₹3,999. Add GDPR addendum for ₹1,999 extra.

Don't Risk Crores in Penalties — Get Your Website Compliant Today

With the DPDP Act now in force and IT Act penalties at historic highs, there has never been a more critical time to ensure your website or app has professionally drafted, legally compliant Terms of Service and Privacy Policy.

Order ToS + Privacy Policy Package — Starting ₹3,999

Includes ToS, Privacy Policy, Cookies Policy, and implementation guide. Made in India, for Indian law.

Frequently Asked Questions (FAQ)

Is a privacy policy mandatory for every website in India?

Yes, if your website collects any personal data from users — including email addresses for newsletters, cookies for analytics, or account information for login — a privacy policy is mandatory under the IT Act and DPDP Act.

What is the difference between a privacy policy and a cookie policy?

A privacy policy covers all personal data handling practices. A cookie policy specifically addresses cookies and similar tracking technologies — what cookies are used, their purpose, duration, and how users can manage them. Many websites combine both, but a separate cookie policy is better practice under the DPDP Act.

Can I use a free privacy policy generator for my website?

Free generators produce generic, one-size-fits-all documents that often miss India-specific legal requirements, DPDP Act compliance, and sector-specific clauses. A custom-drafted policy from legal professionals is strongly recommended — the cost of non-compliance far exceeds the cost of proper drafting.

Do I need a separate privacy policy for my mobile app?

Yes. Mobile apps collect different data than websites (device ID, location, contacts, camera access, etc.) and require a privacy policy tailored to app-specific data collection. App store policies (Google Play, Apple App Store) also require a privacy policy link in the app listing.

How often should I update my ToS and privacy policy?

At minimum: (a) when your data practices change, (b) when new laws or regulations come into effect, (c) when you add new features or third-party services, and (d) annually as a best practice. We notify our clients of legal changes that require document updates.

What is the grievance officer requirement under Indian law?

Under the IT (Intermediary Guidelines) Rules, 2021, all intermediaries must appoint a Grievance Officer who is a resident of India. The officer's name, email address, phone number, and physical address must be published on the website. The officer must acknowledge complaints within 24 hours and resolve them within 15 days.

What are the age requirements under the DPDP Act?

Under the DPDP Act, a "child" is anyone under 18 years of age. Processing the personal data of children requires verifiable parental consent. Websites and apps that serve children must implement additional protections and cannot engage in behavioural monitoring or targeted advertising directed at children.

Disclaimer: This article provides general information and does not constitute legal advice. You should consult a qualified legal professional for advice specific to your situation. Affordable Legal Drafting is a platform for legal document drafting services and does not provide legal representation.

© 2026 Affordable Legal Drafting. All rights reserved. | affordablelegaldrafting.com

Share this article:
Get Your Document Drafted Now