Privacy Policy India IT Act & Terms of Service: The Complete 2026 Compliance Guide
Complete guide to Privacy Policy India IT Act and Terms of Service for websites and apps. Legal compliance under IT Act 2000, DPDP Act 2023, Indian Contract Act. Step-by-step drafting, essential clauses, consequences of non-compliance, and expert drafting services.
Privacy Policy India IT Act & Terms of Service: The Complete 2026 Compliance Guide
Last Updated: August 2026 | Category: Corporate, Business & Commercial Contracts
Table of Contents
- What are Website Terms of Service & Privacy Policy?
- Legal Framework: IT Act 2000, DPDP Act 2023 & More
- The Digital Personal Data Protection Act, 2023: What You Must Know
- Terms of Service: Essential Clauses
- Privacy Policy: Essential Clauses
- ToS vs Privacy Policy: How They Work Together
- Step-by-Step Drafting Process
- Consequences of NOT Having ToS & Privacy Policy
- Penalties Under DPDP Act & IT Act
- Why Choose Affordable Legal Drafting
- Get Your Website Documents Drafted
What are Website Terms of Service & Privacy Policy?
Terms of Service (ToS) — also called Terms of Use, Terms and Conditions, or User Agreement — is the legally binding contract between a website/app owner and its users. It defines the rules, rights, and obligations governing the use of the website, app, or digital service. Under Indian law, a properly drafted ToS creates a binding contract under the Indian Contract Act, 1872, enforceable against every user who accesses or uses the platform.
A Privacy Policy is a legal notice that discloses how a website collects, uses, stores, processes, shares, and protects users' personal data. In India, privacy policies are mandated under the Information Technology Act, 2000 (Section 43A read with the SPDI Rules, 2011) and the recently enacted Digital Personal Data Protection (DPDP) Act, 2023. A robust privacy policy India IT Act compliant document is not just a legal requirement — it is a trust-building tool that assures users their data is safe.
Together, the ToS and Privacy Policy form the legal backbone of any digital presence in India. Whether you run an e-commerce store, a SaaS platform, a content website, a mobile app, or a simple blog, these two documents are non-negotiable for legal compliance and user protection.
Legal Framework: IT Act 2000, DPDP Act 2023 & More
Information Technology Act, 2000
The Information Technology Act, 2000 (IT Act) is the primary legislation governing electronic transactions and cyber activities in India. Key provisions relevant to website and app legal compliance include:
- Section 43A: Mandates that body corporates handling "sensitive personal data" implement and maintain reasonable security practices and procedures. Non-compliance resulting in wrongful loss or gain attracts liability for damages.
- Section 67, 67A, 67B: Penalties for publishing or transmitting obscene or sexually explicit material online — websites hosting user-generated content must have proper moderation policies and disclaimers.
- Section 69A: Government's power to block public access to content — relevant for intermediary liability and content takedown compliance.
- Section 79: Safe harbour provisions for intermediaries (platforms hosting third-party content). Under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, intermediaries must have a ToS, privacy policy, grievance mechanism, and comply with due diligence requirements to qualify for safe harbour protection.
SPDI Rules, 2011 (Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules)
These rules, framed under Section 43A of the IT Act, establish the framework for handling sensitive personal data. Requirements include: (a) obtaining written consent before collecting data, (b) providing a privacy policy, (c) permitting users to review and correct their data, and (d) implementing ISO 27001-compliant security practices for sensitive data.
Digital Personal Data Protection (DPDP) Act, 2023
The DPDP Act replaces the SPDI Rules as India's comprehensive data protection law. It is India's equivalent of the EU's GDPR. The Act applies to all personal data collected from Indian residents (not just sensitive data). Key requirements are discussed in the next section.
Indian Contract Act, 1872
ToS is a contract between the website owner and the user. Section 10 (valid contract requirements) and Section 27 (restraint of trade — relevant for non-compete clauses in ToS) are the most relevant sections.
Consumer Protection Act, 2019
E-commerce websites must comply with the Consumer Protection (E-Commerce) Rules, 2020, which require specific disclosures in the ToS including: seller details, return/refund/cancellation policies, delivery charges, grievance officer details, and country of origin information.
Copyright Act, 1957
ToS typically includes copyright and DMCA-style takedown provisions to protect the platform from copyright infringement liability and to establish the website's IP ownership.
The Digital Personal Data Protection Act, 2023: What You Must Know
The DPDP Act, 2023 is a landmark legislation that fundamentally changes how Indian websites and apps handle personal data. Here are the key requirements that affect your privacy policy and data handling practices:
Consent: The Foundation of Data Processing
Under the DPDP Act, consent must be: (a) free — no coercion or bundled consent, (b) specific — purpose-specific, not blanket, (c) informed — user must know what data is collected and why, (d) unconditional — consent cannot be a precondition for service unnecessarily, and (e) unambiguous — clear affirmative action required (pre-ticked boxes are NOT valid).
Your privacy policy must include a clear consent mechanism. Every purpose of data collection must be separately consented to. Users must have the right to withdraw consent at any time, and withdrawal must be as easy as giving consent.
Data Fiduciary Obligations
As a website owner (data fiduciary), you must: (a) implement appropriate technical and organisational measures to protect data, (b) notify users and the Data Protection Board of data breaches, (c) appoint a Data Protection Officer (if you are a "significant data fiduciary"), (d) ensure data accuracy and completeness, (e) erase personal data when the purpose is served, and (f) establish a grievance redressal mechanism.
Data Principal Rights
Users (data principals) have the following rights under the DPDP Act: (a) right to access their personal data, (b) right to correction and erasure, (c) right to grievance redressal, (d) right to nominate a representative to exercise rights after their death or incapacity, and (e) right to withdraw consent.
Cross-Border Data Transfer
The DPDP Act allows transfer of personal data outside India, subject to certain restrictions for "significant data fiduciaries" and data classified as "critical." This is more liberal than GDPR's approach. However, your privacy policy should disclose if data is transferred outside India and to which jurisdictions.
Exemptions
The DPDP Act exempts: (a) personal data processed for personal/domestic purposes, (b) data processed for employment purposes (limited exemption), (c) data processed by courts and judicial bodies, and (d) data processed for research, archiving, or statistical purposes (with conditions).
Data Protection Impact Assessment (DPIA)
"Significant data fiduciaries" (notified by the central government based on volume, sensitivity, risk to national security, etc.) must conduct DPIAs before processing certain categories of data. Most small and medium websites will not be classified as significant data fiduciaries initially, but this may change.
| Requirement | IT Act / SPDI Rules | DPDP Act, 2023 |
|---|---|---|
| Scope | Sensitive personal data only | All personal data |
| Consent | Written consent | Free, specific, informed, unconditional, unambiguous consent |
| Breach notification | Not explicitly required | Mandatory notification to users and DPA |
| Data Protection Officer | Not required | Required for significant data fiduciaries |
| Cross-border transfer | Restricted — contractual necessity or adequacy required | Permitted, with limited restrictions |
| Penalties | ₹5 crore max + damages | Up to ₹250 crore |
Terms of Service: Essential Clauses
A professionally drafted Terms of Service for an Indian website/app should include the following clauses:
1. Acceptance of Terms
Clearly states that accessing or using the website constitutes acceptance of the ToS. Should include a "browsewrap" or "clickwrap" acceptance mechanism. Clickwrap (user must click "I Agree") is more enforceable in Indian courts than browsewrap (mere use constitutes acceptance).
2. User Accounts and Registration
Requirements for account creation, age restrictions (critical under DPDP Act — children under 18 require verifiable parental consent), accuracy of information, account security obligations, and grounds for suspension/termination of accounts.
3. Use of the Service
Permitted uses of the website, prohibited activities (e.g., hacking, scraping, harassment, uploading malicious content), and the website's right to moderate content and terminate accounts for violations.
4. User-Generated Content
For platforms with user-generated content: content ownership (licence back to the platform), content moderation rights, warranties regarding content lawfulness, and compliance with IT Act Section 79 intermediary guidelines.
5. Intellectual Property Rights
Clarifies that the website's content, design, logo, and software are owned by the website owner and protected under Indian copyright and trademark law. Prohibits reproduction, distribution, or derivative works without permission.
6. Payment and Refund Terms
For e-commerce and SaaS: accepted payment methods, pricing, billing cycle, automatic renewal terms, refund/cancellation policy, tax liability, and chargeback handling.
7. Third-Party Links and Services
Disclaimer regarding third-party websites, services, or advertisements. The website is not responsible for third-party content, privacy practices, or damages arising from third-party interactions.
8. Limitation of Liability
Limits the website's liability to the maximum extent permitted under Indian law. Under the Indian Contract Act, liability cannot be limited for fraud, death, or personal injury caused by negligence. This clause must be carefully drafted to avoid being struck down as unconscionable.
9. Indemnification
User agrees to indemnify the website owner against claims arising from the user's violation of the ToS or applicable law.
10. Termination
Grounds for termination by either party, notice period (if any), effects of termination (deletion of data, cessation of access), and survival of certain clauses (indemnification, IP, governing law).
11. Governing Law and Dispute Resolution
ToS must specify governing law (Indian law) and jurisdiction (specific city and state). Include an arbitration clause for dispute resolution — arbitration under the Arbitration and Conciliation Act, 1996 is faster and more cost-effective than litigation for most website disputes.
12. Amendments
Website's right to modify the ToS. Notice provisions for amendments (email notification or prominent website notice). Users' continued use after amendment constitutes acceptance.
Privacy Policy: Essential Clauses
A DPDP Act and IT Act compliant privacy policy India must include:
1. Types of Information Collected
Categories of personal data collected: (a) personal information (name, email, phone, address, Aadhaar, PAN), (b) financial information (bank details, credit/debit card data), (c) technical data (IP address, browser type, device information, cookies), (d) usage data (pages visited, time spent, actions taken), (e) user-generated content, and (f) location data (if applicable).
2. Purpose of Collection
Each purpose for which personal data is collected must be specified: account creation, service delivery, payment processing, customer support, analytics, marketing, legal compliance, etc. Under the DPDP Act, consent must be purpose-specific.
3. Consent Mechanism
How consent is obtained (opt-in checkboxes, explicit consent for sensitive data). Right to withdraw consent and the process for withdrawal. Consequences of withdrawal (the website may not be able to provide certain services).
4. Data Sharing and Disclosure
Categories of third parties with whom data is shared: service providers (payment gateways, cloud hosting, analytics), government authorities (when legally required), business partners (with consent), and affiliates. For cross-border transfer, specify the jurisdictions and adequacy measures.
5. Data Retention
How long different categories of personal data are retained. Under the DPDP Act, data must be erased when the purpose is served, unless retention is required by law. Specify retention periods for different data categories.
6. Data Security
Security measures implemented (encryption, firewalls, access controls, ISO certification if applicable). While you don't need to reveal all security details, you must state that reasonable security practices are in place as required under Section 43A of the IT Act.
7. Grievance Redressal
Under the IT (Intermediary Guidelines) Rules, 2021 and DPDP Act, websites must appoint a Grievance Officer and provide their contact details. The Grievance Officer must be a resident of India. The privacy policy must include the officer's name, email, address, and response timeline (typically 24 hours for acknowledgement, 15 days for resolution).
8. Cookies Policy
Types of cookies used (essential, functional, analytical, advertising), purpose of each cookie category, cookie duration, and user's ability to manage cookies. Under the DPDP Act, consent is required for non-essential cookies.
9. Data Principal Rights
Detailed explanation of user rights (access, correction, erasure, withdrawal of consent, grievance, nomination) and the process for exercising each right.
10. Children's Data
Under the DPDP Act, data of children (under 18) requires verifiable parental consent. The privacy policy must address whether the website collects data from children, the parental consent mechanism, and special protections.
11. Amendments to Privacy Policy
Website's right to update the privacy policy. Notice and consent requirements for material changes.
12. Contact Information
Website owner's name, registered address, email, phone — the entity ultimately responsible for data protection.
ToS vs Privacy Policy: How They Work Together
Your ToS and Privacy Policy are interdependent documents that serve different but complementary purposes:
| Aspect | Terms of Service (ToS) | Privacy Policy |
|---|---|---|
| Purpose | Governs the relationship between website and user — what users can/cannot do | Discloses how user data is collected, used, stored, and protected |
| Legal basis | Indian Contract Act, 1872 (contract) | IT Act 2000, DPDP Act 2023 (statutory compliance) |
| Enforcement | Binds user through acceptance — breach = breach of contract | Binds website operator — violation = regulatory penalty + user claims |
| Key provisions | IP, prohibited uses, liability limitation, termination, jurisdiction | Data categories, consent, security, sharing, retention, user rights |
| Cross-reference | ToS should reference the Privacy Policy ("Your use is subject to our Privacy Policy") | Privacy Policy should reference the ToS for terms of service regarding data |
Together they protect you from: user lawsuits (contractual), regulatory penalties (statutory), IP theft (contractual), data breach liability (statutory), consumer complaints (both), and intermediary liability (the IT Act intermediary safe harbour requires both documents).
Step-by-Step Drafting Process
Step 1: Website/App Audit (1–2 Days)
Our legal team conducts a comprehensive audit of your digital platform — what data you collect, how you collect it, why you collect it, who you share it with, where you store it, and what third-party services you use (analytics, payment gateways, CRM, advertising networks).
Step 2: Compliance Assessment (1 Day)
We assess which legal frameworks apply to your specific platform: IT Act, DPDP Act, SPDI Rules, Consumer Protection (E-Commerce) Rules, Intermediary Guidelines, sector-specific regulations (health, finance, education), and international laws if you serve users from the EU (GDPR) or California (CCPA).
Step 3: Drafting (2–3 Days)
Our corporate lawyers prepare: (a) a comprehensive Terms of Service tailored to your platform type (e-commerce, SaaS, content platform, marketplace, social media), (b) a DPDP Act and IT Act compliant Privacy Policy, (c) a Cookies Policy, and (d) any sector-specific addendums required.
Step 4: Implementation Review (1 Day)
We review how the documents will be presented on your website — clickwrap acceptance mechanisms, cookie consent banner, privacy policy placement, grievance officer details display. We provide implementation guidance for your development team.
Step 5: Finalisation and Delivery (1 Day)
Documents delivered in HTML (ready for website integration) and Word formats. We also provide a compliance checklist for your development and operations teams.
Turnaround time: 5–7 working days for the complete documentation package. Express delivery within 48 hours available.
Consequences of NOT Having ToS & Privacy Policy
- Massive DPDP Act Penalties: Up to ₹250 crore for significant data fiduciaries, or up to ₹50 crore for other violations. Even a single user complaint can trigger an investigation.
- IT Act Penalties: Under Section 43A, failure to maintain reasonable security practices resulting in wrongful loss can lead to damages equal to the loss suffered. Class-action suits by affected users are possible.
- Loss of Intermediary Safe Harbour: Under Section 79 of the IT Act, intermediaries must have a ToS and privacy policy, a grievance mechanism, and comply with due diligence requirements to qualify for safe harbour protection. Without these, you are liable for all user-generated content on your platform.
- Consumer Complaints: Under the Consumer Protection (E-Commerce) Rules, e-commerce platforms must have specific disclosures. Non-compliance can result in complaints before consumer courts and the Central Consumer Protection Authority.
- User Distrust: 78% of Indian internet users say they would stop using a website that doesn't clearly explain how their data is used. A professional privacy policy builds trust and increases conversion.
- Investor Due Diligence Rejection: Investors now demand data protection compliance as a condition for investment. Websites and apps without proper ToS and privacy policies are considered high-risk and unattractive for investment.
- No Legal Recourse: Without a ToS, you have no contractual basis to take action against users who abuse your platform — whether it's scraping content, posting illegal material, or violating your IP rights.
Penalties Under DPDP Act & IT Act
| Violation | Applicable Law | Maximum Penalty |
|---|---|---|
| Failure to implement reasonable security practices | IT Act Section 43A | Damages for wrongful loss + ₹5 crore |
| Breach of personal data by data fiduciary | DPDP Act Section 32 | ₹250 crore |
| Failure to obtain valid consent | DPDP Act Section 32 | ₹50 crore |
| Failure to notify data breach | DPDP Act Section 32 | ₹25 crore |
| Failure to comply with data principal rights | DPDP Act Section 32 | ₹10 crore |
| Non-compliance with intermediary guidelines | IT Act Section 79 + Rules | Loss of safe harbour + court orders |
| Breach of confidentiality | IT Act Section 72 | ₹1 lakh + imprisonment up to 3 years |
Why Choose Affordable Legal Drafting?
- DPDP Act Specialists: Our legal team has deep expertise in the DPDP Act, 2023 and its implementation rules. We are among the first legal drafting platforms in India to offer DPDP-compliant privacy policies.
- Full IT Act Compliance: Every privacy policy we draft complies with Section 43A, SPDI Rules, Intermediary Guidelines, and the IT Act as a whole.
- Website and App Specific: We draft separate documentation for websites, mobile apps, e-commerce platforms, SaaS products, content platforms, and social media — each with industry-specific clauses.
- GDPR & CCPA Addendums: If you serve users from the EU or California, we add GDPR and CCPA-specific addendums to ensure international compliance.
- Implementation Support: We don't just give you documents — we guide you on how to implement them on your website including cookie consent banners, acceptance flows, and grievance display.
- Affordable Pricing: Complete ToS + Privacy Policy + Cookies Policy package starts at just ₹3,999. Add GDPR addendum for ₹1,999 extra.
Don't Risk Crores in Penalties — Get Your Website Compliant Today
With the DPDP Act now in force and IT Act penalties at historic highs, there has never been a more critical time to ensure your website or app has professionally drafted, legally compliant Terms of Service and Privacy Policy.
Order ToS + Privacy Policy Package — Starting ₹3,999Includes ToS, Privacy Policy, Cookies Policy, and implementation guide. Made in India, for Indian law.
Frequently Asked Questions (FAQ)
Is a privacy policy mandatory for every website in India?
Yes, if your website collects any personal data from users — including email addresses for newsletters, cookies for analytics, or account information for login — a privacy policy is mandatory under the IT Act and DPDP Act.
What is the difference between a privacy policy and a cookie policy?
A privacy policy covers all personal data handling practices. A cookie policy specifically addresses cookies and similar tracking technologies — what cookies are used, their purpose, duration, and how users can manage them. Many websites combine both, but a separate cookie policy is better practice under the DPDP Act.
Can I use a free privacy policy generator for my website?
Free generators produce generic, one-size-fits-all documents that often miss India-specific legal requirements, DPDP Act compliance, and sector-specific clauses. A custom-drafted policy from legal professionals is strongly recommended — the cost of non-compliance far exceeds the cost of proper drafting.
Do I need a separate privacy policy for my mobile app?
Yes. Mobile apps collect different data than websites (device ID, location, contacts, camera access, etc.) and require a privacy policy tailored to app-specific data collection. App store policies (Google Play, Apple App Store) also require a privacy policy link in the app listing.
How often should I update my ToS and privacy policy?
At minimum: (a) when your data practices change, (b) when new laws or regulations come into effect, (c) when you add new features or third-party services, and (d) annually as a best practice. We notify our clients of legal changes that require document updates.
What is the grievance officer requirement under Indian law?
Under the IT (Intermediary Guidelines) Rules, 2021, all intermediaries must appoint a Grievance Officer who is a resident of India. The officer's name, email address, phone number, and physical address must be published on the website. The officer must acknowledge complaints within 24 hours and resolve them within 15 days.
What are the age requirements under the DPDP Act?
Under the DPDP Act, a "child" is anyone under 18 years of age. Processing the personal data of children requires verifiable parental consent. Websites and apps that serve children must implement additional protections and cannot engage in behavioural monitoring or targeted advertising directed at children.