Free · No Sign-up · Instant

DPDP Privacy Policy Generator
for Businesses

Answer 8 simple steps — your policy renders live. Download as .html or .txt.

Step 1 of 9 Business info
Step 1 — Required

Tell us about your business

This goes directly into your policy as the Data Fiduciary — the company responsible for your users' data under the DPDP Act.

Step 2 — DPDP

What personal data do you collect?

Click the chips that apply to your business. Add your own by typing in the field below. Under DPDP, you must disclose every category of data you collect.

Pre-selected = most businesses collect this. Unselect what you don't collect.
Financial, health, biometric. Leave all unselected if not applicable.
Step 3 — DPDP

Why do you collect this data?

Under the DPDP Act, you must state a specific, lawful purpose for every data type you collect. Select all that apply to your business.

Step 4 — DPDP

How long do you keep the data?

Under DPDP Act, you must delete data once the purpose is fulfilled. Specify your retention periods and how users can request deletion.

Data CategoryRetention PeriodLegal Basis for Retention
Step 5 — DPDP

Who do you share data with?

Select all third-party processors you use. These become your Data Processors under the DPDP Act — you're responsible for ensuring they protect your users' data too.

Do you sell personal data for commercial purposes? Selling, renting, or trading user data to third parties for their own use.
Step 6 — DPDP

What security measures do you have?

The DPDP Act requires "reasonable security safeguards." Select everything you've implemented — this goes directly into your policy.

Step 7 — DPDP

Special cases — toggle what applies

These sections are required in your policy regardless. Toggle on to provide specific details; toggle off for the standard DPDP-compliant language.

Cookies & tracking technologies Cookies, pixels, web beacons, local storage used on your website / app.
Children's data Your platform is used by, or processes data of, individuals under 18.
Cross-border data transfers Data is transferred to or stored in servers outside India.
Step 8 — DPDP

Grievance Officer details

The DPDP Act requires you to designate a Grievance Officer who Data Principals can contact about their rights. This is mandatory — without it your policy is incomplete.

Step 9 — Your Policy

Your DPDP privacy policy is ready

Review it below, then copy or download. Share the HTML file directly on your website, or copy the text into your CMS.

Generated Policy

Policy will appear here

Click "Generate My Policy" on step 8 to build your document.

✓ Done

Who needs a DPDP-compliant privacy policy?

If your business collects any personal data from individuals in India through a website or app, the DPDP Act, 2023 applies to you — regardless of company size.

🛒
E-commerce & D2C brands Collect names, addresses, payment data, and order history from customers.
💻
SaaS & tech startups Process user accounts, usage analytics, and billing data.
🎓
EdTech platforms Handle student data, often including minors — heightened DPDP obligations apply.
🏦
Fintech & NBFC Process sensitive financial data, KYC, Aadhaar, and PAN — strict DPDP requirements.
🏥
Healthcare apps Collect sensitive health records — among the most regulated under DPDP.
🌍
Foreign companies with Indian users DPDP applies to any entity processing data of individuals in India, wherever you're headquartered.