Rule 3 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Rule 3 says what the notice from a Data Fiduciary to a Data Principal must look like and contain. It must stand on its own, be written in clear and plain language, list the personal data item by item, state the purpose and the goods or services, and give a link and other means to withdraw consent, exercise rights and complain to the Board.
Rule 3 is in the group that, under rule 1(4), comes into force eighteen months after the date of publication of the Gazette. The notice must be understandable independently of any other information, give a fair account of the details needed for specific and informed consent, include at the minimum an itemised description of the personal data and the specified purpose with a description of the goods, services or uses, and give a communication link and means to withdraw consent, exercise rights and complain to the Board. It applies to every Data Fiduciary that asks for consent.
Where rule 3 sits
Rule 3 is the rule behind section 5 of the Act, which deals with the notice that accompanies a request for consent. The Act's own text is covered in Section 5 of the DPDP Act: the notice to the Data Principal; for consent obtained earlier see Section 5: notice for consent given before commencement. This article only explains what rule 3 adds. Rule 1(4) puts rule 3 in the eighteen-month group; counting from the Gazette date of 13 November 2025, eighteen months end in mid-May 2027; confirm the exact date of publication before relying on a date. The staging is set out in our article on rules 1 and 2.
If you are unsure how this lands on your consent screens, a legal consultation can map it. Rule 3 has three clauses, (a), (b) and (c). Clause (b) has two sub-clauses and clause (c) has three. All of them apply together.
Clause (a): the notice stands alone
The notice must "be presented and be understandable independently of any other information that has been, is or may be made available by such Data Fiduciary".
In plain terms, a person should not need to read the privacy policy, the terms of use or an earlier email to understand what she is being asked to agree to. A notice that says "see our policy for details" does not meet the clause if the details she needs are only in the policy. The clause does not forbid a separate privacy policy; it says the notice must not depend on one.
Clause (b): a fair account in clear and plain language
The notice must "give, in clear and plain language, a fair account of the details necessary to enable the Data Principal to give specific and informed consent for the processing of her personal data". The words "which shall include, at the minimum" follow, so the two items below are a floor, not a ceiling.
- (i) An itemised description of the personal data. A line such as "your information" is not an itemised description. Each category should be named: name, mobile number, delivery address, payment instrument details, location, and so on, as the business actually collects.
- (ii) The specified purpose or purposes, and a specific description of the goods or services to be provided or uses to be enabled by the processing. The purpose has to be tied to what the Data Principal gets. "To improve our services" does not describe goods or services; "to deliver your order and send delivery updates" does.
For the meaning of "specified purpose" the Rules rely on the Act, as rule 2(2) provides; see our article on the definition of specified purpose.
The phrase "specific and informed consent" is the Act's test of valid consent. How the Act states that test is covered in what valid consent requires under section 6. Rule 3 does not add to it; it says what the notice must contain so the test can be met.
Clause (c): link and other means
The notice must "give, the particular communication link for accessing the website or app, or both, of such Data Fiduciary, and a description of other means, if any, using which such Data Principal may" do three things:
| Sub-clause | What the Data Principal must be able to do | Detail in the Rule |
|---|---|---|
| (i) | Withdraw her consent | "with the ease of doing so being comparable to that with which such consent was given" |
| (ii) | Exercise her rights under the Act | No further detail in rule 3; rule 14 deals with how rights are exercised |
| (iii) | Make a complaint to the Board | No further detail in rule 3 |
Two points follow from the text. First, the link is "the particular communication link", meaning a specific link to the website or app, not a general home page address with no route to the right place. Second, "other means, if any" are described only where they exist; the Rule does not require a Data Fiduciary to create a postal or telephone channel, but if it offers one, the notice must describe it.
The ease-of-withdrawal comparison
Sub-clause (i) sets a comparison, not a fixed method. If a user gave consent with one tap on a banner, withdrawing it should be about as easy as that tap. If consent was given in a single click and withdrawal needs a signed letter, the comparison fails. The withdrawal itself is explained in section 6: withdrawal of consent.
Rights and complaints
Sub-clause (ii) points to rights under the Act, and the Rules deal with the manner of exercising them in rule 14, which we cover in how Data Principals exercise their rights. Sub-clause (iii) points to the Board; rule 3 does not say how a complaint is made, and what the Board has published for that is not in the Rules as notified.
A worked example
FitTrack, an invented fitness app, wants to ask new users for consent. A notice that complies with rule 3 would show, on one screen: the items of personal data collected (name, date of birth, mobile number, step count, heart-rate readings); the purpose (to create the account, to show a daily activity summary, to send workout reminders); a link to the app's settings page where consent can be withdrawn in one step; the in-app route to raise a request about her rights; and how to complain to the Board. The same screen should make sense without opening the privacy policy. The Rules contain no Illustration for rule 3, so the example is ours.
What rule 3 does not say
The Rule does not prescribe a language other than "clear and plain", a format, a font size or a length. It does not name any language beyond the requirement of plain language. It does not name a penalty for a defective notice. For penalties see the site's article on the Schedule to the Act. Check later amendments and notifications.
Need help with your DPDP notice?
A notice is the first thing a regulator or a customer sees. We can review your current consent screens and privacy documents against rule 3, clause by clause. Speak to our legal team and bring your sign-up flow along.
Key takeaways
- Rule 3 falls in the group that starts eighteen months after the date of publication of the Gazette (rule 1(4)).
- The notice must be understandable independently of any other information the Data Fiduciary has made available.
- It must give a fair account in clear and plain language, with at the minimum an itemised description of the personal data and the specified purpose with a specific description of goods, services or uses.
- It must give the particular communication link to the website or app, and describe other means, if any, to withdraw consent, exercise rights and complain to the Board.
- Withdrawal must be as easy as giving consent ("comparable").
- Rule 3 states no penalty; check later amendments and notifications.
Read next
- Rules 1 and 2: staged commencement and definitions
- Rule 14: how Data Principals exercise their rights
- Privacy policy draft, DPDP compliant
- Section 5 of the DPDP Act: the notice to the Data Principal
Disclaimer: Based on the Digital Personal Data Protection Rules, 2025 as notified in the Gazette of India on 13 November 2025 (G.S.R. 846(E)), as consulted on 2 October 2026. The Rules come into force in three stages under rule 1; later amendments, notifications and anything published by the Data Protection Board of India should be checked. This article is general information, not legal advice; check the official text before acting.
