Privacy Policy and Terms & Conditions for Your Website — What Indian Law Requires

અપડેટ કર્યું: લેખક WakilBhai Editorial Teamસમીક્ષક Adv. Sneha Iyer, Bar Council of Tamil Nadu & Puducherry, TN/1187/2013
60 સેકન્ડનો જવાબ

Any website or app collecting user data in India needs a privacy policy — the IT Act's SPDI Rules require one, and the DPDP Act, 2023 adds consent, purpose-limitation and grievance duties with penalties up to ₹250 crore for serious breaches. Terms & Conditions are your user contract: liability caps, acceptable use, refunds, governing law. Both drafted for ₹499 each.

DPDP penalties to ₹250 croreConsent + purpose limitation₹499 per document

કાનૂની સમયમર્યાદા

  1. Day 0Before collecting any data (policy must precede collection)
  2. At signupConsent capture (clear, affirmative, purpose-specific)
  3. Defined windowGrievance officer response (publish the contact + respond)
  4. On breachBreach notification (to the Data Protection Board + users)

પગલું-દર-પગલું: શું કરવું

  1. 1

    Privacy policy: the legally required disclosures

    What you collect, why, with whom shared, how long kept.

    વિગતો જુઓ

    Under the SPDI Rules 2011 (IT Act s.43A regime) and the DPDP Act, 2023: disclose what personal data you collect, the specific purposes, third parties it is shared with (analytics, payment gateways, hosting), retention periods, security practices, user rights (access, correction, erasure), and the grievance officer's contact. Cookie and tracking disclosure belongs here too. Copy-pasted US policies fail Indian requirements — they miss the grievance officer and DPDP rights entirely.

    અમે આ તમારા માટે કરીએ છીએ — ₹499
  2. 2

    DPDP Act compliance basics

    Consent, purpose limitation, children's data, breach duties.

    વિગતો જુઓ

    The DPDP Act requires free, specific, informed, affirmative consent (pre-ticked boxes don't count) or a legitimate-use ground; data used only for stated purposes; verifiable parental consent for under-18s (and no tracking/targeted ads at children); reasonable security; and breach notification to the Data Protection Board and affected users. Penalties scale to ₹250 crore for serious security failures. Small businesses aren't exempt — obligations attach to processing, not size.

  3. 3

    Terms & Conditions: your user contract

    Acceptable use, liability caps, refunds, IP, disputes.

    વિગતો જુઓ

    The T&C should cover: account rules and acceptable use, your IP in the platform vs licence to user content, service availability disclaimers and limitation of liability (capped at fees paid is standard), refund/cancellation policy (mandatory disclosure for e-commerce under the Consumer Protection E-Commerce Rules 2020), termination rights, governing law + jurisdiction/arbitration. E-commerce additionally needs seller details, grievance officer, and country-of-origin disclosures.

    અમે આ તમારા માટે કરીએ છીએ — ₹499
  4. 4

    Deploy them so they actually bind

    Clickwrap beats browsewrap; version and date everything.

    વિગતો જુઓ

    Make acceptance explicit: an "I agree" checkbox at signup/checkout (clickwrap) is enforceably a contract; a footer link nobody clicks (browsewrap) is weak. Date and version the documents, log acceptances, present material changes for fresh consent, and keep the grievance officer's details current. Add the refund policy at the point of sale — hidden terms lose in consumer forums regardless of what they say.

ખર્ચ અને શું અપેક્ષા રાખવી

  • Privacy policy drafting

    SPDI + DPDP compliant, WakilBhai

    ₹499
  • Terms & conditions drafting

    Incl. e-commerce rule disclosures

    ₹499
  • Refund policy add-on

    Where selling products/services

    ₹499
  • DPDP compliance consultation

    Consent flows + data mapping basics

    ₹299

These documents are compliance floors, not shields against everything — align what the policy says with what your systems actually do; a policy promising deletion you don't perform is itself the violation.

આ સમસ્યા માટે મફત ફોર્મેટ

વારંવાર પૂછાતા પ્રશ્નો

My website only has a contact form. Do I still need a privacy policy?

Yes — names, emails and phone numbers are personal data; collecting them triggers the disclosure duties. A short-form policy suffices for minimal collection, but it must exist, name the purposes, and give the grievance contact.

Does the DPDP Act apply to my small business?

Yes — it applies to digital personal data processing regardless of business size (with narrow exemptions for purely personal/household use). Penalties are capped case-wise by the Data Protection Board, which weighs gravity — but "we are small" is not an exemption; basic consent + security + grievance compliance is the floor.

Can I just copy a privacy policy from another website?

It will describe their data practices, not yours — which creates the worst position: published promises you don't follow. Indian requirements (grievance officer, SPDI/DPDP rights language) are also missing from most foreign templates. A tailored ₹499 draft costs less than one consumer-forum complaint.

Are my Terms & Conditions actually binding on users?

Yes, when acceptance is real: clickwrap "I agree" at signup binds like a signed contract, and Indian courts enforce reasonable terms (liability caps, jurisdiction, arbitration). Unconscionable terms and hidden material conditions — especially against consumers — get struck; keep refunds and key limits prominent.

What is legally mandatory for an e-commerce site specifically?

The Consumer Protection (E-Commerce) Rules 2020: seller/business details, grievance officer with response timelines, refund-return-exchange policy, country of origin, no manipulated reviews/prices; plus GST-compliant invoicing and the privacy obligations. Marketplaces carry additional duties for listing third-party sellers.

આ પેજ ફક્ત સામાન્ય માહિતી માટે સામાન્ય કાનૂની પ્રક્રિયા સમજાવે છે. આ કાનૂની સલાહ નથી. તમારી પરિસ્થિતિ માટે લાયક વકીલનો સંપર્ક કરો.