Legal Register
Interactive Checklist
C-01 Notice & Consent Product Manager & UX Designer

The 13-Point Notice Content Checklist

Exhaustive 13-point statutory compliance checklist for digital personal data notice design under Section 5(1) of the DPDP Act 2023 and Rule 3 of the DPDP Rules 2025.

Statutory Source: s.5(1)(i)–(iii) + r.3 itemised-data/specific-purpose/independent-comprehensibility; Appendix A.8 notice row
Total Verification Points: 13 Audit Checks
C-01s.5(1)(i)–(iii) + r.3 itemised-data/specific-purpose/independent-comprehensibility; Appendix A.8 notice row

The 13-Point Notice Content Checklist

Does your notice clear r.3? Most don't itemise

Readiness Score
0 / 13 checks
0%
State automatically persisted in browser localStorage

Statutory Grounding & Legal Perimeter

Mandatory statutory clauses, rules, and gazette requirements enforceable under this checklist.

Enforceable Provisions:
Section 5(1)Section 5(2)Section 5(3)Rule 3Rule 3(1)Rule 3(2)
Statutory Context:
This checklist is directly anchored in s.5(1)(i)–(iii) + r.3 itemised-data/specific-purpose/independent-comprehensibility; Appendix A.8 notice row. Failure to maintain verifiable affirmative proof of compliance exposes the enterprise to severe adjudication penalties under Section 33 (Schedule) of the DPDP Act.

Target Architecture & Impacted Systems

Enterprise applications, stores, and integration surfaces evaluated by this checklist.

View Full Systems Topology (SYS-001..014)

Associated Operational Controls (54 OBLs)

Control Master Matrix obligations directly tested by this checklist.

Open Control Matrix →

Audit & Implementation Guidance

Best practices for establishing evidence, avoiding traps, and conducting periodic assurance.

Evidence Retention Standard

Do not rely solely on policy documents or statements of intent. Ensure verifiable evidence artifacts (cryptographic logs, test manifests, signed DPA agreements, or automated crawler receipts) are archived for at least 1 year.

Common Implementation Trap

Avoid declaring compliance based on frontend UI alone. The Data Protection Board evaluates the full data pipeline, including database persistence, read replicas, cache invalidation, and third-party processor synchronization.