By country

Terms & Conditions Generator India

The Digital Personal Data Protection Act 2023 and its Rules - consent notices, Consent Managers and verifiable parental consent.

Generate your terms and conditions Read the terms and conditions guide

Indian terms sit alongside the IT Rules 2021, which require intermediaries to publish rules of use, appoint a grievance officer and act on takedown notices within fixed timelines. Consumer protection e-commerce rules add their own disclosure duties.

India’s Digital Personal Data Protection Act 2023 replaced the older IT Rules framework with a consent-centric statute. It applies to digital personal data processed in India, and to processing outside India connected with offering goods or services to people in India.

The Act is structurally different from GDPR. There is no legitimate interests basis: processing rests on consent or on a defined set of "legitimate uses". Notices must be standalone, plain, and available in English or any of the languages in the Eighth Schedule of the Constitution. A new intermediary role, the Consent Manager, is registered with the Data Protection Board.

The children’s rules are unusually strict. Verifiable parental consent is required for anyone under eighteen, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright rather than merely restricted.

What a terms and conditions in India has to cover

How India actually moves personal data

Consent notices as standalone artefacts

The DPDP notice cannot be buried in a longer policy - it must be a clear, standalone communication itemising the data, the purpose and the rights, presented alongside the request for consent.

Multilingual delivery

Data principals may require the notice in any Eighth Schedule language, which turns translation into a compliance obligation rather than a nicety.

Consent Managers

A registered intermediary through which people can give, manage, review and withdraw consent. If you integrate with one, that relationship needs describing.

Grievance redressal

Both the DPDP Act and the IT Rules require a route to raise a complaint with the business before escalating - the Act to the Data Protection Board, the Rules to a named grievance officer.

Cross-border transfers

Permitted by default except to countries the Government restricts by notification, which inverts the GDPR model of default prohibition with exceptions.

Third parties the draft will ask you about

Razorpay · PayU · Paytm · UPI rails · AWS ap-south-1 · Zoho · Delhivery · MSG91 · Google Workspace

The rules that apply

DPDP Act 2023

Consent or legitimate uses as the only bases, itemised notice requirements, and penalties up to ₹250 crore for failures to prevent a breach.

DPDP Rules

Operational detail on notice content, Consent Manager registration and obligations, breach reporting to the Board, and retention limits for classes of data fiduciary.

Verifiable parental consent

Required for all users under eighteen, with tracking and targeted advertising to children prohibited.

Significant Data Fiduciaries

A designation bringing extra duties: a Data Protection Officer based in India, independent audits and algorithmic due diligence.

IT Rules 2021

Intermediary obligations that continue to apply, including a published privacy policy, grievance officer and takedown timelines.

What the generated terms and conditions contains

DPDP implementation order

  1. Rebuild consent capture around itemised notices

    One notice per purpose, standalone, in plain language, with a withdrawal route as easy as the grant.

  2. Set the age gate to eighteen

    And build a verifiable parental consent flow that does not itself over-collect.

  3. Name a grievance officer and publish response times

    Required by the IT Rules and expected under the Act’s redressal duty.

  4. Assess whether you are a Significant Data Fiduciary

    If designated, appoint an India-based DPO and schedule independent audits.

  5. Plan for multilingual notices

    At minimum English plus the languages of your largest user bases.

Where this usually goes wrong

Relying on legitimate interests

There is no such basis in the DPDP Act. A GDPR-shaped policy that leans on legitimate interests describes a basis Indian law does not recognise.

Age-gating at thirteen

The Indian threshold is eighteen, with verifiable parental consent below it. This is the widest child-protection band of any major regime.

Burying the notice inside the privacy policy

The Act requires a standalone, itemised notice presented with the consent request.

No grievance officer named

The IT Rules require the name and contact of a grievance officer to be published, with response timelines.

Behavioural advertising to under-eighteens

Prohibited, not merely consent-gated. Ad targeting stacks that rely on age-agnostic profiling are non-compliant by default.

Frequently asked questions

Does the DPDP Act apply to companies outside India?

Yes, where the processing relates to offering goods or services to data principals in India. Physical presence is not required.

Is there a legitimate interests basis in Indian law?

No. Processing rests on consent or on the enumerated legitimate uses - employment, emergencies, legal obligations and similar. The GDPR balancing test has no equivalent.

What is a Consent Manager?

A registered intermediary that lets people give, manage, review and withdraw consent across services through a single interface. It is a distinctive feature of the Indian regime.

What age counts as a child under the DPDP Act?

Under eighteen. Verifiable parental consent is required, and tracking and targeted advertising directed at children are prohibited.

Are terms and conditions legally binding?

They are when the user had a genuine opportunity to read them and took a positive step to accept. Clickwrap - a ticked box next to a visible link - holds up far more reliably than a "by using this site you agree" line in the footer.

What is the difference between terms of service and terms and conditions?

Nothing substantive. "Terms and conditions" is the more common phrasing in the UK and Commonwealth markets, "terms of service" in the US and in SaaS. The clauses do the same job.

Can I limit my liability to zero?

No. Most consumer regimes void attempts to exclude liability for death, personal injury or fraud, and unfair-terms rules strike out caps a court considers unreasonable. A cap that is drafted to survive review is worth more than one that is struck out entirely.

Do I need terms if I sell nothing?

If users can register, post, comment or upload, yes - the terms are what let you moderate, suspend and remove content without being in breach of contract yourself.

Terms & Conditions Generator India

Answer a short questionnaire and get a draft written for India. Free to start, no card required.

Generate your terms and conditions

Other documents for India

Each one is written for the same context, not a generic template.

The same document, by country

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.