Day 20 of 22DPDPA · India Privacy· ~60 min
Draft privacy notice + consent mechanism
Scenario
KaizenMotors is launching a customer portal — allowing dealers to check part availability, pricing, warranty status. You must design the DPDPA-compliant privacy notice + consent flow BEFORE launch.
Your role
You are the DPO reviewing the launch.
Your task
Produce: 1. Privacy notice (Board-signable, ~600 words) — plain language, DPDPA-compliant 2. Consent flow design (screen-by-screen) 3. Consent revocation mechanism 4. Preference centre design (what customer can toggle) 5. Audit-log requirements (proving consent when regulator asks)
Deliverable format: Complete privacy-notice document + consent-flow wireframe (text description)
Toolkit
- DPDPA requires: itemised purposes, retention period, DPO contact, rights disclosure, plain language
- Consent flow: cannot be bundled (each purpose separately opt-in)
- Preference centre: real time, per-purpose, machine-readable log
- Consent must be as easy to WITHDRAW as to GIVE (equal friction)
Success criteria (what the AI grades against)
- Privacy notice is in plain language (no legalese)
- Each purpose is individually consentable (not bundled)
- Retention period stated per purpose
- Withdrawal mechanism is as accessible as consent
- Audit log requirements include: timestamp, IP, version of notice, exact toggle state
Log in to submit your deliverable for AI review.
Log in / Register