Day 20 of 22DPDPA · India Privacy· ~60 min

Draft privacy notice + consent mechanism

Scenario

KaizenMotors is launching a customer portal — allowing dealers to check part availability, pricing, warranty status. You must design the DPDPA-compliant privacy notice + consent flow BEFORE launch.

Your role

You are the DPO reviewing the launch.

Your task

Produce: 1. Privacy notice (Board-signable, ~600 words) — plain language, DPDPA-compliant 2. Consent flow design (screen-by-screen) 3. Consent revocation mechanism 4. Preference centre design (what customer can toggle) 5. Audit-log requirements (proving consent when regulator asks)

Deliverable format: Complete privacy-notice document + consent-flow wireframe (text description)

Toolkit

  • DPDPA requires: itemised purposes, retention period, DPO contact, rights disclosure, plain language
  • Consent flow: cannot be bundled (each purpose separately opt-in)
  • Preference centre: real time, per-purpose, machine-readable log
  • Consent must be as easy to WITHDRAW as to GIVE (equal friction)

Success criteria (what the AI grades against)

  • Privacy notice is in plain language (no legalese)
  • Each purpose is individually consentable (not bundled)
  • Retention period stated per purpose
  • Withdrawal mechanism is as accessible as consent
  • Audit log requirements include: timestamp, IP, version of notice, exact toggle state

Log in to submit your deliverable for AI review.

Log in / Register