validation block. These obligations apply
from 13 May 2027 (Rules r.1).
What r.3 asks for
A notice is to be understandable on its own and give an itemised description of the personal data, the specific purposes and the goods, services or uses they enable, and a link and means to withdraw consent (as easily as it was given), to exercise the principal’s rights and to complain to the Data Protection Board, in English or a language of the Eighth Schedule to the Constitution.Fields
All are optional. Notices created before these fields existed return them as
null.
The validation block
DPDP_NOTICE_REQUIRE_RULE3=true (off by default), a notice
missing any element, or in a language outside the list below, is refused with
400 NOTICE_INCOMPLETE and enforced is true.
Languages
language is a BCP 47 tag. For the language element, its primary subtag is
compared with the ISO 639 codes below, case-insensitively, so hi, hin and
hi-IN are all Hindi.
One version, several languages
The samenoticeId and version may be registered once per language, each
with its own content and hash. A consent record names the language shown in
consentNoticeLanguage (Create Consent Record):
without a pinned version it binds the newest notice row in that language, so a
translation of an older version registered later does not displace a newer
version. Without consentNoticeLanguage the record binds, as before, the
pinned version (or the version of the newest notice row in any language) and
the newest row of that version, and records that row’s language. With
DPDP_REQUIRE_NOTICE_LANGUAGE=true (off by default) a version that exists in
more than one language needs consentNoticeLanguage instead
(400 NOTICE_LANGUAGE_REQUIRED). A version in a single language never needs it.
The notice hash
contentHash is the SHA-256 of content alone, as before. noticeHash
covers the whole notice: it is the SHA-256 (lowercase hex) of the UTF-8 bytes
of the RFC 8785 canonical JSON of an object with the members noticeId,
version, language, title, content, purposes, dataFiduciaryContact,
grievanceOfficer, itemisedPersonalData, purposeDetails, withdrawalUrl,
rightsUrl, boardComplaintUrl and contact, each as stored and null when
absent. Two notices with the same text but different structured fields,
language or version have different notice hashes. A consent record stores the
notice hash of the notice it was given against, and its signed proof carries
it as noticeHash with consentNoticeLanguage. Notices created before the
notice hash was kept have it computed from the stored row when read.