The legal pages every Indian business website needs
TL;DR: Indian websites sit under at least four separate legal regimes, and each one imposes its own disclosure requirements. The DPDP Act governs the privacy notice. The IT Rules require a published grievance officer. The Consumer Protection E-Commerce Rules require seller identity, refund and grievance disclosures for anyone selling online. Payment gateways impose their own checklist before they will approve a merchant account.
The result is a set of pages most Indian business sites are missing at least half of. The two most commonly absent are also the two most visible to a regulator: a named grievance officer with contact details, and a privacy notice that states specific purposes rather than boilerplate. Neither takes long to fix.
Which laws actually apply to your site
Most site owners think of this as one question with one answer: do I need a privacy policy? The reality is four overlapping regimes, each with its own trigger.
The Digital Personal Data Protection Act 2023, operational since the DPDP Rules were notified on 13 November 2025, with full compliance required by 13 May 2027. It governs how you collect and process personal data and what your notice must tell people. It applies to any site collecting a name, email or phone number, which is effectively all of them.
The Information Technology Act 2000 and the IT Rules 2021. The Rules require intermediaries to publish the name and contact details of a Grievance Officer and to acknowledge complaints within defined timelines. The definition of intermediary is broader than most people assume, and in practice publishing a grievance contact has become standard expected practice for Indian business sites regardless of exact classification.
The Consumer Protection (E-Commerce) Rules 2020. These apply to anyone selling goods or services online to consumers in India. They require disclosure of the seller's legal name, principal geographic address, contact details, and clear information on returns, refunds, exchanges, warranties, delivery and grievance redressal. They also require appointment of a grievance officer with published details and defined response timelines.
Contract and payment requirements. Terms of service are what make your commercial relationship enforceable. Separately, Indian payment gateways impose their own documentation checklist as a condition of onboarding, and it is stricter than the law in some respects.
The overlap is significant, which is good news: a well-built set of five or six pages satisfies all four. The problem is that most sites have two of them, copied from a template written for a US company in 2018.
The privacy policy, rewritten for DPDP
Under the DPDP Act the privacy notice is not a legal disclaimer. It is the document that makes consent informed, which means a notice nobody can understand undermines the consent it was supposed to support.
That reframing changes how it should be written. Shorter, more specific, in plain language.
What it needs to contain:
The specific personal data you collect. Not "certain information." The actual fields: name, email, phone, shipping address, IP address, payment details, whatever it is.
The specific purpose for each. This is where template policies fail hardest. "To improve our services" is not a purpose. "To deliver your order and send delivery updates by SMS" is. Purpose limitation is a core principle of the Act, and a notice that cannot state a purpose is describing collection you may not be entitled to do.
How consent is obtained and how it can be withdrawn. Including that withdrawal must be as easy as granting, with a working mechanism, not a paragraph about clearing browser cookies.
The rights available to Data Principals. Access, correction, erasure, grievance redressal, and nomination. State them plainly and explain how to exercise each.
Your grievance officer's contact details. Name or designation, email, and a response commitment.
How to complain to the Data Protection Board if your response is unsatisfactory.
Third parties who receive the data. Your processors: hosting, email, analytics, payment gateway, CRM, shipping partner. Categories at minimum, named where practical.
Retention periods. How long you keep each category and what triggers deletion. Vague indefinite retention is difficult to reconcile with the Act's storage limitation expectations.
Cross-border transfer position. Where data goes if it leaves India. The Act permits transfer to jurisdictions not specifically restricted, but the notice should say where.
Children's data. If you process data of anyone under eighteen, verifiable parental consent is required and the notice must explain it.
Language availability. The Act contemplates notices in English or Eighth Schedule languages. If a large share of your audience does not read English, an English-only notice sits awkwardly against the informed-consent requirement.
Two habits worth building in from the start. Version the document, so you can tell later which text a given user agreed to. And date it visibly, because an undated privacy policy tells a regulator nobody has reviewed it.
The grievance officer requirement nobody follows
This is the single most commonly missing element on Indian business websites, and it is also among the easiest to fix.
Multiple regimes converge on it. The IT Rules 2021 require intermediaries to publish a Grievance Officer's name and contact details. The E-Commerce Rules 2020 require e-commerce entities to appoint a grievance officer and display the name, contact details and designation. The DPDP Act requires a Data Fiduciary to publish the contact details of a person able to answer questions about data processing.
What has to be published, at minimum: a name or clear designation, a working email address, a contact number or postal address, and a stated timeframe for acknowledgement and resolution. Under the E-Commerce Rules the expectation is acknowledgement within 48 hours and resolution within a month.
Common failures, all of them easy to spot from outside:
A support@ address with no named person. A grievance page that lists a form and no contact details. A named officer who left the company two years ago. A stated response time with no process behind it. And most often, nothing at all.
A small business can appoint a founder or an operations lead. The role does not require a legal qualification. It requires a real person who will actually see the email, because an unmonitored grievance address is arguably worse than none: it publicly commits you to a timeline you are visibly not meeting.
Terms of use and terms of service
Terms are the contract between you and your users, and they matter most in the situations nobody plans for: a chargeback dispute, a user who abuses your service, a customer who claims you promised something you did not.
Core elements for a typical Indian business site:
Who you are, as a legal entity, with registration details. What the service is and what it is not. Eligibility, including the age threshold. Account rules if you have accounts. Acceptable use, listing what will get someone suspended. Payment terms, pricing, taxes and billing cycle. Intellectual property, covering both your content and any content users submit. Limitation of liability. Termination rights, on both sides. Governing law and jurisdiction, which for an Indian business means Indian law and a named city's courts. And how you notify users of changes to the terms.
Two India-specific notes.
Jurisdiction should be a real place where you can actually litigate. A template naming Delaware courts is not useful to a business operating from Pune.
And GST treatment should be stated clearly: whether displayed prices include GST, and that a GST invoice will be issued. Business customers will ask, and a clear statement prevents disputes at invoice time.
Keep terms and privacy separate. They serve different functions, they are triggered by different laws, and bundling consent to data processing into acceptance of terms is exactly the unconditional-consent problem the DPDP Act prohibits.
Which pages you need, by business type
| Page | Blog / content site | SaaS or service | E-commerce | Marketplace |
|---|---|---|---|---|
| Privacy Policy | Required | Required | Required | Required |
| Grievance Officer details | Required | Required | Required | Required |
| Terms of Use / Service | Recommended | Required | Required | Required |
| Refund & Cancellation | Not applicable | Required | Required | Required |
| Shipping & Delivery | Not applicable | Not applicable | Required | Required |
| Entity & contact disclosure | Recommended | Required | Required | Required |
| Cookie / consent notice | Required | Required | Required | Required |
| Seller details disclosure | Not applicable | Not applicable | Required | Required per seller |
| Pricing & tax disclosure | Not applicable | Required | Required | Required |
The column that surprises people is the first. A content site that runs analytics and a newsletter is processing personal data and needs a privacy notice, a consent mechanism and a grievance contact, even though it sells nothing.
Entity disclosure and contact details
The E-Commerce Rules require anyone selling online to display the legal name of the entity, the principal geographic address of its headquarters, and contact details including email and phone.
This is not the same as a contact form. A form is a convenience. The rules contemplate published details a customer can use without your permission.
What to display: registered legal name as it appears on incorporation documents, not just the brand name. Registered office address. A working phone number. A working email address. GSTIN where applicable. CIN or LLPIN for companies and LLPs.
Where to display it: the footer, a dedicated contact page, and ideally within the terms.
The objection is predictable. Sole proprietors and home-based businesses do not want a residential address on the public internet, and that is a reasonable concern. The practical answers are a virtual office address, a registered coworking address, or a proper business registration that gives you a commercial address to publish. What is not a good answer is publishing nothing, because a site selling to consumers with no identifiable entity behind it fails both the rules and the trust test.
There is a commercial dimension too. Transparent entity details reduce chargebacks and improve conversion, because customers are measurably more willing to buy from a business that is identifiable. This is one of the rare compliance requirements that pays for itself.
What payment gateways check before approving you
Indian payment gateways run their own compliance review before activating a merchant account, and it catches out businesses that assumed the law was the only bar.
The recurring checklist across major Indian gateways:
A privacy policy, live and accessible. Terms and conditions, live and accessible. A refund and cancellation policy with specific timelines, not "refunds at our discretion." A shipping and delivery policy for physical goods, with realistic timeframes. Contact details including a phone number. Clear pricing in Indian rupees. A description of products or services that matches your stated business category. And no prohibited categories, which is where onboarding most often fails unexpectedly.
Two practical points.
The pages must be live before you apply. Gateways check the URLs. A merchant application submitted while the policy pages return 404 gets rejected, and reapplying takes longer than getting it right the first time.
Refund timelines must be specific. "Refunds processed within 7 working days of approval" passes. "Refunds may be processed at the company's discretion" does not, and it is the most common rejection reason after category mismatch.
If you are launching a store, build these pages during development rather than treating them as a launch-week task. Gateway approval sits on your critical path and the pages are a dependency for it.
Where these pages live and how they should behave
Small implementation details that determine whether these pages do their job.
Footer links on every page. Not just the homepage. A customer who lands on a product page from an ad should reach the refund policy in one click.
Stable, readable URLs. /privacy-policy, /terms, /refund-policy, /grievance-redressal. Do not change them once payment gateways and any published notice have referenced them.
Indexable. Do not noindex these pages. They are a trust signal and gateways check them.
Dated and versioned. A visible last-updated date, and an internal version history so you can establish which text applied when.
Accessible without an account. A policy behind a login is not published.
Plain HTML, not a PDF. PDFs are harder to read on mobile, harder to update, and less accessible.
Mobile readable. Most Indian traffic is mobile. A wall of 11px grey text in a fixed-width container is technically published and practically not.
Fast. These pages get crawled and checked by third parties. On a well-configured host they should be near-instant, which our note on Core Web Vitals covers more broadly.
One more thing: keep an archive. When you update a policy, keep the previous version. If a dispute arises about terms that applied eighteen months ago, the archived version is the only way to establish what they were.
FAQs
What legal pages are mandatory for an Indian website?
At minimum a privacy policy and published grievance officer contact details, which apply to essentially every site collecting personal data. Businesses selling online additionally need terms of service, a refund and cancellation policy, shipping and delivery information where physical goods are involved, and disclosure of the legal entity name, address and contact details under the Consumer Protection E-Commerce Rules 2020.
Do I need a privacy policy if my website only has a contact form?
Yes. A contact form collects a name, email and often a phone number, all of which are digital personal data under the DPDP Act. The obligation is triggered by processing personal data, not by selling anything, so blogs, portfolios and brochure sites that run analytics or a newsletter are equally in scope.
What is a grievance officer and does my small business need one?
A grievance officer is a named contact responsible for receiving and resolving user complaints, required under the IT Rules 2021 and the E-Commerce Rules 2020, with a parallel requirement under the DPDP Act to publish a contact for data processing questions. Small businesses can appoint a founder or operations lead; no legal qualification is required. Publish a name or designation, a working email, and a stated response timeframe.
How quickly must a grievance be resolved in India?
Under the Consumer Protection E-Commerce Rules 2020, complaints should be acknowledged within 48 hours and resolved within one month of receipt. Publishing those timelines without a process to meet them creates a visible commitment you are failing, so appoint someone who actually monitors the address before you publish the page.
Can I use a privacy policy template or generator?
As a starting structure, yes, but a generated policy will not be compliant as-is. It will state generic purposes rather than your specific ones, omit the grievance officer, miss the DPDP rights and withdrawal mechanics, and misstate your actual data flows. Use the template for structure and rewrite the substance to describe what your site genuinely does.
Do I need to publish my home address if I run a business from home?
The E-Commerce Rules require the principal geographic address of the entity's headquarters, which is a real problem for home-based sellers. The practical options are a virtual office address, a registered coworking address, or business registration that provides a commercial address. Publishing nothing is not a viable alternative for a business selling to consumers.
What does a payment gateway require before approving a merchant account?
Live and accessible privacy policy, terms and conditions, a refund and cancellation policy with specific timelines, shipping and delivery information for physical goods, contact details including a phone number, pricing in rupees, and a product description matching your stated business category. The pages must be live at the time of application, since gateways check the URLs directly.
Do terms and conditions need to be separate from the privacy policy?
Yes, keep them separate. They serve different purposes and derive from different legal requirements, and bundling consent to data processing into acceptance of terms conflicts with the DPDP Act's requirement that consent be unconditional and specific. Two documents, two decisions, two separate acceptance mechanisms.
What jurisdiction should my terms of service specify?
For an Indian business, Indian law and the courts of a city where you can realistically litigate, typically where your registered office is. Template terms naming a US state are common on Indian sites and practically useless. State the governing law and the exclusive jurisdiction clearly in a single clause.
Should legal pages be indexed by Google?
Yes. Do not add noindex to these pages. They function as trust signals, payment gateways and partners check them directly, and search engines surfacing your refund policy for a customer query is a useful outcome rather than a harmful one.
How often should I update my legal pages?
Review them at least annually, and immediately whenever your data practices change, you add a vendor that processes personal data, you change refund terms, or the law changes. The DPDP compliance deadline of 13 May 2027 makes 2026 a natural review point. Keep a visible last-updated date and archive previous versions.
What happens if my website has no legal pages at all?
You are exposed on several fronts at once: potential DPDP penalties for processing personal data without valid notice and consent, non-compliance with E-Commerce Rules disclosure requirements, and rejection or suspension by payment gateways whose onboarding checks depend on those pages. The practical consequence most businesses hit first is the gateway rejection, because it blocks revenue immediately.
Conclusion
Legal pages get treated as a launch-day chore, generated from a template in ten minutes and never opened again. That works right up until a payment gateway rejects your application, a customer files a consumer complaint, or a regulator asks who your grievance officer is.
The set is small. Privacy policy, terms, refund and cancellation, shipping where relevant, grievance officer details, entity disclosure. Six pages for most businesses, fewer for a content site.
Two of them are worth doing properly rather than quickly. The privacy notice, because under the DPDP Act it is what makes consent informed, which means specific purposes stated in plain language rather than boilerplate about improving services. And the grievance officer page, because it is the most commonly missing element on Indian business sites and the easiest thing for anyone to check from outside.
Everything else is structure: footer links on every page, stable URLs, a visible date, archived previous versions, and text a person can read on a phone.
Set aside a day. It is the cheapest compliance work available to you and it removes an entire category of avoidable problems, including the payment gateway rejection that will otherwise arrive during launch week.
HostCloud gives you fast, always-indexable hosting for these pages along with the rest of your site, on Indian infrastructure with free SSL and one-click WordPress. Plans start at ₹99 a month at https://hostcloud.in.
