Cookie Consent and Website Compliance in India
What Indian businesses need to know about cookie consent and website data collection under DPDP, including notice, consent and vendor considerations.
Every website that uses analytics, advertising pixels, or even a simple contact form is collecting personal data, and that puts it squarely within DPDP's scope, whether or not the word "cookie" appears anywhere in the Act.
Key facts at a glance
- DPDP does not name cookies specifically, but any cookie or tracker that collects personal data falls under its general scope.
- Full substantive DPDP obligations, including notice and consent, become enforceable 13 May 2027, with no stated grace period.
- Penalties for inadequate security safeguards can reach up to Rs 250 crore per instance.
- Third-party analytics and ad-tech tools embedded on a website remain the business's responsibility under DPDP even though a vendor operates them.
- The Consent Manager registration framework under DPDP Rules 2025 becomes operational 13 November 2026.
- Strictly necessary cookies (needed to run the site) are generally treated differently from analytics or advertising cookies that build a visitor profile.
Why "we don't sell data" doesn't mean "we're exempt"
A common misconception is that DPDP only concerns businesses that explicitly sell or trade personal data. In reality, simply operating a website that uses analytics tools, retargeting pixels, or even a basic newsletter signup form involves collecting and processing personal data, whether it is an email address, an IP address tied to a session, or a browsing history used to build an ad profile. All of this brings a website operator within DPDP's scope, regardless of industry.
What kinds of website data collection are typically in scope
Strictly necessary cookies
Cookies required for the website's basic functioning, such as keeping a shopping cart session active or remembering login state, are generally treated as a lower-risk category, though they can still involve personal data.
Analytics cookies
Tools that track page views, session duration, and user journeys typically collect identifiers that, combined with other data, can identify or profile an individual visitor. These usually warrant clear notice and, in many implementations, an opt-out or consent mechanism.
Advertising and retargeting cookies
Pixels used for ad retargeting (showing a visitor an ad for a product they viewed) are among the more visible and scrutinised forms of tracking, since they actively build a behavioural profile used to influence the individual later.
Forms and account data
Contact forms, newsletter signups, and account registration collect personal data directly and explicitly, and are usually the most straightforward category to bring into a DPDP-compliant notice and consent flow.
Practical elements of a DPDP-aligned website approach
| Element | Purpose | Practical note |
|---|---|---|
| Clear, plain-language notice | Tells visitors what data is collected and why | Should be specific, not a vague catch-all statement |
| Consent mechanism for non-essential cookies | Captures visitor choice before non-essential tracking starts | Common practice is a banner with genuine accept/reject options |
| Vendor list and data flow map | Tracks which third-party tools receive visitor data | Include analytics, ad-tech, chat widgets, embedded video, etc |
| Privacy policy page | Central reference for data practices | Should be kept current as tools are added or removed |
| Process for visitor data requests | Handles requests to stop tracking or delete data | Needed once DPDP's data-principal rights are enforceable |
Vendor tools embedded on most websites
Modern websites typically embed several third-party tools: analytics platforms, advertising pixels, chat widgets, embedded video players, and sometimes A/B testing tools. Each of these can collect personal data independently of the website operator's own systems. Under DPDP, the business running the website remains responsible for ensuring these tools are used appropriately, which means reviewing what each vendor collects and why it is embedded in the first place, rather than assuming a plugin is compliance-neutral just because it is common.
A practical starting checklist
List every cookie and tracking tool currently active on the website, and classify each as strictly necessary, analytics, or advertising. Write a plain-language notice describing what is collected and why, avoiding generic boilerplate. Add a genuine choice mechanism for non-essential tracking rather than a banner that only offers "accept." Review vendor agreements for analytics and ad-tech tools for basic security and data-handling commitments. Revisit the list periodically, since marketing and product teams frequently add new tracking tools without looping in whoever owns compliance.
If you are not sure where your website stands on DPDP compliance, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.
Sources
- Ministry of Electronics and Information Technology - meity.gov.in
- Data Protection Board of India (as constituted under DPDP) - meity.gov.in
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- Does DPDP specifically regulate website cookies the way GDPR does in Europe?
- The Digital Personal Data Protection Act 2023 does not name cookies specifically, but any cookie or tracking technology that collects personal data, such as an identifier tied to an individual, falls within DPDP's general scope for personal data processing.
- Do Indian websites need a cookie consent banner?
- DPDP does not mandate a specific banner format, but websites using cookies that collect personal data will generally need to give clear notice and, where required, obtain consent, and a cookie banner is a common practical way to do this.
- Are all cookies treated the same under DPDP?
- No single India-specific rule tiers cookies by type, but as a matter of general data protection principle, strictly necessary cookies (needed to run the site) are usually treated differently from analytics or advertising cookies that build a profile of the visitor.
- When do DPDP's notice and consent obligations become enforceable for websites?
- Full substantive DPDP obligations, including notice and consent requirements, become enforceable on 13 May 2027, with no stated grace period after that date.
- Does using a third-party analytics or ad-tech tool on a website create DPDP risk?
- Yes. If the tool collects personal data of website visitors, the business remains responsible under DPDP for ensuring that vendor's data handling is appropriate, even though the vendor operates the underlying technology.
- What is the penalty risk for poor website data practices under DPDP?
- Penalties for failing to implement reasonable security safeguards can reach up to Rs 250 crore per instance, and website-collected data is squarely within scope if it is not handled with appropriate safeguards.
Check your status
DPDP Gap Assessment
A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.