India’s DPDP Act and Cookie Consent: Compliance Checklist
DPDP Act cookie checklist for Indian websites: personal data trigger, notice and consent principles under the Act, inventory, banner UX, blocking, and vendor steps while Rules are still awaited.
- Coverage: Cookie work is personal-data work when identifiers or profiles can identify a person (Section 2(t)). Account-linked and profile-linked tracking clearly fit; bare random IDs need a counsel call.
- Core duties: Clear, itemised notice (Section 5; expect Rule detail once notified); free, specific, informed, unambiguous consent (Section 6); withdrawal as easy as grant; child protections (Section 9; further Rules once notified).
- Timing: The Act received assent on 11 August 2023. Detailed Rules from MeitY were still awaited. Prepare inventory, notice, and consent flows now ahead of forthcoming Rules.
- Stack: Inventory, granular banner, tag blocking, consent records. Pair with the series map in Cookie Compliance: A Practical Guide.
This is article 4 of the Cookie Compliance series. Article 1 maps India next to GDPR/ePrivacy and CCPA/CPRA. Article 3 covers EU cookie consent, while article 2 shows a OneTrust path. Here the job is a DPDP cookie consent checklist for Indian websites and for global sites that process Indian personal data.
This is practical orientation from the Act and public MeitY materials. It is not legal advice. Confirm edge cases with counsel and check meity.gov.in for current PDFs and any Rules notifications.
What the law actually says about DPDP cookie consent
The DPDP Act, 2023 (Act No. 22 of 2023) never uses the word cookie. There is no India ePrivacy twin. Coverage comes from general personal-data rules when cookies process personal data:
- Personal data (Section 2(t)): data about an individual who is identifiable by or in relation to such data.
- Data Fiduciary: the person who alone or with others determines the purpose and means of processing.
- Consent (Section 6): free, specific, informed, unconditional, and unambiguous, with a clear affirmative action. Withdrawal must be as easy as giving consent.
- Notice (Section 5): clear, standalone notice in plain language with itemised personal data and purposes, plus paths to withdraw, exercise rights, and complain to the Board. Expect Rule-level detail once MeitY notifies Rules.
The Act received assent on 11 August 2023. MeitY had not yet notified detailed Rules as of this writing. Treat the Act’s notice and consent principles as the planning baseline and prepare inventory, notice text, and consent flows now ahead of forthcoming Rules.
Industry and government design papers on consent management systems may appear later as non-binding technical blueprints. Treat those as design input, not statute. Useful themes to watch for: granular categories, essential-only defaults, first-visit banners, preference updates, and consent logging.
When cookie tech triggers DPDP
- Analytics or ads IDs tied to a logged-in account, CRM profile, or phone/email.
- Pixels that build behaviour profiles used for targeting or scoring identifiable users.
- Chat, payment, or support widgets that store identifiable session data in the browser and sync it to a backend.
Conservative product teams plan affirmative consent for optional analytics and marketing categories even while counsel debates edge cases for anonymous random IDs. If you also serve EEA or UK visitors, you already need prior consent under ePrivacy practice (see GDPR Cookie Consent Requirements). Building one geo-aware CMP is usually cheaper than maintaining three banners.
Compliance checklist (use this as a project board)
1. Ownership and scope
- Name a Fiduciary owner (marketing ops or eng) and a counsel contact.
- List countries that matter in analytics (IN, EEA, UK, US-CA, others).
- Decide whether India traffic gets a DPDP-ready opt-in model now. Waiting until Rules land is a common failure mode.
2. Cookie and tag inventory
- Export every GTM or tag container. Walk production pages with browser tools.
- For each cookie, pixel, SDK, and local storage key: name, domain, party, purpose, vendor, data shared, retention if known.
- Mark essential (security, session, load balancing, consent storage) vs optional (analytics, ads, experiments, most chat trackers).
- Delete dead tags. Orphan pixels create notice text that lies.
3. Notice text that can satisfy Section 5 (and later Rules)
Draft a standalone notice (not buried in Terms of Use) that, at minimum, can carry:
- Itemised personal data categories collected through trackers (for example identifiers, usage events, approximate location if you collect it).
- Specified purposes and the goods, services, or uses those purposes enable (site security, traffic measurement, ads measurement, personalisation).
- A link to your site or app and clear means to withdraw consent, exercise rights, and complain to the Board.
Keep language plain. Mirror the same purpose list in the banner and Preference Center so the first click matches the long notice.
4. Consent UX quality (Section 6)
- Clear affirmative action. No pre-ticked optional toggles.
- Specific purposes. Do not bundle unrelated analytics and ads into one forced Accept.
- Reject or decline non-essential with comparable ease to Accept.
- Reopen control (footer Cookie Settings or floating preference icon) so withdrawal stays as easy as the original grant.
- Default: only essential cookies until optional categories are granted.
Align your CMP (for example OneTrust; see How to Set Up OneTrust Cookie Consent) to that model for India geolocation rules: first-visit banner, accept all / decline / customise, essential-only defaults, preference interface, and consent logs with timestamps.
5. Children and youth products (Section 9)
- If your product may attract children, plan verifiable parental consent before processing a child’s personal data.
- Tracking, behavioural monitoring, and targeted advertising directed at children are restricted under the Act’s child provisions. Age gates and ad-stack choices matter here. Expect further Rule detail once notified.
- Book legal review before go-live on kids’ or education products.
6. Tag blocking and records
- Non-essential tags must not fire before grant on consent-required flows.
- Store proof: timestamp, notice or policy version, purposes granted or denied, region rule, CMP identifiers.
- Wire Google Consent Mode v2 if you run Google Ads or GA4 for EEA, UK, or Switzerland traffic; India-only sites still benefit from honest blocking even when Consent Mode is less central.
7. Vendors and contracts
- List processors and ad vendors that receive cookie-derived personal data.
- Update DPAs or processing contracts as counsel requires under the Act.
- Ask vendors how they honour withdrawal and deletion signals from your CMP.
8. Rights and grievance path
- Document how users request access, correction, erasure, and grievance redress for data collected through trackers.
- Make the path reachable from the cookie notice and privacy policy, not only from a buried help article.
9. Near-term timeline while Rules are awaited
- Now to 30 days: Inventory and dead-tag cleanup. Draft itemised notice.
- Days 31 to 60: Configure CMP geo rules for India; equal Accept / Reject / Customise; enable logging.
- Days 61 to 90: Block optional tags by default; test withdrawal; vendor questionnaire pass.
- Quarterly after that: Rescan, refresh categorisation, re-test reject paths, watch meity.gov.in for Rules and commencement updates.
How this differs from GDPR cookie rules
| Topic | India DPDP (cookies by principle) | EEA ePrivacy + GDPR |
|---|---|---|
| Named cookie statute | No | Yes (ePrivacy Art. 5(3) plus GDPR consent) |
| Trigger | Personal data processing via trackers | Storage/access on terminal equipment (with exemptions) |
| Notice | Standalone, itemised (Section 5; Rules forthcoming) | Informed consent notice before non-essential tags |
| Reject UX | Withdrawal as easy as grant; granular practice from industry norms | Equal reject/accept stressed by EDPB Cookie Banner Taskforce |
| Key date | Act on the books; detailed Rules still awaited from MeitY | Already in force for EEA traffic |
If one HTML page serves India and the EU, encode both models in geolocation rules. Do not assume an EU banner automatically meets Section 5 itemisation, and do not assume a soft India notice alone protects EU visitors.
Common mistakes on Indian sites
- Theme banner that says “we use cookies” with Accept only and no purpose list.
- Calling product analytics “essential” so they never ask for consent.
- No reopen control after the first click.
- Inventory that lists three cookies while twenty vendors load.
- Ignoring child-directed advertising risk on apps popular with minors.
- Planning to “install a CMP the week Rules are notified.”
FAQ
Does India require a cookie banner today?
There is no cookie-named statute. Where trackers process personal data, DPDP cookie consent and notice principles under the Act apply. Detailed Rules from MeitY were still awaited as of this writing. Therefore many teams still ship a clear banner now because EU traffic already demands it and because inventory work takes months.
Are design papers on consent management mandatory?
No. Non-binding technical blueprints are still a useful checklist for granular cookie categories, essential-only defaults, and logging. They are not statute.
Can I reuse my GDPR OneTrust template for India?
Often as a starting point. Retune notice copy for Section 5 itemisation, confirm India geolocation rules, and verify withdrawal and rights links point to India-appropriate flows. Article 2 covers the OneTrust install path.
Sources and further reading
- Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), especially Sections 2(t), 5, 6, and 9.
- Check meity.gov.in for current Act PDFs and any Rules or commencement notifications.
- Series: Cookie Compliance: A Practical Guide; OneTrust setup; GDPR cookie consent requirements.
Next in this series
Up next: Cookie Banner Best Practices That Improve Consent Rates. That article covers first-layer design, equal reject, copy that builds trust, and why dark patterns that inflate Accept clicks are the wrong optimisation.
Disclaimer
This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, privacy policies, or other privacy and data-protection controls. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.
Last updated on 7 September 2026
