Compliance

    Cookie Consent Under DPDPA: What Indian Websites Need to Do Differently

    India's DPDPA treats cookies very differently from GDPR. No implied consent, no "legitimate interest" for tracking, and notices must work in Indian languages. Here's what Indian websites need to implement before the May 2027 deadline.

    By truConsent Team
    7 min read

    Cookie consent in India is not a copy-paste job from a GDPR implementation. India's Digital Personal Data Protection Act 2023 has different rules, different terminology, and different language requirements — and the compliance deadline is May 2027.

    This guide covers what Indian websites need to do, what GDPR-style implementations get wrong, and the specific technical and legal requirements your cookie consent setup must meet.

    GDPR vs DPDPA: The Key Differences for Cookie Consent

    DimensionGDPRDPDPA
    Legal basis for trackingLegitimate interest availableLegitimate interest not available as general commercial basis
    Consent requirementRequired for non-essential cookiesAffirmative action required for all non-necessary data collection
    Pre-ticked boxesProhibitedProhibited
    LanguageEU official languagesIndian scheduled languages (22 official)
    WithdrawalMust be as easy as giving consentMust be as easy as giving consent
    TerminologyData Subject, ControllerData Principal, Data Fiduciary

    The structural difference that matters most: GDPR allows "legitimate interest" to justify analytics, session recording, and certain advertising cookies without explicit consent. DPDPA does not provide this as a general commercial exemption. For most Indian websites, analytics and tracking cookies require explicit, affirmative consent.

    What Your Cookie Consent Setup Must Do Under DPDPA

    1. No pre-ticked boxes, no implied consent

    Section 6 of the DPDPA requires consent that is "free, specific, informed, unconditional, and unambiguous." Consent implied by continued use of a website ("by using this site, you agree to cookies") does not meet this standard. Non-essential cookies must be off by default, and the user must actively switch them on.

    2. Purpose-specific consent, per cookie category

    Consent must be specific — which means separate consent for separate purposes. Analytics cookies, personalisation cookies, advertising cookies, and session cookies each require independent consent toggles. A single "Accept All" option without a "Reject All" equivalent of equal prominence does not satisfy the specificity requirement.

    3. Withdrawal must be as easy as giving consent

    Section 6(4) requires that withdrawal be "as easy as giving consent." If your consent banner takes one click to accept but three screens to withdraw, that is non-compliant. The preference centre where a user can withdraw must be accessible at any time — not just on first visit.

    4. Notices in Indian languages

    The DPDPA requires that notice be given in a language the Data Principal understands. For a B2C website with users across Tamil Nadu, Maharashtra, Karnataka, and West Bengal, an English-only cookie banner does not satisfy this requirement. Your CMP must support the Indian scheduled languages relevant to your user base — and translations must be accurate, not machine-generated.

    5. Audit trail — proof of consent

    You must be able to demonstrate that consent was given: timestamp, which notice was shown, which cookie categories were accepted, and any subsequent withdrawals. This audit trail is your evidence if the Data Protection Board of India ever requests compliance documentation.

    6. Data processor obligations for third-party cookies

    Every third-party tool whose cookies fire on your site — Google Analytics, advertising pixels, heatmap tools, A/B testing platforms — is a data processor under the DPDPA. Section 8 requires that you have appropriate agreements in place and that their data processing complies with the DPDPA. Your cookie consent setup should block these cookies until consent is given — and stop them immediately when consent is withdrawn.

    10-Point DPDPA Cookie Consent Checklist

    1. ☐ Non-essential cookies blocked until explicit consent is given
    2. ☐ No pre-ticked boxes for any non-necessary category
    3. ☐ Separate consent toggles for each cookie purpose
    4. ☐ "Reject All" option as prominent as "Accept All"
    5. ☐ Cookie preference centre accessible at any time from the site
    6. ☐ Withdrawal reverses data processing within the session
    7. ☐ Consent notice available in relevant Indian scheduled languages
    8. ☐ Consent audit trail stored with timestamp and notice version
    9. ☐ Third-party cookies blocked until the relevant consent category is active
    10. ☐ Re-consent triggered when notice or purpose descriptions change

    Common Mistakes Indian Websites Are Making Right Now

    Copying a GDPR banner without modification. GDPR-compliant banners often rely on legitimate interest for analytics. That basis is not available under DPDPA. A banner that was compliant for European users may be non-compliant for Indian users.

    Using dark patterns in the consent UI. A brightly coloured "Accept All" button next to a grey, hard-to-find "Manage Preferences" link is a dark pattern. The DPDPA's requirement that consent be "free" and "unambiguous" has been interpreted by regulators in similar jurisdictions to prohibit UI designs that nudge users toward consent.

    Assuming cookie compliance is a one-time setup. When you add a new analytics tool, a new advertising pixel, or a new personalisation platform, your cookie inventory changes. If your CMP doesn't reflect that change, you may be firing unconsented cookies. Cookie compliance needs to be part of your release process, not a one-time implementation.

    Not storing proof of consent. Many website implementations fire cookies based on user interaction but don't store a verifiable record of what was consented to. Without that record, you cannot demonstrate compliance to the Data Protection Board.


    Ready to make your website DPDPA-compliant? Book a walkthrough with truConsent — we'll show you how to get cookie consent, audit trail, and Indian language support set up correctly.

    Continue Reading

    Cookie Consent

    We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. You can manage your preferences or decline non-essential cookies by clicking "Decline".