Does DPDP Require Cookie Consent for All Websites?

Summarise on:
Charu Pel

Charu Pel

Published:

DPDP cookie consent may be required when cookies process identifiable personal data for analytics, advertising, profiling, or personalisation. This guide explains when permission is needed, what a compliant banner should contain, and how businesses should enforce and withdraw user choices.

Overview

The DPDP Act does not contain a separate cookie-consent chapter or automatically exempt every cookie labelled “essential.” Whether the DPDP Act requires cookie consent depends on the information collected, its connection to an identifiable individual, the processing purpose, and whether consent or another recognised processing ground applies.

Cookie compliance therefore requires both a legal assessment and technical verification of what actually loads on the website.

Key Findings

  • Not every cookie automatically requires separate consent.
  • Advertising, profiling, retargeting, and cross-site tracking create higher consent risks.
  • Non-essential cookies should remain blocked until a valid choice is recorded.
  • Consent requires clear notice, affirmative action, easy withdrawal, and reliable evidence.
  • Cookie choices must be enforced across analytics, advertising, and third-party systems.

What Are Cookies?

Cookies are small browser records that help websites maintain information between online interactions. They may support basic website functions or collect information about devices, sessions, preferences, and browsing behaviour.

Websites commonly use cookies for:

  • Login and authentication
  • Shopping carts and session continuity
  • Fraud prevention and account security
  • Language and display preferences
  • Website analytics and performance measurement
  • Content personalisation
  • Advertising, profiling, and retargeting
  • Social-media integrations

Barth, Adam. 2011. “HTTP State Management Mechanism.” RFC Editor. RFC 6265 explains that Cookie and Set-Cookie headers allow websites to maintain state across the otherwise largely stateless HTTP protocol

How Does the DPDP Act Apply to Cookies?

The DPDP Act applies when cookie information qualifies as digital personal data relating to an identifiable individual. A random browser or device identifier may become personal data when connected with an account, location, purchase, browsing history, or other information that identifies a person.

Compliance should focus on actual data use rather than technology labels. Cookies, pixels, tags, browser storage, fingerprinting tools, advertising identifiers, and mobile SDKs may create similar obligations.

What Types of Cookies Are Used by Websites?

Websites use several cookie categories, each presenting a different compliance profile.

  • First-party cookies: Placed directly by the website being visited.
  • Third-party cookies: Placed or accessed by analytics, advertising, payment, or social-media providers.
  • Session cookies: Usually expire when the browser session ends.
  • Persistent cookies: Remain until a specified expiry date or manual deletion.
  • Essential cookies: Support login, security, load balancing, shopping carts, or requested functions.
  • Preference cookies: Remember language, region, accessibility, or display choices.
  • Analytics cookies: Measure traffic, user journeys, engagement, and performance.
  • Advertising cookies: Support attribution, targeting, profiling, and cross-site recognition.

Read also: DPDP Compliance Software in India

No. The DPDP Act does not require cookie consent for every browser record, but businesses should not assume that all “necessary” cookies are automatically exempt.

Cookie usePractical compliance approach
No identifiable personal dataSeparate consent may not be required
Login, security, or requested session functionAssess necessity and another applicable ground
Optional preference or personalisationConsent may be appropriate
Non-essential analyticsPrior consent is generally safer
Advertising, profiling, or cross-site trackingPrior affirmative consent is strongly advisable

Cookies may operate without separate consent where they do not process personal data or another statutory ground clearly supports a user-requested service.

Advertising, retargeting, behavioural tracking, social-media pixels, cross-site tracking, and optional analytics need closer scrutiny. The term exempt cookie should be used carefully because the DPDP Act does not create a blanket exemption for every technology classified as necessary.

Core compliance requires businesses to identify every tracking technology and connect its purpose to a valid processing ground.

Businesses should:

  • Scan websites and applications for cookies, pixels, tags, SDKs, and browser storage.
  • Maintain an inventory showing provider, purpose, duration, data collected, and recipients.
  • Determine whether identifiers can be linked to individuals.
  • Provide clear notice before requesting consent.
  • Block non-essential trackers until a valid choice is recorded.
  • Offer purpose-level choices instead of one bundled permission.
  • Allow users to change or withdraw their choices.
  • Retain consent, rejection, withdrawal, and notice-version evidence.
  • Review trackers after website, campaign, plugin, or vendor changes.

Ministry of Electronics and Information Technology. 2025. “Digital Personal Data Protection Rules, 2025.” Gazette of India. Rule 3 requires notices to explain the personal data and specified purpose and provide accessible routes for withdrawal, rights requests, and complaints.

Read also: Data Principal Rights Under DPDP

Businesses should use a clear cookie banner that records the user’s choice and blocks non-essential tracking until valid consent is given.

Compliant process should:

  1. Scan and classify every cookie and tracker.
  2. Disable non-essential technologies by default.
  3. Display a clear notice before activation.
  4. Offer, accept, reject, and customise options.
  5. Separate analytics, advertising, profiling, and personalisation purposes.
  6. Record the choice, timestamp, channel, device reference, and notice version.
  7. Activate only the approved categories.
  8. Provide a permanent preference-settings link.
  9. Send updated choices to connected vendors and processors.
  10. Retain an audit trail of later changes

Read also: DPDP Privacy Risk Framework

Compliant cookie banners should clearly explain tracking and provide balanced choices instead of pushing users toward automatic acceptance.

Essential banner elements include:

  • A brief explanation of why cookies are used
  • Clear cookie categories and purpose descriptions
  • Accept all, reject non-essential, and customise options
  • Equally understandable acceptance and rejection controls
  • A link to the detailed cookie or privacy notice
  • A preference-management and withdrawal link
  • Accessible and mobile-friendly presentation
  • Multilingual availability where appropriate

Compliance continues after the banner closes. The recorded preference should control analytics, advertising, personalisation, pixels, tags, and connected third-party systems.

Businesses should retain:

  • Approved and rejected purposes
  • Consent timestamp and notice version
  • Consent source and collection channel
  • User, account, or device reference
  • Withdrawal and preference history
  • Vendor or processor acknowledgements

Read also: DPDP Compliance for Startups

Ongoing compliance requires regular technical and governance reviews rather than a one-time banner deployment.

Recommended controls include:

  • Scheduled cookie and tracker scans
  • Testing of pre-consent blocking
  • Testing whether withdrawal stops tracking
  • Reviews after website releases and marketing campaigns
  • Monitoring newly added plugins and third-party scripts
  • Ownership across privacy, legal, marketing, IT, and security teams
  • Comparing banner settings with actual browser network activity
  • Reviewing retention periods and vendor contracts
  • Preserving evidence for audits and complaints

OWASP Foundation. 2025. “Testing for Cookies Attributes.” OWASP Web Security Testing Guide. Secure, HttpOnly, SameSite, Domain, and Path settings help reduce technical cookie risks, but security settings do not replace permission where the DPDP Act requires cookie consent.

Weak classification, manipulative banner design, and incomplete backend enforcement can make collected consent unreliable.

Common mistakes include:

  • Loading analytics or advertising trackers before consent
  • Hiding or weakening the reject option
  • Bundling unrelated purposes
  • Calling marketing cookies essential
  • Ignoring third-party pixels or embedded content
  • Failing to apply withdrawal across connected systems
  • Keeping outdated cookie inventories
  • Failing to preserve notice and consent versions
  • Applying inconsistent preferences across domains or devices

Conclusion

Whether the DPDP Act requires cookie consent depends on the tracker’s data, purpose, identifiability, and applicable processing ground. Reliable compliance combines accurate discovery, documented classification, clear notices, prior blocking, affirmative choices, easy withdrawal, backend enforcement, vendor coordination, secure cookie settings, and audit-ready evidence.

FAQ's

The DPDP Act may require cookie consent when cookies process identifiable personal data and consent is the appropriate processing ground.