DPDP cookie consent may be required when cookies process identifiable personal data for analytics, advertising, profiling, or personalisation. This guide explains when permission is needed, what a compliant banner should contain, and how businesses should enforce and withdraw user choices.
Overview
The DPDP Act does not contain a separate cookie-consent chapter or automatically exempt every cookie labelled “essential.” Whether the DPDP Act requires cookie consent depends on the information collected, its connection to an identifiable individual, the processing purpose, and whether consent or another recognised processing ground applies.
Cookie compliance therefore requires both a legal assessment and technical verification of what actually loads on the website.
Key Findings
- Not every cookie automatically requires separate consent.
- Advertising, profiling, retargeting, and cross-site tracking create higher consent risks.
- Non-essential cookies should remain blocked until a valid choice is recorded.
- Consent requires clear notice, affirmative action, easy withdrawal, and reliable evidence.
- Cookie choices must be enforced across analytics, advertising, and third-party systems.
What Are Cookies?
Cookies are small browser records that help websites maintain information between online interactions. They may support basic website functions or collect information about devices, sessions, preferences, and browsing behaviour.
Websites commonly use cookies for:
- Login and authentication
- Shopping carts and session continuity
- Fraud prevention and account security
- Language and display preferences
- Website analytics and performance measurement
- Content personalisation
- Advertising, profiling, and retargeting
- Social-media integrations
Barth, Adam. 2011. “HTTP State Management Mechanism.” RFC Editor. RFC 6265 explains that Cookie and Set-Cookie headers allow websites to maintain state across the otherwise largely stateless HTTP protocol
How Does the DPDP Act Apply to Cookies?
The DPDP Act applies when cookie information qualifies as digital personal data relating to an identifiable individual. A random browser or device identifier may become personal data when connected with an account, location, purchase, browsing history, or other information that identifies a person.
Compliance should focus on actual data use rather than technology labels. Cookies, pixels, tags, browser storage, fingerprinting tools, advertising identifiers, and mobile SDKs may create similar obligations.
What Types of Cookies Are Used by Websites?
Websites use several cookie categories, each presenting a different compliance profile.
- First-party cookies: Placed directly by the website being visited.
- Third-party cookies: Placed or accessed by analytics, advertising, payment, or social-media providers.
- Session cookies: Usually expire when the browser session ends.
- Persistent cookies: Remain until a specified expiry date or manual deletion.
- Essential cookies: Support login, security, load balancing, shopping carts, or requested functions.
- Preference cookies: Remember language, region, accessibility, or display choices.
- Analytics cookies: Measure traffic, user journeys, engagement, and performance.
- Advertising cookies: Support attribution, targeting, profiling, and cross-site recognition.
Read also: DPDP Compliance Software in India
Do All Cookies Require Consent Under the DPDP Act?
No. The DPDP Act does not require cookie consent for every browser record, but businesses should not assume that all “necessary” cookies are automatically exempt.
| Cookie use | Practical compliance approach |
|---|---|
| No identifiable personal data | Separate consent may not be required |
| Login, security, or requested session function | Assess necessity and another applicable ground |
| Optional preference or personalisation | Consent may be appropriate |
| Non-essential analytics | Prior consent is generally safer |
| Advertising, profiling, or cross-site tracking | Prior affirmative consent is strongly advisable |
Cookies may operate without separate consent where they do not process personal data or another statutory ground clearly supports a user-requested service.
Advertising, retargeting, behavioural tracking, social-media pixels, cross-site tracking, and optional analytics need closer scrutiny. The term exempt cookie should be used carefully because the DPDP Act does not create a blanket exemption for every technology classified as necessary.
What Are the Core Cookie Compliance Requirements Under the DPDP Act?
Core compliance requires businesses to identify every tracking technology and connect its purpose to a valid processing ground.
Businesses should:
- Scan websites and applications for cookies, pixels, tags, SDKs, and browser storage.
- Maintain an inventory showing provider, purpose, duration, data collected, and recipients.
- Determine whether identifiers can be linked to individuals.
- Provide clear notice before requesting consent.
- Block non-essential trackers until a valid choice is recorded.
- Offer purpose-level choices instead of one bundled permission.
- Allow users to change or withdraw their choices.
- Retain consent, rejection, withdrawal, and notice-version evidence.
- Review trackers after website, campaign, plugin, or vendor changes.
Ministry of Electronics and Information Technology. 2025. “Digital Personal Data Protection Rules, 2025.” Gazette of India. Rule 3 requires notices to explain the personal data and specified purpose and provide accessible routes for withdrawal, rights requests, and complaints.
Read also: Data Principal Rights Under DPDP
How Should Businesses Collect Valid Cookie Consent?
Businesses should use a clear cookie banner that records the user’s choice and blocks non-essential tracking until valid consent is given.
Compliant process should:
- Scan and classify every cookie and tracker.
- Disable non-essential technologies by default.
- Display a clear notice before activation.
- Offer, accept, reject, and customise options.
- Separate analytics, advertising, profiling, and personalisation purposes.
- Record the choice, timestamp, channel, device reference, and notice version.
- Activate only the approved categories.
- Provide a permanent preference-settings link.
- Send updated choices to connected vendors and processors.
- Retain an audit trail of later changes
Read also: DPDP Privacy Risk Framework
What Should a DPDP-Compliant Cookie Consent Banner Include?
Compliant cookie banners should clearly explain tracking and provide balanced choices instead of pushing users toward automatic acceptance.
Essential banner elements include:
- A brief explanation of why cookies are used
- Clear cookie categories and purpose descriptions
- Accept all, reject non-essential, and customise options
- Equally understandable acceptance and rejection controls
- A link to the detailed cookie or privacy notice
- A preference-management and withdrawal link
- Accessible and mobile-friendly presentation
- Multilingual availability where appropriate
What Happens After Cookie Consent Is Collected?
Compliance continues after the banner closes. The recorded preference should control analytics, advertising, personalisation, pixels, tags, and connected third-party systems.
Businesses should retain:
- Approved and rejected purposes
- Consent timestamp and notice version
- Consent source and collection channel
- User, account, or device reference
- Withdrawal and preference history
- Vendor or processor acknowledgements
Read also: DPDP Compliance for Startups
How Can Organisations Maintain DPDP Cookie Compliance?
Ongoing compliance requires regular technical and governance reviews rather than a one-time banner deployment.
Recommended controls include:
- Scheduled cookie and tracker scans
- Testing of pre-consent blocking
- Testing whether withdrawal stops tracking
- Reviews after website releases and marketing campaigns
- Monitoring newly added plugins and third-party scripts
- Ownership across privacy, legal, marketing, IT, and security teams
- Comparing banner settings with actual browser network activity
- Reviewing retention periods and vendor contracts
- Preserving evidence for audits and complaints
OWASP Foundation. 2025. “Testing for Cookies Attributes.” OWASP Web Security Testing Guide. Secure, HttpOnly, SameSite, Domain, and Path settings help reduce technical cookie risks, but security settings do not replace permission where the DPDP Act requires cookie consent.
What Cookie Consent Mistakes and Compliance Risks Should Be Avoided?
Weak classification, manipulative banner design, and incomplete backend enforcement can make collected consent unreliable.
Common mistakes include:
- Loading analytics or advertising trackers before consent
- Hiding or weakening the reject option
- Bundling unrelated purposes
- Calling marketing cookies essential
- Ignoring third-party pixels or embedded content
- Failing to apply withdrawal across connected systems
- Keeping outdated cookie inventories
- Failing to preserve notice and consent versions
- Applying inconsistent preferences across domains or devices
Conclusion
Whether the DPDP Act requires cookie consent depends on the tracker’s data, purpose, identifiability, and applicable processing ground. Reliable compliance combines accurate discovery, documented classification, clear notices, prior blocking, affirmative choices, easy withdrawal, backend enforcement, vendor coordination, secure cookie settings, and audit-ready evidence.
FAQ's
The DPDP Act may require cookie consent when cookies process identifiable personal data and consent is the appropriate processing ground.

