Compliance Guide

DPDP for Cookie Consent Dpdp: Expert Guide

DPDP doesn't explicitly regulate cookies, but website tracking and analytics still involve personal. Get a free assessment.

Discuss this page with an LLM

DPDP Action Sheet

Use this before your next workflow goes live. It keeps the useful parts visible and turns DPDP into checks your team can actually answer.

For DPDP for Cookie Consent Dpdp: Expert Guide, the DPDP question is how personal data enters the workflow, where it is stored, which tools touch it, what purpose was explained, and how deletion or withdrawal will work.

1. Lead Forms

Check:

  • What data are you collecting?
  • Is the purpose clear at the point of collection?
  • Is marketing consent separate from service communication?
  • Can the user withdraw consent later?

Common mistake: one checkbox that silently covers newsletters, sales calls, partner sharing and remarketing.

2. Email and WhatsApp

Check:

  • Who is on the list?
  • Where did consent come from?
  • Is the list imported from a vendor, event, webinar, scrape or old CRM?
  • Can you prove the source of consent?

Common mistake: treating every lead as permanently marketable.

3. Ads and Retargeting

Check:

  • Are pixels or ad platforms receiving identifiable user behavior?
  • Are audiences built from customer lists?
  • Are lookalike or remarketing audiences using personal data?

Common mistake: assuming "the ad platform handles it" means your company has no DPDP responsibility.

4. Website Analytics

Check:

  • Which tools run on the site?
  • Are IP address, device identifiers, session IDs or form fields being captured?
  • Is analytics used only for measurement, or also for profiling and targeting?

Common mistake: installing tools first and asking privacy questions later.

5. Vendor List

Make a quick list:

  • CRM
  • Email platform
  • WhatsApp provider
  • Analytics
  • Ad pixels
  • Form tool
  • Landing page builder
  • Webinar tool

For each vendor, answer: what data goes there, why, who can access it and how deletion works.

6. This Week's Action

Map one campaign from first click to final follow-up. Mark every place personal data is collected, enriched, shared, uploaded or used for targeting.

If your team cannot answer where the data came from and where it goes next, start with a data flow map before rewriting policy copy.

Book a DPDP clarity call

Want all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.

Tracking Identifiers as Personal Data

DPDP classifies device IDs, IP addresses, and browser fingerprints as personal data when they identify an individual. Your cookie banner must treat a “Client ID” with the same protection as a physical address. You cannot fire tracking scripts the moment a page loads; you must hold them until the user provides clear, affirmative consent.

The Conflict of “Legitimate Interest”

Unlike other global regulations, the DPDP Act does not provide a broad “legitimate interest” loophole for marketing trackers. You cannot bypass consent by claiming a business need for analytics or retargeting. Every non-essential cookie requires a specific notice in plain English or any of the 22 languages specified in the Indian Constitution.

Data Workflows and DPDP Risk

WorkflowData InvolvedDPDP Risk
Retargeting AdsTracking Pixels & Click IDsProcessing data without a specific purpose notice
User Behavior AnalyticsIP Addresses & Heatmap DataStoring data longer than the session requires
A/B TestingSession Cookies & Device TypeProfiling users without explicit opt-in
Affiliate MarketingReferral IDs & Purchase HistorySharing identifiers with third parties without a DPDP-compliant contract

This week

Audit your website’s header code to list every third-party script currently setting cookies. Identify which scripts fire before a user interacts with your consent banner and disable them to ensure no data is collected before consent is granted.

Now think about your work. Where does personal data enter your workflows? Where does it sit? Who else touches it?

Frequently asked questions

Do I need a consent banner for essential login cookies?

No. Cookies strictly necessary for site functionality, such as keeping a user logged in or holding items in a shopping cart, do not require a consent pop-up.

Is "scrolling down the page" considered valid consent?

No. DPDP requires an affirmative action, such as clicking an "Accept" button. Passive actions like scrolling or staying on a page do not meet the standard for clear consent.

How do I handle third-party pixels from social media sites?

You must ensure these pixels are blocked by your consent management platform until the user opts in. You are responsible for any data these pixels collect from your site visitors.

Book clarity call