What Are the DPDPA Cookie Consent Requirements?
Everything you need to know about DPDPA cookie consent compliance in 2026. Complete guide covering opt-in consent requirements, cookie banner elements, consent records, and technical implementation for India.
Summary
This guide provides comprehensive technical implementation requirements for India (DPDPA). Cookies fall under DPDPA scope as they collect data 'in relation to' identifiable individuals (Section 2(t)). Affirmative opt-in consent required for non-essential cookies that process personal data.
This jurisdiction requires an opt-in consent model (prior consent), meaning websites must obtain explicit user consent before placing non-essential cookies or similar tracking technologies. Users must actively accept cookies through clear consent mechanisms.
Additional requirements for this jurisdiction include: providing consent banners and privacy information in all required languages, and special protections and consent mechanisms for children's personal data.
Website owners and operators subject to these regulations must implement compliant cookie consent banners, maintain proper consent records, and ensure their tracking technologies respect user privacy choices. This guide outlines all technical requirements needed to achieve compliance.
Key Requirements Overview
Technical Requirements
Required Banner Elements
First Layer (Cookie Banner)
- Concise Purpose Summary
- Accept All Button
- Reject All Button Or Link
- Manage Preferences Button
- Link Privacy Policy
Second Layer (Preferences Modal)
- Granular Purpose Toggles
Implementation Guidance
Cookies are not mentioned in the DPDP Act but fall under its scope because they collect data 'in relation to' an identifiable individual (Section 2(t)). Per Section 6 and Draft Rule 3, consent must be free, specific, informed, unconditional, and obtained through affirmative action — pre-ticked boxes do not count. Vague language like 'we use cookies to improve your experience' is not sufficient. Users must be able to accept or reject different categories of cookies independently (granular opt-in per NeGD Business Requirements Document on Consent Management Systems, 2025). The banner must clearly state what data is being collected, for what purpose, and by whom. Consent withdrawal must be available persistently, not just on first visit. You must store an auditable record of what the user consented to, when, and how — this is your proof in case of disputes or regulatory scrutiny. Notices must be provided in English and other scheduled Indian languages as notified. The ASCI Academy whitepaper 'Navigating Cookies' (2025) flags the need to avoid dark patterns in cookie consent flows. The NeGD document also specifies auto-expiry requirements for consent, though no specific duration is mandated in law. Processing without consent is permitted for: legal obligations, state functions, employment purposes, and medical emergencies. Data minimisation and purpose limitation are required. Users (Data Principals) have rights to access, correction, erasure, and grievance redressal. Penalties for non-compliance can reach up to INR 250 crore (approx. USD 30 million).
Special Protections
Children's Privacy
Parental or lawful guardian consent required for children under 18. Processing must not cause harm to a child. Behavioral monitoring and targeted advertising directed at children is prohibited.
Sensitive Data
Explicit consent required. The Act does not create a separate category of sensitive data but the government may notify additional obligations for certain data types.
Record Keeping Requirements
Required Consent Record Fields
For each consent action, you must maintain records containing:
- Timestamp ISO
- User Choices By Purpose
- Policy Version
CookieChimp handles all of this automatically. Our platform maintains comprehensive consent records including all required fields, timestamps, consent strings, IP addresses, user agents, and more. Records are securely stored and easily exportable for compliance audits. Learn more about our consent management
Legal References & Resources
Official legal documents and regulatory guidance for this jurisdiction:
Frequently Asked Questions About DPDPA Cookie Consent
Found an issue or have feedback on this page?
Explore Other Jurisdictions
View AllJapan (APPI)
Japan
Opt-in consent required when cookies identify individuals for analytics or advertising.
China (PIPL)
China
Consent required for personalized ads and sensitive data; notice required for cross-border data transfers.
South Korea (PIPA)
South Korea
Strict opt-in required before placing cookies that collect personal information.
Thailand (PDPA)
Thailand
Consent required for most non-essential data processing including tracking cookies.
Indonesia (PDP Law)
Indonesia
Consent required for most non-essential data processing.