AMLEGALS — Strategic Lawyering
DPDPA compliance · Websites and apps

DPDPA website compliance: notices, cookies, forms and trackers

What the DPDPA and the DPDP Rules, 2025 mean for a website or mobile app: ten points to check, the provision behind each one, and how cookies, tracking tools and app permissions fit in.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 7 min read

A phone and a laptop on a desk, both showing a privacy settings screen with consent toggles
Short answer

A website or app meets the DPDPA when it gives a clear notice before collecting personal data (Section 5, Rule 3), collects only the data needed for each stated purpose (Section 6(1)), asks for consent through a clear affirmative action and lets people withdraw it as easily as they gave it (Section 6(4)), loads advertising and tracking tools only on a valid lawful ground, has contracts with the third parties that process data for it (Section 8(2)), publishes a contact for privacy questions (Rule 9) and a way to make rights requests (Rule 14), and protects the data it collects (Section 8(5), Rule 6). The core duties apply from 13 May 2027.

  • Website compliance
  • Cookie consent
  • Privacy notice
  • Rule 3
  • Section 6
  • Trackers and SDKs
  • Mobile apps
  • Children's data
Applies to
Any website or app that collects digital personal data, including sites run from abroad that offer goods or services to people in India (Section 3)
Core duties apply from
13 May 2027
Points to check
10, from the privacy notice to transfers outside India
Cookies
Not named in the Act. Each one is assessed by what it collects and why

What the DPDPA expects from a website or app

The DPDPA applies to personal data in digital form. A website or app collects personal data through forms, accounts, cookies, analytics tags, advertising pixels, chat widgets and software development kits (SDKs). Each of these is processing under the Act when the data relates to an identifiable person.

The organisation that runs the site and decides why the data is collected is the Data Fiduciary. Third-party tools that process data on its behalf are Data Processors, and under Section 8(1) the Data Fiduciary stays responsible for what they do with that data.

The duties apply from 13 May 2027. A website or app is usually where people first see an organisation's notice and consent request, so gaps there are visible to anyone who visits.

Ten points to check on a website or app

The table lists each point, the provision behind it and what to look for.

DPDPA website and app checks mapped to provisions
PointProvisionWhat to check
Privacy noticeSection 5; Rule 3Clear and plain language, understandable on its own, listing each item of personal data and its purpose, with a link to withdraw consent, make a request and complain to the Board
Notice languagesSection 5(3)An option to read the notice in English or in a language listed in the Eighth Schedule to the Constitution
ConsentSection 6A separate choice for each purpose, given by a clear affirmative action, with no pre-ticked boxes
WithdrawalSection 6(4)A way to withdraw consent that is as easy as giving it, such as a privacy settings link on every page
FormsSection 6(1)Only the fields needed for the stated purpose, with optional fields marked as optional
Cookies, pixels and SDKsSections 4, 6 and 8(2)A list of each tool, what it collects, the lawful ground relied on, and a contract where it processes data for you
ChildrenSection 9; Rule 10If children are likely users: age checks, verifiable consent of a parent or lawful guardian, and no tracking or targeted advertising directed at children
Contact and rightsSections 11 to 14; Rules 9 and 14Published contact details for privacy questions, and a published way to make access, correction, erasure and grievance requests
SecuritySection 8(5); Rule 6Encryption, access control for admin panels, monitoring, and logs kept for at least one year
Hosting and tools abroadSection 16; Rule 15Where data from the site is stored or sent outside India, and whether any destination is restricted by notification

Under the Act, a child is anyone under 18 (Section 2(f)). Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children, subject to the exemptions in the Rules.

Cookies and trackers under the DPDPA

The Act does not mention cookies by name. What matters is whether a cookie or tracker processes personal data, such as an identifier linked to a person, and for what purpose.

Where it does, the processing needs a lawful ground under Section 4: consent, or a legitimate use listed in Section 7. Advertising, retargeting and cross-site tracking are difficult to fit within Section 7, so these tools are usually loaded only after the visitor consents. For cookies needed only to run the service the visitor asked for, such as a login session or a security check, record which ground you rely on and why.

A cookie banner works only if the tools wait for the choice. If tags fire when the page loads, before the visitor chooses, the banner records a choice that was never applied.

  • List every cookie, tag, pixel and SDK on the site, with the company behind it and the data it receives.
  • Group them by purpose, for example: needed to run the site, analytics, advertising.
  • Block analytics and advertising tools until the visitor consents, and confirm this in the browser's network panel.
  • Give visitors a way to change their choice later from every page.
  • Remove tools that nobody in the organisation can explain.

Third-party tools are processors you have appointed

A tag added through a tag manager, or an SDK added to an app, can send personal data to another company. Where that company processes the data on your behalf, it is a Data Processor, and Section 8(2) allows you to engage it only under a valid contract.

Some providers also use the data for their own purposes. For those activities they may act as Data Fiduciaries themselves. Record the role of each provider, activity by activity, and check that the contract matches it.

A hashed email or a device identifier that can be matched back to a person is still data about an identifiable person and should be treated as personal data.

Mobile apps: a permission is not consent

An Android or iOS permission gives an app technical access to data such as location, contacts or the camera. It does not, by itself, give the notice of purpose that Section 5 requires or the specific consent that Section 6 requires.

Show your own notice and choice before or alongside the system prompt, and ask only for the permissions a feature needs. SDKs inside the app are checked the same way as website tags.

Sector rules can add limits. For example, RBI's digital lending directions restrict what lending apps may access on a borrower's phone.

Design choices that undermine consent

Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. A box that is already ticked is not an action by the visitor and is unlikely to meet that standard.

Other designs raise the same problem: a reject option hidden behind several screens, one consent covering many purposes, or a service refused unless the visitor agrees to processing the service does not need. The Central Consumer Protection Authority's Guidelines for Prevention and Regulation of Dark Patterns, 2023 also treat deceptive designs, such as false urgency and basket sneaking, as unfair trade practices.

Form data, accounts and retention

Data sent through contact forms, sign-ups and accounts follows the same rules as any other personal data. Under Section 8(7), it is erased once the purpose is served, unless a law requires it to be kept.

For certain large e-commerce, online gaming and social media platforms, the Third Schedule to the Rules sets a three-year period of inactivity after which personal data must be erased, with notice to the user at least 48 hours before.

Set a retention period for each form and account type, and make sure deletion also reaches copies in email inboxes, CRM tools and spreadsheets.

Questions and answers

DPDPA Website Compliance: common questions

Does the DPDPA require a cookie banner?

The Act does not mention cookies or banners. It requires a lawful ground for processing personal data. Where cookies or trackers process personal data on the basis of consent, a banner or a similar screen is a common way to give notice and collect consent that meets Sections 5 and 6, provided the tools wait for the choice.

Are pre-ticked consent boxes allowed under the DPDPA?

Consent must be given by a clear affirmative action (Section 6). A pre-ticked box is not an action by the visitor and is unlikely to meet the standard.

What must a website privacy notice include under the DPDP Rules?

Rule 3 requires the notice to be in clear and plain language and understandable on its own. It must give an itemised description of the personal data and the specified purpose, the goods, services or uses the processing enables, and a link or other means to withdraw consent, exercise rights and complain to the Board. Section 5(3) requires an option to read it in English or in a language in the Eighth Schedule to the Constitution.

Can we use analytics tools under the DPDPA?

Yes, if there is a lawful ground and the tool is handled as the Act requires. Where an analytics tool processes personal data, consent is usually the ground relied on. Check whether the provider acts as your Data Processor; if it does, Section 8(2) requires a contract. Transfers outside India follow Section 16.

Is an app permission valid consent under the DPDPA?

Not by itself. A permission gives technical access. The DPDPA requires a notice of the purpose and consent specific to it (Sections 5 and 6). Apps should show their own notice and choice alongside the permission prompt.

Does a website run from outside India need to follow the DPDPA?

It can. Under Section 3, the Act applies to processing outside India if it is connected with offering goods or services to people in India.

What is the penalty for website notice and consent failures?

Breaches of the notice and consent duties fall under the general ceiling of up to ₹50 crore in the Schedule. Failing to take reasonable security safeguards to prevent a breach carries a ceiling of up to ₹250 crore, and breaching the duties on children's data up to ₹200 crore. The Board decides the actual amount after an inquiry, having regard to Section 33(2).

Contact

Have your website or app reviewed against the DPDPA

Send the website or app name and what it collects. Your message goes to the AMLEGALS data privacy team.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

DPDPA Website Compliance: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPDPA Website Compliance?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPDPA Website Compliance under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPDPA Website Compliance under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPDPA Website Compliance?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPDPA Website Compliance rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPDPA Website Compliance?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPDPA Website Compliance · DPDPA Exposure Assessment