What must a cookie consent notice cover under DPDP in India? A DPDP-compliant cookie consent notice in India must move away from a single 'Accept All' bar to a granular, category-based mechanism: it should list every cookie and tracking script by category (strictly necessary, functional, analytics, advertising), explain in plain language what each category does and who receives the data, load non-essential scripts only after the visitor has actively opted in, and provide an equally easy way to withdraw consent later. Pre-ticked boxes and implied consent do not meet the DPDP standard of free, specific, informed and unambiguous consent. This Pro kit generates your full cookie notice, the banner and preference-centre copy, a first-vs-third-party script inventory, and the consent-manager (CMP) configuration guidance so your website meets the cookie consent notice India DPDP expectation.
Generate a full cookie consent notice, category-by-category banner copy, a script inventory and CMP configuration guidance tailored to your website — built for the DPDP Act 2023 standard of granular, withdrawable consent.
Every cookie and tracking script on your site should be sorted into one of four categories, because DPDP consent obligations differ by category. Strictly necessary cookies (session tokens, cart state, CSRF/security) keep the site functioning and are the only category that may load before the visitor interacts with the banner — they are essential to deliver the service the user has asked for. Functional cookies (remembered language, saved preferences, live-chat widgets) improve the experience but are not essential, so they should load only after opt-in. Analytics cookies (GA4, Microsoft Clarity, Hotjar) and advertising/retargeting pixels (Meta Pixel, Google Ads, programmatic tags) collect and share behavioural data with third parties, so they carry the highest consent bar and must be blocked until the visitor actively enables them.
The single most common DPDP gap is loading analytics and advertising scripts on page-load, before any consent is captured — a 'notify and continue' banner is not consent. Under the DPDP Act 2023, consent must be free, specific to each purpose, informed and unambiguous, which in practice means a category-based banner where each non-essential category is off by default and the visitor makes an active choice. This kit maps every script you selected above into the correct category so nothing loads prematurely.
Your consent banner has three jobs and this section gives you the exact copy for each: a short plain-language explanation of why cookies are used, a genuine choice between 'Accept all', 'Reject all' and 'Manage preferences' (with 'Reject all' given equal visual weight to 'Accept all' — a hidden or greyed-out reject option undermines the free-choice requirement), and a link to the full cookie notice. The banner copy is written so a non-technical visitor understands what they are agreeing to before they click, which is the essence of informed consent.
The preference centre is where granular, per-category control lives: each category listed with a plain-language description, a toggle that is off by default for every non-essential category, and a short list of the specific scripts in that category so a curious or privacy-conscious visitor can see exactly who receives their data. The kit provides ready-to-paste copy for the banner and every preference-centre toggle, tailored to the categories you selected, so your development or marketing team can drop it straight into your CMP without rewriting.
Cookie categories selected for your notice:
A cookie consent notice India DPDP requirement is fundamentally about consent quality, not just having a banner. The DPDP Act 2023 requires consent to be free, specific, informed, unambiguous and as easy to withdraw as to give. Applied to cookies, that rules out the two most common patterns still seen on Indian websites: the 'we use cookies, by continuing you agree' bar (implied consent, not valid) and the single 'Accept All' button with no way to refuse non-essential tracking. A compliant notice separates strictly necessary cookies from everything else, blocks analytics and advertising scripts until the visitor opts in, and offers a clear reject path with equal prominence to accept.
The DPDP Rules 2025, notified in November 2025 with an implementation window running to full enforcement around May 2027, reinforce the expectation of granular, purpose-specific consent and clear plain-language notice. Websites that run analytics, retargeting pixels or social embeds are sharing behavioural data with third parties, so getting the cookie layer right is one of the most visible and easily-checked parts of a DPDP programme — it is often the first thing a Data Principal or the Data Protection Board looks at.
Fixing cookies is not just a copy exercise — it is a configuration exercise. The notice text must match what the site actually loads, non-essential tags must be genuinely blocked behind consent (not merely hidden), and every consent event needs to be logged so you can prove valid consent later. This kit gives you all three: the notice and banner copy, the script inventory that keeps the notice honest, and the CMP configuration guidance that makes the technical blocking real. Together they turn a decorative cookie bar into a defensible consent programme.
Cookie consent is usually the fastest, most visible DPDP win a website can ship, but it should sit inside a wider compliance posture covering your privacy notice, consent records and data-principal rights. Niti Bharat runs fixed-price DPDP compliance engagements (₹75,000–₹3.2 lakh) that connect your cookie layer to the rest of your programme, so a visitor's cookie choice, your analytics use and your data-sharing disclosures all tell one consistent story.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.