DPDP Act 2023 · Cookies

Cookie consent under the DPDP Act: what Indian websites actually need

Published July 2026 · ~6 min read · by Ronin Works
Short answer

The DPDP Act never says "cookie" — but cookies, device IDs and analytics identifiers that can identify a person are digital personal data, and collecting them for tracking, analytics or ads needs valid consent: plain-language notice, a real choice, an affirmative action, withdrawal as easy as acceptance, and a provable record of it all. Cookies genuinely required to deliver what the visitor asked for (login sessions, carts) sit on much safer ground. An "Accept-only" banner fails.

Indian websites have watched European cookie banners for years as someone else's problem. With the final DPDP Rules notified and full compliance due 13 May 2027, that's over — not because India copied the EU's cookie law, but because India's definition of personal data quietly covers the same territory.

Why cookies are covered without being named

The Act governs digital personal data — any data about an individual who is identifiable by it. An analytics ID that follows one visitor across sessions, an advertising identifier matched to a profile, a device fingerprint: each one singles out a person, which is exactly what makes it useful and exactly what makes it personal data. Once it's personal data, the full consent standard applies to collecting it.

The three kinds of cookies, in DPDP terms

Necessary for the service

Session cookies that keep someone logged in, a cart that holds their order, a security token: this is data processing for the very thing the visitor asked you to do — the strongest ground the Act offers. Keep these lean and document why each one is genuinely necessary.

Analytics

Understanding traffic is legitimate to want — but an identifier that profiles individual visitors needs consent. The honest options: ask for consent like everyone else, or use genuinely aggregate, identifier-free measurement that never singles out a person.

Marketing & advertising

Cross-site tracking, remarketing audiences, ad identifiers — the clearest consent case in the whole Act. Specific, informed, refusable, withdrawable. No consent, no pixel.

What a compliant banner looks like

One irony to avoid

Many cookie-consent tools are themselves tracking machines — set a cookie to remember the consent, fingerprint the visitor, phone home. A consent tool should not create the problem it exists to solve. (This is why Ronin Consent stores the visitor's choice in their own browser and keeps the audit record server-side — the widget itself sets no cookies.)

DPDP vs GDPR, in one paragraph

The mechanics converge — notice, granular choice, affirmative action, easy withdrawal — so if you've seen good European banners, you know the shape. The differences: India has no separate ePrivacy-style cookie law, so everything flows from the personal-data rules; your notice should be accessible in plain language (and ideally in Indian languages, matching the Act's spirit of accessible notice); and your proof obligations run to India's Data Protection Board, with India's penalty schedule behind them.

Want the banner without the project?

Ronin Consent is one script tag: a DPDP-compliant banner, granular choices, one-tap withdrawal, and an append-only consent log — built for MSMEs. Early access is open.

Keep reading

Not a business — just you?

The DPDP Act gives individuals rights too. Saaph.in — a Ronin Works product — finds where your personal data is exposed across the open web and gets it removed under the Act, then keeps watch.

Scan your exposure at Saaph.in →
Enquiry

Need a compliant cookie setup?

Send us a note — we reply within one working day.

✓ Thank you — we'll be in touch.

This article is general information, not legal advice. It summarises the DPDP Act, 2023 and the DPDP Rules as notified in November 2025 as they bear on cookies and similar identifiers; for the authoritative text consult the Gazette notifications or a qualified professional, or talk to Ronin Works.