The average Indian business website runs 25-40 third-party scripts — Google Analytics, Meta Pixel, LinkedIn Insight, HubSpot tracking, Hotjar session recording, ad retargeting pixels, customer chat widgets, and a dozen more. Most of these scripts fire the moment a visitor lands on the page — before any consent banner appears, before the visitor clicks anything, and before the visitor even knows they are being tracked.
Under the DPDP Act 2023, that first unconsented page load is already a violation. Section 6 requires informed, purpose-specific consent before processing personal data. Cookies that track behaviour, identify users, and build profiles are personal data processing. Every page load that fires non-essential scripts without consent is a separate processing event. At scale — thousands of visitors per day — the violation count compounds rapidly.
A cookie banner that says "We use cookies to improve your experience" with a single "Accept" button is not consent. It is a dark pattern. And in 2026, the Data Protection Board treats dark patterns in cookie banners as an active enforcement priority.
PrivacyOS provides a cookie consent management platform that scans every cookie and tracker on your site, classifies them by purpose, blocks non-essential scripts until the visitor explicitly consents, serves jurisdiction-appropriate banners, integrates with Google Consent Mode v2, and maintains immutable audit logs that prove compliance under regulatory scrutiny.
Fill the details to get started with our corporate panel.
Trusted by 1,000+ compliance teams
Cookie banners are the most visible privacy touchpoint on any website. They are the first thing a visitor interacts with. They are the first thing a regulator checks. And they are the easiest violation to detect — a regulator does not need access to your systems. They just need to visit your website.
Multiple factors make cookie consent a high-priority enforcement area:
Anyone — regulators, competitors, journalists, privacy advocates — can visit your site and observe whether scripts fire before consent. Enforcement does not require a complaint or a breach. A routine website review by the Board is sufficient.
Globally, regulators are converging on the same position: cookie banners that nudge, pressure, or confuse users into accepting tracking are not valid consent. The DPDPA's consent standard — free, specific, informed, unconditional, unambiguous — makes every common dark pattern a violation.
Google Consent Mode v2 requires a compliant CMP for Google Analytics and Google Ads to function correctly. Meta's data processing terms require verified consent before pixel data is accepted. Non-compliant cookie consent does not just create regulatory risk — it degrades your advertising data quality.
Each unconsented page load with tracking scripts is a separate processing event. A website with 10,000 daily visitors running analytics and ad pixels without consent generates 10,000 violations per day. The compounding exposure is enormous.
Section 6 applies to all personal data processing — including cookies and tracking scripts that collect, store, or transmit data about identifiable individuals. In practice, this means:
Session cookies required for basic site functionality (login state, shopping cart, language preference) may operate without consent. These do not process personal data for secondary purposes.
Analytics cookies, advertising pixels, session recording tools, social media widgets, A/B testing scripts, heat mapping tools, customer chat tracking, and personalisation engines all require explicit, purpose-specific consent before they execute.
"Accept all cookies" as a single option is not purpose-specific. Users must be able to consent to analytics separately from advertising, and functional cookies separately from personalisation. Bundling everything into one toggle violates Section 6's purpose-specificity requirement.
Section 6(4) requires that withdrawal be as easy as consent. A banner with a prominent "Accept All" and a hidden "Manage Preferences" link violates this principle. "Reject All" must be as prominent and accessible as "Accept All."
Section 6(10) places the burden of proof on the Data Fiduciary. You must demonstrate what banner was shown, what scripts were blocked, what the visitor consented to, when, and through what action. Without timestamped, version-controlled records, you cannot meet this burden.
The Data Protection Board and global regulators have identified specific cookie banner dark patterns as enforcement targets:
Giving one option prominence while hiding or omitting the other removes genuine choice. Consent given without a real alternative is not "free" under Section 6.
Blocking site access until the user accepts all cookies removes choice entirely. Access contingent on consent is not "unconditional" under Section 6.
Categories pre-selected for consent require the user to actively deselect — this is not "unambiguous" affirmative action.
"Improve your experience" instead of "Analytics tracking" or "Third-party advertising" is not "informed" consent. Users must understand what they are consenting to.
"Accept All" in bright colour, large text. "Manage Preferences" in grey, small text, requiring 3 clicks to reject. The design manipulates the outcome.
Showing the banner on every page load until the user accepts, while a "reject" decision is remembered for only one session. This pressures the user into accepting.
Equal prominence for accept and reject. Clear category labels. No pre-ticked boxes. No cookie walls. No asymmetric design. Compliant out of the box.
9 core technical capabilities guaranteeing compliance from code execution to audit trails:
PrivacyOS scans your website to detect every cookie, tracker, pixel, and script — including third-party scripts loaded dynamically through tag managers, ad networks, and embedded widgets. Each detected element is automatically classified into one of four categories:
Essential for basic site functionality. No consent required.
Features that enhance user experience (language preferences, chat widgets). Consent required.
Usage tracking, session recording, heat mapping, A/B testing. Consent required.
Ad targeting, retargeting pixels, conversion tracking, social media tracking. Consent required.
Scanning runs periodically — not just at initial setup. When your marketing team adds a new script through Google Tag Manager, or a developer integrates a new analytics tool, the scanner detects it and flags it for classification. Unclassified scripts are blocked by default until categorised and assigned a consent basis.
This is the technical requirement most cookie banners fail. It is not enough to show a banner and record the user's choice. Non-essential scripts must be technically prevented from executing until consent is granted.
PrivacyOS implements script-level blocking:
The blocking is enforced at the tag level, not at the display level. A banner that shows "Cookies rejected" while scripts continue to fire in the background is a compliance failure. PrivacyOS ensures technical enforcement matches the visitor's stated preference.
Your website serves visitors from multiple jurisdictions. An Indian visitor needs a DPDPA-compliant banner. An EU visitor needs a GDPR-compliant banner with IAB TCF support. A California visitor needs CCPA opt-out language.
Purpose-specific categories, equal accept/reject, multilingual support (all 22 scheduled languages + English).
Granular category consent, IAB Transparency and Consent Framework (TCF) v2.2 integration, legitimate interest handling.
"Do Not Sell or Share My Personal Information" direct opt-out link.
Default global banner with configurable enterprise consent baselines.
One script installation. Multiple jurisdictions. No manual per-region configuration.
Users can consent to analytics but reject advertising. Accept functional cookies but decline everything else. Each category is independent. Each consent decision is recorded separately.
This granularity satisfies DPDPA's purpose-specific requirement and gives users genuine control — not a binary accept-everything-or-nothing choice.
If you use Google Analytics, Google Ads, Google Tag Manager, or any Google marketing tool, Consent Mode v2 integration is essential. Without it, Google tags either fire without consent (a violation) or are blocked entirely (losing all measurement data).
Google tags operate normally with full measurement across sessions.
Google tags operate in restricted mode: no cookies set, no personal data collected, but anonymous pings still sent for basic measurement (conversion modelling, cookieless analytics).
This means you respect consent AND maintain usable analytics data — without choosing between compliance and measurement.
PrivacyOS generates your cookie policy automatically from scan results. The policy lists every cookie detected, its purpose, its category, its duration, and the third party that sets it. When the scanner detects a new cookie, the policy updates automatically.
No more manually maintaining a cookie table that was accurate six months ago. The policy reflects your actual cookie landscape at all times.
Track cookie consent performance through the compliance dashboard:
These analytics help you optimise your banner design within compliance boundaries — improving consent rates without resorting to dark patterns.
Every consent event is logged immutably:
These records satisfy Section 6(10)'s burden of proof. When the Board asks whether consent was obtained before tracking scripts fired, you have timestamped evidence for every visitor interaction.
Cookie consent is the website layer of a broader consent management programme. In PrivacyOS, cookie consent integrates with:
Cookie consent records are part of the unified consent ledger alongside app consent, email consent, and third-party sharing consent. One Data Principal's consent posture — across all channels — is visible in one place.
Cookie scanning feeds into your data discovery inventory. Cookies that collect personal data are mapped as data sources. Third-party cookie providers are flagged for vendor risk assessment.
When a Data Principal requests access, their cookie consent history is part of the disclosure. When they request erasure, cookie identifiers linked to their profile are included in the deletion scope.
Cookie consent rates, category breakdowns, and geo-distribution are part of your overall compliance scorecard.
Technical, visual, and operational errors that trigger Data Protection Board scrutiny:
Showing a consent banner but allowing all scripts to fire regardless of the user's choice. The banner is decorative. The violation is real.
A banner with only an "Accept All" button and a settings gear icon that requires 4 clicks to reach rejection. Not "free" consent.
"Accept cookies to access this site." Consent given under access pressure is not "unconditional."
Your marketing team adds scripts monthly. A scan from six months ago misses half your current trackers. Unclassified scripts firing without consent are violations.
Blocking Google tags entirely when consent is denied loses all measurement. Consent Mode v2 allows restricted measurement without personal data — you maintain analytics capability while respecting consent.
DPDPA and GDPR have different consent requirements. Serving a GDPR banner to Indian visitors (with "legitimate interest" options that do not exist under DPDPA) is non-compliant.
"We have a cookie banner" is not evidence. Without timestamped records of what was shown, what was consented to, and what scripts were blocked/unblocked, you cannot prove compliance.
Omnichannel consent across web, app, email, SMS, and in-store with multilingual support.
Continuous PII inventory scans across product databases, APIs, logs, and cookie storage.
Live visibility into visitor consent ratios, category acceptance rates, and regulatory health.
Answers regarding Indian legal requirements, Google Consent Mode, and dark pattern avoidance
Your website is being tracked right now — by regulators, by privacy advocates, and by the scripts firing on every page load. Cookie consent is the most visible compliance obligation you have, and the easiest one for the Board to check.
PrivacyOS deploys a compliant cookie consent banner on your website within days. Scanner runs. Scripts classified. Non-essential trackers blocked. Banner served. Audit logs active. Your first compliant page load can happen this week.