Home/Services/Cookie Consent Management
TECHNICAL SCRIPT-LEVEL BLOCKING & CMP

Cookie Consent Management — Every Script Blocked Until the User Says Yes

The average Indian business website runs 25-40 third-party scripts — Google Analytics, Meta Pixel, LinkedIn Insight, HubSpot tracking, Hotjar session recording, ad retargeting pixels, customer chat widgets, and a dozen more. Most of these scripts fire the moment a visitor lands on the page — before any consent banner appears, before the visitor clicks anything, and before the visitor even knows they are being tracked.

Under the DPDP Act 2023, that first unconsented page load is already a violation. Section 6 requires informed, purpose-specific consent before processing personal data. Cookies that track behaviour, identify users, and build profiles are personal data processing. Every page load that fires non-essential scripts without consent is a separate processing event. At scale — thousands of visitors per day — the violation count compounds rapidly.

A cookie banner that says "We use cookies to improve your experience" with a single "Accept" button is not consent. It is a dark pattern. And in 2026, the Data Protection Board treats dark patterns in cookie banners as an active enforcement priority.

PrivacyOS provides a cookie consent management platform that scans every cookie and tracker on your site, classifies them by purpose, blocks non-essential scripts until the visitor explicitly consents, serves jurisdiction-appropriate banners, integrates with Google Consent Mode v2, and maintains immutable audit logs that prove compliance under regulatory scrutiny.

Full Consent Platform
0ms Delay
Strict Pre-Consent Blocking
Google v2
Consent Mode Integrated
Geo-Aware
DPDPA + GDPR + CCPA
Website Cookie Audit & Scan
· DPDPA Compliance · Trust Assured
FAST TRACK APPLICATION

Apply for DPDPA Assessment

Fill the details to get started with our corporate panel.

Representative PortraitRepresentative PortraitRepresentative PortraitRepresentative Portrait
4.9/5

Trusted by 1,000+ compliance teams

Why Cookie Consent Is a DPDPA Enforcement Priority

Cookie banners are the most visible privacy touchpoint on any website. They are the first thing a visitor interacts with. They are the first thing a regulator checks. And they are the easiest violation to detect — a regulator does not need access to your systems. They just need to visit your website.

Multiple factors make cookie consent a high-priority enforcement area:

Visibility

Anyone — regulators, competitors, journalists, privacy advocates — can visit your site and observe whether scripts fire before consent. Enforcement does not require a complaint or a breach. A routine website review by the Board is sufficient.

Dark Pattern Crackdowns

Globally, regulators are converging on the same position: cookie banners that nudge, pressure, or confuse users into accepting tracking are not valid consent. The DPDPA's consent standard — free, specific, informed, unconditional, unambiguous — makes every common dark pattern a violation.

Ad Platform Enforcement

Google Consent Mode v2 requires a compliant CMP for Google Analytics and Google Ads to function correctly. Meta's data processing terms require verified consent before pixel data is accepted. Non-compliant cookie consent does not just create regulatory risk — it degrades your advertising data quality.

Scale of Violation

Each unconsented page load with tracking scripts is a separate processing event. A website with 10,000 daily visitors running analytics and ad pixels without consent generates 10,000 violations per day. The compounding exposure is enormous.

What DPDPA Requires for Cookies and Trackers

Section 6 applies to all personal data processing — including cookies and tracking scripts that collect, store, or transmit data about identifiable individuals. In practice, this means:

Strictly necessary cookies may operate without consent

Session cookies required for basic site functionality (login state, shopping cart, language preference) may operate without consent. These do not process personal data for secondary purposes.

Everything else requires consent before firing

Analytics cookies, advertising pixels, session recording tools, social media widgets, A/B testing scripts, heat mapping tools, customer chat tracking, and personalisation engines all require explicit, purpose-specific consent before they execute.

Consent must be purpose-specific

"Accept all cookies" as a single option is not purpose-specific. Users must be able to consent to analytics separately from advertising, and functional cookies separately from personalisation. Bundling everything into one toggle violates Section 6's purpose-specificity requirement.

Rejection must be as easy as acceptance

Section 6(4) requires that withdrawal be as easy as consent. A banner with a prominent "Accept All" and a hidden "Manage Preferences" link violates this principle. "Reject All" must be as prominent and accessible as "Accept All."

Consent must be provable

Section 6(10) places the burden of proof on the Data Fiduciary. You must demonstrate what banner was shown, what scripts were blocked, what the visitor consented to, when, and through what action. Without timestamped, version-controlled records, you cannot meet this burden.

The Dark Patterns Problem

The Data Protection Board and global regulators have identified specific cookie banner dark patterns as enforcement targets:

"Accept All" without "Reject All"

Giving one option prominence while hiding or omitting the other removes genuine choice. Consent given without a real alternative is not "free" under Section 6.

Cookie walls

Blocking site access until the user accepts all cookies removes choice entirely. Access contingent on consent is not "unconditional" under Section 6.

Pre-ticked checkboxes

Categories pre-selected for consent require the user to actively deselect — this is not "unambiguous" affirmative action.

Confusing language

"Improve your experience" instead of "Analytics tracking" or "Third-party advertising" is not "informed" consent. Users must understand what they are consenting to.

Asymmetric design

"Accept All" in bright colour, large text. "Manage Preferences" in grey, small text, requiring 3 clicks to reject. The design manipulates the outcome.

Forced re-consent

Showing the banner on every page load until the user accepts, while a "reject" decision is remembered for only one session. This pressures the user into accepting.

PrivacyOS Banners: Dark Pattern-Free by Default

Equal prominence for accept and reject. Clear category labels. No pre-ticked boxes. No cookie walls. No asymmetric design. Compliant out of the box.

What PrivacyOS Cookie Consent Management Covers

9 core technical capabilities guaranteeing compliance from code execution to audit trails:

Automated Cookie Scanning and Classification

PrivacyOS scans your website to detect every cookie, tracker, pixel, and script — including third-party scripts loaded dynamically through tag managers, ad networks, and embedded widgets. Each detected element is automatically classified into one of four categories:

Strictly Necessary

Essential for basic site functionality. No consent required.

Functional

Features that enhance user experience (language preferences, chat widgets). Consent required.

Analytics

Usage tracking, session recording, heat mapping, A/B testing. Consent required.

Advertising

Ad targeting, retargeting pixels, conversion tracking, social media tracking. Consent required.

Scanning runs periodically — not just at initial setup. When your marketing team adds a new script through Google Tag Manager, or a developer integrates a new analytics tool, the scanner detects it and flags it for classification. Unclassified scripts are blocked by default until categorised and assigned a consent basis.

Script-Level Blocking Before Consent

This is the technical requirement most cookie banners fail. It is not enough to show a banner and record the user's choice. Non-essential scripts must be technically prevented from executing until consent is granted.

PrivacyOS implements script-level blocking:

  • Non-essential scripts are intercepted before execution on page load
  • Scripts fire only after the visitor consents to the specific category
  • If a visitor declines analytics cookies, Google Analytics never loads — not after the page renders, not in the background, not through a tag manager workaround
  • If a visitor declines advertising cookies, Meta Pixel, LinkedIn Insight, and retargeting tags never execute

The blocking is enforced at the tag level, not at the display level. A banner that shows "Cookies rejected" while scripts continue to fire in the background is a compliance failure. PrivacyOS ensures technical enforcement matches the visitor's stated preference.

Geo-Aware Banner Serving

Your website serves visitors from multiple jurisdictions. An Indian visitor needs a DPDPA-compliant banner. An EU visitor needs a GDPR-compliant banner with IAB TCF support. A California visitor needs CCPA opt-out language.

India (DPDPA)

Purpose-specific categories, equal accept/reject, multilingual support (all 22 scheduled languages + English).

EU/UK (GDPR)

Granular category consent, IAB Transparency and Consent Framework (TCF) v2.2 integration, legitimate interest handling.

California (CCPA/CPRA)

"Do Not Sell or Share My Personal Information" direct opt-out link.

Other Jurisdictions

Default global banner with configurable enterprise consent baselines.

One script installation. Multiple jurisdictions. No manual per-region configuration.

Dark Pattern-Free Banner Design

  • Equal prominence for "Accept All" and "Reject All" — same size, same visual weight, same position hierarchy
  • Clear category labels — "Analytics Tracking," "Advertising," "Functional" — not vague euphemisms
  • No pre-ticked boxes — all non-essential categories start unchecked
  • No cookie walls — site remains accessible regardless of consent decision
  • Persistent preference — consent or rejection remembered for the duration you configure (typically 6-12 months), not reset on each visit
  • Customisable design — brand colours, fonts, and layout adjustable while maintaining compliance defaults

Category-Level Granular Consent

Users can consent to analytics but reject advertising. Accept functional cookies but decline everything else. Each category is independent. Each consent decision is recorded separately.

This granularity satisfies DPDPA's purpose-specific requirement and gives users genuine control — not a binary accept-everything-or-nothing choice.

Google Consent Mode v2 Integration

If you use Google Analytics, Google Ads, Google Tag Manager, or any Google marketing tool, Consent Mode v2 integration is essential. Without it, Google tags either fire without consent (a violation) or are blocked entirely (losing all measurement data).

Consent Granted

Google tags operate normally with full measurement across sessions.

Consent Denied

Google tags operate in restricted mode: no cookies set, no personal data collected, but anonymous pings still sent for basic measurement (conversion modelling, cookieless analytics).

This means you respect consent AND maintain usable analytics data — without choosing between compliance and measurement.

Cookie Policy Auto-Generation

PrivacyOS generates your cookie policy automatically from scan results. The policy lists every cookie detected, its purpose, its category, its duration, and the third party that sets it. When the scanner detects a new cookie, the policy updates automatically.

No more manually maintaining a cookie table that was accurate six months ago. The policy reflects your actual cookie landscape at all times.

Consent Analytics Dashboard

Track cookie consent performance through the compliance dashboard:

  • Consent rates — what percentage of visitors accept, reject, or partially consent
  • Category breakdown — acceptance rates for analytics vs advertising vs functional
  • Geo distribution — consent rates by jurisdiction (India vs EU vs US)
  • Trend analysis — how consent rates change over time, after banner design changes, or after policy updates
  • Bounce correlation — whether your banner design is affecting bounce rates (banners that annoy visitors increase bounces)

These analytics help you optimise your banner design within compliance boundaries — improving consent rates without resorting to dark patterns.

Immutable Consent Audit Logs

Every consent event is logged immutably:

Banner version displayed
Categories presented
Consented categories
Rejected categories
Timestamp of action
Visitor location
Scripts blocked/unblocked

These records satisfy Section 6(10)'s burden of proof. When the Board asks whether consent was obtained before tracking scripts fired, you have timestamped evidence for every visitor interaction.

How Cookie Consent Connects to Your Full Consent Programme

Cookie consent is the website layer of a broader consent management programme. In PrivacyOS, cookie consent integrates with:

Full consent management

Cookie consent records are part of the unified consent ledger alongside app consent, email consent, and third-party sharing consent. One Data Principal's consent posture — across all channels — is visible in one place.

Data discovery

Cookie scanning feeds into your data discovery inventory. Cookies that collect personal data are mapped as data sources. Third-party cookie providers are flagged for vendor risk assessment.

DSR automation

When a Data Principal requests access, their cookie consent history is part of the disclosure. When they request erasure, cookie identifiers linked to their profile are included in the deletion scope.

Compliance dashboards

Cookie consent rates, category breakdowns, and geo-distribution are part of your overall compliance scorecard.

Unified Architecture: Cookie consent is not a standalone tool. It is the first touchpoint in a connected compliance programme.

Common Cookie Consent Mistakes

Technical, visual, and operational errors that trigger Data Protection Board scrutiny:

Mistake 1

Banner without blocking

Showing a consent banner but allowing all scripts to fire regardless of the user's choice. The banner is decorative. The violation is real.

Mistake 2

"Accept" only, no "Reject"

A banner with only an "Accept All" button and a settings gear icon that requires 4 clicks to reach rejection. Not "free" consent.

Mistake 3

Cookie wall

"Accept cookies to access this site." Consent given under access pressure is not "unconditional."

Mistake 4

Scanning once, never again

Your marketing team adds scripts monthly. A scan from six months ago misses half your current trackers. Unclassified scripts firing without consent are violations.

Mistake 5

No Google Consent Mode

Blocking Google tags entirely when consent is denied loses all measurement. Consent Mode v2 allows restricted measurement without personal data — you maintain analytics capability while respecting consent.

Mistake 6

Same banner for all jurisdictions

DPDPA and GDPR have different consent requirements. Serving a GDPR banner to Indian visitors (with "legitimate interest" options that do not exist under DPDPA) is non-compliant.

Mistake 7

No audit trail

"We have a cookie banner" is not evidence. Without timestamped records of what was shown, what was consented to, and what scripts were blocked/unblocked, you cannot prove compliance.

Frequently Asked Questions

Answers regarding Indian legal requirements, Google Consent Mode, and dark pattern avoidance

DEPLOY IN DAYS

Get Cookie Compliant This Week

Your website is being tracked right now — by regulators, by privacy advocates, and by the scripts firing on every page load. Cookie consent is the most visible compliance obligation you have, and the easiest one for the Board to check.

PrivacyOS deploys a compliant cookie consent banner on your website within days. Scanner runs. Scripts classified. Non-essential trackers blocked. Banner served. Audit logs active. Your first compliant page load can happen this week.

Call Us: +91 8887946496