Skip to main content

Sources last verified on 25 August 2026. Methodology

DPDP and cookies: the Act never mentions them

Consent

By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 7 min read

The short answer

The DPDP Act 2023 and the DPDP Rules 2025 never mention cookies. The word appears 0 times in both. What the framework governs is personal data, so the duties attach to a cookie only when it carries data about an identifiable individual, which most analytics and advertising cookies do. Whether a bare session token is personal data is unsettled, and our reading is that it usually is, because the Data Fiduciary can relate it to its own session records. Where consent is the ground, the standard is section 6(1): free, specific, informed, unconditional and unambiguous with a clear affirmative action. The word explicit appears nowhere in the Act, so explicit consent is GDPR vocabulary and not Indian law. The requirement most cookie banners actually fail is section 6(4), which makes withdrawing consent as easy as giving it. Section 5, section 6 except sub-section (9), and section 9 are in the group due 18 months after publication, computed as 13 May 2027, which is interpretation until officially confirmed.

TL;DR infographic answering: Does the DPDP Act require cookie consent?

The word "cookie" appears 0 times in the Digital Personal Data Protection Act, 2023. It appears 0 times in the Digital Personal Data Protection Rules, 2025. So do "explicit", "granular", "banner", "browser" and "opt out".

That is not an oversight, and it does not mean cookies are unregulated. It means the framework governs something else, and the duty reaches a cookie only through that something else.

What the Act regulates instead

Section 2(t) defines the subject matter:

Official requirement · verbatim

"“personal data” means any data about an individual who is identifiable by or in relation to such data"

The obligation follows the data, not the storage mechanism. A cookie holding a persistent advertising identifier, a device fingerprint or a logged in user id carries personal data, and everything the framework says about personal data then applies to it. Whether a cookie holding only an opaque session token carries personal data is harder, and no Indian primary source has answered it. On our reading the limb "in relation to such data" is wide enough to reach a token the Data Fiduciary can relate to its own session records and so use to single out that visitor, which is what a server side session normally does. Treat such a token as personal data unless you can show that nothing you hold makes the individual identifiable. How long the cookie lives does not enter the section 2(t) test at all. Two files, same technology, different legal position, decided by what is inside them rather than by the fact that they are cookies.

This is why guidance that starts from "cookie rules" tends to go wrong in both directions at once: it imposes consent where the data identifies no one, and it misses obligations that have nothing to do with banners, such as retention and security.

The most repeated claim about DPDP and cookies is that the Act "requires explicit consent". The word explicit appears nowhere in it. What section 6(1) says is:

Official requirement · verbatim

"The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose."

Explicit consent is GDPR vocabulary. The Indian test is its own list of 5 adjectives plus a clear affirmative action, and the practical consequences differ from the GDPR test in places. Two consequences follow on our reading of those words, and neither is spelled out in the text:

  • Consent by scrolling, or by continuing to browse, is very hard to reconcile with section 6(1). Not because a rule names that pattern, but because neither is a clear affirmative action signifying agreement. No Indian authority has ruled on it, so this is a reading of the words rather than a decided point.
  • A single Accept button covering analytics, advertising and personalisation at once is hard to defend, because consent must be specific. Section 6(1) does not void a bundled consent outright: its own Illustration takes a consent given to 2 things at once and cuts it down to the processing that was necessary, and section 6(2) invalidates any infringing part to the extent of the infringement. So the exposure is not that the button is unlawful, it is that what you actually hold may be far narrower than what the button appeared to collect. That is the honest route to what other guidance calls granular consent. The word granular is not in the Act, and nothing in the text prescribes cookie categories or a particular interface.

The requirement most banners actually fail

Section 6(4) is the provision to check your own site against first, and it is rarely the one cookie guidance leads with:

Official requirement · verbatim

"Where consent given by the Data Principal is the basis of processing of personal data, such Data Principal shall have the right to withdraw her consent at any time, with the ease of doing so being comparable to the ease with which such consent was given."

Comparable ease is a statutory test in India, not a regulator's suggestion. The test is comparable ease, not identical ease, and no Indian authority has yet construed it. An interface where accepting takes 1 click on the first screen while withdrawing takes a visit to a settings page, 3 clicks and a toggle is the pattern most exposed to it, and we would not want to argue that the 2 are comparable. A banner with a prominent Accept and no way back at all is a clearer failure, because section 6(4) gives the right to withdraw at any time and such an interface does not provide it. Our practical recommendation, rather than a requirement of the text: if you build only 1 thing after reading this, build the withdrawal path.

Notice is a content requirement, not a banner requirement

Rule 3 governs the notice that accompanies a consent request. It requires the notice to be presented and understandable independently of any other information, and to give, at a minimum, an itemised description of the personal data and the specified purposes. A line reading "we use cookies to improve your experience" fails the itemised description, and it would fail it in a modal, a footer or a full page. The Rules say nothing about where on a site or app the notice must appear. What Rule 3(a) does constrain is that it be presented independently of any other information, so it cannot be folded into surrounding content.

The one place tracking is named

Tracking appears exactly once in the Act, and not as a consent rule. Section 9(3):

Official requirement · verbatim

"A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children."

That is a prohibition, not a permission that consent unlocks. A consent banner cannot cure it, and parental consent does not convert it into something allowed, because sub-section (3) is not written as a consent requirement at all. If your site is likely to have child users and you run behavioural advertising, that is a design question and not a banner question. The exemptions are narrow and they are not all in one place. Sub-section (4) is the power under which Rule 12 and the Fourth Schedule disapply sub-sections (1) and (3) for listed classes and purposes, and the entries whose conditions speak of tracking are drawn for educational institutions, creches, child transport, and determining a child's real time location for her safety. Sub-section (5) is a separate route, under which the Central Government may notify an age above which a given Data Fiduciary is exempt from sub-sections (1) and (3) where its processing is verifiably safe, and no such notification has issued. None of these is drawn for advertising.

What this means in practice

State the position plainly, because the vocabulary in circulation is not the vocabulary of the law:

Claim in circulationWhat the framework actually says
DPDP requires cookie consentThe word cookie appears 0 times. Section 4(1) allows processing on consent or on a certain legitimate use under section 7, so what needs a lawful ground is the personal data, whatever holds it
DPDP requires explicit consentThe word explicit appears 0 times. The test is section 6(1), 5 adjectives plus a clear affirmative action
DPDP requires granular cookie categoriesGranular appears 0 times. Consent must be specific and limited to what the purpose needs, which is a constraint on scope rather than a prescribed interface
DPDP requires an Accept Cookies buttonNo consent interface and no Accept button is prescribed in the Act or the Rules. What the Rules do prescribe is publication: a communication link under Rule 3(c), and prominent publication of the means to exercise rights under Rule 14(1)
A cookie banner covers youNotice content under Rule 3, withdrawal parity under section 6(4), retention and security all sit outside the banner

When this starts to apply

Section 5, sub-sections (1) to (8) and (10) of section 6, and section 9, which carry the notice, consent and children's provisions this article turns on, are all named in the 18 month commencement group of notification G.S.R. 843(E). Only section 6(9), on registration of Consent Managers with the Board, sits in the earlier 1 year group. Computed from the publication date printed on Gazette issue No. 757, that group is due on 13 May 2027, and that calendar date is interpretation until officially confirmed. None of the obligations described in this article is in force as at 26 August 2026. Section 2, which supplies the definition the scope test rests on, came into force on publication under clause (a) of the same notification.

The reason to act now is not the deadline. It is that a consent interface is one of the hardest things to retrofit, and a withdrawal path that was never built is not something you can add to data you have already shared.

What valid consent requiresWhat a privacy notice must containSection 6, official text with sources

cookiesconsentsection 6myth correction

Share this: