LEGALWEBSITE.inEvery page. Every law. No surprises. All articles
Cookies 6 min readReviewed 5 September 2026

Cookies and trackers: what Indian law actually says

India has no dedicated cookie law. The obligation comes from the DPDP Act where a cookie processes personal data, and from the dark-pattern guidelines where the banner is designed to push a choice.

There is no Indian equivalent of the ePrivacy Directive

No Indian statute regulates cookies as such. Nothing in Indian law requires consent merely because information is stored on a device. This differs from the position in the European Union, and copying an EU cookie banner does not by itself create compliance in India — or breach of it.

The obligation arises indirectly. Where a cookie, pixel, SDK or fingerprinting script processes digital personal data — data about an identifiable individual, which includes an identifier tied to a user profile or device where that identifies a person — the DPDP Act applies to that processing. If the processing is not covered by a legitimate use under Section 7, it needs notice and consent under Sections 5 and 6.

How that translates to a banner

  • Cookies strictly necessary to deliver the service the user asked for — session, authentication, load balancing, security — are ordinarily justified without a separate consent, but should still be disclosed.
  • Analytics, advertising, retargeting, session-replay and third-party chat or embed scripts that process personal data should not run before consent, because consent must precede the processing it authorises.
  • Refusing must be as easy as accepting, both because Section 6(4) requires withdrawal to be as easy as consent and because a one-sided banner is capable of being treated as a dark pattern.
  • Record what the user chose and when, so the choice can be evidenced and honoured on later visits.

The dark-pattern overlay

The Guidelines for Prevention and Regulation of Dark Patterns, 2023, issued by the Central Consumer Protection Authority under the Consumer Protection Act, 2019, list specified deceptive design practices and prohibit their use by platforms offering goods or services in India. Practices in the list that appear in consent design include false urgency, confirm-shaming, interface interference that visually obscures a choice, forced action and nagging.

A banner where 'Accept all' is a filled button and 'Reject' is grey text in the corner, or where refusing requires opening a second screen and toggling items individually, is the design pattern those guidelines are aimed at.

A defensible cookie inventory

For each cookie or tracker, record the name, who sets it (you or a third party), its category, what it does in one sentence, its lifetime, and whether it runs before or only after consent. Publish that table. An inventory that a visitor can check against their own browser is the simplest evidence that the disclosure is accurate.

Sources

  • The Digital Personal Data Protection Act, 2023 — Sections 2(n), 2(t), 5, 6 and 7
  • Guidelines for Prevention and Regulation of Dark Patterns, 2023 (Central Consumer Protection Authority, 30 November 2023)

This note is general information about published law, not legal advice on your facts. For advice, speak to our team.

Check your own site against this

The audit reads your live pages and grades them provision by provision.

Run a free audit

Read next