Key Takeaways
- India's Digital Personal Data Protection Act (DPDPA) was enacted in August 2023, but its Rules weren't notified until November 2025. Full substantive compliance, including cookie consent, notice, and security safeguards, isn't mandatory until May 13, 2027.
- The Consent Manager framework specifically becomes operational November 13, 2026 — earlier than the full compliance deadline, and the piece most directly relevant to how cookie consent gets technically implemented. A Consent Manager works as a middleman between a data fiduciary and a data principal, giving that individual one place to see, manage, and revoke consent across multiple services rather than chasing down each company separately, and it has to register with the Data Protection Board of India under conditions the Board prescribes (Section 6(9)) — not, as some older guides claim, with a "Data Protection Authority," a body the Act doesn't create.
- Penalties run far higher than commonly cited: up to ₹250 crore for inadequate security safeguards and a separate ₹200 crore for failing to notify a breach, which can stack to ₹450 crore for a single incident.
- The Act's text doesn't require granular per-purpose cookie consent, but an April 2025 technical standard (the BRDCMS) signals regulators are moving toward requiring itemized consent by cookie category, including advertising, so treat "general consent is enough" as a description of today's minimum, not a permanent one.
India's DPDPA requires consent before non-essential cookies load, but the deadline for full compliance is May 13, 2027, not today, and the penalty structure has more tiers than most guides mention. Secure Privacy is a cookie and consent management platform that generates DPDPA-compliant banners alongside GDPR, CCPA, and 55+ other privacy laws. Below: the actual phased timeline, what a compliant cookie banner needs right now versus what's coming, and the full, verified penalty schedule.
When Does DPDPA Cookie Consent Actually Become Mandatory?
The DPDPA was passed in August 2023, but a law's Rules, not just its text, are what make it enforceable, and those Rules weren't notified until November 2025. That gap is why cookie-consent guidance written in 2024 describing the law as already "in effect" was describing a law that existed on paper but had no operational enforcement mechanism yet.
The actual rollout runs in phases. The Consent Manager framework, the registered intermediaries who let individuals manage and withdraw consent across services, becomes operational November 13, 2026. Full substantive compliance, covering notice requirements, consent standards, security safeguards, and breach reporting, is due May 13, 2027. Multiple legal and compliance sources describe 2026 as a "soft enforcement" period: expect warnings and guidance rather than active financial penalties before the 2027 deadline passes.
For a business running a website today, that means the practical question isn't "am I already in violation" but "what needs to be in place before May 2027, and does my current cookie banner meet the standard that will be enforced." Building it now, ahead of the deadline, avoids a scramble later.
What Does a Compliant Cookie Banner Actually Need to Say?
Consent under DPDPA must be freely given, specific, informed, unconditional, and unambiguous, communicated in plain language rather than legal or technical jargon. A banner that pre-checks an "accept" option, or that makes continued access to the site contingent on accepting non-essential cookies, doesn't meet this standard. Consent also can't be bundled into a broader terms-of-service acceptance; it needs to be its own clear action.
Unlike GDPR, the Act's text doesn't require granular, purpose-by-purpose consent. A single "accept" action covering cookie use in general is enough to satisfy the law as written, which is a meaningfully lighter technical bar than GDPR's per-category consent requirement.
That said, treat this as today's minimum, not a stable long-term standard. The Business Requirements Document for the Consent Management System, a technical standard released April 15, 2025, pushes toward itemized consent: separate consent for each cookie purpose, including advertising, listed explicitly in the consent notice. That document isn't the law itself, but it signals where the technical implementation standard is heading. A business building its cookie banner now has a real choice: build to today's simpler legal minimum, or build with itemized categories from the start and avoid a second rebuild once BRDCMS-aligned granular consent becomes the practical expectation.
Some compliance guides state granular consent is already mandatory today, citing the Draft DPDP Rules from before the Rules were actually finalized. The finalized Rules, notified November 13, 2025 (gazette G.S.R. 846(E)), don't carry that requirement forward as binding law. Treat any source citing "Rule 3" for a granular-consent mandate as working from outdated draft-era commentary rather than the Rules actually in force.
What Language Does the Consent Notice Need to Be In?
Rule 3 of the finalized DPDP Rules 2025 requires the consent notice, not the cookie banner's accept/reject buttons themselves, but the accompanying notice, to be available in English or any of the 22 languages listed in the Eighth Schedule of the Indian Constitution, when requested. The notice also has to independently stand on its own: clear and understandable without requiring the reader to consult the underlying privacy policy, written in plain language, and itemizing what personal data is collected and why, not just a general statement that data is collected.
Beyond the language and data-and-purpose itemization, the notice needs three more elements: how to reach the data fiduciary directly, whether that's contact information or a dedicated webpage; how a Data Principal exercises their rights, including withdrawing consent; and a specific channel, an email address or contact form, for raising complaints about misuse or mishandling of data. A notice that itemizes data categories and purposes but skips the contact details and complaints channel is still incomplete.
Section 5(1)(iii) of the Act adds one more required element, easy to miss because it's distinct from the general complaints channel above: the notice has to explicitly state how a Data Principal can escalate a complaint to the Data Protection Board of India itself, not just to the business. A notice that only links to a general privacy policy or a company contact form, with no path described for a Board-level complaint, doesn't fully meet Section 5(1).
This is a real, specific, and commonly missed requirement. Building a single English-only notice and banner, then treating DPDPA as fully handled, leaves a genuine compliance gap most guides don't mention by rule number.
Do Dark Patterns Invalidate Consent Under DPDPA?
Yes. A banner that pre-selects "accept," buries "reject" behind extra clicks, or uses confusing wording to nudge a user toward accepting doesn't produce unconditional, unambiguous consent, which means the resulting consent is invalid and the data processing built on it is unlawful. India's Data Protection Board has signaled dark patterns in consent interfaces as an active enforcement focus, consistent with regulators in the EU and under CCPA/CPRA reaching the same conclusion independently. A dark-pattern banner that invalidates consent falls under the Act's residual penalty tier (up to ₹50 crore) unless the underlying failure also implicates security safeguards specifically, in which case the higher tier applies instead.
Consent withdrawal has to be as easy as giving it in the first place. A banner that makes "accept" a single click but buries the withdrawal option three menus deep in a preference center doesn't meet the unconditional-consent standard, even if the initial consent flow looked compliant.
How Do You Actually Implement This, Not Just Describe It?
DPDPA compliance isn't only a legal question; it's also an engineering one, since "unconditional consent, easy to withdraw, itemized by purpose" has to be something a system actually enforces, not just a banner that says the right words. Secure Privacy's Universal Consent API documents this at the endpoint level: a POST records a new consent decision with a customer-defined ConsentType (cookies, chatbot, newsletter, or anything else needing its own record), a PATCH updates an existing decision when a user withdraws or changes it, and a GET returns the full record, including Created and LastUpdated timestamps, which is what turns "we log consent" from a marketing claim into something an auditor can actually query.
For businesses building or embedding a consent flow directly rather than using a hosted banner, native SDKs exist for Android, iOS, Flutter, and React Native, plus, less commonly available among consent platforms, dedicated SDKs for Roku, Tizen, and tvOS for connected-TV apps, which is a real gap in most competing platforms that stop at web and mobile.
What Do the Penalties Actually Look Like?
The Act's Schedule sets out seven separate penalty tiers, not the two or three figures most compliance guides mention. The ones most relevant to a business's cookie-consent posture:
| Violation | Penalty | Section |
|---|---|---|
| Inadequate security safeguards leading to a breach | Up to ₹250 crore | Section 8(5) |
| Failure to notify the Data Protection Board and affected users of a breach | Up to ₹200 crore | Section 8(6) |
| Violations involving children's personal data | Up to ₹200 crore | Section 9 |
| Significant Data Fiduciary obligations breach (audits, risk assessments) | Up to ₹150 crore | Section 10 |
| Any other provision not separately listed | Up to ₹50 crore | Residual/general |
These stack. A breach caused by inadequate safeguards that also isn't reported on time exposes a business to both the ₹250 crore and ₹200 crore tiers on the same incident, a combined ₹450 crore ceiling. A separate ₹10,000 penalty exists under Section 15, but it applies to a Data Principal (the individual whose data it is) for misusing their own rights, such as filing false complaints. It isn't a penalty a business faces for a minor cookie-banner slip, despite how it's sometimes presented in compliance content.
Does DPDPA Apply to Businesses Outside India?
Yes. The Act applies to processing of personal data within India, and to processing outside India if it relates to offering goods or services to people in India. A business with no physical presence in India but with an e-commerce storefront, a subscription service, or any cookie-tracked site that Indian users actually access is in scope on that second basis, not exempted by being headquartered elsewhere.
A banner already built for GDPR or CCPA compliance can extend to DPDPA's consent standard without a separate India-specific implementation, provided the underlying platform actually supports the full range of global privacy laws rather than just the two or three most commonly targeted ones.
FAQ
Is DPDPA actually enforced right now, in 2026?
Partially. The Consent Manager framework becomes operational November 13, 2026, but full substantive compliance, including the cookie consent standard and its associated penalties, isn't mandatory until May 13, 2027. 2026 is widely described as a soft-enforcement period focused on guidance rather than active fines.
Does DPDPA require a separate cookie policy document?
The Act doesn't explicitly mandate a standalone cookie policy, but publishing one, listing specific cookies, their purposes, and any third-party data sharing, is standard practice for meeting the broader notice and transparency requirements the Act does impose.
Can I use one general "accept" button, or do I need separate toggles per cookie category?
As the Act's text currently stands, a single general-consent action is legally sufficient; DPDPA doesn't require GDPR-style per-category consent. The April 2025 BRDCMS technical standard signals movement toward itemized, per-purpose consent, so building granular category toggles now avoids having to rebuild the banner later if that standard becomes the enforced expectation.
What's the actual maximum penalty for a cookie-consent violation?
It depends on which provision is violated. A general violation not covered by a more specific tier caps at ₹50 crore. If the violation stems from or results in inadequate security safeguards, that tier reaches ₹250 crore, and a failure to notify a related breach adds a separate ₹200 crore tier on top.
Does the ₹10,000 penalty apply to businesses?
No. That penalty is under Section 15 and applies to a Data Principal (an individual data subject) who misuses their own rights under the Act, such as filing a false or frivolous complaint. It's not a business-facing cookie-compliance penalty, despite sometimes being listed alongside business penalties in less careful summaries.
Does the DPDPA consent notice need to be in an Indian language, or is English enough?
English is always acceptable. Beyond that, Rule 3 of the finalized DPDP Rules requires the notice to be available in any of the 22 languages listed in the Eighth Schedule of the Indian Constitution when a user requests it, so an English-only notice with no fallback isn't fully compliant even though English alone is a valid starting point.
Can a cookie banner with a pre-checked "accept" box still be DPDPA compliant?
No. Pre-checked consent isn't unambiguous or unconditional, the two standards the Act requires, so consent collected that way is legally invalid regardless of how the rest of the banner is designed.
What is Secure Privacy, exactly?
Secure Privacy is a cookie and consent management platform that generates DPDPA-, GDPR-, and CCPA-compliant consent banners, and covers DSAR handling, DPIA/impact assessments, and vendor risk management from its Business tier up.
Sources
- Digital Personal Data Protection Rules, 2025 (official gazette notification, G.S.R. 846(E)), notified November 13, 2025
- Rule 3 of the DPDP Rules, 2025, covering notice content and language requirements
- The Schedule to the Digital Personal Data Protection Act, 2023, the full penalty tier structure
- Business Requirements Document for the Consent Management System (BRDCMS), released April 15, 2025: a technical standard signaling the direction of granular-consent requirements, not binding law




