Home › Marketing Analytics › DPDP Act for Marketers
MARKETING ANALYTICS · CONSENT

DPDP Act for Marketers: Consent, Cookies and Analytics

India's data protection law now has its Rules and a compliance clock. Here is what it means for your GA4, your pixels, your lead forms and your WhatsApp lists — written for a marketing team, not a courtroom. This is context, not legal advice.

By the Digital Hangover team · Updated September 2026 · 11 min read
Quick answer: The DPDP Act, 2023 governs digital personal data in India, and the DPDP Rules, 2025 (notified 14 November 2025) switch it on in phases over 18 months. For a marketing team that means clear, purpose-specific consent notices before you collect data, a way to withdraw consent as easily as it was given, honouring access and erasure requests, and a consent banner wired into your tag setup. None of this is legal advice — get counsel for compliance decisions.
WHAT CHANGES ON YOUR SITE Consent decides which tags fire Visitor lands Consent notice clear · purpose-specific · separate (DPDP Rules, 2025) accepts declines Tags fire fully GA4 · pixels · recordings personal data collected Consent Mode: restricted no cookies, cookieless pings GA4 models the gap Aug 2023 DPDP Act passed 14 Nov 2025 Rules notified ~May 2027 18-month window ends Consent changes which events fire, so every report changes on the day you switch it on — annotate that date. Marketing context, not legal advice.

Consent decides which tags fire — and the DPDP timeline that decides when you need it working.

Read this first: we run marketing analytics, not a law practice. This page explains what the Act and Rules say so your team can plan, and it links to the primary sources. Every compliance decision — what your notice says, whether a given identifier is "personal data", what you retain — should go through a lawyer.

Most Indian marketing stacks were built on an unspoken assumption: if a visitor didn't object, you could collect. The Digital Personal Data Protection Act flips that to: collect for a stated purpose, with consent, and stop when the purpose ends.

That touches every layer of the stack we describe in our marketing analytics guide — the tags that collect, the pixels that feed ad platforms, the CRM that holds leads, and the reports built on all of it. The pillar gives the summary; this page is the working detail.

What is the DPDP Act, and where do the Rules fit?

The Digital Personal Data Protection Act, 2023 is India's first standalone data protection law. It applies to personal data that is collected digitally, or collected offline and then digitised, and it defines personal data as "any data about an individual who is identifiable by or in relation to such data" (Act text, MeitY, Section 2(t)).

An Act needs Rules to operate. The DPDP Rules, 2025 were notified on 14 November 2025, and the government's own summary describes "an eighteen-month period for phased compliance" (PIB summary of the Rules).

The phasing matters because it tells you what is a deadline and what is merely a start date:

  • From notification (November 2025): the Data Protection Board of India is set up — a "fully digital" four-member body that takes complaints online (PIB).
  • At 12 months (November 2026): the consent manager framework becomes operational, per DLA Piper's India chapter.
  • At 18 months (May 2027): "all other substantive provisions", including the compliance obligations that touch your website and CRM, take effect (DLA Piper).

Two people will read those dates differently. A lawyer sees May 2027 as the date obligations bite. A marketer should see it as the date by which every tag, form and list already has to be working the new way — and tag changes take longer than anyone budgets.

What counts as personal data on a marketing website?

Personal dataPixels & formsCounsel decides edge cases

Anything that identifies a person, or can be combined with other data to identify them, is in scope. On a typical Indian business site that includes far more than the contact form.

One honest caveat before the table: the Act does not mention cookies by name. DLA Piper's chapter notes there is "no regulation of cookies, behavioural advertising, or location data" as specific categories — the question is always whether an individual is "identifiable by or in relation to" the data. Whether a bare GA4 client ID crosses that line is something your counsel should decide; a form submission or a hashed email sent to a pixel plainly does.

Marketing activityPersonal data involvedWhat changes under DPDP
GA4 / web analyticsClient ID cookie, IP address, user ID if set, device and location dataNotice and consent before the tag sets identifiers; a plan for what fires when consent is denied
Meta Pixel, Google Ads tag, LinkedIn Insight TagCookie IDs, click IDs, hashed email/phone via advanced matching, page URLsConsent gates the pixel; purpose must cover ad measurement and audience building, stated separately
Lead forms (enquiry, demo, brochure)Name, phone, email, company, messageItemised notice at the form; purpose-limited use; erase when the purpose ends
WhatsApp click-to-chat and listsPhone number, name, chat contentConsent for marketing messages, easy opt-out, no reuse of a service number for promotions without consent
Email newsletters and nurtureEmail, name, engagement historySpecific consent for marketing; unsubscribe as easy as subscribe; suppression, not deletion-then-re-add
CRM and lead sheets (incl. agency access)Everything above, plus notes and deal historyAccess, correction and erasure requests answered within the window; breach reporting duty
Remarketing and lookalike audiencesCustomer lists uploaded to ad platformsConsent must cover that purpose; withdrawal means removal from the list

What must a consent notice say?

The Act sets the standard: consent must be "free, specific, informed, unconditional and unambiguous with a clear affirmative action", limited to data necessary for the stated purpose (Act, Section 6(1)). The Rules turn that into the notice itself.

PIB's summary is blunt: "Every Data Fiduciary must issue a separate consent notice that is clear and easy to understand" and it must "explain the specific purpose for which personal data is collected and used". Taxmann's analysis of Rule 3 lists what that notice carries:

  • An itemised description of the personal data being collected — not "your information".
  • The specified purpose, and the goods or services that purpose enables.
  • How to withdraw consent — and withdrawal has to be as easy as giving it (Act, Section 6(4)).
  • How to complain to the Data Protection Board.
  • Standalone presentation — understandable "independently of any other information", which rules out burying it in a 4,000-word privacy policy.

In marketing terms: "Accept all" with a link to a policy is not a notice. A short panel that says what you collect (analytics identifiers, ad identifiers, form details), for what (measuring the site, measuring ads, replying to your enquiry), with separate toggles and a withdraw link in the footer, is much closer.

Section 7 of the Act does allow processing of data a person volunteered for the purpose they volunteered it for, without a fresh consent step, as long as they haven't objected. A clinic replying to an appointment enquiry is on that ground. Adding that same person to a promotional WhatsApp broadcast is a different purpose — and a different consent.

What is a consent manager, and why must it be Indian?

A consent manager is a registered intermediary through which a person can give, review and withdraw consents across many companies from one place. PIB states they "must be companies based in India", and the framework goes live at the 12-month mark (DLA Piper). Sansa Legal notes registration with the Board and a minimum net-worth requirement for these entities.

Do not confuse this with your cookie banner. A consent management platform (the banner tool) is a piece of software you run on your site. A DPDP consent manager is a regulated entity registered with the Board. Your banner vendor is not automatically the latter, and as of this writing we could not verify any registered list — ask the vendor directly and ask counsel what, if anything, you must integrate with.

What rights do your visitors get, and what does your stack have to do?

The Act gives every data principal — the person — the right to access their data, correct and update it, seek erasure, nominate someone to act for them, and withdraw consent at any time (Act, Sections 12–13; PIB). The Rules put a clock on it: fiduciaries must "address all requests within a maximum of ninety days" (PIB).

Ninety days sounds generous until you try to answer "what do you hold about me?" across GA4, a Meta custom audience, HubSpot, a Google Sheet the sales team exports every Friday, and a WhatsApp broadcast list on someone's phone. The operational task is knowing every copy.

  • Map the copies. One list of every system that stores a lead: form tool, CRM, email platform, ad-platform audiences, spreadsheets, agency dashboards.
  • Name an owner and an inbox. Requests will arrive by email and WhatsApp, not through a form you designed.
  • Test an erasure end-to-end. Delete one test record and confirm it is gone from every copy, including the uploaded ad audience.

What happens when data leaks?

Two clocks run at once. Taxmann's reading of the Rules: the Board must be notified within 72 hours of becoming aware of a breach, and affected people must be told "without delay", in plain language, with the impact and the remedial steps (PIB; DLA Piper).

The Act's Schedule sets the ceilings, as reproduced by PIB: up to ₹250 crore for failing to maintain security safeguards, up to ₹200 crore for failing to notify a breach, and up to ₹50 crore for other violations. Those are maximums the Board can impose, not tariffs — but they are the reason a shared lead sheet with "anyone with the link" access is now a board-level risk, not a sales-team habit.

What changes in practice: the banner and Google Consent Mode

Consent Mode = Google's mechanismNot an Indian legal requirementExpect a data step-change

A consent notice is the interface. Something still has to tell your tags what the visitor chose. On Google's stack that mechanism is Consent Mode, which "lets you communicate your users' cookie or app identifier consent status to Google. Tags adjust their behavior and respect users' choices" (Google Analytics Help).

Be clear about what it is and isn't. Consent Mode was built around Google's EU user consent policy and its November 2023 update was framed for traffic in the European Economic Area (Google Tag Platform docs). It is a product feature that helps Google's tags honour a choice. It is not an Indian legal requirement, and it is not a consent notice — you still need the notice and the banner. Its usefulness for an Indian site is that it gives you a tested, one-switch way to make GA4 and Google Ads respect what the visitor said.

What the tags actually do, per Google's docs:

  • Consent signals: ad_storage (advertising cookies), analytics_storage (analytics cookies), ad_user_data ("sending user data related to advertising to Google") and ad_personalization ("personalized advertising").
  • Basic implementation: "Google tags blocked until consent is granted" — nothing fires, nothing is modelled.
  • Advanced implementation: tags load before the dialog and "send cookieless pings when cookie consent declined"; that data "is used for behavioral and conversion modeling, to fill the gaps".
  • When ad_storage is denied: "new cookies won't be set for advertising purposes" — but the ping still carries "the full page URL, including any ad click information in the URL parameters".
  • Region-specific defaults: the default command accepts a region list, so you can set denied-by-default for India while leaving other markets as they are; wait_for_update holds tags for a few hundred milliseconds while the banner loads.

Whether advanced mode's cookieless pings are acceptable under a purpose-limited Indian notice is exactly the kind of question for counsel, not for us. Where teams choose basic mode, plan for the consequence: fewer sessions, fewer attributed conversions, and a visible step down in every report the week you switch. Annotate it in GA4 so nobody "fixes" it in six months.

The plumbing lives in Tag Manager — consent settings on each tag, and the banner's update call — which we cover in our Google Tag Manager guide; the property side is in our GA4 setup guide. Meta's Pixel has its own consent handling and the Conversions API does not exempt you — server-side sending is still collection, and our server-side tracking guide says so plainly. For a Meta-specific walkthrough see our Meta Pixel and Conversions API guide.

This is the part most businesses ask us to handle inside a performance marketing engagement: rebuilding the tag layer so consent, GA4 and the ad platforms agree, and then re-baselining the numbers.

Email, WhatsApp and the lead data you keep

Retention is where marketing teams are most exposed, because leads never get deleted. Section 8(7) of the Act requires erasure once the specified purpose is served or consent is withdrawn, unless a law requires you to keep it. The Rules put the same idea as ceasing retention when "it is reasonable to assume that the purpose... is no longer being served" (DLA Piper).

The Third Schedule adds hard numbers for very large platforms only — e-commerce with 2 crore or more registered users, social media at the same threshold, online gaming at 50 lakh — where three years of inactivity triggers erasure, with 48 hours' notice to the person first (Taxmann). Most readers of this page are nowhere near those thresholds. The principle still applies; only the fixed clock doesn't.

A workable posture for a coaching institute or D2C brand, subject to counsel:

  • Enquiry leads that never converted: define a purpose window (say, the admissions cycle), then delete or anonymise.
  • Newsletter and WhatsApp marketing: consent specific to marketing, collected separately from the enquiry; opt-out in every message; a suppression list so a withdrawn number is never re-imported.
  • Ad-platform customer lists: refresh from the CRM on a schedule, so withdrawals actually leave the audience.
  • Children: "verifiable consent from a parent or guardian is required" (PIB) — EdTech and gaming teams collecting student data should treat this as a product decision, not a banner tweak.

The upside: first-party data you were given on purpose

Every constraint above pushes in one direction — toward data people hand you knowingly. Purchase history, a phone number given to get a quote, an email given for a price list. That data is consented, purpose-bound and yours; no browser change or platform policy takes it away.

We keep that strategy on its own page rather than repeat it here: first-party data: why it matters covers how to collect it, store it and activate it. This page's job is to make sure the collection is lawful.

A marketing team's compliance-prep checklist for the window

Work through this with counsel reviewing the outputs, not just the plan. Most of it is inventory and plumbing — the kind of work that fits comfortably in the window if you start now and not at all if you start in April 2027.

  1. Inventory every tag and pixel. Open Tag Manager and list each tag, what identifiers it sets, and which vendor receives them — GA4, Google Ads, Meta, LinkedIn, Clarity, chat widgets. Anything you can't explain, pause.
  2. Inventory every place a lead lives. Form tool, CRM, email platform, WhatsApp lists, ad audiences, spreadsheets, agency dashboards. One row per system, with an owner.
  3. Write the purposes in plain language. "Measure how the site is used", "measure our ads", "reply to your enquiry", "send offers by email/WhatsApp". Each is a separate purpose with a separate consent.
  4. Draft the notice with counsel. Itemised data, purpose, withdrawal route, complaint route — standalone, not a policy link. Put the same text at the banner, the form and the WhatsApp opt-in.
  5. Wire the banner to the tags. Set consent defaults (with a region list if you serve other markets), connect the banner's update call, and set consent settings on every tag in Tag Manager. Decide basic versus advanced Consent Mode with counsel's view in writing.
  6. Re-baseline the reports. Note the switch date in GA4 and your dashboards; expect a step change; compare like with like afterwards.
  7. Build the request and breach runbooks. One inbox for access/correction/erasure, a 90-day tracker, an erasure script that hits every system in step 2, and a breach contact tree that reaches the Board within 72 hours.
  8. Set a retention rule and run it. Purpose windows per list, a suppression list for withdrawals, a monthly job that deletes or anonymises what has aged out — and a log that shows you did.

Where to go from here

Treat the compliance window as a tracking rebuild with a legal reviewer, not a legal project with a tracking footnote. The teams that do this early get a cleaner tag layer, a first-party data set they can defend, and reports that survive the switch. The teams that wait get a banner installed in a hurry and a quarter of unexplained "traffic drops".

Key takeaways: The DPDP Act, 2023 is live and the DPDP Rules, 2025 phase it in over 18 months from 14 November 2025, with the substantive obligations landing in May 2027. Personal data on your site includes analytics and ad identifiers, form fields and phone numbers, so consent must be purpose-specific, separately given and as easy to withdraw as to give. Google Consent Mode is a useful mechanism for honouring that choice, not an Indian legal requirement. Map every copy of your lead data, set retention rules, and get every decision reviewed by counsel — this page is marketing context, not legal advice.

Frequently asked questions

Is the DPDP Act already in force for my website?

Partly. The Act was passed in 2023 and the DPDP Rules, 2025 were notified on 14 November 2025 with an 18-month phased compliance window, per the government's PIB summary. The Data Protection Board was set up first, the consent manager framework follows at 12 months, and the substantive obligations that affect websites, forms and CRMs take effect at 18 months (May 2027). Use the window to rebuild, not to wait. This is marketing context, not legal advice — confirm your own obligations with counsel.

Does India's DPDP Act require a cookie banner?

The Act does not mention cookies by name; it regulates personal data, defined as data about an identifiable individual. Analytics and advertising tags set identifiers and send form data, so most teams plan on a clear, purpose-specific consent notice at the point of collection. Whether a particular identifier is "personal data" in your setup is a question for your lawyer, not a tag manager.

Is Google Consent Mode mandatory under the DPDP Act?

No. Consent Mode is Google's own mechanism, built around its EU user consent policy for the EEA and UK, that lets GA4 and Google Ads tags respect a visitor's consent choice. The DPDP Act does not name it or require it. It is simply a well-documented way to make Google's tags behave once you have a compliant notice and banner in place, and whether its "advanced" mode fits your notice is a decision for counsel.

What happens to my GA4 data when a visitor denies consent?

It depends on how you implement it. In Google's basic Consent Mode setup, tags are blocked until consent is granted, so nothing is recorded for that visitor. In the advanced setup, tags send cookieless pings that Google uses for behavioural and conversion modelling to fill gaps. Either way, expect a visible step-change in sessions and attributed conversions the week you switch — annotate the date in GA4 and your dashboards.

How long can I keep enquiry and lead data under DPDP?

The Act requires erasure once the specified purpose is served or consent is withdrawn, unless another law requires retention. Fixed three-year inactivity clocks in the Rules' Third Schedule apply only to very large platforms (for example e-commerce or social media with 2 crore or more users). Smaller businesses should define a purpose window per list, delete or anonymise leads that age out, keep a suppression list for withdrawals, and have counsel sign off the policy.

Tracking that survives the consent switch

Rebuild your tag layer before the window closes

Consent-aware GA4, Google Ads and Meta tracking, set up inside a performance marketing engagement — so the numbers you report after the switch are ones you can defend.

Explore performance marketing →

Get our posts in Google

Make Digital Hangover a preferred source

One tap tells Google to show more of our SEO and marketing coverage in your Top Stories.