← ALL REGULATIONS
India’s DPDP Act and cookie consent: the Act, the Rules and the deadlines.
India has no cookie-specific rule, but the Digital Personal Data Protection Act requires consent, or one of a short list of legitimate uses, to process digital personal data, and that includes data collected through cookies. Consent must follow a notice and be given by a clear affirmative action, and the Rules phase in over 18 months to May 2027.
DPDP Act at a glanceConsent, with exceptions
- Applies to
- Processing of digital personal data in India, and outside India when it relates to offering goods or services to people in India
- In force
- Act passed August 2023; Rules notified November 2025 and phased in over 18 months, to May 2027
- Enforced by
- Data Protection Board of India, with appeals to the Telecom Disputes Settlement and Appellate Tribunal
- Penalties
- Up to ₹250 crore for failing to take reasonable security safeguards, ₹200 crore for breach notification or children’s data failures, ₹150 crore for a Significant Data Fiduciary’s extra duties, and ₹50 crore for other breaches
WHAT DPDP ACT REQUIRES
What the DPDP Act asks of a site that uses cookies.
THE RULEConsent, or a legitimate usePersonal data may be processed only with consent or for one of the legitimate uses the Act lists, such as data a person voluntarily provided for a specified purpose. For analytics and advertising cookies, that usually means consent.
WITH KATLAIn GDPR mode, the cookie guard refuses every cookie outside the functional category until the visitor chooses, and deletes any that were set before it ran. Auto uses GDPR mode for Indian timezones.
THE RULEFree, specific and unambiguous consentConsent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data the purpose needs.
WITH KATLAAccept, Reject and Customise sit together on the first layer of the banner, and nothing is pre-selected.
THE RULEA notice with, or before, the requestThe request for consent must be accompanied or preceded by a notice that stands on its own, in clear and plain language, with an itemised description of the personal data and its purposes, and how to withdraw consent, exercise rights and complain to the Board.
WITH KATLAThe banner’s Customise layer describes each category and lists its cookies with their purpose, and the generated cookie policy covers every cookie the scan found. A DPDP notice covers all the personal data you process, not only cookies, so it has to come from your own privacy notice.
THE RULEEnglish or a language of the Eighth SchedulePeople must be able to read the notice and the consent request in English or in any language listed in the Eighth Schedule to the Constitution.
WITH KATLAKatla’s banner is available in English and Hindi, and the widget can follow the visitor’s browser language. Generated policies are available in English, but not in Hindi or the other Eighth Schedule languages.
THE RULEWithdrawal as easy as consentWithdrawing consent must be comparable in ease to giving it, and processing must then stop within a reasonable time.
WITH KATLAA floating settings icon, or your own "Cookie settings" link calling katla.open(), reopens the choice on any page.
DPDP Act questions, answered
A summary for website owners, not legal advice. Reviewed against the sources below.
- Does the DPDP Act require a cookie banner?
- It has no cookie rule. It requires notice and consent, or a legitimate use, to process digital personal data, and cookies that collect personal data fall under that. A banner is how most sites ask.
- When do the DPDP Rules apply?
- The Rules were notified in November 2025. The provisions on the Data Protection Board applied at once, consent manager registration applies from November 2026, and the rest, including the notice rules, from May 2027, 18 months after notification.
- What is a consent manager, and is Katla one?
- A consent manager is a company incorporated in India and registered with the Data Protection Board that offers a single, interoperable platform through which a person can give, manage, review and withdraw consent. Katla is not one: it asks for and records consent on your own site.
- Who has to prove that consent was given?
- The business. If consent is questioned, it must show that it gave a notice and that consent was given under the Act. Each decision is stored with its categories, its time and a truncated IP address, and can be queried and exported through the API, CLI or MCP server. Katla keeps the latest decision per visitor. It does not store the wording of the notice the visitor saw.
- What are the penalties?
- Up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to notify a personal data breach or for breaching the obligations on children’s data, up to ₹150 crore for a Significant Data Fiduciary that breaches its additional obligations, and up to ₹50 crore for other breaches of the Act or the Rules.
See what your site sets before anyone asks.
The free plan scans your site, classifies every cookie and generates the policy, without a card. The cookie checker needs no account at all.