Skip to content

DPDP duties for websites apply in full from 13 May 2027. Check your site free

DPDPWeb
Book a free call Free website check

DPDP website implementation: banner, forms and policies, done for you

Fixed scope, fixed price. We set up consent on your website, test every choice a visitor can make, and hand over the evidence.

  • From ₹39,999
  • Setup from 7 working days
Start your implementation Book a free call

Written by . Last reviewed .

What is DPDP website implementation?

DPDP website implementation is a fixed-price DPDP website compliance service: the technical work of making a website ask for consent properly under the DPDP Act, with a clear notice, a cookie banner with a real choice, tags that wait for a yes, consent on forms, an easy way to withdraw, and records that prove it.

The law behind each step is explained in the website guide to the DPDP Act. Not sure where your site stands today? Start with a DPDP website audit.

Is this for your website?

A good fit

  • Your website runs analytics or advertising tags
  • It has lead, demo, newsletter or sign-up forms
  • It gets visitors from India

Not a fit

You need a company-wide DPDP programme, a Data Protection Officer or a legal opinion. We will point you to a privacy or legal partner for that, and handle the website part alongside them.

What we implement

Eight pieces of work across the banner, the forms and the policy pages.

Group A Cookie banner

Website scan

What we do: We list every cookie, tag, pixel, embed and form on your site, and record what loads before a visitor makes a choice.

What you get

A cookie and tag inventory sheet.

Consent banner

What we do: We configure a consent platform with Accept and Reject at equal weight, separate choices for analytics and marketing, and only strictly necessary cookies on by default. The banner text is in plain language. More on DPDP cookie consent banner setup.

What you get

A banner in your brand style, in a consent platform account that you own.

Tag gating and Google Consent Mode v2

What we do: In Google Tag Manager, we tie every tag to a consent type and set the default to denied, so nothing fires without a yes. We move hard-coded scripts into GTM and connect Consent Mode v2. More on Google Consent Mode v2 and GTM tag gating.

What you get

An updated GTM container with version notes, and a consent mapping sheet for every tag.

Withdrawal link

What we do: We add a visible link on every page to reopen the choices. When a visitor switches from Accept to Reject, the tags stop. We test that on every tag.

Act Section 6(4)

What you get

A preference link in your footer and a test record.

Group B Forms

Form notices and consent

What we do: For each form we agree the legal basis with your legal contact, add a short notice saying what you collect and why, and add an unticked consent checkbox with a visible privacy policy link where consent is needed. Consent stays separate from the Terms. More on DPDP consent for website forms.

Act Sections 5, 6(1) and 7(a), Rule 3

What you get

A form inventory and the consent pattern applied to each form.

Group C Policy pages

Privacy policy and cookie policy

What we do: We draft both pages from what your website really collects: the data, the purpose, who receives it and how long it is kept, plus a cookie table that matches the live cookies. Your legal contact approves the final wording. More on DPDP privacy policy and cookie policy drafting.

What you get

A draft privacy policy, a draft cookie policy and a cookie table.

Around all three

Children check

What we do: We check whether any part of the site is aimed at people under 18. If it is, we flag the pages where tracking and targeted advertising must be off, for your legal contact to decide.

Act Section 9

What you get

A short note in the report.

Testing and handover

What we do: We test as a new visitor for every choice: no choice, Accept, Reject, and Accept then Reject. We record what fires each time.

What you get

A test report with before and after evidence, a configuration document and 30 days of support after launch.

Sources for the sections cited above: the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, both published by MeitY.

How we stop tags firing before consent

Three parts work in order. Nothing loads until the visitor has chosen.

  1. Banner

    The banner records the visitor's choice.

  2. Google Tag Manager

    Google Tag Manager reads it. Each tag is set to wait for the matching consent type.

  3. Tags

    No consent, no tag. Change the choice, and the tags follow.

Reject, or no choice yet: the tags stay off.

Accept: only the tags for the accepted consent types load.

What you receive at handover

A printed report and laptop being handed over across a desk
  • A configured consent platform and banner, in an account you own
  • Google Tag Manager container changes, with version notes
  • The form consent pattern applied to every form
  • A draft privacy policy and cookie policy, with a cookie table
  • A test report with before and after screenshots
  • A configuration document
  • 30 days of support after launch

How long it takes

A desk planner with three days marked by orange tabs
DPDP website implementation timeline
WhenWhat happens
Week 1Scan the site, agree the plan and the notice wording.
Week 2Set up the banner, tags and forms. Test every choice.
ThenPolicy sign-off. This depends on your legal team and usually takes two to four weeks.

Example: For Nextranslate, setup took two weeks and legal review took one more week.

What can slow it down: legal sign-off on the notice and policy text, and waiting for access to Google Tag Manager, your consent platform or the website CMS.

What we need from you

  • Access to Google Tag Manager and to the website CMS
  • Access to your consent platform, if you already have one
  • A contact for legal sign-off
  • A list of the marketing tools in use
  • A decision on who owns the consent platform account. We recommend you do.

We never need your CRM or internal systems.

What is not included

  • Data Protection Officer services
  • Legal opinions
  • Mobile apps
  • CRM, HR and back-office data
  • Security audits
  • Breach reporting to the Data Protection Board

The consent platform licence is paid by you directly to the platform.

DPDPWeb works on websites only: cookie banners, form consent, and privacy and cookie policy pages. We are not a DPO service and not a law firm. Nothing on this site is legal advice.

Plans and pricing

Starter

₹39,999

  • 1 domain
  • Up to 5 forms
  • Up to 15 tags
  • 1 language

Timeline: 7 to 10 working days

Growth

₹89,999

  • 1 domain plus up to 3 subdomains
  • Up to 15 forms
  • Up to 40 tags
  • 2 languages

Timeline: 2 to 3 weeks

Scale

from ₹1,79,999

  • Several domains
  • Custom-built web apps
  • Developer spec

Timeline: 4 weeks or more

All plans include the Website Audit, the banner, tag gating, form consent and the policy drafts. GST extra where applicable.

View full pricing
Nextranslate

How this looked for Nextranslate

  • SaaS company
  • Setup in two weeks

Nextranslate, a SaaS company, started with a website audit. It showed that the cookie banner accepted everything and marketing tags fired without consent. We rebuilt the banner, set up consent on the forms, and drafted the privacy and cookie policies. Today the tags wait for consent for visitors in India, the EU and the US. Setup took two weeks, plus one week for legal review.

Implementation questions

Does this make us DPDP compliant?

No single service can. The Act also covers security, contracts, retention and internal data, which sit with your company and its advisers. We implement and test the website side: banner, tags, forms and policy pages.

Which consent platform do you use?

We are not tied to one. We usually set up CookieYes, and we work with the platform you already have if it can block tags properly. The account is in your name and you pay the licence directly.

Will our Google Analytics data drop?

Usually, yes. Once tracking waits for consent, visitors who say no are no longer counted in the same way. We explain the options in Google Consent Mode v2 and what each means for your reports. The choice is made with your legal contact.

Do you need developer time from us?

Often not. Most of the work is done in the consent platform and Google Tag Manager. We need a developer only when tracking scripts are hard-coded in the site or the forms are custom built.

Can you work with our legal team?

Yes, and we prefer it. We supply the facts and the drafts. Your legal contact decides the legal basis for each form and approves the policy wording.

What happens after handover?

You get 30 days of support. After that, a monthly DPDP Care Plan keeps the setup accurate as tags and plugins change.

Do you cover GDPR and CCPA visitors too?

Yes. We have set up consent for GDPR and CCPA, and the banner can apply different rules by region: India, the EU and the US.

Get a fixed quote for your website

Share your URL and we reply with scope, plan and timeline in writing.