Website scan
What we do: We list every cookie, tag, pixel, embed and form on your site, and record what loads before a visitor makes a choice.
What you get
A cookie and tag inventory sheet.
DPDP duties for websites apply in full from 13 May 2027. Check your site free
Fixed scope, fixed price. We set up consent on your website, test every choice a visitor can make, and hand over the evidence.
Written by Shuruthi Sellamuthu. Last reviewed .
DPDP website implementation is a fixed-price DPDP website compliance service: the technical work of making a website ask for consent properly under the DPDP Act, with a clear notice, a cookie banner with a real choice, tags that wait for a yes, consent on forms, an easy way to withdraw, and records that prove it.
The law behind each step is explained in the website guide to the DPDP Act. Not sure where your site stands today? Start with a DPDP website audit.
You need a company-wide DPDP programme, a Data Protection Officer or a legal opinion. We will point you to a privacy or legal partner for that, and handle the website part alongside them.
Eight pieces of work across the banner, the forms and the policy pages.
Group A Cookie banner
What we do: We list every cookie, tag, pixel, embed and form on your site, and record what loads before a visitor makes a choice.
What you get
A cookie and tag inventory sheet.
What we do: We configure a consent platform with Accept and Reject at equal weight, separate choices for analytics and marketing, and only strictly necessary cookies on by default. The banner text is in plain language. More on DPDP cookie consent banner setup.
What you get
A banner in your brand style, in a consent platform account that you own.
What we do: In Google Tag Manager, we tie every tag to a consent type and set the default to denied, so nothing fires without a yes. We move hard-coded scripts into GTM and connect Consent Mode v2. More on Google Consent Mode v2 and GTM tag gating.
What you get
An updated GTM container with version notes, and a consent mapping sheet for every tag.
What we do: We add a visible link on every page to reopen the choices. When a visitor switches from Accept to Reject, the tags stop. We test that on every tag.
Act Section 6(4)
What you get
A preference link in your footer and a test record.
Group B Forms
What we do: For each form we agree the legal basis with your legal contact, add a short notice saying what you collect and why, and add an unticked consent checkbox with a visible privacy policy link where consent is needed. Consent stays separate from the Terms. More on DPDP consent for website forms.
Act Sections 5, 6(1) and 7(a), Rule 3
What you get
A form inventory and the consent pattern applied to each form.
Group C Policy pages
What we do: We draft both pages from what your website really collects: the data, the purpose, who receives it and how long it is kept, plus a cookie table that matches the live cookies. Your legal contact approves the final wording. More on DPDP privacy policy and cookie policy drafting.
What you get
A draft privacy policy, a draft cookie policy and a cookie table.
Around all three
What we do: We check whether any part of the site is aimed at people under 18. If it is, we flag the pages where tracking and targeted advertising must be off, for your legal contact to decide.
Act Section 9
What you get
A short note in the report.
What we do: We test as a new visitor for every choice: no choice, Accept, Reject, and Accept then Reject. We record what fires each time.
What you get
A test report with before and after evidence, a configuration document and 30 days of support after launch.
Sources for the sections cited above: the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, both published by MeitY.
Three parts work in order. Nothing loads until the visitor has chosen.
The banner records the visitor's choice.
Google Tag Manager reads it. Each tag is set to wait for the matching consent type.
No consent, no tag. Change the choice, and the tags follow.
Reject, or no choice yet: the tags stay off.
Accept: only the tags for the accepted consent types load.


| When | What happens |
|---|---|
| Week 1 | Scan the site, agree the plan and the notice wording. |
| Week 2 | Set up the banner, tags and forms. Test every choice. |
| Then | Policy sign-off. This depends on your legal team and usually takes two to four weeks. |
Example: For Nextranslate, setup took two weeks and legal review took one more week.
What can slow it down: legal sign-off on the notice and policy text, and waiting for access to Google Tag Manager, your consent platform or the website CMS.
We never need your CRM or internal systems.
The consent platform licence is paid by you directly to the platform.
DPDPWeb works on websites only: cookie banners, form consent, and privacy and cookie policy pages. We are not a DPO service and not a law firm. Nothing on this site is legal advice.

Nextranslate, a SaaS company, started with a website audit. It showed that the cookie banner accepted everything and marketing tags fired without consent. We rebuilt the banner, set up consent on the forms, and drafted the privacy and cookie policies. Today the tags wait for consent for visitors in India, the EU and the US. Setup took two weeks, plus one week for legal review.
No single service can. The Act also covers security, contracts, retention and internal data, which sit with your company and its advisers. We implement and test the website side: banner, tags, forms and policy pages.
We are not tied to one. We usually set up CookieYes, and we work with the platform you already have if it can block tags properly. The account is in your name and you pay the licence directly.
Usually, yes. Once tracking waits for consent, visitors who say no are no longer counted in the same way. We explain the options in Google Consent Mode v2 and what each means for your reports. The choice is made with your legal contact.
Often not. Most of the work is done in the consent platform and Google Tag Manager. We need a developer only when tracking scripts are hard-coded in the site or the forms are custom built.
Yes, and we prefer it. We supply the facts and the drafts. Your legal contact decides the legal basis for each form and approves the policy wording.
You get 30 days of support. After that, a monthly DPDP Care Plan keeps the setup accurate as tags and plugins change.
Yes. We have set up consent for GDPR and CCPA, and the banner can apply different rules by region: India, the EU and the US.
Share your URL and we reply with scope, plan and timeline in writing.