Whenever you visit a website, there’s a pop-up asking you to accept cookies. Many of us, in urgency, simply click “Accept All” and go inside. Some choose “Preferred cookies only” and save their preferences.

This seems pretty simple, right?

But we need to understand what’s actually happening behind this.

So, what is the link between cookies and privacy?

The Real Problem: What Cookies Actually Do

Think about this: You visit an online clothing store and browse for a blue dress. You don’t buy it, but you leave.

The next day, you’re scrolling through your email, Instagram or YouTube, and suddenly you see ads for blue dresses everywhere. Not just from that store, but from many stores. It’s like the internet is watching what you looked at and following you around with ads.

That’s not a coincidence. That’s cookies.

When you visit a website, small tracking files called cookies are placed on your device. These cookies can record what you click, what you search for, what you look at, how long you stay on a page, and what you add to your cart. This data gets collected and stored.

But it doesn’t necessarily stop there.

You visit a travel website and look at flights to Delhi. Then you go to a news website and suddenly see ads for hotels in Delhi. You search for a health product on one site and later see ads for similar products elsewhere online.

Cookies and related tracking technologies can enable information about your browsing activity to be used across websites and advertising platforms. This can contribute to profiles being built around your interests, behaviour and preferences, which may then be used for targeted advertising.

And often, users accept cookies without fully understanding what is being tracked or how that information will be used.

Digital Personal Data Protection Act, 2023

For robust data protection, the government introduced the Digital Personal Data Protection Act, 2023 (DPDP Act, 2023). The rules were rolled out in November 2025, with mandatory compliance and implementation by May 2027.

Why Cookies Fall Under DPDP

The DPDP Act defines “personal data” as any data about an individual who is identifiable by or in relation to such data.

Think about it: A tracking cookie may identify a user as something like visitor_12345. On its own, that’s simply an identifier. But when combined with email data, purchase history or browsing behaviour, it can become identifiable personal data.

Under Section 2(x), “processing” includes collection, storage, retrieval, use, alignment, disclosure and dissemination — operations performed on personal data. Section 2(b) defines “automated” as a digital process capable of operating automatically in response to instructions.

Cookies can perform this kind of tracking in the background without active user intervention.

The DPDP Act, 2023 provides the legal framework governing the collection and use of personal data.

Websites commonly use cookies for purposes such as:

  • Analytics — understanding user behaviour
  • Personalisation — showing relevant content
  • Marketing — targeted advertising
  • Fraud prevention

The key question is how these purposes are disclosed and how the resulting personal-data processing is managed.

The source analysis identifies the following considerations for cookie consent:

  • Necessary or essential cookies may be treated differently from non-essential cookies.
  • Non-essential cookies may require opt-in consent from the user.
  • Organisations should clearly explain what information is collected and why.
  • Retention periods and parties with access to the data should be disclosed.
  • Users should be informed of relevant withdrawal, deletion and correction rights.

Consent should also provide meaningful choices. Depending on the cookies used, this can include allowing users to:

  • accept essential cookies only;
  • reject analytics cookies;
  • reject marketing cookies; and
  • change their preferences later.

Data Retention

Personal data should not be retained longer than required for the purpose for which it is processed.

Organisations should therefore define appropriate retention periods for cookie-related data rather than retaining it indefinitely.

Vendor Agreements and Roles

Where third-party analytics or advertising platforms are used, agreements should clearly establish the parties’ roles and responsibilities.

Questions to consider include:

  • Is the vendor acting on the organisation’s instructions?
  • Is it processing data for its own purposes?
  • What happens to cookie-related data when the relationship ends?

User Rights

The source highlights several rights and operational considerations organisations should account for, including:

  • understanding what personal data is held;
  • withdrawing consent where applicable;
  • deletion or correction requests where applicable; and
  • access to an appropriate grievance mechanism.

Transparency Around Automated Processing

Because cookies and related technologies can operate automatically, organisations should be transparent about how such processing works, how it affects the user’s experience, and what choices the user has.

Action Items

For organisations reviewing their cookie and privacy practices:

  1. Audit your current cookies.
  2. Review your privacy policy.
  3. Check vendor agreements.
  4. Review your cookie-consent banner and available choices.
  5. Update your privacy notice.
  6. Test your deletion processes.
  7. Document retention policies.
  8. Train relevant teams on DPDP requirements.
  9. Establish an appropriate grievance-response process.

References

  • Justice K.S. Puttaswamy (Retd.) vs. Union of India (2018)
  • Cookies – Invading Our Privacy for Marketing, Advertising and Security Issues: An Analysis with Interpretation, Sowmyan Jegatheesan
  • Data Protection Compliance and Audit Certification (Background Material), ICAI

This resource is intended for general informational and educational purposes and should not be treated as legal advice. Applicability may depend on the specific processing activity, technology and circumstances involved.