Research

Consent, tracking and breaches,
measured and sourced.

Original studies run with our own scanner, reported in aggregate with the method published, and breach case studies built only from official sources.

02

Breach case studies

Eight well-documented security breaches, from Uber in 2016 to MOVEit Transfer in 2023: what happened, the root cause, the regulatory outcome and the control that addresses it, with SOC 2 and ISO 27001 references. Every figure links to a regulator, government advisory, court filing or the company's own disclosure.

Read the breach case studies

03

How we measure

  • A public sample. Sites are drawn from the Tranco research ranking, with the list ID published, plus named sector groups of major brands
  • Two passes, like a real visitor. Each page is loaded once with no consent and once after accepting, so what runs before the choice is separated from what runs after
  • A conservative count. Only identifiers from known analytics and advertising providers count; tag managers, CDNs, bot protection and performance monitoring never do
  • Unmeasurable is not compliant. Sites that fail to load or block automated browsers are excluded and reported, never counted as clean
  • Independent checks. A random sample is re-checked without our scanner's code before anything is published
04

For journalists

Figures may be republished with a link to the study. Per-site results are available for verification on request, not for publication, through our contact page. Our team can explain the method and what the DPDP Act requires from May 2027.

TryTrustable (2026). Cookie consent on Indian websites: 2026 study. https://trytrustable.com/research/indian-websites-cookie-consent-2026
Questions

The things people ask us

Who runs this research?

TryTrustable, using the same scanner that powers our free cookie scan and the consent platform. Every study states its sample, method, exclusions and limits, and is checked independently before publication.

Do you name the websites you scan?

No. Scan studies report aggregate and sector figures only. Per-site data is kept for verification and shared with journalists on request. The breach case studies are different: they name companies only for incidents already public through a regulator, a court, a government advisory or the company's own disclosure.

Can I use the figures?

Yes, with a link to the study.

How often is the research repeated?

We plan to repeat the consent study before the DPDP duties begin on 13 May 2027 and again after, so the change can be measured on the same method.

Book a walkthrough

See what your own site does before consent.

Run the same two-pass scan on your site in about a minute, then fix what fires early.