Research · October 2026

76% of top Indian websites store tracking identifiers before visitors consent

We loaded the homepages of 401 of India's most-visited websites and major brands, once with no consent given and once after accepting. 76% stored a known analytics or advertising identifier before the visitor made any choice, and 16.5% showed a consent banner at all. The DPDP Act's notice and consent duties apply from 13 May 2027.

01

The key findings

76%
store tracking identifiers before consent
16.5%
show a consent banner at all
35%
of banners offer "Reject" up front
3
tracking companies per site, median

Most of India's largest websites start tracking visitors before asking. Of the 401 homepages we could measure, 76% stored a known analytics or advertising identifier, such as a Google Analytics or Meta Pixel cookie, on the first page load before the visitor had clicked anything, and 80% sent data to an analytics or advertising service. Only 16.5% showed a consent banner at all, and where one was shown, 77% of those sites had already stored tracking identifiers before the visitor reached it.

FindingShare of sites
Stored a known analytics or advertising identifier before consent76%
Sent data to a known analytics or advertising service before consent80%
Ran advertising trackers (not just analytics) before consent70%
Passed data to five or more advertising companies before any choice30%
Showed a consent banner on the first visit16.5%
Of sites with a banner, still stored tracking identifiers before the click77%
Of sites with a banner, offered a reject option on its first layer35%

Base: 401 homepages that could be measured, of 471 sampled. 70 could not be measured (did not load, blocked automated browsers or returned nothing) and are excluded, not counted as compliant.

02

How many companies receive data before a visitor chooses?

On the median site, 3 separate analytics or advertising companies received data before the visitor made any choice. One in ten sites passed data to 16 or more, and the heaviest to 64. 30% of sites passed data to five or more advertising companies, most of them ad exchanges and identity providers that a visitor has never heard of.

05

Do top .in sites and major brands differ?

Major consumer brands, which spend most on digital advertising, were the most likely to track before consent. The wider list of most-visited .in domains includes government-adjacent services, utilities and smaller publishers that run fewer tags.

07

Why does this matter before May 2027?

Because the DPDP Act will make this pattern a compliance failure. From 13 May 2027, processing personal data on the basis of consent needs an itemised notice and consent that is free, specific, informed and given by a clear affirmative action (sections 5 and 6). An identifier that links a browser to a person is personal data, and analytics and advertising do not fit the narrow legitimate uses in section 7. A tracker that fires before the visitor chooses has, by definition, not been consented to. For children the position is stricter still: section 9(3) prohibits tracking and targeted advertising directed at them outright.

The same pages already fall short for visitors from the EU and UK, where prior consent for non-essential storage has been required for over a decade. For US visitors the test is different: an opt-out link and honouring the Global Privacy Control signal. The cookie consent checker sets out each regime.

08

What should a website owner do now?

  1. Measure. Run the cookie scanner on your homepage and two inner pages to see what fires before consent. That list, not your tag manager, is what a regulator will see
  2. Block by default. Load analytics and advertising tags only after the visitor chooses, per purpose. Tag-manager containers can stay; the tags inside them must wait
  3. Make refusal equal. Put "Reject" beside "Accept" on the first layer, with the same prominence
  4. Record the choice. Keep which notice each visitor saw, what they chose and when; that record is your proof under section 6(10)
  5. Make withdrawal work. A permanent link to reopen the choice, and deleting the identifiers a revoked purpose created
  6. Write it down. Publish an itemised notice from the consent notice template and a cookie policy built from your scan
09

How was the study done?

  • Sample. The 300 most-visited commercial .in domains in the Tranco list (list ID Q2K34), excluding government, education, link shorteners and registry infrastructure; plus 171 major Indian brands on .com and other domains, grouped into sectors. 471 sites in total, each counted once
  • When and where. 1 October 2026, from a connection in India
  • How. Each homepage was loaded in headless Chrome with a standard desktop browser identity, once with no consent and once in a fresh session after accepting the banner if one was found
  • What counts. The headline counts a site only if a cookie or storage item belonging to a known analytics or advertising provider (for example _ga, _gcl_au, _fbp) was stored in the first pass. Loading a tag manager script alone does not count. Unrecognised first-party cookies, content delivery networks, bot protection, fingerprint-style API reads and performance-monitoring tools are excluded
  • Banners. A banner was recorded if a known consent tool's interface was visible, or a fixed or sticky element talked about cookies and offered a choice. A reject option counts only if it was visible on the banner's first layer
  • Exclusions. 70 sites that blocked automated browsers, failed to load or returned nothing were excluded and are not counted as compliant
  • Checked independently. Forty sites chosen at random were reloaded in a plain browser, without our scanner's code, and their cookies compared with the scanner's verdict. Thirty-nine agreed; the one difference exposed a classification bug, which was fixed and the whole dataset re-labelled before publication
  • Limits. One page per site and one visit from India. Many sites show banners only to EU visitors, and inner pages may behave differently. Trackers that fire only on scroll or click are not captured, so the figures are, if anything, an undercount

We do not name individual websites. Journalists can request the per-site data for verification through our contact page.

10

How to cite this study

TryTrustable (2026). Cookie consent on Indian websites: 2026 study. Homepage scans of 401 top Indian websites, 1 October 2026. https://trytrustable.com/research/indian-websites-cookie-consent-2026

Figures may be republished with a link to this page.

Questions

The things people ask us

What did the study find?

Of 401 top Indian homepages that could be measured, 76% stored a known analytics or advertising identifier before the visitor gave any consent, and 16.5% displayed a consent banner on first visit. A typical site passed data to 3 tracking companies before any choice.

Is it illegal to set trackers before consent in India today?

Not yet under the DPDP Act: its notice and consent duties apply from 13 May 2027. Sites that serve visitors in the EU or UK are already subject to the ePrivacy rules, which require consent before non-essential storage.

Which websites were scanned?

The 300 most-visited commercial .in domains in the Tranco research ranking, excluding government, education, link shorteners and registry infrastructure, plus 171 major Indian brands grouped into sectors.

Why don't you name the websites?

The point is the state of the market before the DPDP duties begin, not any one company. Per-site results are kept for verification and can be shared with journalists on request.

How was a tracker identified?

By matching each cookie, storage item and network request against more than 150 known analytics and advertising providers. The headline counts only identifiers stored on the device. Tag-manager script loads, content delivery networks, bot protection and performance monitoring never count.

How accurate are the results?

Forty sites chosen at random were re-checked in a plain browser without our scanner's code. Thirty-nine agreed; the one difference exposed a classification error, which was fixed and the whole dataset re-labelled before publication. The method is conservative, so the true figures are if anything higher.

Does showing a cookie banner make a site compliant?

No. Of the sites that showed a banner, 77% had already stored tracking identifiers before the visitor clicked, and only 35% offered a reject option on the first screen. A banner has to block tags until the visitor chooses, and refusing must be as easy as accepting.

Can I use these figures?

Yes, with a link to this page.

Can I check my own site?

Yes. The free cookie scanner runs the same two-pass test on any URL, and the cookie consent checker tells you which rules apply to you.

Book a walkthrough

Find out what your own site does before consent.

The scanner runs the same two passes on your site in about a minute. We can walk you through the results and what to change before May 2027.