76% of top Indian websites store tracking identifiers before visitors consent
We loaded the homepages of 401 of India's most-visited websites and major brands, once with no consent given and once after accepting. 76% stored a known analytics or advertising identifier before the visitor made any choice, and 16.5% showed a consent banner at all. The DPDP Act's notice and consent duties apply from 13 May 2027.
The key findings
Most of India's largest websites start tracking visitors before asking. Of the 401 homepages we could measure, 76% stored a known analytics or advertising identifier, such as a Google Analytics or Meta Pixel cookie, on the first page load before the visitor had clicked anything, and 80% sent data to an analytics or advertising service. Only 16.5% showed a consent banner at all, and where one was shown, 77% of those sites had already stored tracking identifiers before the visitor reached it.
| Finding | Share of sites |
|---|---|
| Stored a known analytics or advertising identifier before consent | 76% |
| Sent data to a known analytics or advertising service before consent | 80% |
| Ran advertising trackers (not just analytics) before consent | 70% |
| Passed data to five or more advertising companies before any choice | 30% |
| Showed a consent banner on the first visit | 16.5% |
| Of sites with a banner, still stored tracking identifiers before the click | 77% |
| Of sites with a banner, offered a reject option on its first layer | 35% |
Base: 401 homepages that could be measured, of 471 sampled. 70 could not be measured (did not load, blocked automated browsers or returned nothing) and are excluded, not counted as compliant.
How many companies receive data before a visitor chooses?
On the median site, 3 separate analytics or advertising companies received data before the visitor made any choice. One in ten sites passed data to 16 or more, and the heaviest to 64. 30% of sites passed data to five or more advertising companies, most of them ad exchanges and identity providers that a visitor has never heard of.
How many tracking companies a site uses before consent
Distinct analytics and advertising companies active before any choice, per site. Median: 3.
Which sectors track before consent most?
Every measured media, insurance and travel site stored tracking identifiers before consent. Health, education and classifieds were above 90%. Technology and software companies were the exception on banners, mostly because they sell to Europe and run a consent tool already, yet two in three still stored identifiers before the click.
Tracking identifiers stored before consent, by sector
Share of measured sites in each sector. Sectors with fewer than ten measured sites are not shown.
| Sector | Sites | Identifiers before consent | Data sent before consent | Advertising before consent | Banner shown | Median tracking companies |
|---|---|---|---|---|---|---|
| Insurance | 11 | 100% | 100% | 100% | 9% | 8 |
| Media & entertainment | 23 | 100% | 100% | 96% | 9% | 30 |
| Travel & mobility | 13 | 100% | 100% | 92% | 31% | 6 |
| Jobs, property & classifieds | 15 | 93% | 93% | 93% | 13% | 5 |
| Health | 14 | 93% | 100% | 93% | 0% | 5 |
| Education | 13 | 92% | 92% | 92% | 8% | 5 |
| Banking & finance | 30 | 77% | 80% | 73% | 10% | 4 |
| E-commerce & retail | 26 | 73% | 73% | 69% | 12% | 5 |
| Technology & SaaS | 17 | 65% | 76% | 71% | 82% | 3 |
Major Indian brands, grouped by sector. A tracking company is counted once per site however many cookies it sets.
Which trackers run before consent?
Google's analytics and advertising tags lead, followed by Meta and Microsoft. Below them sits a long tail of programmatic advertising: exchanges, demand platforms and identity services that buy and sell the visit in real time. Each one that fires before consent receives the visitor's IP address and a device identifier.
The 20 trackers most often active before consent
Share of all measured sites where each was active before any choice. A site can run several.
Do top .in sites and major brands differ?
Brands track more than the wider top sites
Share storing tracking identifiers before consent, by how the site entered the sample.
Major consumer brands, which spend most on digital advertising, were the most likely to track before consent. The wider list of most-visited .in domains includes government-adjacent services, utilities and smaller publishers that run fewer tags.
What do the consent banners get wrong?
Of 66 sites that showed a banner, 77% had already stored tracking identifiers before the visitor reached it, so the banner recorded a choice that the page had already overridden. Only 35% offered a reject option on the first layer; the rest put "Accept" on the first screen and refusal one or more clicks away, which regulators in Europe treat as invalid consent.
Consent tools are widely installed but often not switched on for Indian visitors. The table shows the tools whose script loaded on the sites we measured.
| Consent tool whose script loaded | Sites |
|---|---|
| Google Funding Choices | 46 |
| OneTrust | 22 |
| TrustArc | 4 |
| Cookiebot | 3 |
| CookieYes | 2 |
| Sourcepoint | 2 |
| Securiti | 1 |
| consentmanager | 1 |
Detected from the vendor's own script host. A script that loads is not the same as a banner shown: several of these tools display a banner only to visitors from regions where the site has switched it on, so a visitor in India often sees nothing.
Why does this matter before May 2027?
Because the DPDP Act will make this pattern a compliance failure. From 13 May 2027, processing personal data on the basis of consent needs an itemised notice and consent that is free, specific, informed and given by a clear affirmative action (sections 5 and 6). An identifier that links a browser to a person is personal data, and analytics and advertising do not fit the narrow legitimate uses in section 7. A tracker that fires before the visitor chooses has, by definition, not been consented to. For children the position is stricter still: section 9(3) prohibits tracking and targeted advertising directed at them outright.
The same pages already fall short for visitors from the EU and UK, where prior consent for non-essential storage has been required for over a decade. For US visitors the test is different: an opt-out link and honouring the Global Privacy Control signal. The cookie consent checker sets out each regime.
What should a website owner do now?
- Measure. Run the cookie scanner on your homepage and two inner pages to see what fires before consent. That list, not your tag manager, is what a regulator will see
- Block by default. Load analytics and advertising tags only after the visitor chooses, per purpose. Tag-manager containers can stay; the tags inside them must wait
- Make refusal equal. Put "Reject" beside "Accept" on the first layer, with the same prominence
- Record the choice. Keep which notice each visitor saw, what they chose and when; that record is your proof under section 6(10)
- Make withdrawal work. A permanent link to reopen the choice, and deleting the identifiers a revoked purpose created
- Write it down. Publish an itemised notice from the consent notice template and a cookie policy built from your scan
How was the study done?
- Sample. The 300 most-visited commercial
.indomains in the Tranco list (list IDQ2K34), excluding government, education, link shorteners and registry infrastructure; plus 171 major Indian brands on.comand other domains, grouped into sectors. 471 sites in total, each counted once - When and where. 1 October 2026, from a connection in India
- How. Each homepage was loaded in headless Chrome with a standard desktop browser identity, once with no consent and once in a fresh session after accepting the banner if one was found
- What counts. The headline counts a site only if a cookie or storage item belonging to a known analytics or advertising provider (for example
_ga,_gcl_au,_fbp) was stored in the first pass. Loading a tag manager script alone does not count. Unrecognised first-party cookies, content delivery networks, bot protection, fingerprint-style API reads and performance-monitoring tools are excluded - Banners. A banner was recorded if a known consent tool's interface was visible, or a fixed or sticky element talked about cookies and offered a choice. A reject option counts only if it was visible on the banner's first layer
- Exclusions. 70 sites that blocked automated browsers, failed to load or returned nothing were excluded and are not counted as compliant
- Checked independently. Forty sites chosen at random were reloaded in a plain browser, without our scanner's code, and their cookies compared with the scanner's verdict. Thirty-nine agreed; the one difference exposed a classification bug, which was fixed and the whole dataset re-labelled before publication
- Limits. One page per site and one visit from India. Many sites show banners only to EU visitors, and inner pages may behave differently. Trackers that fire only on scroll or click are not captured, so the figures are, if anything, an undercount
We do not name individual websites. Journalists can request the per-site data for verification through our contact page.
How to cite this study
Figures may be republished with a link to this page.
The things people ask us
What did the study find?
Of 401 top Indian homepages that could be measured, 76% stored a known analytics or advertising identifier before the visitor gave any consent, and 16.5% displayed a consent banner on first visit. A typical site passed data to 3 tracking companies before any choice.
Is it illegal to set trackers before consent in India today?
Not yet under the DPDP Act: its notice and consent duties apply from 13 May 2027. Sites that serve visitors in the EU or UK are already subject to the ePrivacy rules, which require consent before non-essential storage.
Which websites were scanned?
The 300 most-visited commercial .in domains in the Tranco research ranking, excluding government, education, link shorteners and registry infrastructure, plus 171 major Indian brands grouped into sectors.
Why don't you name the websites?
The point is the state of the market before the DPDP duties begin, not any one company. Per-site results are kept for verification and can be shared with journalists on request.
How was a tracker identified?
By matching each cookie, storage item and network request against more than 150 known analytics and advertising providers. The headline counts only identifiers stored on the device. Tag-manager script loads, content delivery networks, bot protection and performance monitoring never count.
How accurate are the results?
Forty sites chosen at random were re-checked in a plain browser without our scanner's code. Thirty-nine agreed; the one difference exposed a classification error, which was fixed and the whole dataset re-labelled before publication. The method is conservative, so the true figures are if anything higher.
Does showing a cookie banner make a site compliant?
No. Of the sites that showed a banner, 77% had already stored tracking identifiers before the visitor clicked, and only 35% offered a reject option on the first screen. A banner has to block tags until the visitor chooses, and refusing must be as easy as accepting.
Can I use these figures?
Yes, with a link to this page.
Can I check my own site?
Yes. The free cookie scanner runs the same two-pass test on any URL, and the cookie consent checker tells you which rules apply to you.
Find out what your own site does before consent.
The scanner runs the same two passes on your site in about a minute. We can walk you through the results and what to change before May 2027.