Every website collects data whether anyone planned for it to or not. It sets cookies before a visitor makes a choice, asks for a phone number on a contact form "just in case," and passes browsing data to three or four analytics and advertising tools before the homepage has finished loading. This is normal. Most websites, including well-run ones, work this way.
What has changed is that these ordinary habits now have names, and penalties attached to them. India's Digital Personal Data Protection Act, 2023 (DPDP Act), the EU and UK General Data Protection Regulation (GDPR), and US state privacy laws such as the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA) each treat a mistimed cookie banner or a vague privacy notice as a specific, citable violation, not a design oversight.
This assessment is built for any organisation whose website collects personal data from users in India, the EU, the UK, or the United States: e-commerce platforms, SaaS products, fintech and healthtech companies, marketing, and research agencies, and B2B websites running lead forms, chat widgets, and analytics. If your website has a cookie banner, a contact form, or a login, this applies to you.
Under privacy laws, the legal responsibility for compliance does not rest with the website itself. It rests with the organisation that determines why and how personal data is collected and processed.
Under the Digital Personal Data Protection Act, 2023, this organisation is called the Data Fiduciary. Under the GDPR and UK GDPR, it is called the Data Controller. While the terminology differs, both refer to the entity that decides the purposes and means of processing personal data. Under the GDPR, this responsibility is reinforced by the accountability principle under Article 5(2) and the controller's compliance obligations under Article 24, while the DPDP Act imposes statutory obligations on the Data Fiduciary and, where applicable, additional obligations on Significant Data Fiduciaries under Section 10.
In a company, this responsibility generally rests with the organisation acting through its decision-makers:
Practically, this means that if the marketing team installs tracking cookies, the IT team deploys analytics tools, or the product team launches a new feature without complying with privacy requirements, regulators will hold the organisation responsible because it decided why and how those personal data processing activities would occur.
Most businesses assume their website is compliant because it has a cookie banner and a privacy policy somewhere in the footer. Compliance is not about whether these elements exist. It is about whether they behave the way the law requires, from the moment the page loads to the moment a visitor's data leaves the server. A few patterns turn up on almost every website we review.
Analytics, advertising, and personalisation scripts fire the instant the page loads before the visitor has clicked anything on the cookie banner. The banner exists, but it is not actually doing its job.
Pre-ticked boxes, an "Accept All" button in bold colour next to a greyed-out or hidden "Reject," or one bundled toggle covering analytics, marketing, and third-party sharing at once.
It was written once, years ago, and never updated after the CRM, chatbot, payment gateway, or ad-tech pixels were added.
Missing grievance officer or DPO contact details, a "Do Not Sell or Share" link that goes nowhere, and no response to browser signals such as Global Privacy Control.
None of this looks serious from the inside. It looks like a UX shortcut nobody got around to fixing. Regulators read it differently, as the specific violations mapped out below.
Picture a typical checkout page. A visitor lands on it, the cookie banner appears, and before they have even read it, three tracking scripts have already logged their visit, their device, and the page they came from. They click "Accept" because the button is the only one in colour. Later, they try to find a way to stop marketing emails and cannot locate a working link anywhere on the site. Every step in that sequence is a separate, specific legal violation, not a single vague one.
The table below sets out common website practices against the exact provision each one breaches, across three jurisdictions. This is the same mapping our assessors use during the technical review: a specific section, article, or clause a regulator would actually cite, not a generic checklist.
| Website Practice | DPDP Act, 2023 (India) | GDPR / UK GDPR | US State Laws (CCPA/CPRA) |
|---|---|---|---|
| Trackers or cookies fire before the visitor responds to the consent banner | Section 6. Consent must precede processing; it cannot be assumed from continued browsing. | ePrivacy Directive Art. 5(3) with GDPR Art. 4(11)/6. No storage on or access to a device without prior consent. | Treated as a notice-at-collection and dark-pattern failure under Civil Code Section 1798.100. |
| Pre-ticked consent boxes or one bundled "accept everything" toggle | Section 6(1). Consent must be free, specific, and unconditional. | Recital 32, and the CJEU's Planet49 ruling (C-673/17): a pre-ticked box is not valid consent. | CPRA's dark-pattern prohibition: consent obtained through a confusing or manipulative interface. |
| "Accept" and "Reject" are not equally easy to use | Section 6(1). Consent must be freely given, without coercion. | GDPR Art. 7(2)/(3). Withdrawing consent must be as easy as giving it. | CPPA Enforcement Advisory on symmetry in choice and dark patterns. |
| Privacy notice is outdated, vague, or missing at the point of collection | Section 5. Itemised notice of data collected, purpose, and rights. | GDPR Art. 13/14. Information must be provided at the time of collection. | Notice at Collection requirement, Civil Code Section 1798.100. |
| No working opt-out or "Do Not Sell or Share" link; GPC signals ignored | Section 6(4)/(5). Consent must be as easy to withdraw as to give. | GDPR Art. 21. Right to object to processing. | Civil Code Section 1798.120: opt-out of sale/share. CPRA requires honouring GPC. |
| No grievance officer or DPO contact published on the site | Section 5, read with the grievance redressal obligations in the DPDP Rules. | GDPR Art. 13(1)(b). Controller and DPO contact details must be disclosed. | The privacy policy must list a contact method for rights requests. |
| Cross-border transfer of visitor data to overseas servers or vendors, undisclosed | Section 16. Restrictions and disclosure requirements for transfers outside India. | GDPR Chapter V, Art. 44 to 49. Adequacy decisions, SCCs, or other safeguards. | Third-party categories and recipients must be disclosed in the privacy policy. |
| Data collected from minors without verifiable parental consent | Section 9. Explicit consent of a parent or guardian; no behavioural tracking of children. | GDPR Art. 8. Conditions for a child's consent. | CPRA requires opt-in for known minors under 16, with a higher penalty tier. |
These are not hypothetical numbers. Regulators in all three jurisdictions have already fined companies for exactly this kind of website behaviour. These penalties are imposed on the organisation acting as the Data Fiduciary (under the DPDP Act) or the Data Controller (under the GDPR and UK GDPR).
Up to Rs. 250 crore per violation for security safeguard failures, Rs. 200 crore for failing to notify a breach, Rs. 150 crore for a Significant Data Fiduciary's non-compliance, and Rs. 50 crore for other breaches. The Board can double any of these in aggravated cases.
The higher of 20 million euros or 4% of total worldwide annual turnover
2,500 US dollars per violation if unintentional, 7,500 US dollars if intentional or involving a minor's data, with no overall cap, plus a private right of action of 100 to 750 US dollars per consumer for breaches.
Bars indicate relative regulatory severity within each framework, not a currency conversion. Basis: Section 33 & the Schedule to the DPDP Act; Art. 83 GDPR; Civil Code Sections 1798.155 & 1798.199.90.
France's data protection authority, CNIL, fined Google 150 million euros in 2022 after finding that its cookie banner made rejecting cookies harder than accepting them.
Belgium's data protection authority fined Roularta Media Group for placing statistical and partner cookies without valid consent, using pre-ticked boxes, and giving users no real way to withdraw consent once given.
The California Attorney General has issued violation notices to multiple businesses for failing to honour Global Privacy Control signals and reached a public settlement with Sephora over related non-compliance.
The Court of Justice of the EU settled the pre-ticked box question in the Planet49 case, ruling that a box checked by default does not reflect an active choice by the user, and therefore is not valid consent under either the ePrivacy Directive or the GDPR.
Beyond the fine itself, each of these is also a reputational event. A cookie banner that tricks visitors, or an opt-out link that does not work, is something a customer or journalist can screenshot and share long before a regulator gets involved.
None of the organisations in these cases set out to break the law. In most instances, a consent banner was configured once, at launch, and never revisited as new marketing tools and trackers were added over time. That is exactly the kind of drift this assessment is designed to catch.
This is a standalone, fixed-scope engagement. Run it once as a diagnostic, or annually alongside a DPO-as-a-Service retainer. It goes further than a policy review. Our assessors examine the live website, and every third-party integration connected to it, and record what actually fires, when, and where the data goes afterward.
Review of every website data touchpoint and disclosure: forms, chat widgets, embedded media, login flows, and analytics.
Compliance review benchmarked against the DPDP Act, EU GDPR, UK GDPR, and applicable US State Privacy Laws.
Technical inspection of cookies, tags, pixels, third-party integrations, and consent mechanisms, including banner design, button symmetry, and the granularity of choices offered, to identify what fires before consent and what should not fire at all.
Deep-dive assessment of data collection across the website and every connected third-party service, not the homepage alone.
Consolidated gap analysis and risk register, ranked by regulatory exposure and how quickly each item can be fixed.
Clause-level redlining and harmonisation of existing privacy language across the policy, cookie notice, and consent banners.
Mapping of what the website actually collects against what its privacy, cookie, and consent notices claim it collects, so the two finally match.
Drafting of final, execution-ready privacy documents. This produces a finished fix, not a recommendation memo for someone else to draft later.
A client walkthrough and final alignment session before sign-off.
We map every page, form, and third-party script on the live website, and log what data each one actually collects.
We evaluate the site against the DPDP Act, GDPR, UK GDPR, and applicable US State Privacy Laws, and flag every gap against the specific provision it breaches.
We redline and rewrite the privacy policy, cookie policy, and consent notices, and hand over documents ready to publish.
We walk your team through every change in a final session, so legal, marketing, and engineering are aligned before go-live.
Our assessors are privacy counsel and engineers working side by side. One reads a Data Protection Board order the way the other reads a tag manager configuration. That combination is what turns a compliance report into documents your team can actually publish, rather than another PDF that sits in a shared drive.
This assessment also fits naturally alongside an ongoing DPO-as-a-Service engagement, where your website's consent management, cookie behaviour, and privacy notices are reviewed on a continuing basis rather than once and then forgotten.
We work across the same frameworks covered in this assessment, including DPIAs, ROPAs, and ISO 27001-aligned audits, so a website review can plug directly into a wider privacy and governance programme instead of sitting on its own.
A website compliance and privacy assessment can run as a one-time diagnostic or as the first engagement in an ongoing DPO-as-a-Service relationship. Either way, it starts with a short scoping call to understand your website, your third-party integrations, and the jurisdictions your visitors come from.