WEBSITE COMPLIANCE AND WEBSITE PRIVACY ASSESSMENT

What your website actually does, and what the law requires it to do

Every website collects data whether anyone planned for it to or not. It sets cookies before a visitor makes a choice, asks for a phone number on a contact form "just in case," and passes browsing data to three or four analytics and advertising tools before the homepage has finished loading. This is normal. Most websites, including well-run ones, work this way.

3 Legal frameworks benchmarked — DPDP, GDPR/UK GDPR, US State Laws
8 Specific website practices mapped to citable provisions
Rs. 250 Cr Maximum DPDP Act exposure per violation
Lapating

What has changed is that these ordinary habits now have names, and penalties attached to them. India's Digital Personal Data Protection Act, 2023 (DPDP Act), the EU and UK General Data Protection Regulation (GDPR), and US state privacy laws such as the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA) each treat a mistimed cookie banner or a vague privacy notice as a specific, citable violation, not a design oversight.

This assessment is built to find those gaps on your website before a regulator, a customer, or a competitor does, and to hand you documents your team can publish immediately, not just a list of problems.
Scope of engagement

Who This Is For?

This assessment is built for any organisation whose website collects personal data from users in India, the EU, the UK, or the United States: e-commerce platforms, SaaS products, fintech and healthtech companies, marketing, and research agencies, and B2B websites running lead forms, chat widgets, and analytics. If your website has a cookie banner, a contact form, or a login, this applies to you.

01

E-commerce platforms

02

SaaS products

03

Fintech & healthtech companies

04

Marketing & research agencies

05

B2B websites running lead forms

06

Any site with a cookie banner, contact form, or login

Accountability

Who Is Legally Responsible?

Under privacy laws, the legal responsibility for compliance does not rest with the website itself. It rests with the organisation that determines why and how personal data is collected and processed.

India — DPDP Act, 2023

Data Fiduciary
Under the Digital Personal Data Protection Act, 2023, the organisation that decides why and how personal data is processed is called the Data Fiduciary, with additional statutory obligations on Significant Data Fiduciaries under Section 10.

EU & UK — GDPR / UK GDPR

Data Controller
Under the GDPR and UK GDPR, this same organisation is called the Data Controller. Its responsibility is reinforced by the accountability principle under Article 5(2) and the controller's compliance obligations under Article 24.

Under the Digital Personal Data Protection Act, 2023, this organisation is called the Data Fiduciary. Under the GDPR and UK GDPR, it is called the Data Controller. While the terminology differs, both refer to the entity that decides the purposes and means of processing personal data. Under the GDPR, this responsibility is reinforced by the accountability principle under Article 5(2) and the controller's compliance obligations under Article 24, while the DPDP Act imposes statutory obligations on the Data Fiduciary and, where applicable, additional obligations on Significant Data Fiduciaries under Section 10.

Responsibility

Organisation's Decision-Makers

In a company, this responsibility generally rests with the organisation acting through its decision-makers:

01

Board of Directors

02

Managing Director

03

Chief Executive Officer

04

Founders

05

Partners (in the case of a partnership)

06

Legal Team

07

Compliance Team

08

Privacy Team

09

Information Security

10

Information Technology

11

Marketing Team

12

Product Team

Practically, this means that if the marketing team installs tracking cookies, the IT team deploys analytics tools, or the product team launches a new feature without complying with privacy requirements, regulators will hold the organisation responsible because it decided why and how those personal data processing activities would occur.

The pattern

Where Websites Quietly Break the Law

Most businesses assume their website is compliant because it has a cookie banner and a privacy policy somewhere in the footer. Compliance is not about whether these elements exist. It is about whether they behave the way the law requires, from the moment the page loads to the moment a visitor's data leaves the server. A few patterns turn up on almost every website we review.

High risk

Consent arrives too late

Analytics, advertising, and personalisation scripts fire the instant the page loads before the visitor has clicked anything on the cookie banner. The banner exists, but it is not actually doing its job.

High risk

Consent is not really a choice

Pre-ticked boxes, an "Accept All" button in bold colour next to a greyed-out or hidden "Reject," or one bundled toggle covering analytics, marketing, and third-party sharing at once.

Moderate risk

The privacy notice does not match what the website actually does

It was written once, years ago, and never updated after the CRM, chatbot, payment gateway, or ad-tech pixels were added.

High risk

No working way to say no

Missing grievance officer or DPO contact details, a "Do Not Sell or Share" link that goes nowhere, and no response to browser signals such as Global Privacy Control.

None of this looks serious from the inside. It looks like a UX shortcut nobody got around to fixing. Regulators read it differently, as the specific violations mapped out below.

The technical review

The Violation Map

Picture a typical checkout page. A visitor lands on it, the cookie banner appears, and before they have even read it, three tracking scripts have already logged their visit, their device, and the page they came from. They click "Accept" because the button is the only one in colour. Later, they try to find a way to stop marketing emails and cannot locate a working link anywhere on the site. Every step in that sequence is a separate, specific legal violation, not a single vague one.

The table below sets out common website practices against the exact provision each one breaches, across three jurisdictions. This is the same mapping our assessors use during the technical review: a specific section, article, or clause a regulator would actually cite, not a generic checklist.

Website Practice DPDP Act, 2023 (India) GDPR / UK GDPR US State Laws (CCPA/CPRA)
Trackers or cookies fire before the visitor responds to the consent banner Section 6. Consent must precede processing; it cannot be assumed from continued browsing. ePrivacy Directive Art. 5(3) with GDPR Art. 4(11)/6. No storage on or access to a device without prior consent. Treated as a notice-at-collection and dark-pattern failure under Civil Code Section 1798.100.
Pre-ticked consent boxes or one bundled "accept everything" toggle Section 6(1). Consent must be free, specific, and unconditional. Recital 32, and the CJEU's Planet49 ruling (C-673/17): a pre-ticked box is not valid consent. CPRA's dark-pattern prohibition: consent obtained through a confusing or manipulative interface.
"Accept" and "Reject" are not equally easy to use Section 6(1). Consent must be freely given, without coercion. GDPR Art. 7(2)/(3). Withdrawing consent must be as easy as giving it. CPPA Enforcement Advisory on symmetry in choice and dark patterns.
Privacy notice is outdated, vague, or missing at the point of collection Section 5. Itemised notice of data collected, purpose, and rights. GDPR Art. 13/14. Information must be provided at the time of collection. Notice at Collection requirement, Civil Code Section 1798.100.
No working opt-out or "Do Not Sell or Share" link; GPC signals ignored Section 6(4)/(5). Consent must be as easy to withdraw as to give. GDPR Art. 21. Right to object to processing. Civil Code Section 1798.120: opt-out of sale/share. CPRA requires honouring GPC.
No grievance officer or DPO contact published on the site Section 5, read with the grievance redressal obligations in the DPDP Rules. GDPR Art. 13(1)(b). Controller and DPO contact details must be disclosed. The privacy policy must list a contact method for rights requests.
Cross-border transfer of visitor data to overseas servers or vendors, undisclosed Section 16. Restrictions and disclosure requirements for transfers outside India. GDPR Chapter V, Art. 44 to 49. Adequacy decisions, SCCs, or other safeguards. Third-party categories and recipients must be disclosed in the privacy policy.
Data collected from minors without verifiable parental consent Section 9. Explicit consent of a parent or guardian; no behavioural tracking of children. GDPR Art. 8. Conditions for a child's consent. CPRA requires opt-in for known minors under 16, with a higher penalty tier.
Regulatory exposure

What This Actually Costs

These are not hypothetical numbers. Regulators in all three jurisdictions have already fined companies for exactly this kind of website behaviour. These penalties are imposed on the organisation acting as the Data Fiduciary (under the DPDP Act) or the Data Controller (under the GDPR and UK GDPR).

DPDP Act, 2023

Rs. 250 CrSection 33 and the Schedule to the DPDP Act

Up to Rs. 250 crore per violation for security safeguard failures, Rs. 200 crore for failing to notify a breach, Rs. 150 crore for a Significant Data Fiduciary's non-compliance, and Rs. 50 crore for other breaches. The Board can double any of these in aggravated cases.

GDPR / UK GDPR

€20M / 4%Art. 83, GDPR

The higher of 20 million euros or 4% of total worldwide annual turnover

CCPA / CPRA

$2,500–7,500Civil Code Sections 1798.155 and 1798.199.90

2,500 US dollars per violation if unintentional, 7,500 US dollars if intentional or involving a minor's data, with no overall cap, plus a private right of action of 100 to 750 US dollars per consumer for breaches.

Bars indicate relative regulatory severity within each framework, not a currency conversion. Basis: Section 33 & the Schedule to the DPDP Act; Art. 83 GDPR; Civil Code Sections 1798.155 & 1798.199.90.

Enforcement record

This Has Already Happened to Other Companies

France · 2022

€150 million — Google

France's data protection authority, CNIL, fined Google 150 million euros in 2022 after finding that its cookie banner made rejecting cookies harder than accepting them.

Belgium

Roularta Media Group

Belgium's data protection authority fined Roularta Media Group for placing statistical and partner cookies without valid consent, using pre-ticked boxes, and giving users no real way to withdraw consent once given.

California

Sephora & Global Privacy Control

The California Attorney General has issued violation notices to multiple businesses for failing to honour Global Privacy Control signals and reached a public settlement with Sephora over related non-compliance.

EU

Planet49 (C-673/17)

The Court of Justice of the EU settled the pre-ticked box question in the Planet49 case, ruling that a box checked by default does not reflect an active choice by the user, and therefore is not valid consent under either the ePrivacy Directive or the GDPR.

Beyond the fine itself, each of these is also a reputational event. A cookie banner that tricks visitors, or an opt-out link that does not work, is something a customer or journalist can screenshot and share long before a regulator gets involved.

None of the organisations in these cases set out to break the law. In most instances, a consent banner was configured once, at launch, and never revisited as new marketing tools and trackers were added over time. That is exactly the kind of drift this assessment is designed to catch.

The engagement

The Website Compliance and Privacy Assessment

This is a standalone, fixed-scope engagement. Run it once as a diagnostic, or annually alongside a DPO-as-a-Service retainer. It goes further than a policy review. Our assessors examine the live website, and every third-party integration connected to it, and record what actually fires, when, and where the data goes afterward.

Scope of Work

Review of every website data touchpoint and disclosure: forms, chat widgets, embedded media, login flows, and analytics.

Compliance review benchmarked against the DPDP Act, EU GDPR, UK GDPR, and applicable US State Privacy Laws.

Technical inspection of cookies, tags, pixels, third-party integrations, and consent mechanisms, including banner design, button symmetry, and the granularity of choices offered, to identify what fires before consent and what should not fire at all.

Deep-dive assessment of data collection across the website and every connected third-party service, not the homepage alone.

Consolidated gap analysis and risk register, ranked by regulatory exposure and how quickly each item can be fixed.

Clause-level redlining and harmonisation of existing privacy language across the policy, cookie notice, and consent banners.

Mapping of what the website actually collects against what its privacy, cookie, and consent notices claim it collects, so the two finally match.

Drafting of final, execution-ready privacy documents. This produces a finished fix, not a recommendation memo for someone else to draft later.

A client walkthrough and final alignment session before sign-off.

Four stages, in order

How the Engagement Runs

01

Discovery

We map every page, form, and third-party script on the live website, and log what data each one actually collects.

02

Assessment

We evaluate the site against the DPDP Act, GDPR, UK GDPR, and applicable US State Privacy Laws, and flag every gap against the specific provision it breaches.

03

Fix

We redline and rewrite the privacy policy, cookie policy, and consent notices, and hand over documents ready to publish.

04

Closure

We walk your team through every change in a final session, so legal, marketing, and engineering are aligned before go-live.

The output

What You Receive

MAP

Website Data Touchpoint and Disclosure Mapping

DIVE

Deep-Dive Data Collection Compliance Assessment

Covering the website and all connected third-party integrations
GAP

Website Privacy Compliance Gap and Recommendation Report

With a solution roadmap and implementation support through to closure
POL

Final Data Privacy Policy

Fully drafted and ready to publish
CKE

Final Cookie Policy

Fully drafted and ready to publish
CON

Final Consent Notice or Notices

Fully drafted and ready to publish
LANG

Harmonised Privacy Language Recommendations

Across all customer-facing documents
CLS

Final Review Walkthrough and Closure Session

With your team
Every deliverable is built to be used as it is. Legal and engineering teams can hand it straight to the CMS or consent management platform without a second round of drafting.
Why us

Why Run This With Us

Our assessors are privacy counsel and engineers working side by side. One reads a Data Protection Board order the way the other reads a tag manager configuration. That combination is what turns a compliance report into documents your team can actually publish, rather than another PDF that sits in a shared drive.

This assessment also fits naturally alongside an ongoing DPO-as-a-Service engagement, where your website's consent management, cookie behaviour, and privacy notices are reviewed on a continuing basis rather than once and then forgotten.

We work across the same frameworks covered in this assessment, including DPIAs, ROPAs, and ISO 27001-aligned audits, so a website review can plug directly into a wider privacy and governance programme instead of sitting on its own.

2Disciplines under one roof — privacy counsel & engineering
4Frameworks benchmarked in this assessment
3Adjacent programmes it plugs into — DPIA, ROPA, ISO 27001
Get started

Ready to Start.

A website compliance and privacy assessment can run as a one-time diagnostic or as the first engagement in an ongoing DPO-as-a-Service relationship. Either way, it starts with a short scoping call to understand your website, your third-party integrations, and the jurisdictions your visitors come from.