Consent Mode v2 and India’s DPDP Act: A Marketer’s Guide
Consent Mode v2 is Google's tracking signal layer. India's DPDP Act is the law behind it. Here's how the two fit together, plus a practical compliance checklist.

Consent Mode v2 is Google’s way of telling its own tags — Google Analytics 4, Google Ads, Floodlight — whether a visitor agreed to be tracked, before those tags write a single cookie. India’s Digital Personal Data Protection Act, 2023 (the DPDP Act) does not name Consent Mode anywhere, but it does legally require the thing Consent Mode depends on: real, recorded, withdrawable consent collected before you process anyone’s personal data.
So the practical answer for an Indian website is this. Consent Mode v2 is mandatory only for your traffic from the European Economic Area and the UK, because Google requires it. The DPDP Act makes a proper consent banner, a consent log, and a one-click withdrawal path necessary for your Indian traffic too — and Consent Mode is the cheapest way to make your Google tags actually obey that banner.
What Consent Mode v2 actually is
Consent Mode is a signal layer, not a cookie banner. Your consent management platform (CMP — the tool that shows the banner and stores the choice) collects the decision. Consent Mode is how that decision is passed to Google’s tags.
It carries four signals. Two existed in version 1: ad_storage (may we use advertising cookies?) and analytics_storage (may we use analytics cookies?). Version 2 added two more: ad_user_data (may we send personal data to Google for ads?) and ad_personalization (may we use this person for remarketing?).
Each signal is simply granted or denied. Google’s documented enforcement deadline for the two new signals was March 2024 for European traffic — miss them and remarketing audiences and enhanced conversions stop working for that traffic. The technical spec sits in Google’s tag platform developer documentation, and the underlying policy obligation is Google’s EU user consent policy.
What the DPDP Act changes for Indian websites
The DPDP Act was passed in August 2023, and the Digital Personal Data Protection Rules that make it operable were notified by the Ministry of Electronics and Information Technology (MeitY) in November 2025 with a phased schedule. Consent Manager registration provisions land at the 12-month mark; the substantive obligations most marketers care about — notice, consent, data principal rights, breach reporting — arrive roughly 18 months after notification, in mid-2027. Verify current dates against the notified text before you brief a client, because the phase-in is staged.
Five changes matter most if your job involves tracking pixels:
- Consent is the default basis for marketing. Section 6 requires consent that is, in the Act’s own words, “free, specific, informed, unconditional and unambiguous” with a clear affirmative action. There is no “legitimate interest” escape hatch for advertising the way there arguably is under Europe’s GDPR.
- Notice must be itemised and plain. You have to say what data, for what purpose, in language a normal person understands — and offer it in English plus the languages in the Eighth Schedule of the Constitution.
- Withdrawal must be as easy as consent. If accepting takes one tap, withdrawing must too. A buried email address does not count.
- Anyone under 18 is a child. You need verifiable parental consent, and behavioural advertising targeted at children is prohibited outright. India’s threshold is far higher than the 13–16 range used in Europe.
- Penalties are large. The Schedule to the Act allows up to ₹250 crore for failing to maintain reasonable security safeguards, up to ₹200 crore for not reporting a breach, and up to ₹50 crore for other contraventions.
India also introduces a genuinely new institution: the Consent Manager, a registered intermediary through which people can give, review and withdraw consent across companies. The Rules set qualifying conditions, including a minimum net worth in the ₹2 crore range, so this will be a small, licensed market rather than a plugin you install.
GDPR vs DPDP: the differences that trip marketers up
| Question | GDPR (EU/UK) | DPDP Act (India) |
|---|---|---|
| Can I track on legitimate interest? | Sometimes, with a balancing test | No — consent or a listed legitimate use |
| Who counts as a child? | Under 13–16, varies by country | Under 18, nationwide |
| Behavioural ads to children | Heavily restricted | Prohibited |
| Data export rules | Adequacy decisions and contractual safeguards | Permitted except to restricted countries |
| Sensitive data category | Yes, special categories | No separate category |
| Maximum financial exposure | Up to 4% of global turnover | Up to ₹250 crore per contravention |
| Is Consent Mode v2 required? | Effectively yes, for Google ads and analytics | Not by law — but you still need the consent behind it |
Basic vs Advanced Consent Mode: pick deliberately
Once you implement Consent Mode you choose one of two setups, and the choice has real measurement consequences.
| Basic | Advanced | |
|---|---|---|
| When tags load | Only after consent is granted | On page load, in a restricted state |
| Data sent if visitor refuses | Nothing | Anonymous cookieless pings |
| Conversion modelling | Limited | Supported, subject to Google’s volume thresholds |
| Privacy optics | Cleanest story for a regulator | Needs a clear notice explaining the pings |
| Typical fit | Health, finance, legal, edtech for minors | Retail, D2C, travel, SaaS |
A worked example, with numbers
Take an illustrative Bengaluru D2C skincare brand: 500,000 sessions a month, ₹12 lakh monthly Google Ads spend, 6% of traffic from the EEA and UK.
That 6% is 30,000 sessions. Without Consent Mode v2 signals, Google stops adding those European users to remarketing audiences and stops accepting their hashed email data for enhanced conversions. If European traffic converts at 1.5% at a ₹4,000 average order value, that is roughly ₹18 lakh of annual revenue you can no longer retarget or attribute properly — from a market you were already paying to reach.
Now the Indian side. Suppose 68% of Indian visitors accept analytics cookies. In Basic mode, GA4 sees about 340,000 of 500,000 sessions and your dashboards quietly under-report by roughly a third. In Advanced mode, the refusing 32% still send anonymous pings, and Google models part of the gap — so your reported conversions stay closer to reality. Neither number is a compliance outcome. Both are budget-allocation outcomes, which is why this is a marketing problem, not just a legal one.
The DPDP + Consent Mode v2 checklist
- Audit what actually fires. Open your tag manager and list every tag, pixel and script. Most sites find third-party tags nobody remembers adding.
- Classify by purpose — strictly necessary, analytics, advertising, personalisation. DPDP notice requirements are purpose-based.
- Install a CMP that supports Consent Mode v2. For EEA and UK traffic, use one from Google’s certified CMP partner list, which also handles the IAB Transparency and Consent Framework string.
- Give Accept and Reject equal visual weight. No pre-ticked boxes, no grey “Reject” against a bright “Accept”, no cookie wall.
- Block by default. Set consent to denied for all four signals until the visitor chooses. Use tag manager’s consent settings, not custom triggers you will forget to maintain.
- Log every consent event — timestamp, version of the notice shown, the choices made. Under DPDP, you must be able to demonstrate consent, not just claim it.
- Build the withdrawal path. A persistent “Cookie preferences” link in the footer, plus an account-level control if you have logins.
- Write the notice in plain language, and translate it. Budget for at least Hindi plus your two largest regional-language markets.
- Extend consent beyond the browser. Customer Match uploads, offline conversion imports, WhatsApp Business broadcasts and SMS campaigns all need their own documented opt-in. Consent Mode does not cover them.
- Handle age. If your audience plausibly includes under-18s — edtech, gaming, entrance-exam prep — you need an age gate and parental verification before any behavioural targeting.
- Appoint an owner and name a grievance contact publicly. Significant Data Fiduciaries additionally need a Data Protection Officer based in India.
Six mistakes we keep seeing
Calling a notice a consent. A bar that says “by continuing you agree” collects nothing that DPDP recognises.
Banner installed, tags unchanged. The commonest failure by far: the CMP records a refusal, and GA4 fires anyway because nobody wired the consent signal into the tag.
Assuming Google’s CMP list covers India. Certification is about Google’s European policy. It does not make you DPDP-compliant, and it says nothing about Meta, Amazon Ads or your CRM.
No withdrawal route. If a user cannot find the preferences link in five seconds, withdrawal is not “as easy as” consent.
Ignoring the under-18 rule. This is the sleeper clause for Indian edtech and gaming. A ban on behavioural ads to children is not a consent problem you can solve with a checkbox.
Treating the 2027 deadline as far away. Retrofitting consent across a CDP, a data warehouse and four ad platforms takes quarters, not weeks.
What this means for you
- This quarter: run the tag audit and check whether your CMP is genuinely passing all four Consent Mode v2 signals. Google Tag Assistant will show you the consent state on page load.
- Choose Basic or Advanced on purpose, and document why. Regulated or child-adjacent audiences: Basic. Retail and D2C: Advanced, with the pings disclosed in your notice.
- Re-baseline your reporting. Tell your leadership that conversion counts will shift when consent gating goes live, before the numbers move. Attribution debates started after the fact never end well.
- Take consent upstream. Lead forms, WhatsApp opt-ins and offline lists need purpose-specific consent recorded at collection. Fixing this later means discarding list segments you cannot prove.
- Treat first-party data as the hedge. Logged-in users, email subscribers and loyalty members who consented explicitly are the only audience assets that get more valuable as consent rates fall.
Frequently asked questions
Is Consent Mode v2 mandatory in India?
No Indian law requires Consent Mode v2. It is a Google product requirement, and it is effectively mandatory for traffic from the European Economic Area and the UK — including EEA visitors to an Indian website. For purely Indian traffic, Consent Mode is optional but strongly recommended, because it is the standard mechanism for making Google’s tags respect the consent the DPDP Act requires you to collect.
Does the DPDP Act require a cookie banner?
The Act never uses the word “cookie”. It requires notice and consent before processing digital personal data, and most tracking cookies and pixels process personal data. In practice that means a consent banner with a genuine reject option, a stored record of the choice, and an easy way to withdraw. Cookies that are strictly necessary to deliver the service the user asked for sit on safer ground.
What is the penalty for getting consent wrong in India?
The Schedule to the DPDP Act allows the Data Protection Board to impose up to ₹250 crore for failing to maintain reasonable security safeguards, up to ₹200 crore for failing to report a personal data breach, and up to ₹50 crore for other contraventions. Penalties are assessed case by case, weighing the nature of the breach and any mitigation you can evidence.
Can I keep using Google Analytics 4 under the DPDP Act?
Yes. GA4 remains usable, provided you obtain consent before analytics cookies are set, disclose the purpose in your notice, and honour withdrawal. DPDP is more permissive than GDPR on cross-border transfers — data may move abroad except to countries the government restricts — so the Schrems-style concerns that plagued Analytics in Europe do not apply the same way in India.
