Original Research

How India's DPDP Act Breaks GA4 and Remarketing, and What Actually Fixes It

Under the DPDP Act, 2023 and the DPDP Rules, 2025, running GA4 scripts or firing Meta and Google remarketing pixels before a user gives explicit, affirmative consent is non-compliant, full stop. Here's exactly why, on what legal basis, and the real technical setup that keeps a brand's marketing measurable without breaking the law.

Key Takeaways

  • DPDP requires opt-in, not opt-out. Tracking scripts, GA4's base tag, Meta and Google remarketing pixels, cannot fire on page load by default. They must stay blocked until a user takes a clear, affirmative action to consent.
  • There is no “legitimate interest” escape hatch. Unlike GDPR, the DPDP Act gives private organisations exactly one legal basis for marketing and analytics processing: consent. Its narrow “Certain Legitimate Uses” exemption covers state functions, medical emergencies, and employment, not advertising or web analytics.
  • The enforcement clock is real and close. The Consent Manager framework opens for registration in November 2026, full enforcement lands by 13 May 2027, and penalties run up to ₹250 crore per incident.
  • Consent-gated tag management is the real, working fix. Blocking GA4, Meta Pixel, and Google Ads remarketing tags behind a Consent Management Platform, paired with Google Consent Mode v2 and, where possible, server-side measurement, keeps a brand compliant without abandoning measurement entirely.

The Core Problem: Identifiers Are Personal Data

Meta and Google's remarketing pixels collect IP addresses, device signatures, browser storage state, and hashed user parameters, used for retargeting, profiling, and attribution. GA4 sets pseudonymous identifiers, the _ga cookie, a client_id, to track a visitor's behaviour across sessions and visits.

Under the DPDP framework, an online identifier that can single out an individual or be used to build a behavioural profile counts as digital personal data. That's the entire basis of the compliance problem: these tools work by collecting exactly the kind of identifier the Act defines as personal data, and they're built, by default, to start collecting it the moment a page loads, before any consent has been given.

Consent Must Be Explicit and Prior, Not Implied

The DPDP Act sets a specific, real bar for what counts as valid consent: free, specific, informed, unconditional, and given through a clear, affirmative action. Implicit models, “by continuing to browse, you agree,” or a pre-ticked consent banner checkbox, fail that bar outright. A tag must remain blocked until a user actively clicks “Accept” or selects specific tracking preferences, not until they simply continue using the site.

Why this is a real, structural problem, not a paperwork one: most Indian websites currently fire GA4 and remarketing pixels the instant a page loads, with a cookie banner appearing alongside them, not gating them. That sequencing itself is the violation, regardless of what the banner's copy says, because the data collection has already happened by the time a user makes any choice at all.

Why “Legitimate Interest” Doesn't Save You Here

Marketers familiar with GDPR often look for an equivalent shortcut in DPDP, and it genuinely doesn't exist. GDPR's “legitimate interest” basis, the ground most commonly used in the EU for exactly this kind of processing, analytics, direct marketing, ad attribution, has no counterpart under India's DPDP Act.

The DPDP Act recognises only two bases for processing personal data: consent, and a narrow, closed statutory list the Act calls “Certain Legitimate Uses,” covering things like state functions, medical emergencies, employment-related processing, and specific government-notified purposes. Behavioural tracking, advertising attribution, and web analytics are not on that list, and there's no flexible balancing test private organisations can run to argue their way onto it. Consent is the only real legal basis available for this kind of processing.

The Real Enforcement Timeline

This isn't a distant, theoretical risk. The Data Protection Board of India has been operational since November 2025. The Consent Manager registration framework, the mechanism through which users will formally grant, review, and withdraw consent across every company holding their data, opens for registration in November 2026. Full enforcement obligations under the Act take effect by 13 May 2027.

The penalties are real and material: up to ₹250 crore per incident, with repeat or more serious violations exposed to penalties as high as ₹10,000 crore. Category-specific ceilings apply too, up to ₹250 crore for failing to implement reasonable security safeguards, and up to ₹200 crore each for failing to notify a breach or for children's-data violations, and these can stack when a single incident triggers more than one failure. A brand that waits until the enforcement date to start fixing its tracking setup is starting the clock far too late; a genuine tag-management and consent-infrastructure overhaul is real engineering and legal work, not a banner swap.

What Regulators Already Expect, Ahead of the 2027 Deadline

MeitY's Business Requirements Document for Consent Management Systems (BRDCMS), first published in 2025, isn't itself binding law, but it's the clearest available signal of how the Data Protection Board expects consent to actually work in practice: banners offering Accept, Reject, and Customise together, not Accept-only; no cookie walls; genuine category-level choice rather than one master switch; consent that expires and is re-sought periodically rather than treated as permanent; and notices available in the languages a site's real audience actually uses.

Children's data is the strictest part of the Act. Section 9 sets an 18-year threshold, stricter than GDPR's 13-16 or COPPA's 13, and requires verifiable parental or guardian consent before processing a child's data at all. Separately, and regardless of any consent obtained, the Act flatly prohibits tracking, behavioural monitoring, or targeted advertising directed at children, with no consent mechanism, parental or otherwise, that unlocks this.

Breach notification follows a real, two-stage process under Rule 7: an initial intimation to the Data Protection Board “without delay” on becoming aware of a breach, followed by a detailed report within 72 hours covering scope, cause, remedial steps, and a summary of notices sent to affected individuals, who must also be notified directly. There's no minimum-severity threshold; a breach affecting ten records triggers the same obligation as one affecting ten million.

Granular Purpose Specification: One Banner Isn't Enough

A single blanket “Accept All” banner that bundles essential site operations together with advertising and measurement, with no way to accept one and decline the other, is a real, specific compliance gap. Users must be given a genuine, granular choice across functional, analytical, and marketing purposes, not one all-or-nothing switch.

The Real Technical Fix: Consent-Gated Tag Management

Balancing DPDP compliance with genuine campaign measurement, in practice, comes down to three real, standard adjustments to how a marketing stack is set up.

First, consent-gated tag management: configuring Google Tag Manager, or a dedicated Consent Management Platform, to physically block the GA4 base tag, the Meta Pixel, Google Ads remarketing tags, and any third-party webhooks until an explicit consent event has actually been logged, not just displayed.

Second, Google Consent Mode v2, a real, four-parameter framework: ad_storage, ad_user_data, and ad_personalization for advertising, and analytics_storage for analytics. Each parameter defaults to denied before a user interacts with the consent banner, and updates to granted only once they've made an affirmative choice. It's worth being precise here: Google currently mandates Consent Mode v2 for advertisers specifically targeting the EEA and UK, not India. Using it for DPDP compliance is a sound, real technical adaptation of an existing framework, not a requirement Google itself has issued for the Indian market. When a user declines, Consent Mode v2 still allows Google's systems to model aggregate behaviour from anonymised signals, real, if imperfect, measurement continuity, rather than a total data blackout.

Third, server-side measurement: routing core conversion tracking, Meta's Conversions API, GA4 via server-side Google Tag Manager, through a server-side pipeline that only fires events after consent has been verified, rather than relying on a browser-side script that can fire before a user has made any choice.

What Each Measurement Strategy Actually Costs You

StrategyAccuracy vs. Actual TrafficRemarketing CapabilityDPDP Risk
Standard client-side GA4 / Pixels (unconsented, firing on load)40%–60% (consent drop-off)Full, but only for consented usersNon-compliant as commonly implemented
GA4 + Consent Mode v2 modelling80%–90% (modelled output)Full for opted-in users; modelled for opted-outCompliant
Cookieless analytics (e.g. Plausible, Matomo)95%+ (aggregate, actual)NoneCompliant
Server logs / first-party telemetry100% (includes bot traffic)NoneCompliant

“Accuracy vs. actual traffic” describes how closely each approach's reported numbers track genuine, real visitor activity. Every non-compliant row trades real legal risk for a completeness of data that a fully consent-gated setup structurally cannot match without also gaining full remarketing capability back.

The Real Trade-Off Marketers Are Actually Facing

There's a genuine, honest trade-off buried in that table, not a single “correct” answer. Fully compliant, consent-gated GA4 with Consent Mode v2 keeps real remarketing capability alive for users who opt in, and real, modelled visibility into the users who don't, at a real cost: a meaningful share of traffic will decline consent, and that share won't build a remarketing audience or show up as a fully deterministic conversion. Cookieless and server-log approaches solve compliance cleanly, at the real cost of losing remarketing entirely.

The decision isn't whether to comply, that part isn't optional. It's how much of the old, unconsented tracking volume a brand is willing to lose in exchange for staying inside the law, and how much of that loss can genuinely be recovered through Consent Mode v2's modelling rather than treated as pure, permanent measurement loss.

Want the actual setup steps? We've published a real, step-by-step guide to implementing Consent Mode v2 through Google Tag Manager, including a direct answer to whether this can genuinely be implemented in India and what actually happens to Meta and Google remarketing when a user declines consent. Read the implementation guide.

References

  • Digital Personal Data Protection Act, 2023, and the DPDP Rules, 2025 (notified by MeitY, November 2025).
  • Data Protection Board of India, operational since November 2025.
  • MeitY, Business Requirements Document for Consent Management Systems (BRDCMS), 2025.
  • Google, Consent Mode: Frequently Asked Questions, and Consent Mode v2 technical documentation.

Need help navigating the marketing impact of the DPDP Act? Reach out to us for a no-obligation chat, or explore our Brand & Digital Strategy practice.

Let's talk about what this could look like for your brand

Start a Project