Sector aggregates measured from what organisations’ public web presence actually shows. Every statistic below carries all three states — present, absent, and could not assess — and every sector states how much of its register was actually assessed.
METHODOLOGY v1 · SNAPSHOT 16 August 2026 · STATUS PUBLISHED
That is 8.3% of this sector's register. 16 of 18 checks cleared the publication floor this quarter; 1 did not reach the minimum panel, and 1 is withheld because the instrument for it does not measure what the check is named. Each says which, and why, in place of a number.
web.consent-mechanism
This checks whether a consent banner or similar mechanism appears before analytics, advertising or other tracking tools start collecting data — versus those tools just running silently on page load.
DPDP requires consent to be obtained before personal data is collected for a given purpose, not retroactively.
web.consent-withdrawal
This checks whether there's a lasting way for a visitor to come back later and turn off tracking or update their preferences — not just a one-time banner they can never see again.
641 did not apply and are excluded from the denominator.
DPDP requires withdrawing consent to be as easy as giving it — a banner that only ever appears once fails that on its face.
web.cookie-policy
Cookies and similar trackers quietly collect information about how visitors use your site (often for analytics or advertising). This checks whether you publish a page explaining what's used and why, when trackers are present.
378 did not apply and are excluded from the denominator.
If a tracker collects data that can identify a person (even indirectly), DPDP's notice-and-consent duties apply to it.
web.dpo-contact
Similar to the grievance contact, this checks for a published contact person or role responsible for data protection at your company.
INSUFFICIENT PANEL THIS QUARTER
22 organisations were assessed for this check — below the minimum panel this series publishes a percentage from. No rate is shown, because a rate from this few would not mean anything.
688 did not apply and are excluded from the denominator.
Businesses DPDP classifies as "Significant" must appoint a Data Protection Officer based in India — smaller businesses should still name someone accountable.
web.form-notice-proximity
When a visitor fills out a form on your site (contact, signup, checkout), this checks whether there's a nearby note or link explaining what that data will be used for.
REPORTED AS A BOUND · 326 ASSESSED
present bounded (complementary); indeterminate<3. Exact counts are withheld here: at this size a precise figure could identify the organisations behind it.
384 did not apply and are excluded from the denominator.
DPDP requires notice to accompany the request for consent — a form with no context nearby doesn't meet that.
web.google-consent-mode
Some tools (like Google's tag manager) support a setting where trackers stay quiet by default and only activate once someone has actually agreed. This checks whether that default-off behaviour is switched on.
385 did not apply and are excluded from the denominator.
Ties directly to DPDP's requirement that processing only begin once valid consent has actually been given.
web.gpc-declaration
Some browsers let a visitor set a single preference that says "don't sell or share my data," which sites can read automatically. This checks whether your site recognises and publishes support for that signal.
385 did not apply and are excluded from the denominator.
web.grievance-contact
This checks whether your site publishes a named contact (a "grievance officer" or equivalent) that a visitor can write to about how their data is handled.
DPDP s.13 requires a named Grievance Officer who must respond to complaints within a defined period.
web.header.csp
This is a server setting (CSP) that restricts which scripts and resources a page is allowed to load, so if an attacker manages to inject malicious code, its damage is limited.
web.header.hsts
This is a small instruction (HSTS) your server can send telling browsers "always use the encrypted connection for this site, never fall back to unencrypted." Without it, there's a brief window where a visitor's first connection could be downgraded.
A technical detail under the same DPDP security-safeguards duty as encryption itself.
web.header.referrer-policy
When someone clicks a link from your site to another, browsers can pass along the exact web address they came from — which, if that address contains a search term, an order ID, or a token, hands that information to the destination site.
web.header.xcto
This setting (X-Content-Type-Options) stops a browser from guessing a file's type in a way that could turn an ordinary file (like an uploaded image) into something that runs as code.
web.header.xfo
This setting (X-Frame-Options) stops other sites from loading your pages inside an invisible frame to trick visitors into clicking something they didn't mean to ("clickjacking") — for example, a hidden "submit payment" button under what looks like a game.
web.https
When someone visits your site, an encrypted connection (the padlock/HTTPS you see in a browser) scrambles everything sent between their browser and your server, so nobody else on the network can read it.
DPDP requires "reasonable security safeguards" for personal data — encrypting the connection is the baseline, not the ceiling.
web.language-option
This checks whether your privacy notice or consent banner offers at least one Indian language alongside English.
DPDP allows notices in English or any language listed in the Constitution's Eighth Schedule (Hindi, Tamil, Bengali, and others).
web.privacy-policy-content
Having a privacy policy page isn't the same as it covering the right things. This checks the actual text for the core items a real notice should include — who you are, what you collect, why, how long you keep it, who you share it with, and how someone can complain or withdraw consent.
EXCLUDED FROM THIS EDITION · 427 ASSESSED
Excluded from this edition because the instrument does not measure what this check is named. A notice scores as present only if it mentions all fourteen disclosure elements we test, and two of those fourteen are GDPR-specific — the lawful basis for processing, and automated decision-making or profiling. The DPDP Act has no equivalent of either, so an Indian organisation can publish a complete and compliant notice and still register as absent here. Publishing the resulting rate would say something about our instrument, not about the sector. The check returns in a future edition once each disclosure element is scored and published on its own.
283 did not apply and are excluded from the denominator.
DPDP sets out specific items a notice must cover — purpose, retention, sharing, rights, and how to complain or withdraw consent.
web.privacy-policy-link
A privacy policy is the page that tells visitors what personal data you collect and why. This checks whether a working link to one exists — usually in the footer.
DPDP requires this notice to be given in clear, plain language before or when data is collected.
web.tls-chain
The padlock relies on a security certificate being installed completely. If part of it is missing, some visitors' browsers or apps (often older phones) may show a warning or refuse to connect, even though the site looks fine on a modern browser.
Falls under the same DPDP reasonable-security-safeguards duty as the padlock check.
This is an outside-in scan of a homepage and the standard compliance pages. DPDP compliance runs far deeper than any such scan can see — consent records, retention, breach process. Nothing here says any organisation is compliant or non-compliant, and this series carries no statutory recognition.
A site that blocked the scanner, or that we could not reach, is published as exactly that. It degrades our own coverage figure rather than quietly inflating anyone’s failure rate.
Below the publication floor we print “insufficient panel”, never a number. Where an outcome is held by very few organisations, a bound replaces the exact figure — and the complementary figure is withheld too, so the exact count cannot be recovered by subtraction.
web.ccpa-optout-link — a US opt-out signal, not a DPDP obligation — measured, kept in the downloadable table, not presented as an India normThe complete aggregate table is downloadable — every sector, every check, the three-state counts, the register size, and a flag on each cell we withheld and why. Check the arithmetic.
Download CSV ↓Download JSON ↓Read the methodology → — the panel, the instrument, the publication rules, the coverage chain, and what this method cannot see.
Organisations may ask to be permanently excluded from the panel — honoured forever, no questions, at hello@consentree.in.